Outdated Systems at Processor Cause 2.5M-Person Greek Data Breach
The breach affecting approximately 2.5 million individuals stemmed from outdated information systems and inadequate security controls at the data processor's end, highlighting the critical importance of maintaining up-to-date infrastructure regardless of organizational type. The HDPA's decision to fine both the controller (Ministry of Social Cohesion and Family) and the processor underscores that GDPR accountability flows through the entire data processing chain. Public-sector organizations cannot rely on resource constraints or public interest mandates as defenses against GDPR security obligations. This case demonstrates that failure to enforce security standards on third-party processors carries significant financial and reputational consequences for the data controller as well.
Tactical Insight
Immediate actions
- Conduct an emergency audit of all processor-held systems to identify outdated software, operating systems, or infrastructure components.
- Invoke contractual rights under data processing agreements to demand evidence of patching and remediation from processors.
- Notify the relevant supervisory authority if a reportable breach has not already been disclosed within the 72-hour GDPR window.
Long-term improvements
- Embed mandatory security baseline requirements (including patch currency standards) into all Data Processing Agreements (DPAs) with third-party vendors.
- Establish a formal Vendor Risk Management programme that includes periodic security assessments and audit rights for all processors handling personal data at scale.
- Implement a technology refresh lifecycle policy that prevents critical systems from operating beyond a defined end-of-support threshold.
Detection & compliance measures
- Deploy continuous vulnerability scanning across all environments, including processor-managed systems where contractually permitted, to detect unpatched components early.
- Require processors to provide regular compliance evidence (e.g., penetration test results, patch status reports) mapped to GDPR Article 28 obligations.
- Establish a Data Protection Impact Assessment (DPIA) trigger for any processing activity involving over 100,000 individuals to proactively identify and mitigate systemic risks.