Greek SA Imposes Administrative Fines on a Telecommunications Company and a Data Processor for Personal Data Breach and Insufficient Security Measures

Kişisel Verilerin Korunması Hukuku

The Greek Supervisory Authority (“Greek SA”), by its decision of 25 June 2025, has imposed administrative fines on a telecommunications company and a data processor on the grounds of unlawful processing of personal data and inadequate implementation of security measures.

According to the examination, the following matters have been determined in summary:

  • In a store operated by the distributor of the company, 15 prepaid mobile connections were activated without the complainant’s knowledge or consent. The complainant became aware of this situation only when she was summoned by the judicial authorities in relation to criminal offences allegedly committed through these connections.
  • The data processor claimed that the intention had been to register the connections under the identity of a group tour leader; however, due to the inadvertent use of a copy of the complainant’s identity card stored in the system, the connections were registered in the complainant’s name.
  • As a result of the audit carried out by the Authority, it was established that the data processor acted in contravention of the instructions of the data controller, failed to comply with the subscriber identification procedure, and violated its security obligations.
  • With regard to the data controller, it was determined that appropriate technical and organisational measures had not been implemented, that due diligence had not been exercised in the selection and supervision of data processors, that the principle of data accuracy had been infringed, and that incorrect information had been provided to the competent public authorities.

Within this scope:

  • An administrative fine of EUR 40,000 was imposed on the data processor for violation of security obligations under Articles 32 and 29 of the GDPR.
  • With respect to the data controller, an administrative fine of EUR 350,000 was imposed for infringements of obligations under Articles 28(1)–(3) of the GDPR, an administrative fine of EUR 150,000 was imposed for violations of Articles 12(1) and 12(3) of Law 3471/2006 (the national law incorporating the ePrivacy Directive), and an administrative fine of EUR 200,000 was imposed for infringement of the principle of data accuracy pursuant to Article 5(1)(d) of the GDPR.

You can access the full text of the decision here.

 

Kind regards,

Zumbul Attorneys-at-Law

info@zumbul.av.tr

All information and documents on our website have been prepared by Zumbul Attorneys at Law for general informational purposes only, in accordance with the Attorneyship Law, other relevant legislation and the Professional Rules of Attorneyship of the Union of Turkish Bar Associations. These publications are not intended for advertising or commercial purposes. The information and documents provided are of a general nature and under no circumstances, do they guarantee or warrant that the content is complete, accurate, up-to-date, or reliable. You should not rely on the information and documents on this website without first consulting a lawyer or expert. The links included in our website’s publications are sourced from publicly available materials and are provided solely for the convenience of visitors in accessing additional information. These links do not constitute any form of recommendation or endorsement of the linked persons, institutions or organizations. The information on this website does not in any way constitute legal advice or establish an attorney-client relationship with visitors to the site. All content on this website is the property of by Zumbul Attorneys at Law, and no content may be copied, reproduced, or used without prior written permission.