Hellenic DPA decision on a data breach involving E.E.T.A.A. S.A. as processor for the Ministry of Social Cohesion and Family Affairs

  • National News
  • gr

Background information

  • Date of final decision: 28/07/2026
  • National case
  • Controller: Ministry of Social Cohesion and Family Affairs
  • Legal Reference(s): Article 25 (Data protection by design and by default), Article 28 (Processor), Article 32 (Security of processing), Article 33 (Notification of a personal data breach to the supervisory authority) and Article 34 (Communication of a personal data breach to the data subject)
  • Decision: Administrative fine, Compliance order, 

Summary of the Decision

Origin of the case  

The Hellenic Data Protection Authority (DPA) investigated a large-scale personal data breach affecting the information systems of the Hellenic Agency for Local Development and Local Government (E.E.T.A.A.) S.A., which were used to implement programmes of the Ministry of Social Cohesion and Family Affairs.

Key Findings

The breach affected databases containing personal data of a large number of data subjects, including identification and contact details, financial and health data. The Hellenic DPA found that the Ministry of Social Cohesion and Family Affairs, in its capacity as controller, had complied with its obligations concerning the notification of the breach to the Authority and its communication to the affected data subjects. However, the Authority found that the success of the attack was associated with E.E.T.A.A.’s continued use of outdated information systems and inadequate security measures, despite its awareness of the relevant risks. The DPA found infringements of the requirements relating to the security of processing, as well as deficiencies in compliance with the requirements of Article 28 GDPR governing the relationship between the controller and the processor.

Decision

The Hellenic DPA imposed administrative fines of EUR 200 000 on the Ministry of Social Cohesion and Family Affairs and EUR 150 000 on E.E.T.A.A. It also ordered the parties (i.e. the Ministry and E.E.T.A.A.) to enter into a data processing agreement pursuant to Article 28 GDPR and to fully implement the planned measures to strengthen the security of their information systems.

For further information: 

Relevant topics
Fines
Data subject rights

Latest news

  • National News

Dutch DPA fines Uber EUR 824 990 000 for unlawful automated decision-making and insufficient information on profiling

  • National News
  • se

Swedish DPA fines Miljödata i Karlskrona approximately EUR 160 000 for insufficient technical and organisational measures to ensure information security

  • National News

The Irish Data Protection Commission fines Google EUR 403 000 000 following Inquiry into Google’s processing of location data