Background information Date of final decision: 28 February 2024 National case Legal Reference (s): Article 5(1)(f)(Principle of integrity and confidentiality), Article 32 (Security of processing) Controller: HELLENIC POST SERVICES S.A. Decision: Infringement of the GDPR, administrative fine Key words: non-compliance with technical and organisational measures, network vulnerabilities, unauthorised access, dark web, data breach, data breach notification, network intrusion, ransomware, security policy implementation, remote desktop, incident investigation, security review, privileged access