Skip to content

Swiss Chinese Law Association — Geneva

SCLA | Swiss Chinese Law Association

Legal Observatory / AI and Data

Legal Update European Union Rules in force

Hellenic DPA Fines Greek Ministry and Data Processor EUR 350,000 Following Major Data Breach

The Hellenic DPA fined the Greek Ministry of Social Cohesion and Family Affairs EUR 200,000 and its processor E.E.T.A.A. S.A. EUR 150,000 over a major data breach involving outdated systems.

What Changed

  • Hellenic DPA imposed administrative fines totaling EUR 350,000 on the Ministry of Social Cohesion and Family Affairs and processor E.E.T.A.A. S.A.
  • The authority cited violations of Articles 25, 28, and 32 GDPR due to outdated IT systems and deficient controller-processor governance.
  • Compliance orders were issued forcing the execution of a compliant Article 28 data processing agreement and immediate system security upgrades.

Public sector controllers and third-party IT service providers operating across the European Union face heightened regulatory scrutiny regarding technical security and processor oversight under the General Data Protection Regulation (GDPR).

The Hellenic Data Protection Authority (DPA) issued a final decision on 28 July 2026 concerning a large-scale personal data breach affecting the information systems of the Hellenic Agency for Local Development and Local Government (E.E.T.A.A.) S.A., which processed data on behalf of the Ministry of Social Cohesion and Family Affairs. The breach compromised databases containing sensitive personal information, including identification details, contact information, financial records, and health data of a large number of data subjects.

Following its investigation, the Hellenic DPA established that the Ministry, acting as controller, complied with its statutory breach obligations under Article 33 (notifying the supervisory authority) and Article 34 (communicating the breach to affected data subjects). However, the authority found that the attack succeeded because E.E.T.A.A. continued using outdated information systems and inadequate security controls despite knowing the associated risks. This constituted non-compliance with Article 25 (data protection by design and by default) and Article 32 (security of processing). The DPA also identified systemic compliance deficiencies under Article 28, which regulates controller-processor contractual arrangements.

Consequently, the Hellenic DPA imposed administrative fines of EUR 200,000 on the Ministry of Social Cohesion and Family Affairs and EUR 150,000 on E.E.T.A.A. S.A. Additionally, the authority ordered both parties to execute a formal data processing agreement compliant with Article 28 GDPR and to fully implement planned technical measures to reinforce system security.

Who May Be Affected

Public sector data controllers, IT service processors, and data subjects in Greece whose identification, contact, financial, and health data were compromised.

Cross-Border Context

Applies EU GDPR standards regarding joint responsibilities of controllers and third-party processors across European Member States.

What to check next

  • Review the full decision text issued by the Hellenic Data Protection Authority (EL).
  • Monitor supervisory follow-up regarding the implementation of required technical measures and Article 28 agreements.

This article provides general information and does not constitute legal advice. Consult the official text and obtain advice appropriate to your circumstances where needed.

Keep the issues that matter to you in view

Subscribe to SCLA updates and choose your interests.