Hellenic DPA fines Ministry and EETAA for data breach
The enforcement action highlights the liability of both controllers and processors for inadequate security and non‑compliant processing agreements under the GDPR.
ADTP Regulatory Watch· October 8, 2026· Hellenic Data Protection Authority
ImpactHigh 62
Type⚖️ Dpa Action
Statusdecidedcase outcome
JurisdictionEU-GR
What happened
The Hellenic Data Protection Authority issued a final decision on 28/07/2026 imposing administrative fines of EUR 200,000 on the Ministry of Social Cohesion and Family Affairs and EUR 150,000 on E.E.T.A.A. S.A. for security deficiencies. The DPA also ordered both parties to conclude a GDPR‑compliant data processing agreement and to fully implement security upgrades.
Penalty
The Hellenic DPA imposed administrative fines of EUR 200 000 on the Ministry of Social Cohesion and Family Affairs and EUR 150 000 on E.E.T.A.A.
Why it matters for trust and compliance
Its status is decided. The case has an outcome that others may cite.
The enforcement action highlights the liability of both controllers and processors for inadequate security and non‑compliant processing agreements under the GDPR.
Penalty: The Hellenic DPA imposed administrative fines of EUR 200 000 on the Ministry of Social Cohesion and Family Affairs and EUR 150 000 on E.E.T.A.A..
It relates to GDPR. The regulations library explains what that law requires.
Who is affected
governmentcontrollerprocessorMinistry of Social Cohesion and Family AffairsE.E.T.A.A. S.A.
Recommended actions
Check that privacy notices describe the practices this addresses.
Map the security requirements to existing controls and close gaps.
Check breach-notification procedures and timelines against the requirement.
Confirm handling of sensitive data categories meets the stricter rules.