REGULATORY WATCH BRIEF High 62 ⚖️ Dpa Action decided

Hellenic DPA fines Ministry and EETAA for data breach

The enforcement action highlights the liability of both controllers and processors for inadequate security and non‑compliant processing agreements under the GDPR.

ImpactHigh 62
Type⚖️ Dpa Action
Statusdecided case outcome
JurisdictionEU-GR

What happened

The Hellenic Data Protection Authority issued a final decision on 28/07/2026 imposing administrative fines of EUR 200,000 on the Ministry of Social Cohesion and Family Affairs and EUR 150,000 on E.E.T.A.A. S.A. for security deficiencies. The DPA also ordered both parties to conclude a GDPR‑compliant data processing agreement and to fully implement security upgrades.

Penalty

The Hellenic DPA imposed administrative fines of EUR 200 000 on the Ministry of Social Cohesion and Family Affairs and EUR 150 000 on E.E.T.A.A.

Why it matters for trust and compliance

  • Its status is decided. The case has an outcome that others may cite.
  • The enforcement action highlights the liability of both controllers and processors for inadequate security and non‑compliant processing agreements under the GDPR.
  • Penalty: The Hellenic DPA imposed administrative fines of EUR 200 000 on the Ministry of Social Cohesion and Family Affairs and EUR 150 000 on E.E.T.A.A..
  • It relates to GDPR. The regulations library explains what that law requires.

Who is affected

government controller processor Ministry of Social Cohesion and Family Affairs E.E.T.A.A. S.A.

Recommended actions

  1. Check that privacy notices describe the practices this addresses.
  2. Map the security requirements to existing controls and close gaps.
  3. Check breach-notification procedures and timelines against the requirement.
  4. Confirm handling of sensitive data categories meets the stricter rules.