HDPA (Greece) · 30 November 2021
Cosmote
About: Accountability, DPIA, Data principles, Data security, Processor obligations, Transparency
- Regulator
- HDPA (Greece)
- Decided
- 30 November 2021
- Country
- Greece
- Sector
- Not given
- Regulator’s reference
- 4/2022
- Fino case number
- 2021/GR/034
What happened
The Greek DPA fined two mobile telecommunications company COSMOTE and its parent company OTE, €6,000,000 and €3,250,000 respectively. The first for failing to carry out the data protection impact assessment under Article 35(7) GDPR, for not complying with the principle of transparency under Article 5(1) GDPR and for not anonymising the data under Article 25(1) GDPR, among others. The second for failing to implement the appropriate technical and organisational measures under Article 32 GDPR.
Summary from GDPRhub (noyb), written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 5Principles relating to processing of personal data5(1)(a) · 5(1)(f) · 5(2)Read →
- Art. 13Information to be provided where personal data are collected from the data subjectRead →
- Art. 14Information to be provided where personal data have not been obtained from the data subjectRead →
- Art. 25Data protection by design and by default25(1)Read →
- Art. 26Joint controllersRead →
- Art. 28ProcessorRead →
- Art. 32Security of processingRead →
- Art. 35Data protection impact assessment35(7)Read →
- Art. 83General conditions for imposing administrative finesRead →
- Accountability
- DPIA
- Data principles
- Data security
- Processor obligations
- Transparency
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2021/GR/034.