Hellenic Data Protection Authority (HDPA) · 11 October 2023
Not named in the source
Non-compliance with general data processing principles
Fine€1,000Fine issued
- Regulator
- Hellenic Data Protection Authority (HDPA)
- Decided
- 11 October 2023
- Country
- Greece
- Sector
- Not given
- Regulator’s reference
- Not recorded
- Fino case number
- 2023/GR/005
What happened
DEYA X violated GDPR's data minimization principle Article 5(1)(c) by sharing an employee's personal and health data with multiple recipients without proper justification. The HDPA ordered DEYA X to create internal policies to ensure GDPR compliance. A fine of 1,000 euros was also imposed.
Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Data principles
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2023/GR/005.