HDPA (Greece) · 5 June 2026
ZENITH SA (ΖΕΝΙΘ ΑΕ) · PIRAEUS BANK (ΤΡΑΠΕΖΑ ΠΕΙΡΑΙΩΣ)
The source names these parties without saying which one the decision is about. I’m checking it.
About: Data principles, Data subject rights, Processor obligations, Transparency
- Regulator
- HDPA (Greece)
- Decided
- 5 June 2026
- Country
- Greece
- Sector
- Not given
- Regulator’s reference
- 8/2026
- Fino case number
- 2026/GR/010
What happened
The DPA fined an energy provider €100,000 and a bank €10,000 over a customer’s disputed direct debit mandates. Both controllers failed to properly respond to his access requests and breached the accuracy principle, while the energy provider also failed to control its processor.
Summary from GDPRhub (noyb), written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 5Principles relating to processing of personal data5(1)(d)Read →
- Art. 12Transparent information, communication and modalities for the exercise of the rights of the data subject12(1) · 12(3)Read →
- Art. 15Right of access by the data subject15(1)Read →
- Art. 28Processor28(1)Read →
- Data principles
- Data subject rights
- Processor obligations
- Transparency
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2026/GR/010.