Greece Greece

Athens Urban Transport Organization

50,000 €

GDPR enforcement action by Hellenic Data Protection Authority (HDPA) on 2023-09-25.

Rank · Sector
#79
of 168 in Transportation and Energy
Rank · Greece
#18
of 93
Rank · All fines
#734
of 3,051

Case details

Authority
Hellenic Data Protection Authority (HDPA)
Date
2023-09-25
Controller / Processor
Athens Urban Transport Organization
Sector
Transportation and Energy
Quoted Articles
Art. 5 (1) e) GDPR, Art. 25 (1) GDPR, Art. 35 (1) GDPR
Type of violation
Non-compliance with general data processing principles

Summary

The Hellenic DPA imposed a fine of EUR 50,000 on the Athens Urban Transport Organization. As part of its investigation, the DPA found that the controller had failed to comply with the principle of data protection by design and by default. It also failed to carry out a data protection impact assessment and to set appropriate retention periods for the storage of personal data.

Open original source Links to the regulator's original publication or another source.

Related fines