Piraeus Bank S.A.
GDPR enforcement action by Hellenic Data Protection Authority (HDPA) on 2026-06-05.
Case details
- Authority
- Hellenic Data Protection Authority (HDPA)
- Date
- 2026-06-05
- Controller / Processor
- Piraeus Bank S.A.
- Sector
- Finance, Insurance and Consulting
- Quoted Articles
- Art. 15 GDPR
- Type of violation
- Insufficient fulfilment of data subjects rights
Summary
The Greek DPA has imposed a fine of EUR 10,000 on Piraeus Bank S.A. In a complaint logged in 2023, a data subject stated that they had entered into a contract with a sales partner of the data controller acting as processor in May 2020. The contract covered three supply mandates. The data subject opted to pay for one of these via direct debit, providing their IBAN for this purpose and signing only one mandate. However, Zenith then debited payment for all three mandates via direct debit from a joint account at Piraeus Bank. When the data subject requested information on how the direct debit mandates had been set up, the bank replied that it only acted as an intermediary for the payments and did not supply any information. The authority found that, for SEPA payments, the bank is not an intermediary, but a controller; therefore, it is obligated to provide data subjects with all requested information. Furthermore, the authority stated that, once the data subject had informed the bank about the fraudulent SEPA mandate, the bank was obliged to investigate with the debtor, Zenith. The controller was also fined by the authority (ETid ).