Greece Greece

Piraeus Bank S.A.

10,000 €

GDPR enforcement action by Hellenic Data Protection Authority (HDPA) on 2026-06-05.

Rank · Sector
#215
of 333 in Finance, Insurance and Consulting
Rank · Greece
#63
of 102
Rank · All fines
#1,508
of 3,152

Case details

Authority
Hellenic Data Protection Authority (HDPA)
Date
2026-06-05
Controller / Processor
Piraeus Bank S.A.
Sector
Finance, Insurance and Consulting
Quoted Articles
Art. 15 GDPR
Type of violation
Insufficient fulfilment of data subjects rights

Summary

The Greek DPA has imposed a fine of EUR 10,000 on Piraeus Bank S.A. In a complaint logged in 2023, a data subject stated that they had entered into a contract with a sales partner of the data controller acting as processor in May 2020. The contract covered three supply mandates. The data subject opted to pay for one of these via direct debit, providing their IBAN for this purpose and signing only one mandate. However, Zenith then debited payment for all three mandates via direct debit from a joint account at Piraeus Bank. When the data subject requested information on how the direct debit mandates had been set up, the bank replied that it only acted as an intermediary for the payments and did not supply any information. The authority found that, for SEPA payments, the bank is not an intermediary, but a controller; therefore, it is obligated to provide data subjects with all requested information. Furthermore, the authority stated that, once the data subject had informed the bank about the fraudulent SEPA mandate, the bank was obliged to investigate with the debtor, Zenith. The controller was also fined by the authority (ETid ).

Open original source Links to the regulator's original publication or another source.

Related fines