Public Power Corporation S.A. (DEI)
GDPR enforcement action by Hellenic Data Protection Authority (HDPA) on 2026-06-02.
Case details
- Authority
- Hellenic Data Protection Authority (HDPA)
- Date
- 2026-06-02
- Controller / Processor
- Public Power Corporation S.A. (DEI)
- Sector
- Transportation and Energy
- Quoted Articles
- Art. 5 (1) a), b), d), e) GDPR, Art. 32 GDPR
- Type of violation
- Insufficient legal basis for data processing
Summary
The Greek DPA has imposed a fine of EUR 320,000 on Public Power Corporation S.A. (DEI). The controller is a Greek electricity supplier. The controller hired four call centres for marketing purposes; these centres acted as processors for the controller. The authority found that, in all four cases, the controller had failed to implement measures to ensure the security of processing personal data. Consequently, customers received unsolicited calls from the processors. The authority found that DEI had failed to implement an automated, unified opt-out register and had relied on manual supervision without an auditable trail. Furthermore, the processor contracts were inadequate in that they did not document periodic audits or approve sub-processors, and encryption was only implemented when required. The authority also fined all the processors.