Ypiresia 800 Teleperformance Single Member S.A.
GDPR enforcement action by Hellenic Data Protection Authority (HDPA) on 2026-06-02.
Case details
- Authority
- Hellenic Data Protection Authority (HDPA)
- Date
- 2026-06-02
- Controller / Processor
- Ypiresia 800 Teleperformance Single Member S.A.
- Sector
- Industry and Commerce
- Quoted Articles
- Art. 5 (1) a), b), d), e) GDPR, Art. 32 GDPR
- Type of violation
- Insufficient technical and organisational measures to ensure information security
Summary
The Greek DPA has imposed a fine of EUR 90,000 on Ypiresia 800 Teleperformance Single Member S.A. The controller is a Greek electricity supplier. For marketing purposes, the controller hired four call centres to act as processors, one of which was Ypiresia. The authority found that the controller and processors had failed to implement measures to ensure the security of processing personal data in all four cases. Consequently, customers received unsolicited calls from the processors. Specifically, Ypiresia, acting as a processor, made an encoding error when checking its non-call list against the controller's opt-out register. This resulted in two calls being made to data subjects who had specifically opted out. Both the controller and the processor stated that such an error had not occurred since 2019, but the two complaints were logged in 2021. The controller aswell as the other processors were fined by the authority.