Greece Greece

Ypiresia 800 Teleperformance Single Member S.A.

90,000 €

GDPR enforcement action by Hellenic Data Protection Authority (HDPA) on 2026-06-02.

Rank · Sector
#84
of 619 in Industry and Commerce
Rank · Greece
#18
of 102
Rank · All fines
#538
of 3,152

Case details

Authority
Hellenic Data Protection Authority (HDPA)
Date
2026-06-02
Controller / Processor
Ypiresia 800 Teleperformance Single Member S.A.
Sector
Industry and Commerce
Quoted Articles
Art. 5 (1) a), b), d), e) GDPR, Art. 32 GDPR
Type of violation
Insufficient technical and organisational measures to ensure information security

Summary

The Greek DPA has imposed a fine of EUR 90,000 on Ypiresia 800 Teleperformance Single Member S.A. The controller is a Greek electricity supplier. For marketing purposes, the controller hired four call centres to act as processors, one of which was Ypiresia. The authority found that the controller and processors had failed to implement measures to ensure the security of processing personal data in all four cases. Consequently, customers received unsolicited calls from the processors. Specifically, Ypiresia, acting as a processor, made an encoding error when checking its non-call list against the controller's opt-out register. This resulted in two calls being made to data subjects who had specifically opted out. Both the controller and the processor stated that such an error had not occurred since 2019, but the two complaints were logged in 2021. The controller aswell as the other processors were fined by the authority.

Open original source Links to the regulator's original publication or another source.

Related fines