PRELUDE GROUP E.E.
GDPR enforcement action by Hellenic Data Protection Authority (HDPA) on 2026-06-02.
Case details
- Authority
- Hellenic Data Protection Authority (HDPA)
- Date
- 2026-06-02
- Controller / Processor
- PRELUDE GROUP E.E.
- Sector
- Industry and Commerce
- Quoted Articles
- Art. 28 GDPR, Art. 29 GDPR, Art. 32 GDPR
- Type of violation
- Insufficient technical and organisational measures to ensure information security
Summary
The Greek DPA has imposed a fine of EUR 80,000 on PRELUDE GROUP E.E. The controller is a Greek electricity supplier. For marketing purposes, the controller hired four call centres to act as processors, one of which was PRELUDE GROUP. The authority found that the controller and processors had failed to implement measures to ensure the security of processing personal data in all four cases. Consequently, customers received unsolicited calls from the processors. Specifically, PRELUDE GROUP had contracted an undisclosed sub-processor without the controller's authorisation, thereby processing the data subject's personal data without a sufficient legal basis. Furthermore, it relied on outdated file exchanges for its opt-out list. The controller aswell as the other processors were fined by the authority.