Greece Greece

CQS S.A. Customer-Centric Services

20,000 €

GDPR enforcement action by Hellenic Data Protection Authority (HDPA) on 2026-06-02.

Rank · Sector
#182
of 619 in Industry and Commerce
Rank · Greece
#50
of 102
Rank · All fines
#1,152
of 3,152

Case details

Authority
Hellenic Data Protection Authority (HDPA)
Date
2026-06-02
Controller / Processor
CQS S.A. Customer-Centric Services
Sector
Industry and Commerce
Quoted Articles
Art. 32 GDPR
Type of violation
Insufficient technical and organisational measures to ensure information security

Summary

The Greek DPA has imposed a fine of EUR 20,000 on CQS S.A. Customer-Centric Services. The controller is a Greek electricity supplier. For marketing purposes, the controller hired four call centres, which acted as processors; CQS was one of these processors. The authority found that the controller and processors had failed to implement measures to ensure the security of processing personal data in all four cases. Consequently, customers received unsolicited calls from the processors. Specifically, CQS had relied on manual exclusion of the phone numbers of data subjects who had opted-out of the processing activities. These events took place between 2021 and 2024, the controller aswell as all other processors were fined by the authority.

Open original source Links to the regulator's original publication or another source.

Related fines