Greece Greece

General Hospital of Thessaloniki

25,000 €

GDPR enforcement action by Hellenic Data Protection Authority (HDPA) on 2026-07-07.

Rank · Sector
#97
of 286 in Health Care
Rank · Greece
#41
of 105
Rank · All fines
#1,025
of 3,170

Case details

Authority
Hellenic Data Protection Authority (HDPA)
Date
2026-07-07
Controller / Processor
General Hospital of Thessaloniki
Sector
Health Care
Quoted Articles
Art. 5 (1) f) GDPR, Art. 12 GDPR, Art. 13 GDPR, Art. 32 (1) GDPR, Art. 33 (1) GDPR, Art. 34 (1) GDPR, Art. 37 GDPR
Type of violation
Insufficient technical and organisational measures to ensure information security

Summary

The Greek DPA has imposed a fine of EUR 25,000 on the General Hospital of Thessaloniki. A list of the hospital's weekly surgery patients was published on the controller's website. Although the controller's employees had pseudonymised the names by hand, the list for one week in May 2024 remained unredacted, making the phone numbers of patients, and in some cases their companions, accessible. The relevant document contained information on 2,820 patients, including details of their condition and planned surgery. Although the link was replaced within a week, the file remained on the server and was indexed by Google. This meant that, via reverse phone number search services, the data subjects could be identified. The controller did not inform the data subjects about the incident, nor did they include contact information for their DPO on their website.

Open original source Links to the regulator's original publication or another source.

Related fines