General Hospital of Thessaloniki
GDPR enforcement action by Hellenic Data Protection Authority (HDPA) on 2026-07-07.
Case details
- Authority
- Hellenic Data Protection Authority (HDPA)
- Date
- 2026-07-07
- Controller / Processor
- General Hospital of Thessaloniki
- Sector
- Health Care
- Quoted Articles
- Art. 5 (1) f) GDPR, Art. 12 GDPR, Art. 13 GDPR, Art. 32 (1) GDPR, Art. 33 (1) GDPR, Art. 34 (1) GDPR, Art. 37 GDPR
- Type of violation
- Insufficient technical and organisational measures to ensure information security
Summary
The Greek DPA has imposed a fine of EUR 25,000 on the General Hospital of Thessaloniki. A list of the hospital's weekly surgery patients was published on the controller's website. Although the controller's employees had pseudonymised the names by hand, the list for one week in May 2024 remained unredacted, making the phone numbers of patients, and in some cases their companions, accessible. The relevant document contained information on 2,820 patients, including details of their condition and planned surgery. Although the link was replaced within a week, the file remained on the server and was indexed by Google. This meant that, via reverse phone number search services, the data subjects could be identified. The controller did not inform the data subjects about the incident, nor did they include contact information for their DPO on their website.