Greece Greece

Hellenic Agency for Local Development and Local Government S.A. (EETAA)

150,000 €

GDPR enforcement action by Hellenic Data Protection Authority (HDPA) on 2026-07-28.

Rank · Sector
#39
of 385 in Public Sector and Education
Rank · Greece
#16
of 105
Rank · All fines
#437
of 3,170

Case details

Authority
Hellenic Data Protection Authority (HDPA)
Date
2026-07-28
Controller / Processor
Hellenic Agency for Local Development and Local Government S.A. (EETAA)
Sector
Public Sector and Education
Quoted Articles
Art. 28 (3) GDPR, Art. 32 (1) GDPR
Type of violation
Insufficient technical and organisational measures to ensure information security

Summary

The Greek DPA has imposed a fine of EUR 150,000 on the Hellenic Agency for Local Development and Local Government S.A. (EETAA). The entity that was fined ran the IT system for the Infant and Child Care Centres voucher programme and another family support pilot programme as a processor. The voucher programme began in the 2014/15 school year. From 1st to 5th March 2025, the IT system was subject to a two-stage ransomware attack. A malicious third party encrypted the on-premises database and left a note stating that data had possibly been exfiltrated from the database. The processor subsequently shut down the systems, making it impossible to investigate the attack vector in-house. A total of 700,000 applications concerning 2.5 million data subjects were affected, including children, parents, partners, legal representatives, and employees of care providers. Furthermore, approximately 700 data subjects were affected by the family support pilot programme. The encrypted and potentially exfiltrated data included names, dates of birth, tax and social security numbers, disability status and certificates, foster or guardianship information, income data, nationality and residence permits, contact details, attendance times and IBANs. This vulnerability was well-known and easily exploitable, so the risk was foreseeable. At the time of the attack, no processing agreement was in place. The processor could not prove that they had informed the ministry, acting as the data controller, of these circumstances. The Ministry of Social Cohesion and Family was also fined for the event.

Open original source Links to the regulator's original publication or another source.

Related fines