BULLETIN №082Last updated · 02 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 24 May 2022 | Anonymised (HDPA 26/2022)A fine of EUR 2,000 was imposed for sending unsolicited political communication by SMS without the recipient's prior consent. The authority treated this as a breach of data protection and electronic communications rules. | GR | HDPA | ePrivacy | €2,000 | ↗ |
| 08 Mar 2017 | Elliniki Etaireia Systimikon MeletonThe company was fined by the HDPA for illegally collecting and using personal data for direct marketing purposes. The infringement involved unsolicited electronic communications sent without prior consent from the data subjects. | GR | HDPA | ePrivacy | €3,000 | ↗ |
| 01 Jan 2022 | CosmoteThe Greek data protection authority imposed a €6 million fine on Cosmote under decision 4/2022. The sanction concerned inadequate security measures and retaining more data than permitted after a 2020 cyberattack. | GR | Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα | GDPR | €6,000,000 | ↗ |
| 18 Dec 2013 | Anonymised (HDPA 154/2013)The HDPA imposed a fine of EUR 3,000 on the company for unlawfully collecting an individual's creditworthiness data. The case concerned processing without a valid legal basis, which breaches data protection rules. | GR | HDPA | GDPR | €3,000 | ↗ |
| 29 Apr 2022 | Fire Brigade HeadquartersFire Brigade Headquarters was fined EUR 5,000 by the HDPA. The authority found a failure to fulfill data protection officer duties required under national law. | GR | HDPA | GDPR | €5,000 | ↗ |
| 23 May 2022 | ANOIXISThe fine was imposed for sending unsolicited SMS messages for direct marketing without prior consent. The company also failed to provide a valid opt-out address, affecting data subjects’ rights of access and objection. | GR | HDPA | ePrivacy | €54,000 | ↗ |
| 10 Oct 2022 | EKO ABEEThe fine was imposed for a violation of Article 15 GDPR because the controller failed to provide the data subject with access to their personal data. The case concerns non-compliance with the obligation to ensure the right of access within the required scope. | GR | HDPA | GDPR | €10,000 | ↗ |
| 13 May 2015 | HellastatHellastat was fined EUR 3,000 by the HDPA for failing to inform data subjects. The authority found a breach of data protection rules requiring transparent notice to individuals. | GR | HDPA | GDPR | €3,000 | ↗ |
| 07 Oct 2019 | OTEOTE was fined by the HDPA EUR 200,000 for failing to process unsubscribe requests from marketing emails due to a technical error. The issue affected about 8,000 subscribers and had been ongoing since 2013. | GR | HDPA | GDPR | €200,000 | ↗ |
| 29 Dec 2017 | Anonymised (HDPA 151/2017)The controller of the blog dexiextrem.blogspot.gr was fined EUR 2,000 for failing to comply with the data subject’s right to object to the processing of personal data. The authority found a breach of Article 13 of Law 2472/1997 in connection with the publication of personal data. | GR | HDPA | GDPR | €2,000 | ↗ |
| 21 May 2025 | NN ΕλληνικήThe Greek Data Protection Authority imposed a €22,000 fine on NN Ελληνική for refusing to provide recorded telephone calls in response to a data subject access request. The case concerns failure to comply with access rights obligations under data protection law. | GR | Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα | GDPR | €22,000 | ↗ |
| 22 Oct 2024 | political partyThe Hellenic Data Protection Authority imposed a 10,000 EUR fine on a political party for unlawful processing of the personal data of overseas voters. The case concerns data protection breaches in the handling of electoral information. | GR | Hellenic Data Protection Authority | GDPR | €10,000 | ↗ |
| 29 May 2023 | NOVA TELECOMMUNICATIONS & MEDIA MONOPROSOPI A.E.The company was fined for repeatedly sending unsolicited electronic communications for marketing purposes despite the complainant’s objections. The authority also found failures to comply with requests for access, objection, and restriction of processing. | GR | HDPA | ePrivacy | €50,000 | ↗ |
| 29 Apr 2022 | Fire Brigade HeadquartersA fine was imposed for unlawful processing of personal data, which breached data protection principles and security obligations. The case concerned failures to ensure compliance with data protection requirements. | GR | HDPA | GDPR | €25,000 | ↗ |
| 11 Nov 2011 | Galineio Melathro Private ClinicThe clinic disclosed sensitive personal data without informing the data subject in advance. This breached the individual's right to object to the processing. | GR | HDPA | GDPR | €1,000 | ↗ |
| 19 May 2011 | Anonymised (HDPA 59/2011)The company was fined for unlawfully processing email addresses without prior consent. The authority found this to be a breach of data protection law. | GR | HDPA | GDPR | €2,000 | ↗ |
| 10 Aug 2015 | Anonymised (HDPA 95/2015)A fine was imposed on the residential complex “Lofos Edison” for installing additional surveillance cameras without authorization. The authority also noted that the installation was not properly notified to the competent authority. | GR | HDPA | GDPR | €1,000 | ↗ |
| 09 Aug 2013 | General Secretariat for Information SystemsThe General Secretariat for Information Systems was fined EUR 150,000 by the HDPA for failing to implement appropriate security measures. The breach led to unauthorized processing of Greek taxpayers’ personal tax data from 2000 to 2012. | GR | HDPA | GDPR | €150,000 | ↗ |
| 09 Aug 2012 | Iatriko AthinonThe fine was imposed for failing to implement appropriate organizational and technical measures to secure sensitive medical data. The case concerned insufficient protection of special-category personal data. | GR | HDPA | GDPR | €7,500 | ↗ |
| 18 Dec 2013 | Bank of CyprusBank of Cyprus was fined EUR 5,000 by the HDPA. The authority found illegal access to and disclosure of creditworthiness data from the Tiresias database. | GR | HDPA | GDPR | €5,000 | ↗ |