BULLETIN №082Last updated · 03 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 11 Jul 2025 | NN HellasNN Hellas was fined EUR 20,000 for failing to satisfy the complainant’s access request concerning recorded telephone conversations. The authority found a violation of Article 15 GDPR. | GR | HDPA | GDPR | €20,000 | ↗ |
| 26 May 2014 | General Hospital PapageorgiouGeneral Hospital Papageorgiou was fined EUR 1,000 by the HDPA for transferring sensitive health data without prior authorization. The hospital also failed to inform the data subject, breaching Greek data protection law. | GR | HDPA | GDPR | €1,000 | ↗ |
| 09 Oct 2018 | Vodafone-PanafonVodafone-Panafon was fined by the HDPA for making unsolicited marketing calls to subscribers who had opted out of such contact. The authority found that the conduct breached privacy and data protection rules. | GR | HDPA | ePrivacy | €12,000 | ↗ |
| 08 Jan 2015 | OTEThe Hellenic Data Protection Authority fined OTE EUR 60,000 for failing to implement adequate security measures. The deficiency led to a data breach involving personal data of a large number of subscribers. | GR | HDPA | ePrivacy | €60,000 | ↗ |
| 07 Jul 2015 | OLYMPION XENODOXEION AEThe company was fined by the HDPA EUR 5,000 for failing to implement appropriate organizational and technical security measures. The deficiency led to a data breach involving credit card information. | GR | HDPA | GDPR | €5,000 | ↗ |
| 07 Apr 2021 | Ignatiadis Nikolaos and SIA E.E.The company was fined for unlawfully using a surveillance camera to monitor employees. The authority found a breach of data protection principles and an absence of a valid legal basis for processing. | GR | HDPA | GDPR | €2,000 | ↗ |
| 08 Aug 2014 | PARAMOUNT A.E.The company was fined EUR 5,000 by the HDPA for processing publicly available personal data without consent. The authority found a breach of the principles of lawful data collection and proportionality. | GR | HDPA | GDPR | €5,000 | ↗ |
| 13 Jun 2025 | Anonymised (HDPA 21/2025)A fine of EUR 1,000 was imposed for violating the data subject’s right of access. The entity did not provide the requested video footage. | GR | HDPA | GDPR | €1,000 | ↗ |
| 11 Jul 2025 | MEDIADENTMEDIADENT was fined for failing to cooperate with the supervisory authority. The case concerned Article 31 GDPR, which requires controllers and processors to cooperate with the authority during its work. | GR | HDPA | GDPR | €2,000 | ↗ |
| 04 Aug 2017 | VodafoneThe HDPA imposed a €10,000 fine on Vodafone for unlawfully processing the complainant's credit card data without consent. The case concerns a breach of the legal basis requirements for personal data processing. | GR | HDPA | GDPR | €10,000 | ↗ |
| 21 Aug 2018 | Alpha BankAlpha Bank was fined by the HDPA for failing to maintain and process accurate data of its debtors. The authority found that the bank’s conduct breached data protection requirements. | GR | HDPA | GDPR | €10,000 | ↗ |
| 19 May 2011 | Anonymised (HDPA 59/2011)The company was fined for sending unsolicited electronic messages and faxes without subscriber consent. This conduct breached e-privacy rules governing direct electronic communications. | GR | HDPA | ePrivacy | €2,000 | ↗ |
| 07 Apr 2021 | MZN HELLAS A.E.The company was fined for sending unsolicited marketing SMS messages to a customer who had explicitly objected to such communications. The authority found this to be a breach of GDPR rules on data subject rights and data protection by design. | GR | HDPA | GDPR | €20,000 | ↗ |
| 08 Aug 2014 | Compass ExpoCompass Expo was fined EUR 10,000 by the HDPA for sending unsolicited electronic communications without recipients' consent. The authority found a breach of Article 11 of Law 3471/2006. | GR | HDPA | ePrivacy | €10,000 | ↗ |
| 05 Jul 2022 | Global Greece MEPEThe company was fined for sending unsolicited marketing emails without obtaining the recipients’ prior explicit consent. The authority found this conduct to be in breach of Article 11 of Law 3471/2006. | GR | HDPA | ePrivacy | €3,000 | ↗ |
| 20 Jun 2022 | Anonymised (HDPA 23/2022)A fine was imposed for failing to respond to a data access request within the required timeframe. The case concerns a breach of the controller’s obligations to facilitate data subject rights. | GR | HDPA | GDPR | €2,000 | ↗ |
| 30 May 2018 | Alpha BankAlpha Bank was fined by the HDPA for failing to respond to a data subject access request within the prescribed timeframe. The case concerned Article 12 of Law 2472/1997 and the bank’s obligations to facilitate data subject rights. | GR | HDPA | GDPR | €10,000 | ↗ |
| 20 Feb 2026 | VodafoneThe Greek Data Protection Authority fined Vodafone EUR 30,000 for GDPR breaches related to a subscriber’s request to access recorded phone conversations. The authority found violations of transparency obligations under Article 12 and of the rights of access and restriction of processing under Articles 15 and 18 GDPR. | GR | Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα | GDPR | €30,000 | ↗ |
| 21 Jul 2025 | VIVLIOPOLEION TIS ESTIAS, I.D. KOLLAROU & SIA A.E.The company was fined by the HDPA 4,000 EUR for failing to notify the data breach to the supervisory authority and the affected data subjects in a timely manner. The case indicates non-compliance with the statutory notification deadlines following a security incident. | GR | HDPA | GDPR | €4,000 | ↗ |
| 20 Nov 2006 | Anonymised (HDPA 61/2006)A hospital was fined for failing to properly inform the complainant about the transmission of sensitive health data. The case concerns a breach of the duty to provide clear information to the data subject. | GR | HDPA | GDPR | €3,000 | ↗ |