BULLETIN №082Last updated · 03 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 13 Jun 2025 | Anonymised (HDPA 21/2025)A fine was imposed for breaching the principles of lawfulness, fairness, and transparency in data processing in connection with a video surveillance system. The case concerned improper processing of personal data through video monitoring. | GR | HDPA | GDPR | €2,000 | ↗ |
| 20 Nov 2006 | Anonymised (HDPA 61/2006)An insurance company was fined for unlawfully transmitting the complainant’s sensitive health data. The case concerned a breach of the rules governing the lawful processing of special-category personal data. | GR | HDPA | GDPR | €15,000 | ↗ |
| 04 Sept 2024 | Agrotikos Elaiourgikos Synetairismos StylidasAgrotikos Elaiourgikos Synetairismos Stylidas was fined EUR 2,000 by the HDPA. The authority found breaches of data minimization and transparency principles, as well as inadequate technical and organizational measures in its video surveillance system. | GR | HDPA | GDPR | €2,000 | ↗ |
| 29 Apr 2022 | Fire Brigade HeadquartersA fine of EUR 5,000 was imposed for failing to respond to a data access request. The breach concerned access rights under the GDPR and national law. | GR | HDPA | GDPR | €5,000 | ↗ |
| 08 Aug 2014 | Anonymised (HDPA 104/2014)The supervisory authority found that the controller processed personal data without the data subjects' consent. The breach concerned the principles governing data processing under Greek law. | GR | HDPA | GDPR | €6,000 | ↗ |
| 25 Sept 2023 | OASAThe Athens Urban Transport Organization (OASA) was fined for failing to timely conduct a Data Protection Impact Assessment (DPIA) for its Automatic Fare Collection System. The authority found this to be a breach of data protection principles in connection with the system's processing activities. | GR | HDPA | GDPR | €20,000 | ↗ |
| 21 Jul 2025 | VIVLIOPOLEION TIS ESTIAS, I.D. KOLLAROU & SIA A.E.The company was fined by the HDPA in the amount of €2,000 for failing to build data protection into the design of its processing and for not applying privacy by default. The authority treated this as a breach of GDPR requirements on privacy by design and by default. | GR | HDPA | GDPR | €2,000 | ↗ |
| 24 Mar 2022 | Anonymised (HDPA 17/2022)A fine of EUR 3,000 was imposed for sending unsolicited political communication by SMS without prior consent. The conduct was found to breach Article 11 of Law 3471/2006. | GR | HDPA | ePrivacy | €3,000 | ↗ |
| 22 Jun 2017 | Vodafone-PanafonVodafone-Panafon was fined EUR 10,000 by the HDPA for a significant delay in responding to a data subject access request. The authority found a breach of Article 12 of Law L.2472/1997. | GR | HDPA | GDPR | €10,000 | ↗ |
| 21 Oct 2014 | ACDACD was fined by the HDPA 1,000 EUR for sending unsolicited marketing emails without the recipients’ consent. This breached Article 11 of Law 3471/2006. | GR | HDPA | ePrivacy | €1,000 | ↗ |
| 24 Jun 2025 | I ASPIDA TOU DAVIDThe HDPA imposed a EUR 1,000 fine on I ASPIDA TOU DAVID. The authority found that the entity failed to cooperate, which breaches GDPR requirements. | GR | HDPA | GDPR | €1,000 | ↗ |
| 21 Aug 2018 | National Bank of GreeceNational Bank of Greece was fined EUR 5,000 by the HDPA for failing to maintain accurate data about its debtors. The case concerned compliance with data protection obligations. | GR | HDPA | GDPR | €5,000 | ↗ |
| 27 May 2024 | Anna-Michelle AsimakopoulouAnna-Michelle Asimakopoulou was fined by the HDPA for sending unsolicited political communications by email to individuals who had registered their email addresses for official use with the Greek government. The case concerned the use of those addresses for political outreach, despite being collected for a different purpose. | GR | HDPA | GDPR | €5,000 | ↗ |
| 27 Dec 2012 | Euro-Catering O.E.The company was fined for failing to comply with a prior decision by the authority. It was noted that it no longer operated the stores concerned and that its financial situation was difficult. | GR | HDPA | GDPR | €10,000 | ↗ |
| 25 Jul 2013 | Anonymised (HDPA 90/2013)HDPA imposed a fine of EUR 1,000 on Anonymised (HDPA 90/2013) for the illegal collection and further processing of personal data. The case concerns a breach of the lawful processing requirements. | GR | HDPA | GDPR | €1,000 | ↗ |
| 19 Mar 2015 | Trust Center A.E.The company was fined for failing to adequately inform data subjects about the processing of their creditworthiness data. The authority found a breach of Article 11 of the Greek data protection law. | GR | HDPA | GDPR | €3,000 | ↗ |
| 20 Mar 2017 | Eurobank Ergasias A.E.Eurobank Ergasias A.E. was fined EUR 10,000 by the HDPA. The authority found that the bank did not adequately satisfy the complainant’s right of access to recorded telephone conversations. The case concerned the legal obligation to provide access to such recordings. | GR | HDPA | GDPR | €10,000 | ↗ |
| 12 Jun 2023 | Piraeus Bank S.A.Piraeus Bank S.A. was fined by the HDPA EUR 100,000 for processing personal data without a legal basis. The breach affected a large number of data subjects, which increases its compliance significance. | GR | HDPA | GDPR | €100,000 | ↗ |
| 19 Jul 2013 | ALL THE WORLD - COSMOS ONLINEThe company was fined for sending unsolicited marketing emails without obtaining prior consent from recipients. This conduct breached ePrivacy rules governing electronic communications. | GR | HDPA | ePrivacy | €8,000 | ↗ |
| 16 Jan 2026 | Πυροσβεστικό ΣώμαThe Hellenic Data Protection Authority imposed a €10,000 fine on the Fire Service for unlawfully processing an employee’s special-category health data. The authority found breaches of GDPR lawfulness and data minimization principles and noted that the data were accessible through an internal electronic application. | GR | Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα | GDPR | €10,000 | ↗ |