7/2026
The Greek DPA (HDPA) received twelve complaints filed against DEI, the Greek Public Power Corporation, (the controller) from telephone subscribers (data subjects) regarding the receipt of telephone calls for the purpose of promoting its products and services. The controller had outsourced the telephone calls to four call-centre companies acting as processors: CQS S.A. (Processor A), Teleperformance (Processor B), Mediatel (Processor C) and Prelude Group (Processor D). Processor D stated that it had used the services of INFOBELL (subcontractor) for the operation of its outbound calling system. The controller stated that its processors made approximately two million calls per year to provide contract-related information and conduct customer-satisfaction surveys, as well as around 50,000 promotional calls per month. The complaints concerned calls made on the controller’s behalf relating to billing and tariff information, the expiry of electricity supply contracts, customer-satisfaction surveys and other products or services. One complaint concerned an Air Miles programme, through which customers could collect airline miles. Several data subjects had either registered their telephone numbers in the national opt-out register or had expressly asked not to be contacted again. Under Article 11 of Greek Law 3471/2006, telephone subscribers may register their numbers in a national do not call register to indicate that they do not wish to receive unsolicited marketing calls. In two cases, the controller acknowledged that calls had been made to numbers included in the Greek Do Not Call register and attributed this to a technical malfunction in the process used to compare and exclude telephone numbers from the calling lists. In another case, a request not to receive further calls was processed eleven days after it was first submitted. The case file also concerned calls described by the controller and the processors as informational or as surveys regarding customer-satisfaction, during which lower-rate tariffs, e-billing or other programmes offered by the controller were mentioned. One data subject submitted recordings obtained through an access request, which documented a call involving both a customer-satisfaction survey and information about a programme offering lower charges. The DPA requested explanations from the controller and the processors. In their submissions, they argued, among other things, that the calls were linked to existing customer relationships and were intended to provide contractual or regulatory information, assess customer satisfaction or improve service quality rather than promote products. They also maintained that the calls made to numbers included in the do-not-call register resulted from isolated technical failures and referred to their contracts, opt-out procedures, staff training and quality-control measures. Holding — Regarding the controller, the DPA held that it was responsible for determining the purposes of the processing and the essential means by which the telephone calls were carried out. It was therefore required to provide its processors with appropriate tools and instructions, ensure the effective consolidation of the applicable opt-out registers and adequately supervise the processors’ compliance. Moreover, it found that the controller did not have a unified, automated and fully traceable mechanism for managing the different opt-out registers. Instead, it maintained separate subsystems that could lead to discrepancies or delays. The available arrangements also lacked complete audit trails capable of showing who had carried out a call, when a number had been checked and which data had been accessed or modified. The DPA considered that the controller relied mostly on manual or administrative supervision instead of technical monitoring. The DPA further found that the controller’s agreements with its processors were insufficient to ensure the implementation of appropriate technical and organisational measures. The contracts did not contain specific periodic audits, continuous assessment mechanisms or measurable compliance requirements. They also lacked sufficiently detailed provisions regarding evidence of compliance, the prior approval of subprocessors, voice-transmission encryption, protection against internal threats and backup procedures. Regarding certain calls described as customer-satisfaction surveys or as information about energy prices, the DPA held that such calls would fall outside the rules on unsolicited marketing only where they remained strictly limited to matters affecting the existing contractual relationship. The DPA found that the calls were not limited to providing information or conducting customer-satisfaction surveys, but also included direct commercial offers aimed at retaining customers or promoting new products. It therefore characterised them as “mixed-purpose” calls, in which the provision of information served as a pretext for making offers without first checking the opt-out register. The DPA concluded that these were not isolated incidents but a systematic and established practice, as the controller stated that the agents followed predefined scripts and did not act on their own initiative. The calls therefore fell within Article 11 of Law 3471/2006. The DPA also examined the provided information relating to the Air Miles programme. It found that the policy did not clearly distinguish the relevant purposes and legal bases, used broad descriptions of the processing activities, did not explain how data accuracy would be maintained, failed to specify concrete retention periods and provided insufficiently clear information regarding the right to erasure. The DPA fined the controller €190,000 for the infringement of Article 32 GDPR, €230,000 for the infringement of Article 11 of Law 3471/2006 and €130,000 for the infringement of Article 5 GDPR. It also ordered the controller, within six months, to amend its agreements with the processors by introducing explicit technical instructions, improve its technical and organisational procedures and establish a procedure for auditing the cooperating call centres. Regarding processor A, the DPA found that it relied on manual procedures to remove telephone numbers from calling lists. This increased the risk of human error and did not provide reliable evidence of who had recorded an objection or when the relevant change had been made. It held that processor A therefore infringed Article 32 GDPR and fined it €20,000. In addition, the DPA determined that processor A was also involved in a call presented as a customer-satisfaction survey during which a programme offered by the controller was mentioned. The DPA considered that the call included a direct commercial offer and therefore fell within Article 11 of Law 3471/2006, since it was directed to a subscriber who had opted out of marketing calls and imposed a €40,000 fine. As regards processor B, the DPA found that its systems had produced mismatches between the controller’s customer lists and the applicable opt-out registers, resulting in calls being made to numbers that should have been excluded. The DPA considered that this demonstrated insufficient automation and a possible absence of complete records documenting the checks performed before each call. It concluded that processor B violated Article 32 GDPR and imposed a €50,000 fine. It also fined €40,000 processor B for violating Article 5 GDPR due to the shortcomings identified in the processing relating to the Air Miles programme. Regarding processor C, the DPA pointed out that the method it used for the updates of its opt-out lists, created a gap between the submission of an objection and its addition to the updated list, during which the person could still receive a call. It therefore found the procedure insufficient under Article 32 GDPR and fined €45,000 processor C. Furthermore, the DPA also examined a recording of a call made by processor C. Although the call was presented as a customer-satisfaction survey, the agent referred to a programme offering lower charges. The DPA therefore classified the call as a mixed-purpose communication falling within Article 11 of Law 3471/2006. It also rejected the argument that the subsequent calls had been requested by the data subject, since that explanation was not supported by the call records or the recording. It imposed €55,000 a fine for this. As regards processor D, the DPA found that it had used a subcontractor to carry out telephone calling activities without obtaining the controller’s prior specific or general written authorisation. It held that this was contrary to the applicable contractual terms and fined it €30,000 for breaching Article 28 GDPR and Article 29 GDPR. It further held that the technical and organisational measures governing its operations were outdated and incomplete. Processor D relied on manual exchanges of files and did not adequately address the risks associated with large-scale digital processing. Additionally, the DPA found that its subcontractor maintained separate calling lists outside the controller’s direct control. It fined €50,000 processor for violations of Article 32 GDPR. Moreover, the DPA ordered all processors to improve their technical procedures within six months.
How it connects
Related across sources
Full text 71 findings
Athens, June 2, 2026 Ref. No. 2444 Decision 7/2026 The Personal Data Protection Authority convened, following an invitation from its President, in a teleconference meeting on December 17, 2025, in order to examine the case referred to in the background of this decision Present were Georgios Batzalexis, Deputy Chair; regular member Nikolaos Livos, as rapporteur, and alternate members Demosthenes Vougioukas and Maria Psalla, replacing regular members Konstantinos Lambrinoudakis and Grigoris Tsolias, who, although duly summoned in writing, were unable to attend due to a conflict of interest. The meeting was also attended, without the right to vote, at the Chairman’s request, by the expert Panagiotis Tsopelas and Pantelis Kammas, IT auditors, attended as assistants to the rapporteur. Finally, Eirini Papageorgopoulou attended as Secretary and Georgia Palaiologou as coordinator, both employees of the Administrative Affairs Department of the Authority.
” (hereinafter “DEH” or “the company”) from telephone subscribers regarding the receipt of telephone calls for the purpose of promoting the company’s products and services. In these cases, which are included in the appendix to this document, the Authority forwarded each complaint to DEI so that the company could investigate the allegations and present its views. Subsequently, the Authority reviewed PPC’s views to ensure the facts of each case were complete, sending additional documents requesting clarification, where deemed necessary. In cases where, following the above-described review of each case, a potential violation of 1of the applicable legislation on the protection of personal data, the Authority grouped the relevant complaints so that they could be examined together. After the complaint files and after taking into account PPC’s views on each of these complaints, they were categorized, based on the responses of the companies involved, as follows: Category A: Complaints not related to a sales call, but rather to information regarding PPC’s charges.
Category B: Complaints where the call was not made. Category C: Complaints not related to a sales call, but to information regarding a third-party service. Category D: Complaints not related to a promotional call, but to information regarding the expiration of the contract. Category E: Calls made due to a technical malfunction. Category F: Complaints not related to a promotional call, but to a customer satisfaction survey. Analysis of complaints Category A complaints (1, 3, 4): As part of the review of cases with ref. nos. Γ/ΕΙΣ/8816/14-11-2024 (No. 1), G/EIS/6145/23-07-2024 (No. 3), and G/EIS/5386/20-06-2024 (No. 4), the Authority sent to the Public Power Corporation (PPC) documents bearing ref. nos. Γ/ΕΞΕ/362/24-01-2025, Γ/ΕΞΕ/2119/05-08-2024, and C/EXE/2107/02-08-2024, requesting its views on the complaints. ” (hereinafter “MEDIATEL”) and “SERVICE 800 TELEPERFORMANCE SINGLE-MEMBER PUBLIC LIMITED SERVICE PROVIDER” (hereinafter “TP”) for the purpose of providing information regarding the categories and charges on the bills, given that with the implementation of the new rate schedules and price fluctuations via the energy exchange, new charges may arise.
In the case of complaint No. 1, the complainant contacted the company in writing and stated his objection to receiving telephone calls, but the representative handling the matter did not realize that the request was an objection and directed him to register in the registry under Article 11. The complainant followed up, and his request was granted after an 11-day delay. In the case of complaint No. 3, the call concerned informing the consumer about extreme wholesale prices. In the case of complaint No. 4, , seven calls were made to the complainant, four of which went unanswered, while during the last call, the complainant requested to be excluded from future calls. Category B(2) Complaint: As part of the review of complaint ref. no. Γ/ΕΙΣ/6785/30-08-2024, the Authority sent PPC document ref. no. Γ/ΕΞΕ/2643/02-10-2024 requesting its views on the allegations. DEI responded with document no.
” (hereinafter “PRELUDE”) to the phone number listed in the complaint. Category C(5) Complaint: As part of the review of complaint no. Γ/ΕΙΣ/1611/28-02-2024, the Authority sent PPC document ref. no. Γ/ΕΞΕ/1059/05-04-2024 requesting its views on the allegations. PPC responded with document no. , he can accumulate miles for flights by purchasing products. To substantiate this claim, DEI submitted hyperlinks 1 to the service’s terms and conditions and a relevant attached file. Complaint Category D(6): In the context of the review of complaint no. gr/en/home/myrewards/myrewards-miles/ 3Authority sent PPC a document bearing ref. no. Γ/ΕΞΕ/1208/22-04-2024 requesting its views on the allegations. DEI responded with document no. C/EIS/4020/02-05-2024, in which it states that the purpose of the calls was to notify the complainant of the imminent expiration of his contracts. Complaints in Category E(7,8): As part of the review of Ref.
No. Γ/ΕΙΣ/5490/30-08-2021 (No. 7), the Authority sent PPC a document bearing ref. no. Γ/ΕΞΕ/2019/06-09-2021 requesting its views on the allegations. PPC responded with document no. Γ/ΕΙΣ/6030/22-09-2021, in which it confirms that the call in question was made by a PPC representative for the purpose of providing information on personalized products, lower prices, and payment plans. Furthermore, the response states that the call to the complainant was due to a technical error, as the system incorrectly failed to recognize that the complainant’s phone number is listed in the registry under Article 11 of Law 3471/2006. Finally,DEI states that it is focusing its efforts on optimizing its system in order to minimize, if not eliminate, technical failures such as this one. In the context of the review of complaint no. Γ/ΕΙΣ/5344/18-08-2021 (item no. 8) complaint, as supplemented by document Ref.
No. Γ/ΕΙΣ/5784/15-09-2021, the Authority sent PPC document Ref. No. Γ/ΕΞΕ/2987/22-12-2021 requesting its views on the allegations. PPC responded with document no. Γ/ΕΙΣ/46/05-01-2022, in which it states that following a relevant review, it was confirmed that the customer is registered in the registry under Article 11 of Law No. 3471/2006. Furthermore, it was determined that the complainant’s phone number had not been excluded from promotional activities due to a technical malfunction. Finally, they confirm that the issue that arose concerns an isolated incident, and that they have implemented the necessary recommendations and technical checks to prevent similar failures in the future. Complaints in Category F (9–12): As part of the review of complaint no. Γ/ΕΙΣ/4187/24-06-2021 (item no. 9) 4, the Authority sent PPC a document bearing ref. no. Γ/ΕΞΕ/1695/13-07-2021 requesting its views on the allegations.
DEI responded with document No. Γ/ΕΙΣ/5019/July 30, 2021, in which it states that it is conducting a survey on the satisfaction of existing customers, with the aim of improving the customer experience , in the context of which the calls to the complainant were also made. Specifically, eight (8) calls were made, five (5) of which went to voicemail. According to PPC’s response, during the first successful call, a third party answered and the call was terminated. During the second successful call, the account holder answered and rated DEI with a score of five (5) to PPC. During this call, mention was also made of the e-bill, which the complainant found interesting and asked to be called back. When they called back, the complainant’s husband answered and expressed his dissatisfaction with the calls, as their phone number had been added to the registry under Article 11. Following notification of the complaint by the Authority, DEI attempted to contact the complainant again in order to provide an explanation.
During their last conversation, they explained that the initial calls were not made to promote products, but to conduct a satisfaction survey, and at the end, the complainant’s stated that he was satisfied with the discussion and convinced by the explanations he was given. In the context of the review of complaints with ref. nos. Γ/ΕΙΣ/3872/11-06-2021 (serial no. 10) and Γ/ΕΙΣ/3287/19-05-2021 (No. 12), as supplemented by document ref. no. C/EIS/3288/May 19, 2021, the Authority sent to PPC documents bearing ref. nos. PPC responded with document no. Specifically, regarding the first call made on May 19, 2021, it is reported that clear information was provided that the call was being made on behalf of DEI and specifically for a customer satisfaction survey. A. CUSTOMER SERVICE PROVIDER CUSTOMER SERVICE CENTER” (hereinafter “CQS”). He then stated that the phone 5number had been included in the registry under Article 11.
The call then ended after a farewell. Regarding the second call made on June 11, 2021, after the information system indicated that the complainant, as an existing customer, had not responded to the relevant survey, PPC reports that it contacted with the complainant to thank her for her cooperation, as well as to discuss a satisfaction survey they were conducting, since the relevant questionnaire had not been completed during the first call. Furthermore, according to PPC’s response, mention was made of the new “MY HOME ENTER” program, about which the complainant stated she was not interested, and the call was ended. Finally, PPC states that the above calls do not fall under the provisions of Article 11 of Law 3471/2006, as the purpose of the communication was not to promote sales but to conduct a satisfaction survey; therefore, they do not constitute unsolicited communication. In connection with the review of complaint No.
Γ/ΕΙΣ/3769/08-06-2021 (Ref. No. 11) complaint, as supplemented by document Ref. No. Γ/ΕΙΣ/4011/17-06-2021, the Authority sent PPC document Ref. No. Γ/ΕΞΕ/1598/28-06-2021 requesting its views on the allegations. PPC responded with document no. Γ/ΕΙΣ/4638/13-07-2021, in which it confirms that by signing the contract for the supply of electricity on January 22, 2021, the complainant did not consent to receiving information about new products and services through automated or non-automated means, nor to participate in statistical surveys. Four months after signing the contract, the PPC customer service system identified the complainant as a candidate for a satisfaction survey. For this reason, the complainant was contacted on May 28, 2021, during which the complainant expressed his dissatisfaction with PPC regarding high charges. Since then, PPC has not contacted the complainant again. However, on June 1, 2021, the PPC call center received an incoming call from the complainant—which was not completed—and a callback was scheduled for the following day, during which instructions were given that, should the complaint concern the charge for mailing a paper bill, the customer should be offered the option to sign up for 2 A feature that allows a customer to ask a company to call them back, rather than having to wait on hold.
6. Communication regarding the above matter was completed on June 3, 2021. Consequently, based on the above, PPC asserts that, out of respect for its customer’s privacy, it did not engaged in any product promotion or statistical surveys in any of these instances, except for those that constitute a contractual obligation. Specifically, the first call was intended to conduct a satisfaction survey as provided for in Article 11 of the contract entered into by its customers, while the calls made after June 2, 2021 do not constitute unsolicited communication, as they are a follow-up to the initial call made by the complainant to PPC. Subsequently, the Authority sent PPC document no. Γ/ΕΞΕ/2157/28-09- 2021, which it also shared with the complainant, in order to obtain further clarifications, such as how the customer is informed that they will participate in a satisfaction survey upon signing the contract, as well as whether the customer was given the opportunity to object to this during the telephone conversation.
It was also requested to clarify the difference between the purpose of “conducting a satisfaction survey” and “conducting a survey to better understand the needs, preferences, and experiences regarding PPC’s services,” for which the data subject has stated in the consent form for natural persons regarding the processing of their personal data by PPC, that they do not consent, and finally because the instruction was given during the call scheduled for June 2, 2021, that in the event the customer expresses a complaint regarding the billing of the , they should be offered, among other things, an upgrade to the HomeEnter+ plan, which includes the electronic billing service (e-bill), even though the complainant has stated on the consent form that he does not consent to receiving information via any means regarding new products and services. Furthermore, the Authority sent the complainant document no.
Γ/ΕΞΕ/2158/28-09-2021, to which the PPC’s response was attached, and asked him to confirm the content of the calls, bearing in mind that the company does not state in its response that the course of the phone calls, any products or services were promoted. 3 Abbreviation for “electronic bill”: this is the digital version of a bill, which replaces the traditional paper bill sent by mail. 7 DEI responded with document no. Γ/ΕΙΣ/7005/29-10-2021, in which it states, among other things, that the term “eligible for a satisfaction survey” refers to a customer who has completed a billing cycle (issuance of a bill and a settlement statement), or a customer who has called the customer service department more than three times and is being contacted to determine the status of request and their level of satisfaction with the service. It is also noted that the key difference between this satisfaction survey and other surveys is that it records customer satisfaction in relation to their specific contract on an individualized basis, and the results are entered into each customer’s file to improve service.
In contrast, surveys conducted to better understand needs, preferences, and experiences regarding PPC’s services are conducted among the general public and are usually anonymous; the anonymous responses are compiled and statistically analyzed to draw draw conclusions and make recommendations to management. Another equally important difference is that conducting a satisfaction survey is a contractual and regulatory obligation 4 of the Public Power Corporation (PPC) toward the customer, in accordance with Article 11 of the General Terms and Conditions for the Supply of Electricity to Residential Customers, whereas the other surveys require consent. Finally, it states that the instruction to the partner regarding the referral to the HomeEnter program was issued after the complainant’s dissatisfaction regarding the charge on the paper bill was recorded, and that the complainant had called the Public Power Corporation (DEI) the previous day; therefore, the call to him does not constitute unsolicited contact.
For his part, the complainant submitted to the Authority the documents bearing ref. nos. Γ/ΕΙΣ/6610/13-10-2021, G/EIS/6701/16-10-2021, G/EIS/6702/16-10-2021, G/EIS/6703/16-10- 2021, Γ/ΕΙΣ/6709/16-10-2021, Γ/ΕΙΣ/6710/16-10-2021, Γ/ΕΙΣ/7047/01-11-2021, C/EIS/7252/November 8, 2021, C/EIS/7266/November 8, 2021, C/EIS/8108/December 10, 2021, C/EIS/8141/13-12- 2021, and C/EIS/8158/14-12-2021 supplementary documents, in which it states, among 4, the Supplier undertakes to act in accordance with fair business practices to maintain the highest quality of service for the Customer. , response to supply requests, calculation of Supply Charges, call center support, response to inquiries, complaints, replies to letters, payment methods, documentation, and the adequacy of responses—particularly regarding charges, staff conduct) 8others, that he has been registered with the electronic billing service (e-bill) service, that he did not contact the number 21242148250 on June 1, 2021, and that the phone calls were made from the above phone number for the purpose of conducting a satisfaction survey as well as promoting the myHomeEnter+ program.
As evidence of the above, it submits a breakdown of outgoing calls as well as the recorded files of the calls in question. Upon review of the submitted records, it appears that the calls were made by MEDIATEL for the purposes of a satisfaction survey and to provide information about a program with lower rates, namely myHomeEnter+. The recorded files came into the possession of the complainant after he exercised his right of access with the Public Power Corporation (PPC), and he was aware of their existence since he had been informed at the start of the calls that the calls would be recorded for PPC, for security and to ensure service quality, that the recording would be retained for twenty-four (24) months, and that he could learn about his rights on the PPC website. Specifically, he requested the recorded files of six (6) calls in total, but ultimately received four of them. Regarding the two missing recordings, he was informed that following a review, it was determined that while the two conversations were logged in their systems, they were not recorded due to a technical malfunction.
Information on contractors and subcontractors PPC submitted to the Authority, under ref. nos. Γ/ΕΙΣ/2282/19-03-2025, Γ/ΕΙΣ/2675/01- 04-2025, a list of partner call centers dating back to 2021, including both active ones and those with which the respective contract has expired. In addition, it submitted, in the same emails, the relevant service contracts , which include the data processing agreements regarding promotional telephone calls on behalf of DEI. Furthermore, it submitted: (b) a power of attorney (Γ/ΕΙΣ/3458/25-04-2025) for the company TP, c) a list (Γ/ΕΙΣ/2675/01-04-2025) of the telephone numbers used by the executives and sub-executives of PRELUDE and c) certificate of representation (Γ/ΕΙΣ/2675/01-04-2025) for the company MEDIATEL. 5 Abbreviation for “electronic bill”: a digital version of a bill that replaces the traditional paper bill sent by mail. 9 According to the contracts submitted by the Public Power Corporation (PPC), the phone numbers used to make calls are not included in the corresponding contracts with the partner call centers.
These telephone numbers were disclosed only for the company PRELUDE through the submission of a signed affidavit by its legal representatives. Special “Do Not Call” List (Do Not Call List) PPC informed the Authority that partner companies are required to maintain an opt-out list, which includes all subscribers or call recipients who have indicated that they do not wish to receive telephone communications from or regarding their PPC account. Regarding the notification and synchronization process, call centers are required to promptly notify DEI of any new opt-out requests and to update their own systems within 24 hours. , SFTP). PPC maintains the central objection database, into which the records of all partners are integrated. Responsibility for final updates and compliance remains with PPC, but the partner must maintain local copies of the exclusion list. Technical Measures for Communications Security In accordance with the relevant contracts, partner companies implement, among other things, the following technical measures to enhance the security of procedures: • Access control and authentication: All users have unique accounts and credentials for accessing the systems, with the implementation of least-privilege and role-based access policies.
This includes an authentication and audit logging mechanism, as well as automatic account logout in case of inactivity. • Physical and logical system security: Access to premises and to 6An API is a standardized interface that defines how an application or service can interact with another through specific commands, parameters, and data exchange formats 7A secure protocol for transferring files over a network that allows for the encrypted exchange files between two systems, without third parties being able to read or alter the content. 10 Information systems are restricted exclusively to authorized personnel. Firewalls, antivirus software, network segmentation, and mechanisms event monitoring mechanisms are implemented. Workstations are protected by password and screen lock policies, and the use of unauthorized devices is prohibited. • Communications and data transfer security: Communications between MEDIATEL and PPC take place via secure channels (VPN 9, SFTP, or equivalent), with data encrypted during transmission and, where required, during storage.
Telephone connections are made via an internal VoIP 10 system with controlled access, restrictions on outbound traffic, and data exchange only between authorized points. • Logging and Traceability: All processing actions are logged (date, time, operator, action), with logs retained for a specified period and protected against modification. Provision is made for periodic review of the logs by the Security Officer or the DPO. • Incident Management and Business Continuity: There is a procedure for reporting security incidents and a response plan. The operator is required to notify PPC without delay of any incident and must have a recovery plan in place with regular backups. • Organizational and training measures: Ongoing training for the 8A firewall is a mechanism or software that monitors, filters, and controls data traffic between networks, with the aim of allowing only authorized communication and block malicious or unauthorized access.
Antivirus is security software that detects, prevents, and removes malicious software (malware), such as viruses, Trojans, worms, spyware, or ransomware. Network segmentation is the technique of dividing a single network into smaller, isolated segments in order to restrict access and reduce the spread of threats or unauthorized actions. Virtual Private Network (VPN): a network encryption and routing technology that allows users or systems to securely connect to a private corporate network via the public Internet. 10 VOIP (Voice Over Internet Protocol) refers to voice transmission via the Internet Protocol. It is the technology that enables the transmission of voice (phone calls) over the Internet or a local network. 11 Staff training on data protection and information security issues, confidentiality agreements for all employees who have access to data, as well as the appointment of a Security Officer/DPO to oversee compliance.
Consolidation of the Opt-Out Registry PPC maintains the central opt-out registry (unified opt-out), but each partner is required to verify, before every outbound call, whether the phone number is included in the Data Controller’s opt-out registry or in the registries of telecommunications providers, and to block the number if it is listed. Conducting Inspections at Partner Call Centers PPC reserves the right to conduct or commission third parties to conduct inspections, whether regular or unscheduled, to verify the call center’s compliance with the obligations set forth in the annex to the contracts and the provisions of Regulation (EU) 2016/679 (General Data Protection Regulation—hereinafter GDPR). Partner call centers are required to provide full access to information, records, technical data, and personnel, as well as any reasonable assistance required to verify compliance. Consequently, they may not refuse an inspection, nor may they invoke trade secrets, and must provide call logs, dispute records, security reports, and allow for random call monitoring.
The types of audits provided for include regular compliance audits—annual or semiannual—as well as special audits following a violation or complaint, internal assessment of call quality and legality, technical system audits, information security audits, annual audits of dispute files/registers, and cross-checking DEI—provider—partner lists. Partners are required to maintain records of all processing activities they perform on behalf of DEI and to make them available upon request, including the results of internal audits. Compliance reports must be submitted to PPC at least once time per half-year and must include metrics such as the opt-out rate for verifications, the number of failed call audits, security incidents, and the results of internal audits. In the event of non-compliance, contractors are required to immediately take the necessary corrective measures and notify PPC in writing within five (5) business days; that is, contractors must immediately correct 12any non-compliance and document in writing what has been corrected.
Summoning to a hearing and briefs following the summons In light of the above, the Authority, by letters ref. nos. Γ/ΕΞΕ/900/13-03-2025, G/EXE/901/13-03-2025, G/EXE/903/13-03-2025, G/EXE/904/13-03-2025, C/EXE/905/13-03- 2025, summoned the companies TP, CQS, MEDIATEL, PRELUDE, and DEI, respectively, and to appear before the Authority’s Division on April 2, 2025—a postponement from March 26, 2025— in order to discuss the aforementioned jointly examined complaint cases. The following individuals were present at the hearing: 1. On behalf of DEI, Ioanna Voulgaridou, with AMDS …, A, Director of Legal Support for Commercial Activities at PPC; B, Director of Customer Communications at PPC; C, the company’s Data Protection Officer; and D, Director of Alternative Channels and Small and Medium-Sized Enterprises, 2. on behalf of TP, Aikaterini Paida, with AMDS …, and E (Deputy Data Protection Officer), Data Protection Officer of the company, 3.
on behalf of CQS, Asimakis – Konstantinos Alexopoulos, with Data Protection Officer ID …, and F, Director of Operations 4. on behalf of MEDIATEL, Artemia Milioti, with AMDS …, and Z, the Data Protection 5. On behalf of PRELUDE: Konstantinos Liannis, with AMDS …, and H. During the hearing, the following points, among others, were raised: PPC stated that it makes approximately 2,000,000 calls per year to inform customers about their contracts and conduct satisfaction surveys, as well as approximately 50,000 calls per month to promote products and services. These calls are made by partner companies with which PPC has entered into the appropriate contracts. Regarding the complaints, the company stated, among other things, the following: • Regarding complaint No. 1, the complainant was contacted for an informational meeting in connection with receiving the first bill, in order to provide him with explanations regarding the charges; therefore, the provision of Article 11(13) does not apply.
Furthermore, whenever a customer is contacted by the Public Power Corporation (PPC), an identification procedure is carried out first. In this particular case, when the representatives realized they were speaking with the complainant’s son, the conversation was terminated. • Regarding complaint No. 2, it was reported that the complainant was never contacted by the partner company PRELUDE on the date he stated, a fact confirmed by a relevant statement from the telephone provider. • Regarding complaint No. 3, it was reported that the subscriber was called to participate in a satisfaction survey and to receive information regarding her first bill. During the call, the customer stated that she wished to be added to the (Do Not Call – hereinafter DNC) list,¹¹ and her request was granted immediately. • Regarding complaint No. 4, it was reported that the call took place on June 10, 2024, to provide information regarding the first bill.
During the call, the customer requested a callback, as he did not have time at that moment. Subsequently, several calls were made that went unanswered, while the customer finally answered on June 25, 2024, at which time he stated that he wished to be added to the DNC list. His request was granted immediately. • Regarding complaint No. 5, it was reported that the customer was called on February 28, 2024, for informational purposes and that, during the call, she requested to be added the DNC list, a request that was granted immediately. • Regarding complaints nos. 7 and 8, in which calls were made to subscribers registered in the registry under Article 11, it was reported that this was due to a technical error in TP’s software, which controls which PPC customer phone numbers are included in the list of the Article 11 registry, so that they can be excluded from the calls. Subsequently, the phone numbers of the two customers were removed from the call list so that they would not be called again.
Since then, from 2019 to the present, there has been no other similar incident, even though approximately 2,500,000 outbound calls have been handled for PPC’s campaigns. 11 List of telephone numbers whose owners have expressly stated that they do not wish to receive sales calls or calls promoting products and services. 14 • Regarding complaints nos. 9 and 10, which are similar cases, it was reported that the calls were answered by different individuals, who requested not to be called again. However, since they had not communicated with the customer directly, it was deemed necessary to call back. These calls were made as part of the context of customer satisfaction surveys. It was also reported that during the call, reference was made to the My Home Enter+ program. Furthermore, the requests not to be called again were submitted by the spouses of the two customers. Finally, it was noted that in many cases, phone numbers are provided that do not belong to the customers themselves, but to members of their families.
• Regarding complaint No. 11, it was reported that the complainant was contacted as part of a PPC customer satisfaction survey. During the phone call , he expressed a complaint regarding the charge for the paper bill and 12 was directed to sign up for the e-bill service , so that he could receive his bills electronically. He asked for the call to be rescheduled, as he did not have time for that particular conversation. He then contacted the Public Power Corporation (PPC) himself on June 1, 2021, and June 3, 2021, and stated that he did not wish to receive calls. His request was granted immediately, and his number was added to the DNC list so that he would not be called again. Furthermore, it was noted that during the first call, the customer rated PPC a 4 out of 5 due to the charge for the paper bill, and that during these calls, any mention of product promotion. Finally, it was noted that the customer participated normally in the survey without expressing any further reaction.
Regarding the questions posed by the Authority’s representatives during the hearing, the following points are highlighted: • In response to the Authority’s question as to why so many and repeated calls, PPC responded that it is required to inform consumers about specific issues explicitly provided for in the Supply Code. Furthermore, for customers who have not provided an email address or are not familiar with electronic means of communication, the 12 Abbreviation for “electronic bill”: the digital version of a bill, which replaces the traditional paper bill sent by mail. 15 Notifications are provided by phone. At the same time, the Public Power Corporation (PPC) conducts satisfaction surveys for the benefit of its customers, in order to identify any issues of of dissatisfaction. These calls are made by appropriately trained individuals who possess the necessary expertise to analyze the bills.
It was also noted that if a large number of customers called the call center at the same time, it would result in wait times and delays in service. According to PPC, customers who receive proactive calls rate the company higher on average than those who call on their own. • When asked how PPC managed to notify such a large number of subscribers by phone regarding the rate adjustment clause, the company replied that it informed a sample of customers rather than the entire customer base, based on certain criteria that were not specified during the hearing. • When asked whether the content of the conversations—such as the questions asked during the calls—was predetermined, the response was that there are scripts that customer service representatives follow. These scripts include various branches, which are followed depending on the customer’s responses. Furthermore,checks are performed to ensure that agents adhere to the above scripts.
• When asked whether the software can detect technical errors, the response was that in some cases the system generates an electronic trace. However, for the two cases of technical errors examined, no such trace was found in the report. • In response to a question regarding the methodology followed by partner companies for grouping provider registries, obtaining the list PPC customers, and the exclusion of telephone numbers included in the registry under Article 11 or on the DNC list, PPC replied that each call center receives updated lists on a monthly basis from the telecommunications providers. They then cross-reference these lists with the PPC’s customer list and inform the company that approximately 50% of the numbers have been excluded due to the registry under Article 11. Regarding the DNC list, 16, it was reported that PPC maintains its own request database, which is continuously updated from all communication channels (email, retail locations, call centers of PPC or partner companies).
Whenever PPC generates a new call list, it excludes the phone numbers included in the updated database. Finally, it was noted that a Customer Relationship Management (CRM) system 1 has been under development for the past year, through which improvement initiatives will be implemented once the project is completed, as all campaigns will be conducted through the CRM. When a customer indicates their objection to receiving calls, the system will be updated and will exclude them from all current campaigns. When asked whether partner companies also have access to this system, PPC responded that partner do not have access to it. Subsequently, PPC submitted the email with reference number Γ/ΕΙΣ/3470/25-04-2025 email, which included: • The data protection policy, • a copy of the electricity supply contract, • the company’s data protection policy, • a copy of the evaluation form, • the complaint handling procedure, • a guide to procedures for handling do-not-call lists, • a copy of the form for exercising rights, • a memorandum in which the company asserts, among other things, that: 1.
The phone calls were not advertising or promotional, but informative or service-related, within the context of an existing contractual relationship or customer satisfaction surveys. They do not fall under Article 11 of Law 3471/2006, 13 Customer Relationship Management (CRM) is both a strategy and a set of processes, practices, and technologies that a business uses to understand, manage, and improve its relationships with its customers, both existing and potential 17; therefore, they do not violate the provision regarding the Register under Article 11, 2. only two isolated incidents involved technical failure, 3. 1. 2. 3. legitimate interest (Article 6(1)(f)) — for satisfaction surveys and service improvement. 4. 1. 2. 3. very limited instances of marketing due to technical issues with external partners. 5. 1. 2. 3. mechanisms for call quality control. 6. 1. 2. 3. 4. 99%, 6. the calls were made lawfully, at the direction of DEI, and without any intent to violate Article 11 of Law 3471/2006.
Any discrepancies were due to a technical error, which was corrected, 7. TP complies with DNC procedures, holds ISO certifications, and implements best practices for security and data verification. MEDIATEL submitted an email with reference number Γ/ΕΙΣ/3464/25-04-2025, which includes: • Training procedures, • complaint handling procedures, • a memorandum in which it asserts, among other things, that: 1. MEDIATEL acts as a data processor on behalf of PPC, within the framework of a commercial partnership for making outbound calls to existing customers, 2. The calls are for informational purposes and not for promotional purposes, 3. The company was instructed by PPC to contact its customers to inform them about charges and details of their first bill, 4. MEDIATEL’s actions do not violate Article 11 of Law 3471/2006, since these are not unsolicited promotional communications, but rather informational calls related to an existing contractual relationship, 5.
MEDIATEL acted exclusively on the instructions of DEI, without any initiative or use of its own data. 6. 1 Regarding complaint no. Γ/ΕΙΣ/8816/24-06-2024 (item 1): The call was made on November 6, 2024, and the call was answered by another person who explained that the complainant has a hearing impairment and has provided this number as his contact number. The caller requested that the information be sent via email, and the call ended without any request for objection. MEDIATEL did not receive a request for cancellation 23 either in writing or verbally. 2 regarding complaint no. Γ/ΕΙΣ/3769/08-06-2021 (item no. 11), The complainant answered the questions, gave PPC a positive rating, and did not express any objection. A few days later, he contacted the PPC call center, without success, and made two follow-up calls. On the third call, he stated that he did not wish to receive any further communications, so the company immediately notified the Public Power Corporation to add his number to the DNC list.
PRELUDE submitted an email with reference number Γ/ΕΙΣ/2675/01-04-2025, which included: • A certificate from the company “INFOBEL SOFTWARE APPLICATION DEVELOPMENT & PROVISION OF TELECOMMUNICATIONS SERVICES, SINGLE-MEMBER COMPANY LIMITED LIABILITY” (hereinafter “INFOBELL”), stating that no calls were made from its systems from the number 2109998681 to the number … (complainant’s number) on August 30, 2024, • a list of numbers registered in the registry under Article 11, • sworn statement regarding the exclusive use of the number 2109998681, • a memorandum in which it asserts, among other things, that: 1. It acts as a data processor on behalf of PPC, pursuant to the contract dated April 1, 2024, for the purpose of attracting prospective customers and brokering the conclusion of contracts for the supply of natural gas and electricity, 2. implements strict procedures for cross-checking lists of telephone numbers against the Registry referred to in Article 11, in order to prevent any communication with individuals who have opted out, 3.
maintains an internal compliance system and outbound telephone call software (Dialer) managed by a partner company, 4. Regarding the alleged incident, it states that no 24 calls were made from the number it uses exclusively to the complainant. The Authority, after reviewing the evidence in the case file of the jointly examined cases and the findings of the hearing before it, the submissions and statements of the parties, having heard the rapporteur and the clarifications from the assistant rapporteurs, who were present without the right to vote, following thorough deliberation, HAS DECIDED IN ACCORDANCE WITH THE LAW 1. The issue of telephone calls for the purpose of direct marketing of products or services and for any kind of advertising purposes is regulated by Article 11 of Law 3471/2006, which introduces regulations concerning unsolicited communications (see paragraphs 1 and 2). Specifically, Article 11, paragraph 1, of Law 3471/2006 states that: “The use of automated calling systems, particularly via facsimile (fax) or electronic mail, and, more generally, the sending of unsolicited communications by any means of electronic communication, without human intervention, for the purposes of direct marketing of products or services and for any kind of advertising purposes, is permitted only if the subscriber gives express prior consent,” while paragraph 2 of the same article stipulates that: “It is not unsolicited communications involving human intervention (calls) for the above purposes, provided that the subscriber has declared to the provider of the publicly available service that he or she generally does not wish to receive such calls.
” Consequently, telephone calls involving human intervention, for the purposes outlined above, are permitted unless the called party has indicated that they do not wish to receive them (“opt-out” system). Advertisers, when conducting telephone promotional activities involving human intervention, must obtain from all providers up-to-date copies of the registries referred to in Article 11 of Law 3471/2006 and ensure that they have available the declarations of subscribers that have 25up to thirty days prior to the telephone call (see also the Authority’s Decisions Nos. 62–67/2016). 2. Furthermore, a natural person’s telephone number constitutes personal data, since it can serve as a means of indirectly identifying its holder (see Article 4(1) of Regulation (EU) 2016/679, hereinafter the GDPR), enabling communication with that individual. Furthermore, according to Opinion 4/2007 of the EU Article 29 Working Party regarding the concept of personal data, particularly in the context of electronic services, indirect identifiers may, in certain cases, be sufficient to distinguish an individual from others within a specific group, even if their name has not been verified.
3. Making telephone calls for the purpose of promoting products and services is governed, in principle, by Article 11 of Law 3471/2006. It should be noted, however, that Article 3(2) of this law specifies that “Law No. ” Already, under Article 84 of Law 4624/2019 (Government Gazette A’ 137/August 29, 2019), as currently in force pursuant to Article 44 of Law 5002/2022 (Government Gazette A’ 228/Dec. 9, 2022), Law 2472/1997 was repealed. Furthermore, following the entry into force of the General Data Protection Regulation (GDPR), any prior reference to Law 2472/1997—which had been enacted to transpose Directive 95/46/EC—is deemed as a reference to the GDPR (see also Article 94(1) of the GDPR). Consequently, for any matter relating to the provision of electronic communications services to subscribers or users who are natural persons and which is not specifically regulated in Law 3471/2006, the GDPR shall apply (see also Article 95 of the GDPR as well as Recital No.
173). 4. Article 4(7) of the General Data Protection Regulation defines the controller as “…the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determine the purposes and means of the processing of personal data…”. ” 5. Article 28 of the GDPR, which governs matters concerning the processor, provides in paragraph 1 that when processing is to be carried out 26on behalf of a controller, the controller shall use only processors that provide sufficient guarantees regarding the implementation appropriate technical and organizational measures, so that the processing complies with the requirements of this Regulation and ensures the protection of rights of the data subject, while paragraph 3 stipulates that processing by the processor shall be governed by a contract or other legal act governed by Union or Member State law, which binds the processor in relation to the controller and specifies the subject matter and duration of the processing, the nature and purpose of the processing, the type of personal data and the categories of data subjects, and the obligations and rights of the data controller.
Such a contract or other legal act shall provide, in particular, that the processor shall process personal data only on the basis of documented instructions from the data controller and takes all necessary measures pursuant to Article 32 of the GDPR. 6. ” This provision imposes an obligation on the processor to process data only on the instructions of data controller, unless the law provides otherwise. Consequently, a violation of this provision by processors constitutes a violation of the GDPR on their part. 7. Article 32 of the GDPR stipulates, among other things, that both the controller and the processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risks, taking into account the latest developments, the costs of implementation, and the nature, scope, of application, the context, and the purposes of the processing, as well as the risks of varying likelihood and severity to the rights and freedoms of natural persons.
The controller and the processor shall take measures to ensure that any natural person who 27acts under the supervision of the controller or the processor and has access to personal data processes such data only on instructions from the controller. It follows from these provisions that the responsibility for maintaining appropriate security measures rests with both the controller and the processor; consequently, liability for a breach of security measures should be apportioned and attributed appropriately. 8. The EDPS Guidelines 07/2020 on the concepts of the controller and processor under the GDPR, it is stated (Recital 127) that the level of instructions provided by the controller to the processor regarding the measures to be taken depends on the specific circumstances. In some cases, the data controller may provide a clear and detailed description of the security measures that must be implemented.
In other cases, the data controller may describe the minimum security objectives to be achieved, while at the same time asking the data processor to propose the implementation of specific security measures. In any case, the data controller must provide the processor with a description of the processing activities and the security objectives (based on the data controller’s risk assessment), as well as approval of the measures proposed by the processor. 9. ” Consequently, in cases where a processor, even within the broader context of collaboration with a data controller, carries out processing activities for which it has no documented instructions (whether specific or general) from the data , then the processor must be considered the controller, since it determines the purposes and means of those activities, in accordance with the 17 case law of the CJEU . 17See, in this regard, the CJEU judgment of Dec.
5, 2023, Case C-683/21, paras. 35–36, 84–85, and, for a detailed analysis, G. Tsolia, “The Delimitation of the Scope of Application of the GDPR Based on the Case Law of the Court of Justice of the European Union, on Lawspot dated February 15, 2024 2810. Paragraph 3 of Article 4 of Law No. 3471/2006 stipulates that the recording of of conversations and related traffic data is permitted when they take place during the course of lawful professional practice for the purpose of providing evidence of a commercial transaction or other business-related communication, provided that both parties, after being informed in advance of the purpose of the recording, give their consent. By order of the Personal Data Protection Authority, the manner in which the parties are informed and consent is provided, as well as the manner and duration of retention of the recorded conversations and related traffic data.
11. The information in the case files of the complaints under joint review indicates that PPC, through a contract, entrusts partner call centers with making telemarketing calls to promote its own products and services. Through the contracts, written instructions, and other directives it provides to these partner call centers, PPC establishes a series of specifications that define the framework for the operations of each partner, with the aim of meeting the requirements of the General Data Protection Regulation (GDPR) and Law 3471/2006. The PPC fully defines the purpose of the processing, and thus its objective, while also specifying the key characteristics of the processing methods. PPC’s responsibility, as the data controller, is to provide appropriate tools, principles, and guidelines to prevent unauthorized calls. This includes the consolidation of the individual registries of service providers into a single “Opt-out” Registry and the maintenance of a special opt-out registry listing those who have specifically objected to receiving telephone calls (pursuant to Article 21 of the General Data Protection Regulation).
Furthermore, PPC’s responsibility concerns the adequacy of the control and supervision of data processors, as well as the actions it took as soon as it became aware of the complaints. The controller and the processor are responsible for implementing appropriate measures to ensure an adequate level of security against the risks. Liability for failure to implement appropriate measures, in violation of Articles 28 and 32 of the GDPR, should be shared by the data controller and the data processor. Consequently, in cases where a failure occurs in the implementation of security measures by the 29processor, the processor bears a greater degree of responsibility for implementing the security measures. However, if in certain cases it turns out that the processor violates the obligations imposed on it by the contract and processes data beyond or in violation of the controller’s instructions, then this constitutes a violation of Article 29 of the GDPR.
Furthermore, any technical error must be documented and substantiated. Based on the principle of accountability, such errors are recorded and may also relate to data breach incidents under Article 33 of the GDPR. 12. With regard to the processing activities related to the complaints under review and the legal basis, the following points are noted: (a) With regard to the Public Power Corporation (PPC), it appears from the outcome (recurring technical malfunctions, the placement of “mixed-type” calls, delayed fulfillment of of requests), taking into account Articles 24 and 32 of the General Data Protection Regulation (GDPR), there is insufficient documentation of the procedures for consolidating objection registries and the absence of a comprehensive audit trail. The data indicate that PPC maintains separate subsystems, without a unified, automated, and fully traceable mechanism, a situation that may lead to discrepancies or delays.
It is recommended that a central opt-out registry, with automated synchronization via a secure API 19 and mechanisms for logging every action, in order to ensure integrity and accountability. , who made the call, when, and what data they viewed or modified). In other words, compliance appears to be based on manual or administrative controls rather than technical traceability controls. Therefore, it is necessary to implement a clear policy for managing contractors and conduct regular audits to ensure the proper implementation of contractual data protection clauses 18A documented record of actions within an information system that allows for the monitoring, verification, and demonstration of the legitimacy and security of each data processing operation. 19An API is a standardized interface that defines how one application or service can interact with another through specific commands, parameters, and data exchange formats 30.
b) With regard to CQS, it appears—taking into account Article 32 of the GDPR— that the company relies on manual procedures to exclude numbers from call lists, resulting in an increased risk of human error and incomplete documentation. Manual verification does not ensure full compliance and does not provide reliable evidence in the event of an audit. It is recommended that manual procedures be replaced by automated checks and the implementation of a dual-confirmation system for any exception entered manually. Furthermore, every action must be logged in an audit trail to document which user made the change and when. c) With regard to TP, taking into account Article 32 of the GDPR, an issue of failure has arisen concerning isolated instances of discrepancies between the customer list and the blocking registers, resulting in calls to numbers that should have been blocked. This fact demonstrates inadequate automation of the verification process and a possible lack of complete recording of the steps preceding each call.
It is recommended to implement a mechanism for automatically cross-checking the lists before each telephone call, as well as maintaining a detailed log of actions documenting which number was checked, when, and with what result. The procedure must be integrated into a campaign quality control system, with accuracy and compliance metrics. d) With regard to MEDIATEL, it appears—taking into account Article 32 of the GDPR—that the company relies on daily synchronization via SFTP, which resulting in a time window during which calls may be made before the blocking list is updated. This delay constitutes a technical and organizational weakness regarding the updating of data. It is recommended to transition to a real-time 20A documented audit trail of actions in an information system, which allows for the monitoring, verification, and proof of the legitimacy and security of every data processing operation.
21SFTP (Secure File Transfer Protocol) is a secure file transfer protocol that enables the encrypted exchange of data between two computers on a network. 31 in real time via a secure interface (API), or at least an increase in the frequency of synchronization with the corresponding reference files. At the same time, notification mechanisms for delayed entries and performance metrics that commit the company to specific levels of accuracy and update speed. e) With regard to PRELUDE, it appears that the company uses INFOBELL as a subcontractor to make telephone calls, without prior specific or general written authorization from the Data Controller (DEI), in violation of the terms of their contract and Articles 28 and 29 of the GDPR. The involvement of an undeclared subcontractor, within the meaning of Article 32 of the GDPR, undermines the security of the processing and renders the data transfer chain opaque and uncontrollable.
Furthermore, the technical and organizational measures described in the contract are deemed outdated and inadequate, as they focus on traditional, manual procedures for exchanging physical files, failing to address the risks associated with large-scale digital processing. Consequently, it becomes difficult to fully document the data verification process prior to each query. The lack of automated synchronization creates a direct risk of using outdated data, while making it difficult to verify compliance with the the retention limit (120 days), given that INFOBELL maintains independent lists outside the control of the Data Controller. It is imperative to improve the data exchange methodology and the establishment of an automated validity-checking mechanism that will reject, in real time, numbers included in the Article 11 Registry or other exclusion lists, while ensuring full traceability of these checks .
13. Taking all of the above into account, it is evident that the aforementioned shortcomings highlight the need for a unified and fully automated framework for managing telephone calls, which is proposed to be based on: a. A central blocking registry accessible in real time by all partners, 32 b. automated checks and mechanisms to prevent calls to unauthorized numbers, c. continuous logging and monitoring of actions for accountability purposes, d. enforcement of the stipulated contractual terms through compliance metrics and audits of personnel, e. automatic blocking of outbound calls to numbers listed in the Registry under Article 11 of Law No. 3471/2006 (opt-out) or those on DNC lists. The implementation of these measures enhances transparency, integrity, and compliance with the principles of security and accountability in the processing of personal data. The necessity of adopting these measures is further reinforced by the reference, in 22 context of the hearing, to the CRM software development process with the aim of future improvement of the system.
14. Regarding the calls concerning the PPC myRewards Miles service, based on review of the memoranda, the privacy policy accepted by the user upon registration, and the relevant complaints, the following issues arose: • There does not appear to be a clear distinction between the legal bases for processing and sufficient information regarding data use as defined in Article 5(1)(a) of the GDPR (lawfulness, transparency, integrity). Specifically, the policy states that: o “We will use your personal data only for the purposes for which we collect it, unless we reasonably determine that we will need to use it for another purpose and that reason is compatible with the original purpose. If you would like to receive an explanation regarding whether processing for the new purpose is compatible with the original purpose, please contact us. If we need to use your personal data 22CRM (Customer Relationship Management) is a system, process, or software that enables an organization to collect, organize, and manage customer information for the purpose of serving customers, analyzing data, and leveraging it for commercial purposes.
22Do Not Call: A list of phone numbers belonging to individuals who do not wish to receive phone calls for advertising or promotional purposes. 33 If we use your data for an unrelated purpose, we will notify you to explain the legal basis that allows us to do so,” o “Our website may include links to third-party websites, distinct embedded web pages (microsites 2), plugins, and applications. If you select or activate these links, you grant third parties the right to collect or share data about you. We do not control third-party websites and are not are responsible for their own privacy policies; furthermore, in the event that supplementary services are provided to you by third parties through the booking process, you should be aware that the AEGEAN Group may act as a data processor on behalf of these third parties. ) without it appearing that the purpose limitation, as defined in Article 5(1)(b) of the GDPR, is accurately ensured, • there is no mention of mechanisms for updating data.
Consequently, accuracy does not appear to be ensured as defined in Article 5(1)(d) of the GDPR, as defined in Article 5(1)(b) of the GDPR, • the policy does not specify specific retention periods for data. , promotion of a specific program, campaign, service, or initiative). 34 • The policy is vague regarding the exercise of the right to erasure. ” Consequently, transparency does not appear to be ensured pursuant to Article 5(1)(a) of the GDPR with regard to Article 17 of the GDPR, 15. Requests for information for the purposes of investigating, verifying, or providing updates regarding wholesale prices constitute lawful processing only if they are limited to providing information regarding changes that affect the existing contractual relationship. However, based on the audio recording provided to the complainant by PPC and submitted to the Authority (as an attachment to complaint No. Γ/ΕΙΣ/3769/08-06-2021 and email No.
C/EIS/8158/12-14-2021), in conjunction with PPC’s response bearing ref. no. C/EIS/5845/09-17-2021, it is found that the partner companies MEDIATEL and CQS deviated from the lawful purpose. Specifically, these companies did not limit themselves to simply providing information or conducting satisfaction surveys; rather, the conversations were accompanied by direct sales pitches aimed at retaining customers or promote new products. In particular, in the conversation referenced in the complaint with No. Γ/ΕΙΣ/3769/08-06-2021 (No. 11), the MEDIATEL representative can be heard, among other things, stating: “(…) next, we’d like to inform you about a plan with lower rates (…)”, while the Public Power Corporation (PPC) acknowledges in writing that the company CQS made a similar call in the case of the complaint with ref. no. Γ/ΕΙΣ/3287/19-05-2021 (case no. 12). Consequently, these communications fall within the scope of Article 11 of Law 3471/2006, as they constitute unsolicited communication involving human for commercial promotion purposes to subscribers who have explicitly stated in the Do Not Call Registry that they do not wish to receive such calls.
These circumstances indicate that the calls are of a “mixed nature,” where the information provided serves as a pretext for making offers without prior verification against the Register; and, in combination with the PPC’s statement that its representatives operate based on predetermined scripts and do not act on their own initiative, it is evident that “mixed-nature” calls are not isolated incidents, but constitute a systematic and established practice of the partner companies. Finally, regarding the claim by PPC (in complaint No. 11) that the calls were made at the 35request of the complainant or as a result of his complaint, it should be noted that this claim is not corroborated by the call log or the content of the recorded conversation submitted to the Authority by the complainant. 16. Upon examination of the contracts with the partner telecommunications providers and other documents submitted following the hearing—including those with reference numbers Γ/ΕΙΣ/2282/19- 03-2025 and Γ/ΕΙΣ/2675/01-04-2025, the following findings were made regarding the conduct of audits and the implementation of appropriate technical and organizational measures the following: • The contracts include clauses regarding the processing of personnel data , which explicitly stipulate that contractors act only on the instructions of PPC, include provisions regarding confidentiality, technical security measures, and an obligation to report breaches, and state that PPC may conduct audits or request inspections.
, SLA 24 for updating the objection list, response time to requests from data subjects), b) the obligation to cooperate in the event of audits is vague and does not include any reference to the specific 25 provision of evidence of compliance (such as penetration tests, 24A Service Level Agreement (SLA) is a contractual agreement between a provider and a customer that defines specific, measurable performance metrics (service levels), as well as obligations, key performance indicators (KPIs), control procedures, and penalties in the event of non-compliance. 25A controlled security evaluation process for an information system through simulation real-world attacks by malicious users, with the aim of identifying and confirming vulnerabilities that can be exploited for unauthorized access or data tampering. 12, NIST SP 800-115) 36 log audits or audit trail reports), 27 28 c) there is no mention of a subcontractor pre-approval process or a mechanism for notifying changes to subcontractors, 29 d) there is no provision for voice transmission encryption (SIP-TLS, 30 SRTP) for internal outgoing/incoming calls, e) data encryption is limited solely to the transport layer.
With regard to storage, the lack of specific specifications and the vague wording “where required” render the protection framework incomplete, f) no measures are provided for protection against internal threats, (h) The methodology for maintaining backup copies is not specified, nor are the type and number of media that should be used. 17. Based on the foregoing, the Authority finds that there are grounds to exercise its corrective powers under Articles 58(2)(i) and 83 of the General Data Protection Regulation (GDPR) to impose fines with respect to the infringements identified above and its corrective powers under Article 58(2)(d) to order the data controller or the processor to bring the processing operations into compliance with the provisions of this Act. In determining the fines that the Authority deems effective, 26A process by which logs are examined and evaluated to identify discrepancies, violations, or unauthorized actions, as well as to verify the proper operation and compliance of the information system.
4, NIST SP 800-92) 27A chronologically organized set of records documenting the sequence of actions that affected a given piece of data, a process, or an information system at any stage. (Sources: ISO/IEC 27001:2022, ISO/IEC 27701:2019, NIST SP 800-92) 28 A person authorized by the principal data controller to perform specific processing operations on behalf of the data controller, following prior specific or general written authorization from the data controller. 29 SIP-TLS is the secure version of the SIP (Session Initiation Protocol) protocol —a signaling protocol used to establish, manage, and terminate communication sessions between two or more network participants), which is used to initiate, manage, and terminate voice or video calls over the Internet. TLS (Transport Layer Security) adds encryption and authentication to the communication. 30 SRTP is the secure version of RTP (Real-Time Transport Protocol—a network protocol used to transmit audio and video in real time over networks), which carries the audio stream itself during a VoIP call.
While SIP-TLS protects the signaling, SRTP protects the voice itself. 37. In a balanced and preventive manner, the assessment criteria set forth in Article 83(2) of the GDPR that apply to the present case are taken into account, as specifically interpreted by the EDPB’s Guidelines 4/2022 on the 31 calculation of administrative fines . as well as the following: I. The companies’ most recent available turnover, specifically: • DEI: €8,978,607,000 (for the year 2024). 34 (for the year 2024). • TP: €464,259,782 (for the year 2024). 09 (for the year 2024). • PRELUDE: No financial statements were found on file in the General Commercial Register of Enterprises. II. That the severity of the violations found is deemed, in all cases, to be minor, taking into account the number of complaints and phone calls found to have been made in violation of the law, the time period, the small number of violations relative to the total number of calls made, and the fact that the Authority’s Authority’s inspections that a small percentage of those receiving unlawful calls file a complaint (see Authority Decisions 60–63/2018).
III
The Authority considers the following as mitigating factors: a. The gradual improvement of the measures implemented to ensure compliance with the GDPR and Law 3471/2006, b. The technical difficulties in integrating the Registry. c. The difficulty in implementing the Registry provision (for all companies). iv. The Authority considers the following to be aggravating factors: a. 1 38 technical and organizational measures. b. That the controls exercised by the data controller over the processors, as well as those exercised by the processors over their subcontractors, were not sufficient to ensure compliance with the terms of their contracts with one another. c. The fact that, in certain cases, ambiguous explanations were provided to the Authority. d. The fact that consumer information calls regarding energy prices and satisfaction surveys were of a “mixed” nature. e. The fact that, in cases where consent is obtained, the applicable privacy policy does not ensure sufficient clarity and transparency regarding the purposes and legal bases for processing.
FOR THESE REASONS The Authority: a. : i. pursuant to Article 58(2)(i) of the General Data Protection Regulation (GDPR), the effective, proportionate, and deterrent administrative fine appropriate to the specific case in light of its specific circumstances, in the amount of €190,000 32, for the aforementioned established violation of Article 32 of the General Data Protection Regulation, as analyzed in recitals 11, 12(a), 13, and 16 of this decision. ii. Pursuant to Article 58(2)(i) of the GDPR, the effective, proportionate, and deterrent administrative fine appropriate in this specific case in light of its specific circumstances, in the amount of €230,000 for the 33 established violation of Article 11 of Law 3471/2006, as detailed in recitals 11, 12(a), and 15 of this decision. iii. 00145% of the company’s turnover 39 in light of the specific circumstances of this case, in the amount of €130,000 34for the aforementioned established violation of Article 5 of the GDPR, as detailed in recital 14 of this decision, iv.
pursuant to Article 58(2)(d) of the GDPR, orders that, within a six-month period, amend the contracts with the contractors so that they contain explicit instructions on how to technically improve their their procedures so that failures such as those described in recitals 13 and 16 of this decision are not permitted to occur, v. pursuant to Article 58(2)(d) of the General Data Protection Regulation (GDPR), orders that, within a period of six months from the notification of this decision, it implement an audit procedure for its partner call centers, which shall include, at least twice a year, a full or sample-based inspection of a large number of outbound calls from each partner company, and to notify the Authority following the implementation of this procedure, taking into account the provisions set forth in recital 16(a) of this decision, vi. pursuant to Article 58(2)(d) of the GDPR, it orders that, within a period of six months, it improve its technical and organizational procedures so that failures such as those described in recitals 12(b) and 13–16 of this decision.
b. , a customer-service provider: i. pursuant to Article 58(2)(i) of the General Data Protection Regulation (GDPR), the effective, proportionate, and deterrent administrative fine appropriate to the specific case in light of its specific circumstances, in the amount of €20,000 35 for the aforementioned established violation of Article 32 of the GDPR, as detailed in recital 12(b) of this decision, ii. 070% of the company’s turnover 40 in accordance with the specific circumstances of this case, in the amount of €40,000 36 for the aforementioned established violation of Article 11 of Law 3471/2006, as detailed in recital 15 of this decision, iii. pursuant to Article 58(2)(d) of the General Data Protection Regulation (GDPR), orders that, within a period of six months, to technically improve its procedures so as to prevent failures such as those detailed in recitals 12(b) and 13 of this decision.
c. It orders SERVICE 800 - TELEPERFORMANCE SINGLE-MEMBER SOCIETE ANONYME SERVICE PROVIDER: i. pursuant to Article 58(2)(i) of the General Data Protection Regulation (GDPR), the effective, proportionate, and deterrent administrative fine appropriate to the specific case 37 in accordance with the specific circumstances of the case, in the amount of €50,000, for the aforementioned established violation of Article 32 of the General Data Protection Regulation, as detailed in recital 12(c) of this decision. ii. Pursuant to Article 58(2)(i) of the GDPR, the effective, proportionate, and deterrent administrative fine appropriate in this specific case in light of its specific circumstances, in the amount of €40,000 38 for the aforementioned established violation of Article 5 of the GDPR, as detailed in paragraph 14 of present decision. iii. Pursuant to Article 58(2)(d) of the GDPR, it orders that, within a six-month period, it must technically improve its procedures so as to prevent failures such as those described in recitals 12(c), 13, and 14 of this decision.
d. A. to: i. 0086% of the company’s turnover 41 in accordance with the specific circumstances of this case, in the amount of €45,000 39 for the aforementioned established violation of Article 32 of the GDPR, as detailed in recital 12(d) of this decision. ii. pursuant to Article 58(2)(i) of the GDPR, the effective, proportionate, and deterrent administrative fine appropriate in this specific case 40 in light of the specific circumstances of the case, in the amount of €55,000 for the aforementioned established violation of Article 11 of Law 3471/2006, as detailed in recital 15 of this decision, iii. pursuant to Article 58(2)(d) of the General Data Protection Regulation (GDPR), orders that, within a six-month period, to technically improve its procedures so as to prevent failures such as those detailed in recitals 12(d) and 13 of this decision. e. : i. pursuant to Article 58(2)(i) of the GDPR, an effective, proportionate, and deterrent administrative fine appropriate to the specific case in accordance with its particular circumstances, in the amount of €50,000 for the aforementioned established violation of Article 32 of the GDPR, as detailed in recital 12(e) of this decision, ii.
pursuant to Article 58(2)(i) of the GDPR, the effective, proportionate, and deterrent administrative fine appropriate in this specific case in light of its specific circumstances, in the amount of €30,000 for the aforementioned established violation of Articles 28 and 29 of the GDPR, as detailed in recital 12(e) of this decision, iii. pursuant to Article 58(2)(d) of the General Data Protection Regulation, orders that, within a period of six months, to technically improve its procedures so as to prevent failures such as those detailed in recitals 12(e) and 13 of this decision. 1929% of the company’s turnover 42The Vice Chair The Secretary Georgios Batzalexis Georgia Palaiologou 43