HDPA: Hellenic Open University found to have met breach notification duties after
The Hellenic Open University (‘the controller’) submitted initial and supplementary notifications to the DPA after it was subject to a data breach resulting from a ransomware attack.
Original title: HDPA (Greece) - 14/2026
Holding
The DPA held that the controller complied with its notification obligations under Article 33 and Article 34 GDPR, despite the initial notification being supplemented at a later time. Regarding the controller’s compliance with Article 32 GDPR (i.e. the obligation to implement adequate security measures), the DPA held that the cause of the incident was a human error, which could have been prevented through targeted training and improved authentication measures with individuals which have access to the system administration. In accordance with Article 58(2)(d) GDPR, the DPA ordered the controller to implement targeted training plans for system administrators and to fully implement the security measures mentioned above, within 6 months of this decision and to inform the DPA of such.
From GDPRhub’s case note — a summary of the decision, not its own words. Read it in the text ↓
The breach affected the personal data of 30,000 individuals in the controller’s information system and involved a leak of 813 GB of personal data that was later posted on the dark web but with restricted access as to its content. After respective requests and instructions by the DPA, the controller communicated the data breach to the affected individuals in accordance with Article 34 GDPR since the DPA considered a public notice insufficient. The controller also provided the DPA with further information, amongst others, regarding the nature of the breach and personal data affected. The controller took measures to prevent successful installation of malware in the future and to prevent future incidents and take measures to mitigate damage to affected parties, in accordance with Article 33 GDPR.
Full text 18 findings
Machine translation of the decision, via GDPRhub — not the official text. Read the original
Athens, July 15, 2026 Ref. No.: 3164 DECISION 14/2026 The Data Protection Authority (hereinafter the “Authority”), met, following an invitation from the acting Chair, Deputy , Georgios Batzalexis, for a meeting via teleconference on November 4, 2025, in order to examine the case referred to in the background section of this decision. Present at the meeting were the Authority’s Deputy Chair, Georgios Batzalexis, and the regular members Spyridon Vlachopoulos, Konstantinos Lambrinoudakis, Charalambos Anthopoulos, Christos Kalloniatis, and Katerina Iliadou, as well as the alternate members Demosthenes Vougioukas, serving as rapporteur, and Maria Psalla, replacing regular member Grigoris Tsolias, who, although duly summoned in writing, was unable to attend due to a conflict of interest. Also present, by order of the Vice President, without the right to vote, were Georgia Panagopoulou and Ioannis Lykotrafitis, IT specialists, serving as assistant rapporteurs, and Irini Papageorgopoulou, an employee of the Authority’s Administrative Affairs Department , as secretary. The Authority took the following into account: The Hellenic Open University (hereinafter “HOU”) submitted to the Authority, pursuant to Regulation (EU) 2016/679 (General Data Protection Regulation—hereinafter GDPR), the initial notification of a personal data breach, ref. no. Γ/ΕΙΣ/8375/31-10-2024, regarding a personal data breach, which was subsequently supplemented by the supplementary notification bearing ref. no. Γ/ΕΙΣ/8569/07-11-2024.
According to the notification, the incident consists of a breach of the confidentiality and availability of the Hellenic Open University’s personal data, as a result of a malicious external ransomware attack on its information systems. The breach affects approximately 30,000 data subjects, including students, graduates, faculty, administrative staff, and HOU suppliers, whom the HOU states have been notified due to the grave nature of the potential consequences of the incident. Specifically, it is noted that this was done, on the one hand, through an announcement on the main website (www.eap.gr) for the academic community and stakeholders (students, alumni, faculty, administrative staff, suppliers), and, on the other hand, through announcements and email messages for faculty and administrative staff. Copies of the relevant updates/announcements are attached to this supplementary notification. Finally, the Hellenic Open University notes that, since this is a ransomware attack by the RansomHub cyber-extortion group, it is necessary to conduct a thorough investigation to fully determine the nature of the breach and the instance in which personal data has been compromised. After reviewing the initial and supplementary notifications, the Authority sent document no. Γ/ΕΞΕ/3339/26-11-2024 to the Hellenic Open University, requesting that it to submit, within a reasonable period of time, a new supplementary or complete/final notification clarifying points such as: the nature of the breach and the instance in which personal data has been compromised, the security measures taken before and after the incident, as well as the results of its investigation, along with the relevant evidence. Furthermore, the Authority, in the same document, requested the EAP to specify whether any further specific information provided to the affected individuals regarding the actions they should take to protect themselves. Since the EAP had not submitted any new supplementary or complete/final notification or any other written update, the Authority, in its ref. no. Γ/ΕΞΕ/536/07-02-2025, again requested EAP to provide the aforementioned requested information or other relevant written information regarding the reasons for the delay in responding to its letter. Subsequently, the EAP submitted a second supplementary notification of a personal data breach, bearing ref. no. Γ/ΕΙΣ/1364/14-02-2025 second supplementary notification of a personal data breach, informing the Authority, among other things, that the investigation into the incident is ongoing and that a file 813 GB in size has reportedly been leaked and posted on a dark web platform, although full access to its contents has not yet been possible. For this reason, the EAP notes that it has not yet issued a specific notification to the data subjects, as it first wishes to identify the data subjects whose personal data is contained in this file. The Authority then, in document no. Γ/ΕΞΕ/766/06-03-2025, instructed the EAP to immediately notify all potential data subjects of the personal data breach, in accordance with Article 34(4) of the GDPR. In this document, the Authority notes, among other things, that even if the EAP is unable to determine with accuracy which data subjects have been affected by the breach, due to the volume of the database available online to anyone interested, it is safer for the rights and freedoms of the data subjects to assume that the data of all data subjects held in the EAP’s records of the Hellenic Open University. Public announcement, in this specific case, is not considered an appropriate means of effectively informing the data subjects. Failure to notify even a single data subject whose data (including, possibly, identification information and credit card payment details) may have been compromised, combined with the likely malicious intent of those responsible for the breach, can have an impact on the data subject or even cause serious harm. Furthermore, notifying data subjects of the data breach directly allows for the provision of specific information, tailored to the personal data held for each category of data subject, regarding the risks posed by the breach and the 3actions these data subjects can take to protect themselves from the potential negative consequences of the breach. The Hellenic Open University (HOU) responded to the above directive issued by the Authority with document no. C/EIS/6684/16-07-2025, to which is attached the March 28, 2025 public detailed notice informing data subjects, pursuant to the App relevant order of the Authority, regarding the circumstances and facts of the breach, the protective measures, and the Directives for the necessary preventive measures to be taken by each data subject, as well as the final report from the investigation of the incident. The above includes, among other things, the following: Regarding the method of attack, it is described in Confidential Appendix B, Point 1. The above EAP document also states that: “Prior to the incident, the EAP had procured, through competitive procedures for specialized information security software, which, during the period of their installation and implementation, were recognized as leading tools in the field for which they were procured. The Hellenic Open University (HOU) had been continuously educating users on the proper use of information systems and the risks of the internet. Although the HOU successfully and frequently thwarts attacks of various kinds at different levels of its services , in this particular attack it was not possible to fully prevent the full extent of the attack and its consequences, as attack techniques were used that were aimed at misleading end users, with the goal of gaining unauthorized access to internal systems.” Furthermore, regarding the handling of the incident and the notification of data subjects regarding the incident, relevant reports/complaints were submitted to the Authority, which were forwarded to the EAP with corresponding 1https://www.eap.gr/2025/03/28/enimerosi-skhetika-me-entopismeno-peristatiko-kakovoulis- epithesis/ 4transmission documents. The relevant documents are listed in Appendix A of this document. Regarding the manner in which the EAP handled and responded to the requests and inquiries submitted to it by data subjects and their legal representatives, the following is stated: “Responses are provided personally to each data subject – sender, in accordance with the provisions set forth in the Authority’s order dated March 6, 2025. It was further determined, subject to any subsequent clarification to the contrary – recommendation from the Authority—that, given the obligation for all students, faculty, etc., to visit the Hellenic Open University website for a series of matters, the posting of the attached detailed announcement complies with the letter and spirit of the law and the Authority’s decision, whereas the attempt to provide written, personalized, and individual notifications to all affected parties— numbering over 36,000—not only poses an obvious risk unjustified disruption, constitutes, in our view, an unnecessary method that would require a disproportionate effort under Article 33 of Law 4624/2019 both on the part of the administrator and on the part of the Authority.” Subsequently, the Authority summoned the EAP via letter ref. no. Γ/ΕΞΕ/3027/01-09- 2025, to a hearing via teleconference. The following individuals joined the teleconference: A, Rector of the Hellenic Open University; B, Vice Rector for Finance and Infrastructure; C, Vice Rector for Research and Innovation, and the HOU’s authorized Lawyers Network & Information Services, and F, Associate at the Network & Information Services office of the Hellenic Open University. Subsequently, the Hellenic Open University submitted, within the prescribed deadline, the memorandum bearing ref. no. Γ/ΕΙΣ/9334/26- 09-2025, along with the relevant supporting documents. The aforementioned memorandum was supplemented by document no. Γ/ΕΙΣ/9674/02-10-2025, which contained the letters sent by the Hellenic Open University to the individuals who filed appeals to the Authority (see Appendix A), as well as by document No. Γ/ΕΙΣ/9675/02-10-2025 , which contained a copy of the email sent to data subjects who have an email account with the Hellenic Open University. It should be noted that, although reference was made to the document with ref. no. Γ/ΕΙΣ/6684/16-07- 52025 regarding the specific notification of data subjects via personal e-mail messages, the content of said notification email was submitted to the Authority with the supplementary document bearing ref. no. Γ/ΕΙΣ/9675/02-10- 2025 from the EAP. Specifically, in the aforementioned memorandum, the EAP briefly states, among other things, the following: Regarding the notification of data subjects, it is stated that “… the EAP , in full compliance with the Authority’s directive, proceeded, on the one hand, to post a detailed announcement on its website on March 28, 2025, with an extensive description of the incident, the nature of the breach, the risks, and the specific individual protective measures that are recommended and that each data subject must take; and, second, a mass email campaign notifying recipients of the incident, which was sent during the first week of April 2025 through April 13, 2025, along with further protection Directives, to all data subjects listed in the an institutional email account, namely to students, alumni, instructors, faculty members, and administrative university administrative staff, estimated at approximately 108,000.” Regarding the causes of the incident, the information provided in Confidential Appendix B is reiterated, Point 1. The key details of the security measures related to the incident that had been taken prior to the incident are described in Confidential Annex B, Point 2. The key details of the security measures taken after the incident are described in Confidential Annex B, Point 3. The Authority, after reviewing the case file and hearing the rapporteur and the clarifications provided by the assistant rapporteurs, who were present without the right to vote, and following a thorough discussion, HAS DECIDED IN ACCORDANCE WITH THE LAW 61 From the provisions of Articles 51 and 55 of the GDPR and Article 9 of Law 4624/2019 (Government Gazette A’ 137), it follows that the Authority has the competence to supervise the implementation of the provisions of the GDPR, this Law, and other regulations concerning the protection of individuals with regard to the processing of personal data.
According to article 4(12) of the GDPR, a “data breach” means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure or unauthorized access to personal data that has been transmitted, stored, or otherwise processed.”
According to Article 4(1) of the GDPR, personal data is “any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one whose identity can be determined, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier identifier, or one or more factors specific to the physical, physiological, genetic, psychological, economic, cultural, or social identity of that natural person.”
Article 5(1) of the GDPR sets forth the principles governing the processing of personal data. These include the principle of integrity and confidentiality (subparagraph (f)), according to which data must be processed in a manner that ensures the appropriate security of personal data, including, among other things, its protection against unauthorized or unlawful processing and accidental loss, destruction, or damage, through the use of appropriate technical or organizational measures.
Furthermore, in accordance with the principle of accountability introduced by the second paragraph of the aforementioned Article 5, it is expressly stipulated that the controller “shall be responsible for and able to demonstrate compliance with paragraph 1 (“accountability”)”. This principle, which constitutes a cornerstone of the GDPR, entails the controller’s obligation to 7 design, implement, and generally adopt the necessary measures and policies, so that data processing complies with the relevant legal provisions and, furthermore, to be able to demonstrate at any time compliance with the principles of Article 5(1) of the GDPR.
In accordance with the definitions in Article 25 of the GDPR: “1. Taking into account the latest developments, the cost of implementation, and the nature, scope, the context and the processing purposes, as well as the risks of varying likelihood and severity to the rights and freedoms of natural persons arising from the processing, the controller shall implement, effectively, both at the time of defining processing methods and during the processing itself, appropriate technical and organizational measures, such as pseudonymisation, designed to implement data protection principles, such as data minimisation, and to incorporate the necessary safeguards into the processing in such a way as to meet the requirements of this Regulation and to protect data subject rights.”
Article 32(1) and (2) of the GDPR stipulate that: “1. Taking into account the latest developments, the costs of implementation, and the nature, scope, context, and processing purposes, as well as the risks of varying likelihood and severity to the rights and freedoms of natural persons, the controller and the processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risks (…) 2 When assessing the appropriate level of security , particular account shall be taken of the risks arising from the processing, in particular from accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access to personal data that has been transmitted, stored, or otherwise processed .”
According to Article 33 of the GDPR: “1. In the event of a personal data breach, the controller shall notify without undue delay and, 8 if possible, within 72 hours of becoming aware of the incident, the personal data breach to the SA that is competent pursuant to Article 55, unless the personal data breach is unlikely to pose a risk to the rights and freedoms of natural persons. Where the notification to the supervisory authority is not made within 72 hours, it shall be accompanied by a justification for the delay. (...) 3 The notification referred to in paragraph 1 shall, as a minimum: (a) describe the nature of the data breach , including, where possible, the categories of data and the approximate number of data subjects affected, as well as the categories and approximate number of affected personal data records; (b) provides the name and contact information of the data protection officer or another point of contact from which further information can be obtained; c) describe the potential consequences of the data breach , (d) describes the measures taken or proposed to be taken by the controller to address the personal data breach, as well as, where appropriate, measures to mitigate any potential adverse consequences thereof. 4 If and to the extent that it is not possible to provide this information simultaneously, it may be provided in stages without undue delay. 5 The controller shall document any personal data breach , consisting of the facts pertaining to the personal data breach, the consequences, and the corrective measures taken. Such documentation shall enable the SA to verify compliance with this article.”
Pursuant to Article 34 of the GDPR: “1. Where a personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall notify the data subject of the personal data breach without undue delay 9 of the data subject. 2 The notification to the data subject referred to in paragraph 1 of this article shall clearly describe the nature of the personal data breach and shall contain at least the information and measures referred to in article 33 paragraph 3, subparagraphs (b), (c), and (d). 3 The notification to the data subject referred to in paragraph 1 is not required if any of the following conditions are met: (a) the controller has implemented appropriate technical and organizational protection measures, and the measures (a) the controller has implemented appropriate technical and organizational measures for data protection, and those measures were applied to the personal data affected by the data breach , in particular measures that render the personal data unintelligible to anyone who is not authorized to access it, such as (b) the controller subsequently took measures to ensure that the high risk to the rights and freedoms of data subjects referred to in paragraph 1 to the data subject rights and freedoms; (c) it would require disproportionate effort. In this case, a public announcement is made instead, or a similar measure is taken to inform the data subjects in an equally effective manner. 4 If the controller has not already notified the data subject of the personal data breach, data subject, the SA may, after assessing the likelihood of high risk arising from the data breach , require the controller to do so, or may decide that any of the conditions referred to in paragraph 3 are met.”
The security obligation set forth in Article 32 of the GDPR constitutes a “means” obligation rather than a “results” obligation and imposes on the data controller in processing, to take appropriate technical and organizational measures, which, taking into account the characteristics of specific processing, are intended both to reduce the likelihood of a personal data breach occurring and to limit its severity should a risk materialize. Therefore, 10 security measures are not required to eliminate every form of risk, and the mere occurrence of a personal data breach does not, in and of itself, a violation of Article 32 of the GDPR. The above interpretation has been confirmed by the Court of Justice of the European Union in its decision 2 in Case C-340/21 (see paragraphs 29–31), in which it was held that the reference in Article 32(1) and (2) of the GDPR to a “security level appropriate to the risk” and to an “appropriate level of security” demonstrates that the GDPR establishes a risk management framework and does not aim to eliminate the risks of personal data breaches. From the wording of Articles 24 and 32 of the GDPR, it follows that these provisions impose on the controller the obligation to adopt technical measures for processing and organizational measures with the purpose of preventing, to the extent possible, personal data breaches. The appropriateness of these measures must be assessed on a case-by-case basis, taking into account the criteria set forth in the above articles, as well as the specific data protection needs and the risks arising from the specific processing. Consequently, Articles 24 and 32 of the GDPR cannot be be interpreted to mean that the unauthorized disclosure of or access by a third party to personal data is, in and of itself, sufficient to conclude that the security measures taken were inadequate, without affording the data controller the opportunity to rebut that conclusion. Furthermore, the Court recalled that this interpretation is confirmed by the combined reading of Articles 24 and 32 of the GDPR with Article 5 para 2 and Article 82 of the same Regulation, in light of recitals 74, 76 and 83 thereof, from which it follows, in particular, that the controller is required to mitigate the risks of personal data breaches rather than to prevent every data breach (January 25, 2024, C-687/21, para. 39). Consequently, a breach of the security obligation under article 32 of the GDPR 2 (Case C-340/21, Natsionalna agentsia za prihodite) - https://eur-lex.europa.eu/legal- content/EN/TXT/?uri=CELEX:62021CA0340 11 may be established regardless of whether a personal data breach has occurred .
Therefore, the Authority may impose a fine not for the occurrence of a personal data breach per se, but for the fact that the breach in question was made possible or facilitated by the absence or inadequacy of the security measures implemented by the controller , taking into account current technological capabilities and security practices currently considered best practices (state-of-the- art).
With regard to the assessment of the data controller’s obligation to implement appropriate measures , the Court has ruled that the adequacy of technical and organizational measures must be assessed in two stages: first, by identifying the risks of personal data breaches posed by the specific processing and their potential consequences on the rights and freedoms of natural persons, taking into account their likelihood and severity; and second, by examining whether the measures taken by the controller are appropriate to those risks, taking into account the state of the art, the costs of implementation, as well as the nature, scope, context, and processing purposes (Dec. 14, 2023, C-340/21, paragraph 42).
Consequently, the Authority does not examine the data breach in and of itself, but assesses whether, taking into account the state of the art, the characteristics of the processing, the likelihood and severity of the risks, as well as the extent of the security obligation, the EAP complies with the obligations imposed by Article 32 of the GDPR, having implemented appropriate technical and organizational measures.
In the present case, the evidence in the case file indicates that the controller complied with the obligations of controllers arising from the aforementioned 12 Articles 33 and 34 of the GDPR regarding the handling of personal data breach incidents personal data, given that: (a) it submitted the relevant notification to the Authority within seventy-two (72) hours of becoming aware of the incident, b) the notification, as completed, provides all the information required under Article 33 of the GDPR, c) it conducted a risk assessment for the affected data subjects due to the incident and notified them, in accordance with the relevant provisions of Art. 34 of the GDPR, following the relevant order issued by the Authority (Ref. No. Γ/ΕΞΕ/766/06-03-2025). It should be noted that the facts that led to the Authority’s order are not being reexamined, as they were already the subject of the Authority’s aforementioned decision. Consequently, this document does not examine any potential violation of Article 34, and following the implementation of the aforementioned order, there is no longer any need to examine the provision in question. d) Regarding the causes of the incident and compliance with Art 32 of the GDPR: The distribution of the malware was made possible by a human error, which could have been prevented through even more targeted training as well as improvements to authentication measures for Users with system administration privileges. The fact that the malware was able to scan the network and exploit security vulnerabilities suggests that, despite the implementation of robust security practices, the internal network configuration did not function effectively enough to prevent this specific method of intrusion and propagation. In particular, regarding the inadequate isolation of the internal network prior to the incident, this is also implied by the fact that one of the security measures that EAP decided to implement after the incident included a reassessment and redesign of its internal network, as described in Section 3 of Appendix B.
The handling of the incident is deemed adequate, taking into account the actions taken by the EAP, both to recover the encrypted data—even though this was not successful—to 13 restore the operation of its systems, and for taking appropriate measures to prevent a similar successful installation of malicious software in the future. In other words, following the incident, the Hellenic Open University took all possible corrective actions regarding security measures to prevent future security incidents, as well as actions to mitigate any damage to affected parties (such as providing updates both through its website as well as directly via email).
It also responded in full to each of the reports/complaints listed in Appendix A .
The Authority, taking the above into account, and considering, on the one hand, the large number of affected data subjects and, on the other hand, that the data controller has undertaken adequate processing to address the incident and to prevent a similar incident in the future, while also taking into account the cost of implementing these measures, considers that the appropriate corrective measure is the order pursuant to Article 58(2)(b) of the GDPR. FOR THESE REASONS The Authority, pursuant to Article 58(2)(e) of the General Data Protection Regulation, orders the Hellenic Open University to undertake targeted training initiatives for data controllers, as well as to fully implement all of the measures referred to in Recital 14, para (d), which it has already planned, within an exclusive deadline of six (6) months from the receipt of this letter, and to inform the Authority accordingly by submitting the appropriate documentation. 14 The Acting Chair Deputy Chair The Secretary Georgios Batzalexis Irini Papageorgopoulou 15