Enforcement · Hellenic Data Protection Authority (HDPA) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Athens Urban Transport Organization: Non-compliance with general data processing principles
How it connects
Related across sources
Guidance Guidelines 4/2019 on Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020 Guidance Art. 29 WP Guidelines on GDPR transparency requirements (WP260 rev.01) Guidance Guidelines 05/2022 on the use of facial recognition technology in the area of law enforcement Guidance EDPB Annual Report 2021 Guidance Guidelines 10/2020 on restrictions under Article 23 GDPR Literature HOW GDPR TREATS AUTOMATED DECISION-MAKING
Full text
The Hellenic DPA imposed a fine of EUR 50,000 on the Athens Urban Transport Organization. As part of its investigation, the DPA found that the controller had failed to comply with the principle of data protection by design and by default. It also failed to carry out a data protection impact assessment and to set appropriate retention periods for the storage of personal data.
Industry: Transportation and Energy
Original document at the source www.dpa.gr