Skip to content
Enforcement · Hellenic Data Protection Authority (HDPA) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Vodafone – PANAFON A.E.E.T.: Insufficient technical and organisational measures to ensure information security

€550,000 Fine
Vodafone – PANAFON A.E.E.T.
GREECE
Art. 5 GDPR Art. 28 GDPR

How it connects

Full text

The Greek DPA has imposed a fine of EUR 550,000 on Vodafone – PANAFON A.E.E.T. The controller failed to implement sufficient technical and organisational measures to ensure data security, resulting in a telecommunications shop being able to wrongfully assign multiple SIM cards to an individual. The controller also failed to use a processor that could guarantee the implementation of sufficient technical and organisational measures, and failed to govern the processing with an adequate data processing agreement.

Industry: Media, Telecoms and Broadcasting

Similar Content