# General Hospital of Thessaloniki: Insufficient technical and organisational measures to ensure information security

- Type: Enforcement
- Source: Hellenic Data Protection Authority (HDPA)
- Date: 2026-07-07
- Original: https://www.enforcementtracker.com/ETid-3297
- Canonical: https://overview.legal/posts/593139
- Topics: Supervisory Authorities, Data Breaches, Notification Obligation, Personal Data, Supervision, Transparency, Security

## Summary

The Hellenic Data Protection Authority (HDPA) fined the General Hospital of Thessaloniki €25,000 for failing to implement adequate technical and organizational measures to ensure the security of personal data, in violation of GDPR Articles 5(1)(f) and 32(1). The authority also found deficiencies in the hospital's transparency obligations under Articles 12 and 13, its breach notification duties under Articles 33 and 34, and its failure to appoint a Data Protection Officer as required by Article 37. The enforcement action arose in the healthcare sector in Greece.

## Full text

Hellenic Data Protection Authority (HDPA) fined General Hospital of Thessaloniki €25,000 on 2026-07-07 for: Insufficient technical and organisational measures to ensure information security.
GDPR Articles: Art. 5 (1) f) GDPR, Art. 12 GDPR, Art. 13 GDPR, Art. 32 (1) GDPR, Art. 33 (1) GDPR, Art. 34 (1) GDPR, Art. 37 GDPR
Sector: Health Care
Country: Greece
Source: http://www.dpa.gr/sites/default/files/2026-09/13_2026%20anonym.pdf

---
Generated by overview.legal · https://overview.legal/posts/593139 · 2026-10-08
