Skip to content
Content type · 47 documents

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

Country: Cyprus (47) Clear filter
€25,000 Bank of Cyprus Public Company Limited: Insufficient technical and organisational measures to ensure information security Cypriot Data Protection Commissioner fined Bank of Cyprus Public Company Limited €25,000 on 2025-08-05 for: Insufficient technical and organisational measures to ensure… Security Insurance Aug 5, 2025
€10,000 Housing Finance Corporation: Insufficient legal basis for data processing The Cypriot DPA has imposed a fine of EUR 10,000 on the Housing Finance Corporation. The controller stored client loan data for longer than necessary and did not ensure that the… Controllers Insurance Processing Agreement Mar 10, 2025
€3,000 Senira Limited: Insufficient cooperation with supervisory authority The Cypriot DPA fined Senira Limited EUR 3,000 for failing to sufficiently cooperate with the DPA. Supervisory Authorities Supervision Processing Agreement Sep 4, 2024
€1,500 Aylo Social LTD: Insufficient fulfilment of data subjects rights The Cypriot DPA has imposed a fine of EUR 1,500 on Aylo Social LTD for failing to comply with a deletion request. Processing Agreement Personal Data Supervisory Authorities Feb 8, 2024
€2,000 Brivio Limited: Insufficient fulfilment of data subjects rights The Cypriot DPA has imposed a fine of EUR 2,000 on Brivio Limited for failing to respond to a request for information in a timely manner. Personal Data Supervisory Authorities Processing Agreement Feb 8, 2024
€1,500 Physician: Non-compliance with general data processing principles The Cypriot DPA has imposed a fine of EUR 1,500 on a physician. An individual had filed a complaint with the DPA because the physician had accessed their personal data in a… Health Data Healthcare Healthcare Dec 7, 2023
€45,000 Open University of Cyprus: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 45,000 on Open University of Cyprus. The university had suffered a data breach involving hackers publishing personal data of students,… Data Breaches Security Privacy by Design & Default Nov 22, 2023
€9,000 NAGA Markets Europe Ltd: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 9,000 on NAGA Markets Europe Ltd. The controller had suffered a data breach in which an unknown person accessed the company's database,… Data Breaches Security Processing Agreement May 2, 2023
€3,250 Epic Ltd.: Insufficient legal basis for data processing The Cypriot DPA has imposed a fine of EUR 3,250 on Epic Ltd. The contoller had made unsolicited calls to 332 former customers without a valid legal basis. The DPA also found that… Processing Agreement Controllers Telecommunications Feb 3, 2023
€7,000 Πολίτης newspaper: Non-compliance with general data processing principles The Cypriot DPA has imposed a fine of EUR 7,000 on the newspaper 'Πολίτης'. The controller had unlawfully published the names and pictures of two police officers. Controllers IP Address Processing Agreement Jan 16, 2023
€8,000 Cypriot Ministry of the Interior: Non-compliance with general data processing principles The Cypriot DPA has imposed a fine of EUR 8,000 on the Cypriot Ministry of the Interior. The Ministry of Interior had unlawfully transmitted personal data of employees to the… Public Authority Personal Data IP Address Jan 1, 2023
€3,000 Breikot Management Ltd: Non-compliance with general data processing principles The Cypriot DPA has imposed a fine of EUR 3,000 on Breikot Management Ltd. The DPA found that the company had violated the principle of minimization by processing excessive… IP Address Personal Data Processing Agreement Jan 1, 2023
€8,000 Bank of Cyprus Public Company Ltd.: Non-compliance with general data processing principles The Cypriot DPA has imposed a fine of EUR 8,000 on Bank of Cyprus Public Company Ltd.. The controller had stored inaccurate data about a data subject in its system. Accuracy Controllers Personal Data Jan 1, 2023
€4,000 English School Cyprus: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 4,000 on the English School in Cyprus. The school had reported a data breach to the DPA under Art. 33 GDPR. A teacher had used the email… Data Breaches Security Public Sector Mar 22, 2022
€5,000 English School staff union (ESSA): Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 5,000 on the English School staff union (ESSA). The school had notified the DPA of a data breach under Art. 33 GDPR. A teacher, also a… Data Breaches Security Processing Agreement Mar 21, 2022
€10,000 Εκδοτικού Οίκου Δίας: Insufficient legal basis for data processing The Cypriot DPA has imposed a fine of EUR 10,000 on the publisher Εκδοτικού Οίκου Δίας. A public figure had filed a complaint with the DPA. The publisher had published incorrect… Personal Data Telecommunications Processing Agreement Feb 4, 2022
€5,000 Cypriot Ministry of Defense: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 5,000 on the Cypriot Ministry of Defense. The controller had suffered a cyber attack which, according to the DPA, had been caused due to… Security Public Sector Privacy by Design & Default Jan 1, 2022
€7,500 DW Dynamic Works LIMITED: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 7,500 on DW Dynamic Works LIMITED. The controller operated as a processor for the Cypriot Ministry of Denfese. The minsitry had suffered… Security Controllers Processors Jan 1, 2022
€5,000 Cyprus Electricity Authority: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 17,000 on Bank of Cyprus Public Company Ltd. In the context of a sale of credit facilities, the bank had inadvertently transferred data… Security Processing Agreement Privacy by Design & Default Jan 1, 2022
€5,000 DW Dynamic Works LIMITED: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 5,000 on DW Dynamic Works LIMITED. The controller operated as a processor for Hermes Airport Ltd.. Hermes had suffered a cyberattack… Security Controllers Processors Jan 1, 2022
€3,750 PRINTAFORM Ltd.: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 3,750 on PRINTAFORM Ltd. PRINTAFORM, which worked as a processor for Universal Life Insurance Public Co Ltd, had suffered a data breach… Data Breaches Security Processors Jan 1, 2022
€5,000 Cyprus Judo Federation: Insufficient cooperation with supervisory authority The Cypriot DPA has imposed a fine on the Cyprus Judo Federation. The father of a member had filed a complaint with the DPA because the judo coach of his minor son had published… Social Media Supervisory Authorities Processing Agreement Jan 1, 2022
€3,500 Universal Life Insurance Public Co Ltd.: Insufficient data processing agreement The Cypriot DPA has imposed a fine of EUR 3,500 on Universal Life Insurance Public Co Ltd. The processor of the data controller had suffered a data breach in which personal data… Controllers Processing Agreement Insurance Jan 1, 2022
€2,000 Oroklini Municipal Council: Insufficient cooperation with supervisory authority The Cypriot DPA has fined the Oroklini Municipal Council EUR 2,000 for not properly cooperating with the DPA during an investigation. Supervisory Authorities Public Sector Public Authority Jan 1, 2022
€6,000 Hermes Airport Ltd.: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 6,000 on Hermes Airport Ltd. The controller had suffered a cyber attack which, according to the DPA, had been caused due to a lack of… Security Controllers Processors Jan 1, 2022
€17,000 Bank of Cyprus Public Company Ltd.: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 17,000 on Bank of Cyprus Public Company Ltd. In the context of a sale of credit facilities, the bank had inadvertently transferred data… Security Processing Agreement Insurance Jan 1, 2022
€1,500 Physician: Insufficient cooperation with supervisory authority The Cypriot DPA has imposed a fine of EUR 1,500 on a physician. The DPA had conducted an investigation against the physician for the unlawful operation of a video surveillance… Supervisory Authorities Video Surveillance Monitoring Jan 1, 2022
€925,000 WS WiSpear Systems Ltd: Non-compliance with general data processing principles The Cypriot DPA has imposed a fine of EUR 925,000 on WS WiSpear Systems Ltd. The company had collected various data from individuals (Media Access Control addresses and… Fairness & Transparency IP Address Processing Agreement Nov 12, 2021
€10,000 Mediterranean Hospital of Cyprus: Insufficient cooperation with supervisory authority The Cypriot DPA has fined Mediterranean Hospital of Cyprus EUR 10,000 for failing to provide information requested by the DPA during an investigation. Supervisory Authorities Supervision Processing Agreement Sep 17, 2021
€25,000 Hellenic Technical Enterprises Ltd.: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 25,000 on Hellenic Technical Enterprises Ltd.. The controller hat designed the ticket sales system of the soccer clubs AC Omonia and… Security Controllers Processing Agreement Sep 6, 2021
€40,000 AC Omonia: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 40,000 on the soccer club AC Omonia. Due to a lack of security measures in the club's ticket sales system, it was possible for an… Security Personal Data Processing Agreement Sep 6, 2021
€40,000 APOEL FC: Insufficient technical and organisational measures to ensure information security The Cypriot DPA has imposed a fine of EUR 40,000 on the soccer club APOEL FC. Due to a lack of security measures in the club's ticket sales system, it was possible for an… Security Personal Data Processing Agreement Sep 6, 2021
€25,000 Hellenic Bank: Insufficient technical and organisational measures to ensure information security The Cypriot DPA imposed a fine of EUR 25,000 on Hellenic Bank. The bank had closed one of its branches in the city of Nicosia in 2015. When moving out of the space, a safe… Data Breaches Security Processing Agreement Mar 3, 2021
€40,000 Electricity Authority of Cyprus: Insufficient legal basis for data processing The Cypriot DPA imposed a fine of EUR 40,000 on the Electricity Authority of Cyprus. The controller used an automated system based on the so-called Brad-Factor to manage, monitor… Employees Controllers Personal Data Mar 3, 2021
€10,000 Cypriot Real Estate Registration Authority: Insufficient fulfilment of information obligations The Cypriot DPA imposed a fine of EUR 10,000 on the Cypriot Real Estate Registration Authority. The data subject submitted a written request to the controller requesting various… Right of Access Procedures Right of Access Public Authority Mar 3, 2021
€6,000 KEPIDES: Insufficient technical and organisational measures to ensure information security The Cypriot DPA imposed a fine of EUR 6,000 against KEPIDES (real estate company). The controller had submitted a list of buyers of the properties it manages to a parliamentary… Anonymization Security Controllers Mar 3, 2021
€6,000 Cyprus Police: Insufficient technical and organisational measures to ensure information security A police officer had unauthorized access to a database holding personal data about vehicle owners and used the database for non-official purposes to pass information from the… Integrity and Confidentiality Principle Data Breaches Security Oct 22, 2020
€15,000 Bank of Cyprus Public Company Ltd: Insufficient technical and organisational measures to ensure information security The data subject made a claim for access to information according to Art. 15 GDPR, which could not be answered, since the insurance contract of the data subject could not be found… Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Oct 19, 2020
€1,000 Grant Ideas Ltd: Insufficient legal basis for data processing Sending emails to data subjects without sufficient legal basis. Personal Data Processing Oct 19, 2020
€1,000 eShop for Sports (M.L. PRO.FIT SOLUTIONS LTD): Insufficient legal basis for data processing Sending SMS marketing messages without consent. In particular, no appropriate measures were taken, such as the possibility for telephone users to block marketing messages from the… Direct Marketing Consent Processing Jan 13, 2020
€9,000 Social Insurance Services of the Ministry of Labor, Welfare and Social Insurance: Insufficient technical and organisational measures to ensure information security Granting the police access to personal data and failing to take adequate measures to secure the data, despite the warnings of the Supervisor, constituted a breach of Article 32 of… Right of Access Security Insurance Jan 13, 2020
€10,000 LGS Handling Ltd, Louis Travel Ltd, and Louis Aviation Ltd: Insufficient legal basis for data processing The decision found that the use of the Bradford factor for profiling and monitoring sick leave constituted unlawful processing of personal data in breach of Article 6 and Article… Integrity and Confidentiality Principle Fines Audit Logs Oct 25, 2019
€2,000 LGS Handling Ltd, Louis Travel Ltd, and Louis Aviation Ltd: Insufficient legal basis for data processing The decision found that the use of the Bradford factor for profiling and monitoring sick leave constituted unlawful processing of personal data in breach of Article 6 and Article… Integrity and Confidentiality Principle Fines Audit Logs Oct 25, 2019
€70,000 LGS Handling Ltd, Louis Travel Ltd, and Louis Aviation Ltd: Insufficient legal basis for data processing The decision found that the use of the Bradford factor for profiling and monitoring sick leave constituted unlawful processing of personal data in breach of Article 6 and Article… Integrity and Confidentiality Principle Fines Audit Logs Oct 25, 2019
€14,000 Doctor: Insufficient legal basis for data processing A patient complained to the Commissioner that the request for access to her medical file was not satisfied by the hospital because the dossier could not be identified/located by… Healthcare Controllers Healthcare Jan 1, 2019
€5,000 State Hospital: Insufficient fulfilment of data subjects rights A patient complained to the Commissioner that the request for access to her medical file was not satisfied by the hospital because the dossier could not be identified/located by… Healthcare Healthcare Personal Data Jan 1, 2019
€10,000 Newspaper: Insufficient legal basis for data processing The publication of the newspaper, both in hard copy and in electronic form, allegedly involved inconvenience, unnecessary and unlawful detention of a citizen, and revealed the… Telecommunications Processing Law Enforcement Jan 1, 2019