Hellenic DPA decision on a data breach involving E.E.T.A.A. S.A. as processor for the Ministry of Social Cohesion and Family Affairs

The Hellenic Data Protection Authority (DPA) investigated a large-scale personal data breach affecting the information systems of the Hellenic Agency for Local Development and Local Government (E.E.T.A.A.) S.A., which were used to implement programmes of the Ministry of Social Cohesion and Family Affairs. The Hellenic DPA found that the Ministry of Social Cohesion and Family Affairs, in its capacity as controller, had complied with its obligations concerning the notification of the breach to the Authority and its communication to the affected data subjects. However, the Authority found that the success of the attack was associated with E.E.T.A.A.’s continued use of outdated information systems and inadequate security measures, despite its awareness of the relevant risks. The DPA found infringements of the requirements relating to the security of processing, as well as deficiencies in compliance with the requirements of Article 28 GDPR governing the relationship between the controller and the processor. The Hellenic DPA imposed administrative fines of EUR 200 000 on the Ministry of Social Cohesion and Family Affairs and EUR 150 000 on E.E.T.A.A. the Ministry and E.E.T.A.A.) to enter into a data processing agreement pursuant to Article 28 GDPR and to fully implement the planned measures to strengthen the security of their information systems.

This article was collected and archived by Digital Sovereignty Watch from an institutional or public source relevant to digital sovereignty, technology policy, cybersecurity, cloud services, artificial intelligence or European regulation.

Read original source