Greek DPA issues decision on personal data breach at Hellenic Open University

Original title: Απόφαση για περιστατικό παραβίασης προσωπικών δεδομένων Ελληνικού Ανοικτού Πανεπιστημίου

The Greek Data Protection Authority (Hellenic DPA) issued Decision No. 14 on 15 July 2026 concerning a personal data breach incident at the Hellenic Open University. The decision addresses the handling of a data protection violation and establishes requirements for the institution's compliance with GDPR obligations regarding breach notification and data protection measures. Organizations operating in Greece must ensure they have adequate breach response procedures and notification protocols to meet regulatory expectations.

What changed

  • Greek DPA Decision No. 14 (15 July 2026) addresses a confirmed personal data breach at the Hellenic Open University, establishing regulatory expectations for breach handling and response procedures.
  • The decision sets precedent for how educational institutions in Greece must manage data protection incidents and demonstrates enforcement of GDPR obligations by the Greek supervisory authority.

Who is affected

Educational institutions in Greece, particularly universities and research organizations operating under Greek jurisdiction that process personal data subject to GDPR.

Summary generated by a language model; the official text prevails. Not legal advice.