DPA Greece fines Vodafone for data breach and inadequate security measures

Original title: Επιβολή προστίμου στη Vodafone για περιστατικό παραβίασης και ανεπαρκή μέτρα ασφάλειας

The Greek Data Protection Authority (DPA) has issued a fine to Vodafone for a data breach incident and for failing to maintain adequate security measures. This decision demonstrates the DPA's enforcement of GDPR requirements regarding data protection and security obligations. Organisations operating in Greece must ensure robust security controls and proper incident response procedures to comply with data protection regulations.

What changed

  • DPA Greece (Decision 28/25.06.2025) issued an administrative fine against Vodafone for a data breach incident and inadequate security measures as required under GDPR Article 83

Who is affected

Telecommunications companies and data controllers operating in Greece; organisations subject to GDPR requirements

Summary generated by a language model; the official text prevails. Not legal advice.