Cosmote – €9,100,000 Fine (Greece, 2021)

€9,100,000Hellenic Data Protection Authority30 November 2021Greece
final
ePrivacy
Fine

Cosmote, a mobile telecommunications company in Greece, was fined €9.1 million for mishandling personal data after a cyber attack. The company failed to protect sensitive subscriber information, which included phone numbers and personal details, leading to a significant breach. This case highlights the importance of strong data protection measures for businesses handling personal information.

What happened

Cosmote was fined for a data breach that exposed sensitive personal information of millions of subscribers due to inadequate security measures.

Who was affected

Millions of Cosmote subscribers whose personal data, including phone numbers and demographic information, was compromised in the breach were affected.

What the authority found

The Hellenic Data Protection Authority found that Cosmote violated multiple GDPR rules by not adequately protecting personal data and failing to ensure its security.

Why this matters

This ruling serves as a warning to all companies about the need for robust data protection practices. It emphasizes that failing to secure personal data can lead to severe financial penalties.

GDPR Articles Cited

AI-verified

Art. 13(GDPR)
Art. 14(GDPR)
Art. 26(GDPR)
Art. 28(GDPR)
Art. 32(GDPR)
Art. 5(1)(a) GDPR
Art. 5(1)(f) GDPR
Art. 5(2) GDPR
Art. 83(GDPR)
Art. 25(1) GDPR
Art. 35(7) GDPR
View original scraped data
Art. 5(1)(a) GDPR
Art. 5(1)(f) GDPR
Art. 5(2) GDPR
Art. 13(GDPR)
Art. 14(GDPR)
Art. 25(1) GDPR
Art. 26(GDPR)
Art. 28(GDPR)
Art. 32(GDPR)
Art. 35(7) GDPR
Art. 83(GDPR)

Original data from scraper before AI verification against source document.

National Law Articles

AI-identified

Article 2(3) and (4) Law 3471/2006
Article 5 Law 3471/2006
Article 6 Law 3471/2006
Article 12(1) and (5) and (6) Law 3471/2006

Entities Involved

Cosmote
OTE
Source verified 2 April 2026
articles corrected
national law identified
amount discrepancy
entity split needed
date discrepancy
scope corrected
Full Legal Summary
Detailed

In 2020 the mobile telecommunications company COSMOTE (part of the OTE group of companies) reported a personal data breach to the Helenic DPA (HDPA) caused by an external cyber attack. The starting point of the breach was a server of the OTE group, which has an annual turnover of €3,258 billion. The breach included a 30 GB file of personal data for the period of 01.09.2020 - 05.09.2020 from one of COSMOTE's servers. The file contained subscriber data of millions of people, and consisted of the following data: phone numbers, base station coordinates, IMEI, IMSI, timestamp, duration of the call, provider indicator, subscription plan, age, gender, average revenue per user. The general company policy of COSMOTE regarding this kind of data was the following: First, COSMOTE collected the following information: phone numbers, base station coordinates, IMEIs, IMSIs, timestamps, durations of calls, provider indicators. Second, COSMOTE stored this data for three months. It used it for its failure management system, that means detecting technical failures or errors in the transmission of communications. As a telecommunications company it is legally obligated to have an effective failure management system to provide uninterrupted services. Third, after three months it did not delete the data but supplemented the data with subscription plan, age, gender and the average revenue per person data. It “anonymised” this file, stored it up to 12 months and used it for statistical purposes to optimise the design of their mobile network. The breach consisted of this 30 GB supplemented file. The HDPA held that COSMOTE violated Articles 5 and 6 Law 3471/2006 (national law implementing the [https://eur-lex.europa.eu/legal-content/DE/ALL/?uri=celex%3A32002L0058 Directive 2002/58/EC Directive on privacy and electronic communications]). The processing and storage of traffic data can be permitted under Article 6 Directive 2002/58/EC for the purpose of issuing invoices, offering services of

Violations (1)

Cookies Placed Before Consent
critical

Non-essential cookies (tracking, advertising) are placed on the user's device before obtaining valid consent.

Art. 6(1) GDPR

Related Enforcement Actions (0)

No other enforcement actions found for Cosmote in GR

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

30 November 2021

Authority

Hellenic Data Protection Authority

Fine Amount

€9,100,000

GDPRhub ID

gdprhub-4584

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Cosmote - Greece (2021). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: