Cosmote – €9,100,000 Fine (Greece, 2021)
Cosmote, a mobile telecommunications company in Greece, was fined €9.1 million for mishandling personal data after a cyber attack. The company failed to protect sensitive subscriber information, which included phone numbers and personal details, leading to a significant breach. This case highlights the importance of strong data protection measures for businesses handling personal information.
What happened
Cosmote was fined for a data breach that exposed sensitive personal information of millions of subscribers due to inadequate security measures.
Who was affected
Millions of Cosmote subscribers whose personal data, including phone numbers and demographic information, was compromised in the breach were affected.
What the authority found
The Hellenic Data Protection Authority found that Cosmote violated multiple GDPR rules by not adequately protecting personal data and failing to ensure its security.
Why this matters
This ruling serves as a warning to all companies about the need for robust data protection practices. It emphasizes that failing to secure personal data can lead to severe financial penalties.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
National Law Articles
Entities Involved
In 2020 the mobile telecommunications company COSMOTE (part of the OTE group of companies) reported a personal data breach to the Helenic DPA (HDPA) caused by an external cyber attack. The starting point of the breach was a server of the OTE group, which has an annual turnover of €3,258 billion. The breach included a 30 GB file of personal data for the period of 01.09.2020 - 05.09.2020 from one of COSMOTE's servers. The file contained subscriber data of millions of people, and consisted of the following data: phone numbers, base station coordinates, IMEI, IMSI, timestamp, duration of the call, provider indicator, subscription plan, age, gender, average revenue per user. The general company policy of COSMOTE regarding this kind of data was the following: First, COSMOTE collected the following information: phone numbers, base station coordinates, IMEIs, IMSIs, timestamps, durations of calls, provider indicators. Second, COSMOTE stored this data for three months. It used it for its failure management system, that means detecting technical failures or errors in the transmission of communications. As a telecommunications company it is legally obligated to have an effective failure management system to provide uninterrupted services. Third, after three months it did not delete the data but supplemented the data with subscription plan, age, gender and the average revenue per person data. It “anonymised” this file, stored it up to 12 months and used it for statistical purposes to optimise the design of their mobile network. The breach consisted of this 30 GB supplemented file. The HDPA held that COSMOTE violated Articles 5 and 6 Law 3471/2006 (national law implementing the [https://eur-lex.europa.eu/legal-content/DE/ALL/?uri=celex%3A32002L0058 Directive 2002/58/EC Directive on privacy and electronic communications]). The processing and storage of traffic data can be permitted under Article 6 Directive 2002/58/EC for the purpose of issuing invoices, offering services of
Violations (1)
Non-essential cookies (tracking, advertising) are placed on the user's device before obtaining valid consent.
Art. 6(1) GDPR
Related Enforcement Actions (0)
No other enforcement actions found for Cosmote in GR
This is the only recorded action for this entity in this jurisdiction.
Similar Cases
Enforcement actions with similar violations
Details
Fine Date
30 November 2021
Authority
Hellenic Data Protection Authority
Fine Amount
€9,100,000
GDPRhub ID
gdprhub-4584About this data
Cite as: Cookie Fines. Cosmote - Greece (2021). Retrieved from cookiefines.eu
Last updated: