AEGEAN BUNKERING SERVICES INC (ABS) – €150,000 Fine (Greece, 2019)

€150,000Hellenic Data Protection Authority19 December 2019Greece
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

The Hellenic Data Protection Authority fined AEGEAN BUNKERING SERVICES INC (ABS) EUR 150,000 for failing to protect personal data and not complying with GDPR rules. ABS had unauthorized access to their data room, leading to data being copied and a clone server being created. This case highlights the importance of securing personal data and following GDPR requirements.

What happened

ABS was fined for failing to protect personal data and not complying with GDPR rules after unauthorized access to their data room.

Who was affected

People related to ABS, whose digital documents and communications were accessed without authorization.

What the authority found

The authority decided that ABS failed to comply with GDPR by not securing personal data and ignoring compliance requirements.

Why this matters

This case underscores the need for companies to secure personal data and comply with GDPR requirements. It serves as a reminder that failing to protect data can result in significant fines and legal consequences.

GDPR Articles Cited

AI-verified

Art. 32 GDPR
Art. 33 GDPR
Art. 5(1) GDPR
Art. 5(2) GDPR
Art. 6(1) GDPR
Art. 58(2)(d) GDPR
Art. 58(2)(i) GDPR
Art. 83(5)(a) GDPR
View original scraped data
Art. 5(1) GDPR
Art. 5(2) GDPR
Art. 6(1) GDPR
Art. 32 GDPR
Art. 33 GDPR
Art. 58(2)(d) GDPR
Art. 58(2)(i) GDPR
Art. 83(5)(a) GDPR

Original data from scraper before AI verification against source document.

Entities Involved

AEGEAN BUNKERING SERVICES INC (ABS)
ERNST&YOUNG HELLAS CERTIFIED AUDITORS-ACCOUNTANTS (EY Greece)
Aegean Marine Petroleum Network Inc. (AMPNI) (Reorganised as Minerva Bunkering)
Source verified 6 March 2026
verified correct
Full Legal Summary
Detailed

ABS filed a complaint against companies AMPNI and EY Greece for alleged violations of Article 33 GDPR. According to the complainant people related to the defendants entered without authorisation ABS's data room and illegally copied to mobile data carriers the entire digital content of the server which contains digital documents, e-mails and other electronic communications of ABS's employees with third parties as well as of third parties' employees. Then, these people created a clone server. Further, 11 other complaints filed before the HDPA by data subjects in relation to this incident. The DPA had to assess whether there was violation by both defendants regarding the notification obligation for personal data breaches to the supervisory authority. The HDPA ordered AMPNI as the data controller in this case to bring the processing operations at stake into compliance with the GDPR within three months from the receipt of this decision as foreseen under Article 58(2)(d) GDPR. The company must take all necessary measures for internal compliance and accountability according to Article 5(1) GDPR, Article 5(2) GDPR and Article 6(1) GDPR. Since the company had totally ignored the its compliance with the mentioned provisions, the HDPA issued a fine EUR 150,000 according to Article 58(2)(i) GDPR and Article 83(5)(a) GDPR.

Related Enforcement Actions (0)

No other enforcement actions found for AEGEAN BUNKERING SERVICES INC (ABS) in GR

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

19 December 2019

Authority

Hellenic Data Protection Authority

Fine Amount

€150,000

GDPRhub ID

gdprhub-1989

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. AEGEAN BUNKERING SERVICES INC (ABS) - Greece (2019). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: