APOEL – Court Ruling (Cyprus, 2026)

Court Ruling
Commissioner for Personal Data Protection12 May 2026Cyprus
final
Court Ruling

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

The Commissioner for Personal Data Protection in Cyprus found that UAB Whitebridge.ai failed to provide a user access to their personal data. This ruling emphasizes the need for companies to respond promptly to user requests for their data.

What happened

UAB Whitebridge.ai did not respond to a user's request for access to their personal data within the required timeframe.

Who was affected

A user who requested access to their personal data from UAB Whitebridge.ai.

What the authority found

The authority ruled that Whitebridge.ai violated GDPR rules by not providing the user access to their data as required.

Why this matters

This case serves as a reminder for companies to have efficient processes in place for handling data access requests. It reinforces the importance of transparency and user rights in data protection.

GDPR Articles Cited

AI-verified

Art. 25(GDPR)
Art. 28(GDPR)
Art. 33(GDPR)
Art. 24(1) GDPR
Art. 32(1) GDPR
View original scraped data
Art. 24(1) GDPR
Art. 25(GDPR)
Art. 28(GDPR)
Art. 32(1) GDPR
Art. 33(GDPR)

Original data from scraper before AI verification against source document.

Decision AuthorityCyprus Administrative Court
Reviewed AuthorityCPC_CY

Entities Involved

OMONIA
€40,000
(controller)
APOEL
€40,000
(controller)
Platform Provider
€25,000
(processor)
Source verified 16 May 2026
entity split needed
amount discrepancy
authority corrected
Full Legal Summary
Detailed

On 26 July 2021, a journalist informed the Cypriot DPA of a security vulnerability on an online platform. This online platform hosted ticket purchase sites of two Cypriot football clubs, OMONIA and APOEL (the controllers). This flaw in the system allowed a user to identify, through a reserved-seat icon, the name and ID number of the fan who had reserved the seat. By using that information, the user could then download the fan card, including the fan’s photograph. The DPA ordered the controllers to submit a personal data breach notification in accordance with Article 33 GDPR. In addition, it asked them to provide information on whether a penetration test had been carried out on the platform and to submit their contracts with the platform provider which acted as the processor of this data. Both controllers submitted the Personal Data Breach Notification Form and the requested documents. The DPA fined each controller €40.000 and the processor €25.000 for the violations of Article 24(1) GDPR, Article 25 GDPR and Article 32(1) GDPR. The controllers and the processor appealed the decision, mainly disputing their responsibility for the required security measures, their respective roles under the GDPR, and the proportionality of the fines. One of the controllers challenged only part of that fine. The court held that, by submitting the breach notification form, the controllers had accepted both that there had been a personal data breach under Article 33 GDPR and that they acted as controllers for the purposes of the GDPR. The court further held that the platform provider acted as a processor under the relevant contracts and was therefore bound by Articles 28 and 32 GDPR. The court upheld the DPA’s finding that the controllers and the processor had infringed the GDPR. It rejected one of the controllers’ arguments that it had no duty to carry out a penetration test before the platform was launched. The court held that Article 24 GDPR, Article 25 GDPR and Article 32 GDPR imp

Outcome

Court Ruling

A ruling by a national court on a data-protection matter.

Related Cases (0)

No other cases found for APOEL in CY

This is the only recorded case for this entity in this jurisdiction.

Details

Ruling Date

12 May 2026

Authority

Commissioner for Personal Data Protection

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. APOEL - Cyprus (2026). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: