MEDE S.A. – €160,000 Fine (Greece, 2026)

€160,000Hellenic Data Protection Authority12 June 2026Greece
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

MEDE S.A. received a fine for not properly responding to a person's requests about their CCTV footage. The company failed to provide clear information about how they collected and used personal data. This case highlights the importance of being transparent with visitors about data practices, especially for businesses using surveillance systems.

What happened

MEDE S.A. did not adequately respond to a person's requests for information regarding their CCTV data collection and processing.

Who was affected

The person who submitted access requests regarding their personal data captured by MEDE S.A.'s CCTV systems was affected.

What the authority found

The Hellenic Data Protection Authority found that MEDE S.A. did not comply with GDPR requirements for transparency and access to personal data.

Why this matters

This ruling emphasizes that companies must be clear and responsive when individuals ask about their personal data. Businesses using CCTV should ensure they have proper privacy notices and procedures in place.

GDPR Articles Cited

AI-verified

Art. 31(GDPR)
Art. 5(1)(a) GDPR
Art. 5(1)(b) GDPR
Art. 5(1)(c) GDPR
Art. 5(2) GDPR
Art. 12(1) GDPR
Art. 12(2) GDPR
Art. 13(1) GDPR
Art. 13(3) GDPR
Art. 15(1) GDPR
Art. 15(3) GDPR
Art. 37(7) GDPR
View original scraped data
Art. 5(1)(b) GDPR
Art. 5(1)(c) GDPR
Art. 5(1)(a) GDPR
Art. 5(2) GDPR
Art. 12(1) GDPR
Art. 12(2) GDPR
Art. 13(1) GDPR
Art. 13(3) GDPR
Art. 15(1) GDPR
Art. 15(3) GDPR
Art. 31(GDPR)
Art. 37(7) GDPR

Original data from scraper before AI verification against source document.

Entities Involved

MEDE S.A.
€65,000
(controller)
MARKET IN S.A.
€95,000
(controller)
Source verified 1 July 2026
entity split needed
amount discrepancy
Full Legal Summary
Detailed

A data subject submitted access requests to “MEDE S.A.”, a company operating an exhibition centre (controller A), and “MARKET IN S.A.”, a supermarket chain (controller B). He requested information concerning the collection and processing of his personal data through their respective CCTV systems. In particular, he asked for the relevant privacy notices, information on the personal data processed, the recipients of those data and copies of CCTV material disclosed to third parties. He also submitted photographs which allegedly originated from the CCTV systems of both controllers. Both controllers initially requested further clarification. After the data subject clarified and repeated his request, they made clarifications concerning their CCTV policies and stated that they had never disclosed CCTV photographs depicting the data subject to third parties. They maintained that they could not answer the remaining questions. The data subject then lodged separate complaints with the Greek DPA (HDPA) against both controllers. He alleged that they had inadequately responded to his access requests, unlawfully processed his personal data through their CCTV systems and unlawfully disclosed CCTV material to third parties. Controller A claimed that its only active cameras were located at the entrance and on the ground floor of the exhibition centre and that they did not record sound. It stated that no recording had taken place on the first floor, where the data subject worked. Controller A further argued that it had lawfully used CCTV photographs to legal proceedings involving controller A, a third party and the data subject, in order to defend its legal rights. It further argued that the third party had obtained the CCTV material through the court file in those proceedings and did not receive them directly from it. According to controller B, following an incident outside its premises, its security guards manually turned the cameras towards the data subject’s vehicle, printed the r

Related Enforcement Actions (0)

No other enforcement actions found for MEDE S.A. in GR

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

12 June 2026

Authority

Hellenic Data Protection Authority

Fine Amount

€160,000

GDPRhub ID

gdprhub-10087

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. MEDE S.A. - Greece (2026). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: