MEDE S.A. – €160,000 Fine (Greece, 2026)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
MEDE S.A. received a fine for not properly responding to a person's requests about their CCTV footage. The company failed to provide clear information about how they collected and used personal data. This case highlights the importance of being transparent with visitors about data practices, especially for businesses using surveillance systems.
What happened
MEDE S.A. did not adequately respond to a person's requests for information regarding their CCTV data collection and processing.
Who was affected
The person who submitted access requests regarding their personal data captured by MEDE S.A.'s CCTV systems was affected.
What the authority found
The Hellenic Data Protection Authority found that MEDE S.A. did not comply with GDPR requirements for transparency and access to personal data.
Why this matters
This ruling emphasizes that companies must be clear and responsive when individuals ask about their personal data. Businesses using CCTV should ensure they have proper privacy notices and procedures in place.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
Entities Involved
A data subject submitted access requests to “MEDE S.A.”, a company operating an exhibition centre (controller A), and “MARKET IN S.A.”, a supermarket chain (controller B). He requested information concerning the collection and processing of his personal data through their respective CCTV systems. In particular, he asked for the relevant privacy notices, information on the personal data processed, the recipients of those data and copies of CCTV material disclosed to third parties. He also submitted photographs which allegedly originated from the CCTV systems of both controllers. Both controllers initially requested further clarification. After the data subject clarified and repeated his request, they made clarifications concerning their CCTV policies and stated that they had never disclosed CCTV photographs depicting the data subject to third parties. They maintained that they could not answer the remaining questions. The data subject then lodged separate complaints with the Greek DPA (HDPA) against both controllers. He alleged that they had inadequately responded to his access requests, unlawfully processed his personal data through their CCTV systems and unlawfully disclosed CCTV material to third parties. Controller A claimed that its only active cameras were located at the entrance and on the ground floor of the exhibition centre and that they did not record sound. It stated that no recording had taken place on the first floor, where the data subject worked. Controller A further argued that it had lawfully used CCTV photographs to legal proceedings involving controller A, a third party and the data subject, in order to defend its legal rights. It further argued that the third party had obtained the CCTV material through the court file in those proceedings and did not receive them directly from it. According to controller B, following an incident outside its premises, its security guards manually turned the cameras towards the data subject’s vehicle, printed the r
Related Enforcement Actions (0)
No other enforcement actions found for MEDE S.A. in GR
This is the only recorded action for this entity in this jurisdiction.
Details
Fine Date
12 June 2026
Authority
Hellenic Data Protection Authority
Fine Amount
€160,000
GDPRhub ID
gdprhub-10087About this data
Cite as: Cookie Fines. MEDE S.A. - Greece (2026). Retrieved from cookiefines.eu
Last updated: