ZENITH SA (ΖΕΝΙΘ ΑΕ) – €110,000 Fine (Greece, 2026)

€110,000Hellenic Data Protection Authority5 June 2026Greece
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

ZENITH SA was fined for mishandling a customer's direct debit authorizations, leading to unauthorized payments. This case is important because it shows that companies must follow proper procedures when managing customer contracts and payment authorizations. Businesses should ensure they have clear processes to avoid similar issues.

What happened

ZENITH SA was fined for incorrectly processing direct debit payments after a customer did not authorize them.

Who was affected

A customer who had unauthorized direct debit payments taken from their bank account by ZENITH SA.

What the authority found

The Hellenic Data Protection Authority ruled that ZENITH SA failed to properly manage customer consent for direct debit payments, violating GDPR rules.

Why this matters

This case serves as a reminder for companies to have clear and accurate processes for handling customer authorizations. Proper management can prevent unauthorized transactions and protect customer trust.

GDPR Articles Cited

AI-verified

Art. 5(1)(d) GDPR
Art. 12(1) GDPR
Art. 12(3) GDPR
Art. 15(1) GDPR
Art. 28(1) GDPR
View original scraped data
Art. 5(1)(d) GDPR
Art. 12(1) GDPR
Art. 12(3) GDPR
Art. 15(1) GDPR
Art. 28(1) GDPR

Original data from scraper before AI verification against source document.

Entities Involved

ZENITH SA (ΖΕΝΙΘ ΑΕ)
€100,000
(controller)
Piraeus Bank
€10,000
(controller)
Source verified 11 July 2026
entity split needed
amount discrepancy
Full Legal Summary
Detailed

On 27 May 2020, a data subject entered into an electricity supply contract by telephone with the Greek energy provider ZENITH (controller A) for three service connections. The contract was concluded through controller A’s processor, Sigma and Kappa Import S.A. During the call, the data subject provided his bank account number (IBAN), at least for the purpose of paying one of the services by direct debit. On 4 June 2020, during a subsequent phone call with the processor, the data subject stated that he did not want the other two services to be paid by direct debit. When the relevant contract documents were later sent to him for signature, he signed only one of the three direct debit mandate forms. However, the data subject subsequently noticed that all three electricity bills were being paid by direct debit. On 13 August 2020, he contacted controller A to complain about the matter. Controller A replied on 2 September 2020 that two additional direct debit mandates had been activated inadvertently because its processor had failed to take the necessary steps. The data subject then repeatedly requested copies of the signed direct debit mandates, but claimed that controller A did not properly respond to those requests. The data subject also contacted his bank, Piraeus Bank (controller B), since the disputed payments were being made from his bank account. He argued that he had never authorised the two additional direct debit payments and made an access request on 16 February 2023, requesting copies of the direct debit mandates and information concerning their activation. Controller B replied that it acted only as an intermediary in the execution of payments and had a merely administrative role in the process. It did not provide copies of the mandates or access to the relevant electronic records held in its systems. On 22 October 2023, the data subject lodged two separate complaints with the Greek DPA (HDPA) against controller A and controller B, arguing that both controlle

Related Enforcement Actions (0)

No other enforcement actions found for ZENITH SA (ΖΕΝΙΘ ΑΕ) in GR

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

5 June 2026

Authority

Hellenic Data Protection Authority

Fine Amount

€110,000

GDPRhub ID

gdprhub-10118

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. ZENITH SA (ΖΕΝΙΘ ΑΕ) - Greece (2026). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: