Υπουργείο Κοινωνικής Συνοχής και Οικογένειας – €200,000 Fine (Greece, 2026)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
Greece's Hellenic Data Protection Authority fined the Ministry of Social Cohesion and Family €200,000 for a data breach affecting over 2.5 million people. The breach involved sensitive personal information from two programs aimed at supporting families and children. This ruling stresses the importance of safeguarding personal data in government systems.
What happened
The Ministry of Social Cohesion and Family was fined for a data breach that exposed personal data of approximately 2.5 million individuals.
Who was affected
Around 2.5 million people, including children and their families, were affected by the data breach.
What the authority found
The authority found that the Ministry did not adequately protect personal data, violating GDPR's requirements for data security and processing.
Why this matters
This case serves as a warning to public agencies about the need for robust data protection measures. Organizations handling large amounts of personal data must prioritize security to prevent breaches.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
Entities Involved
The Ministry of Social Cohesion and Family (the controller), and the Hellenic Local Development and Local Government Company (the processor) notified the DPA that information systems operated by the processor were subject to a data breach. The data breach concerned databases used for the implementation of two initiatives, the Daycare Centers Program and the Neighborhood Nannies Program. These databases included data relating to staff, legal representatives of the organisation, the applicants, and the beneficiaries of the initiatives (which included children) affecting a total of approximately 2,500,700 data subjects. Such personal data included names, tax ID's, date of birth, bank information and address and contact details of the individuals. The processor also suffered disruption of the systems. The controller blamed the incident on the processor and claimed that upon noticing the breach they immediately acted in compliance with the GDPR, notifying both the DPA and the processor, and took all necessary measures to restore the availability of the systems, and minimise the impact on data subjects. The processor admitted that it was aware of the risks that their systems pose, and the need for system improvement and update. The processor claimed that to remediate to these risks, it had previously requested the controller and other ministries to grant financial resources to modernise the information systems. The processor's financial resources in relation to the project were dependent entirely on state funding. The processor also argued that despite its awareness of the risks, it could not stop the processing in light of the public interest. The processor The DPA held that the incident being the result of a known, reasonably foreseeable, and exploitable technical vulnerability, the processor violated its obligations to ensure data integrity, confidentiality and security, under Articles 5(1)(f) and 32 GDPR. The DPA rejected the argument according to which the pub
Related Enforcement Actions (0)
No other enforcement actions found for Υπουργείο Κοινωνικής Συνοχής και Οικογένειας in GR
This is the only recorded action for this entity in this jurisdiction.
Details
Fine Date
28 July 2026
Authority
Hellenic Data Protection Authority
Fine Amount
€200,000
GDPRhub ID
gdprhub-10246About this data
Cite as: Cookie Fines. Υπουργείο Κοινωνικής Συνοχής και Οικογένειας - Greece (2026). Retrieved from cookiefines.eu
Last updated: