KOTSOVOLOS S.A – €40,000 Fine (Greece, 2021)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
KOTSOVOLOS S.A was fined EUR 40,000 for not giving a customer access to correspondence about canceling credit card installments after a product return. The company claimed the communication was internal and couldn't be shared. This case underscores the importance of transparency and granting access to personal data under GDPR.
What happened
KOTSOVOLOS S.A refused to provide a customer with access to correspondence about canceling credit card installments.
Who was affected
A customer who returned a product and requested access to correspondence about canceling credit card installments.
What the authority found
The Hellenic Data Protection Authority fined KOTSOVOLOS S.A for not complying with the customer's right of access under GDPR.
Why this matters
This case highlights the necessity for companies to be transparent and provide access to personal data when requested by customers. Failing to do so can result in significant fines and legal consequences.
GDPR Articles Cited
Entities Involved
The complainant had bought a product from a seller (Controller A). It was agreed that the price of the product would not been paid in full at the time of the sale, but rather via several installments. Shortly thereafter, the Complainant decided to return the product. Despite this return, the Complainant realized that he was still being charged every month on his credit card. he therefore contacted Controller A in writing (via the Facebook Messenger App) and asked the latter to notify the bank (Controller B) of the need to cancel his credit card installments. Controller A however did not notify Controller B. The Complainant therefore attempted to directly contact Controller B with the same request. Controller B never answered him. The Complainant then requested Controller A to provide him with a copy of the correspondence it had with Controller B with respect to the installments. Controller A however refused to grant him access to this information on the basis of that the communication that had taken place with the bank constituted an internal communication with "no possibility of disclosure". In this context, the Complainant decided to file a complaint with the Greek DPA (the HDPA) The HDPA held that Controller A and B should have responded positively to the request of the Complainant in accordance with Article 12(2) GDPR and Article 15 GDPR. The HDPA imposed an administrative fine of EUR 20,000 on each Controller for failure to comply with the the right of access.
Related Enforcement Actions (0)
No other enforcement actions found for KOTSOVOLOS S.A in GR
This is the only recorded action for this entity in this jurisdiction.
Details
Fine Date
26 August 2021
Authority
Hellenic Data Protection Authority
Fine Amount
€40,000
GDPRhub ID
gdprhub-4007About this data
Cite as: Cookie Fines. KOTSOVOLOS S.A - Greece (2021). Retrieved from cookiefines.eu
Last updated: