Cosmote – €9,100,000 Fine (Greece, 2021)

€9,100,000Hellenic Data Protection Authority30 November 2021Greece
final
ePrivacy
Fine

The Hellenic Data Protection Authority fined Cosmote €9.1 million after a data breach exposed personal information of millions of subscribers. The breach occurred due to a cyber attack on Cosmote's server, revealing sensitive data like phone numbers and call details. This case highlights the importance of strong data protection measures for telecom companies.

What happened

Cosmote experienced a data breach that exposed a 30 GB file containing personal data of millions of subscribers due to a cyber attack.

Who was affected

Millions of Cosmote subscribers whose personal data, such as phone numbers and call details, were exposed in the breach.

What the authority found

The Hellenic Data Protection Authority found Cosmote violated GDPR by failing to adequately protect personal data and placing cookies before obtaining consent.

Why this matters

This case underscores the critical need for telecom companies to implement robust data protection strategies. It also serves as a warning about the consequences of inadequate data security and the importance of obtaining user consent before processing personal data.

GDPR Articles Cited

AI-verified

Art. 13 GDPR
Art. 14 GDPR
Art. 26 GDPR
Art. 28 GDPR
Art. 32 GDPR
Art. 5(1)(a) GDPR
Art. 5(1)(f) GDPR
Art. 5(2) GDPR
Art. 83 GDPR
Art. 25(1) GDPR
Art. 35(7) GDPR
View original scraped data
Art. 5(1)(a) GDPR
Art. 5(1)(f) GDPR
Art. 5(2) GDPR
Art. 13 GDPR
Art. 14 GDPR
Art. 25(1) GDPR
Art. 26 GDPR
Art. 28 GDPR
Art. 32 GDPR
Art. 35(7) GDPR
Art. 83 GDPR

Original data from scraper before AI verification against source document.

National Law Articles

AI-identified

Article 2(3) and (4) Law 3471/2006
Article 5 Law 3471/2006
Article 6 Law 3471/2006
Article 12(1) and (5) and (6) Law 3471/2006

Entities Involved

Cosmote
OTE
Source verified 4 March 2026
articles corrected
national law identified
amount discrepancy
entity split needed
date discrepancy
Full Legal Summary
Detailed

The case involved a data breach due to a cyber attack, unrelated to cookie or consent violations.

Violations (1)

Cookies Placed Before Consent
critical

Non-essential cookies (tracking, advertising) are placed on the user's device before obtaining valid consent.

Art. 6(1) GDPR

Related Enforcement Actions (0)

No other enforcement actions found for Cosmote in GR

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

30 November 2021

Authority

Hellenic Data Protection Authority

Fine Amount

€9,100,000

GDPRhub ID

gdprhub-4584

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Cosmote - Greece (2021). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: