Ministry of Foreign Affairs – Violation Found (Greece, 2020)

Violation Found
Hellenic Data Protection Authority11 August 2020Greece
final
Violation Found

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

The Greek Data Protection Authority found security issues at the Ministry of Foreign Affairs during an audit. The Ministry was ordered to follow the Authority's recommendations to improve data security. This case underscores the need for strong data protection measures in government systems.

What happened

The Hellenic Data Protection Authority found security issues at the Ministry of Foreign Affairs during an audit.

Who was affected

Personal data stored in the Ministry of Foreign Affairs' central database, including special categories of data.

What the authority found

The Authority ordered the Ministry to comply with its security recommendations to protect personal data better.

Why this matters

This case highlights the importance of robust data security practices, especially in government systems handling sensitive information. It serves as a reminder that authorities can mandate improvements to protect personal data.

GDPR Articles Cited

Art. 32 GDPR
Art. 58(2)(d) GDPR
Full Legal Summary
Detailed

The HDPA ran an on site audit at the Ministry of Foreign Affairs as being the data controller according to VIS Regulation and VIS Decision. VIS is an information system for exchanging data among states within Schengen area with an aim to improve common VISA policies. The audit was focused on security issues, which are provided for in Article 32 GDPR and Article 32 of VIS Regulation. Further security requirements are provided for in Article 9 of Council Decision 2008/633/JHA (VIS Decision). Fundamental element of the system is a central database which contains personal data including special categories. The HDPA prepared a detailed analysis of the findings arisen from the audit as well as of the relevant risks, which is however included in a final confidential report. Based on these findings, the HDPA ordered the Ministry of Foreign Affairs to comply with its recommendations that are included in the confidential report according to Article 58(2)(d) GDPR and inform the HDPA accordingly.

Outcome

Violation Found

The DPA found a violation but did not impose a fine.

Related Enforcement Actions (0)

No other enforcement actions found for Ministry of Foreign Affairs in GR

This is the only recorded action for this entity in this jurisdiction.

Details

Decision Date

11 August 2020

Authority

Hellenic Data Protection Authority

GDPRhub ID

gdprhub-2678

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Ministry of Foreign Affairs - Greece (2020). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: