Municipality X (To ensure the confidentiality of the specific municipality, the term "X" is employed as a placeholder.) – Violation Found (Greece, 2023)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
A city council in Greece faced issues after a data breach exposed citizens' personal information on its website. The council quickly took down the site but was still ordered to restrict access to personal data until it could ensure safety. This incident shows the importance of protecting personal data online.
What happened
A data breach allowed citizens' personal information to be accessed easily on the city council's website.
Who was affected
Citizens whose personal data was exposed due to the website vulnerability.
What the authority found
The Hellenic Data Protection Authority issued a temporary order requiring the city council to restrict access to personal data files until proper security measures were in place.
Why this matters
This ruling underscores the responsibility of organizations to secure personal data and respond swiftly to breaches. It serves as a warning for all entities to prioritize data protection and compliance with GDPR.
GDPR Articles Cited
National Law Articles
On 20 June 2023, an individual reported a data breach on city council X's website, because citizens' personal data was easily accessible on the controller's website by modifying the last five digits of the permalink (URL). On 21 June 2023, the HDPA communicated orally with the city council regarding the breach. In response, the controller promptly ceased the website's operations and officially notified the HDPA of the breach in accordance with Article 33 GDPR. Corrective measures to fix the issue were also implemented. Despite this, the website remained vulnerable, leading to continued exposure of personal data. Due to the ongoing unresolved data breach and the substantial risks it posed for a large number of persons, the HDPA issued a temporary order under Article 58(2) GDPR and Article 15(8) of Law 4624/2019. The interim order instructed the city council to take immediate action to restrict access to personal data files on its website and to cease all processing operations. The HDPA noted that the order was to stay in place until it could be ensured that the files containing user personal data could only be accessed by authorized users or the data subjects themselves. These restrictions will remain in effect until the SA issues a new decision, allowing processing operations to begin again.
Outcome
Violation Found
The DPA found a violation but did not impose a fine.
Related Enforcement Actions (0)
No other enforcement actions found for Municipality X (To ensure the confidentiality of the specific municipality, the term "X" is employed as a placeholder.) in GR
This is the only recorded action for this entity in this jurisdiction.
Details
About this data
Cite as: Cookie Fines. Municipality X (To ensure the confidentiality of the specific municipality, the term "X" is employed as a placeholder.) - Greece (2023). Retrieved from cookiefines.eu
Last updated: