the Municipality of Alimos – €15,000 Fine (Greece, 2024)

€15,000Hellenic Data Protection Authority5 July 2024Greece
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

The Municipality of Alimos in Greece was fined EUR 15,000 after personal data of citizens was made accessible on a website due to a security flaw. This is important because it shows that organizations must protect personal information from unauthorized access. Local governments and businesses should implement strong security measures to safeguard user data.

What happened

Files containing personal data of citizens were accessible to anyone who changed a specific part of the website's URL.

Who was affected

Citizens of the Municipality of Alimos whose personal data was exposed online.

What the authority found

The Hellenic Data Protection Authority found that the municipality failed to implement adequate security measures, violating multiple GDPR articles.

Why this matters

This ruling highlights the responsibility of organizations to ensure data security. It serves as a warning that neglecting security can lead to serious consequences, including fines.

GDPR Articles Cited

AI-verified

Art. 5(1)(f) GDPR
Art. 25(1) GDPR
Art. 28(3) GDPR
Art. 32(1) GDPR
Art. 33(4) GDPR
Art. 34(1) GDPR
Art. 34(2) GDPR
View original scraped data
Art. 5(1)(f) GDPR
Art. 25(1) GDPR
Art. 28(3) GDPR
Art. 32(1) GDPR
Art. 33(4) GDPR
Art. 34(1) GDPR
Art. 34(2) GDPR

Original data from scraper before AI verification against source document.

Source verified 13 March 2026
entity split needed
Full Legal Summary
Detailed

Files containing personal data of citizens of the Municipality of Alimos (the controller) were accessible to any visitor of a specific website. To get access to those files, visitors had to change the last five-digit number appearing of the website’s URL. An individual (the data subject) complained about the abovementioned functionality with the Greek DPA (HDPA). For the data subject the functionality was a data breach. The DPA informed the controller about the complaint. In response, the controller notified the DPA of the data breach in accordance with Article 33 GDPR. The controller argued that they relied on services provided by third party (the processor). Nevertheless, the controller immediately implemented appropriate measures and the data were no longer publicly accessible. The controller stated that out of 45,000 available files, only 1,200 files were accessed and the access was made from two specific IP addresses. The data subject informed the DPA twice that despite update of the website it was still possible to access the personal data. Then, each time, the controller implemented additional updates and new measures. Regarding the data breach, the controller emphasised that it lasted for a short time, affected a small number of files, containing the data of simple nature and corrective measures were applied. As a result, the breach was assessed by the controller as posing a low risk. The DPA upheld the complaint. The DPA found the controller violated Article 5(1)(f), Article 25(1), Article 28(3), Article 32(1), Article 33(4), Article 34(1), Article 34(2) GDPR. The controller failed to implement appropriate technical and organizational security measures to preserve the confidentiality of the personal data, as well to verify the accuracy of implemented measures. That led to the data breach. The data breach caused unauthorised access to personal data of citizens of the Municipality of Alimos, for example copies of identity cards, driving licenses. The

Related Enforcement Actions (0)

No other enforcement actions found for the Municipality of Alimos in GR

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

5 July 2024

Authority

Hellenic Data Protection Authority

Fine Amount

€15,000

GDPRhub ID

gdprhub-8325

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. the Municipality of Alimos - Greece (2024). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: