Hellenic DPA decision on a data breach involving E.E.T.A.A. S.A. as processor for the Ministry of Social Cohesion and Family Affairs
Greece's data protection authority ruled against the Ministry of Social Cohesion and Family Affairs following a large-scale personal data breach, finding violations across multiple GDPR articles including security, breach notification, and data protection by design. The ministry's processor, E.E.T.A.A. S.A., was also implicated in the decision, which resulted in fines and a compliance order.
Why this matters: When a government ministry responsible for family and social welfare suffers a data breach, the people exposed are often those least equipped to deal with the fallout. These are not just names and emails. They are likely benefit recipients, vulnerable families, and people who had no choice but to share personal details with the state. The Greek DPA found failures at multiple levels, from security practices to breach notification. That means people may not have been told their data was exposed. Governments owe citizens more than a fine after the fact.
Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · AI governance · General readers · Policy
This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.