Imposition of fine on a telecommunications company for violations of data subject’s rights
Greece's data protection authority fined Vodafone-Panafon in February 2026 for failing to properly handle a customer's data rights requests. The violations covered multiple GDPR obligations, including timely responses, the right of access, and the right to restrict processing.
Why this matters: This is a straightforward accountability case. A person asked a major telecom for their data, and the company dragged its feet or ignored them. That is exactly what GDPR was built to stop. Telecoms hold a lot: call records, location history, billing details, device identifiers. When they make it hard to access or restrict that data, the rights exist only on paper. Regulators fining companies for process failures, not just breaches, is how those rights stay real.
Who should care: Lawyers · Privacy officers · Compliance · General readers · Policy
This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.