ΔΔΚ - 14/2021
| ΔΔΚ - 14/2021 | |
|---|---|
| Court: | ΔΔΚ (Cyprus) |
| Jurisdiction: | Cyprus |
| Relevant Law: | Article 24(1) GDPR Article 25 GDPR Article 28 GDPR Article 32(1) GDPR Article 33 GDPR |
| Decided: | 12.05.2026 |
| Published: | |
| Parties: | APOEL OMONIA HELLENIC TECHNICAL ENTERPRISES LTD Commissioner for Personal Data Protection |
| National Case Number/Name: | 14/2021 |
| European Case Law Identifier: | |
| Appeal from: | Commissioner (Cyprus) |
| Appeal to: | |
| Original Language(s): | Greek |
| Original Source: | CYLAW (in Greek) |
| Initial Contributor: | n/a |
A court upheld the DPA’s finding of a failure to implement adequate security measures concerning two football clubs and their ticket purchase platform provider after a security vulnerability allowed access to fans’ personal data. However, the court annulled the fines, on grounds of proportionality
English Summary
Facts
On 26 July 2021, a journalist informed the Cypriot DPA of a security vulnerability on an online platform. This online platform hosted ticket purchase sites of two Cypriot football clubs, OMONIA and APOEL (the controllers). This flaw in the system allowed a user to identify, through a reserved-seat icon, the name and ID number of the fan who had reserved the seat. By using that information, the user could then download the fan card, including the fan’s photograph.
The DPA ordered the controllers to submit a personal data breach notification in accordance with Article 33 GDPR. In addition, it asked them to provide information on whether a penetration test had been carried out on the platform and to submit their contracts with the platform provider which acted as the processor of this data. Both controllers submitted the Personal Data Breach Notification Form and the requested documents.
The DPA fined each controller €40.000 and the processor €25.000 for the violations of Article 24(1) GDPR, Article 25 GDPR and Article 32(1) GDPR.
The controllers and the processor appealed the decision, mainly disputing their responsibility for the required security measures, their respective roles under the GDPR, and the proportionality of the fines. One of the controllers challenged only part of that fine.
Holding
The court held that, by submitting the breach notification form, the controllers had accepted both that there had been a personal data breach under Article 33 GDPR and that they acted as controllers for the purposes of the GDPR. The court further held that the platform provider acted as a processor under the relevant contracts and was therefore bound by Articles 28 and 32 GDPR.
The court upheld the DPA’s finding that the controllers and the processor had infringed the GDPR. It rejected one of the controllers’ arguments that it had no duty to carry out a penetration test before the platform was launched. The court held that Article 24 GDPR, Article 25 GDPR and Article 32 GDPR impose a continuing obligation on controllers and processors to ensure a level of security appropriate to the risk. Since Article 32 GDPR lists security measures only by way of example, their duties were not limited to the measures expressly mentioned in that provision. The court also held that the processor’s prior internal checks did not change the outcome, as the duty to implement appropriate security measures is ongoing.
However, the court annulled the administrative fines, insofar as challenged, because their amount had not been determined in accordance with the principle of proportionality. In particular, the court noted that one controller had been fined €40,000 although the infringement affected 3,652 persons, while the other controller received the same fine despite the fact that only up to 100 persons were affected. By contrast, the processor, which was involved in both infringements, received a lower fine of €25,000.
The court held that the DPA had failed to respect the principle of proportionality when imposing the fines, given that the underlying facts were essentially the same and that liability under the GDPR is shared between controllers and processors.
Comment
Share your comments here!
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the Greek original. Please refer to the Greek original for more details.
CYPRUS BAR ASSOCIATION Search - List of Administrative Court Decisions - Show Reports (Noteup on) - Remove Underlining ADMINISTRATIVE COURT (Joint Cases No. 14/2021, 1387/2021 and 1395/2021) May 12, 2026 [MICHAEL, D/to the D.D.] (Case No. 14/2021) OMONIA FOOTBALL LTD Applicant v. OF THE REPUBLIC OF CYPRUS, THROUGH THE COMMISSIONER FOR THE PROTECTION OF PERSONAL DATA As the Application .......... (Case No. 1387/2021) APOEL FOOTBALL (PUBLIC) LTD Applicant v. OF THE REPUBLIC OF CYPRUS, THROUGH THE COMMISSIONER FOR THE PROTECTION OF PERSONAL DATA Where the Application .......... (Case No. 1395/2021) HELLENIC TECHNICAL ENTERPRISES LTD Applicant v. OF THE REPUBLIC OF CYPRUS, THROUGH THE COMMISSIONER FOR THE PROTECTION OF PERSONAL DATA Where the Application .......... X. Christofi for Christofi & Associates D.E.P.E., for the applicant in Case No. 14/2021. N. Triantafyllidi (Ms) together with trainee lawyer V. Karathanasi (Ms) for Christos M. Triantafyllidi, for the applicant in Case No. 1387/2021. A. Papamichael (Ms) together with trainee lawyers A. Afxentiou and K. Vassiliou (Ms) for A & A K. Emilianidis, K. Katsaros and Associates D.E.P.E., for the applicant in Case No. 1395/2021. Th. Piperi - Christodoulou (Ms) for the Attorney General, for the respondent in the application. DECISION MICHAEL, D.D.D.: All applicants request the annulment of the decision of the defendant dated 6.9.2021 by which it ruled that they acted in violation of the General Data Protection Regulation EU Regulation 2016/679 (hereinafter the "General Regulation") and imposed on them an administrative fine of €40,000, €10,000 and €25,000 respectively. It is clarified that the applicant Apoel is challenging part of the administrative fine imposed on her and not the total of €40,000. On 26.7.2021, a journalist informed the defendant of a security flaw in the electronic platform stadium360.net which allowed a user to identify the name and ID number of the fan who reserved the seat in a reserved seat icon and then, using this information, to download the fan card with the photo of the person in question. The said electronic platform hosts the ticket purchase websites of the clubs of the applicants in Cases No. 14/2021 and 1387/2021 and the applicant in Case No. 1395/2021 is the data controller. Since the defendant in the application established the violation after testing, it requested by letters dated 28.7.2021 from the applicants Omonia and Apoel to submit a notification of a personal data breach incident and to send it the processing outsourcing contracts with the applicant Hellenic. The information was submitted, clarifying questions were answered, a preliminary inspection report was submitted and on 6.8.2021 the defendant in the application informed the applicants in writing that it identified a prima facie violation and to submit their positions by 13.8.2021, a deadline that was later extended. The applicants submitted their positions in writing and on 6.9.2021 the contested decisions were issued. The applicant Omonia suggests that the principles of fair trial were violated because the indictment was not justified with reference to the appropriate technical and organizational security measures that the applicant was required to implement and by extension what the violations were and if the defendant's application resulted in a finding of a violation, then the applicant should be invited to present mitigating factors. It also suggests that the contested decision suffers from a lack of proper investigation and reasoning, an error of fact and law, an unjustifiably high administrative fine, incorrect application of Article 83 of the General Regulation and a violation of the principle of proportionality in relation to the amount of the administrative fine. The applicant Apoel suggests that the contested decision is vitiated by an error since the applicant was not obliged to conduct a penetration test on the basis of the provisions of Articles 24(1) and 32(1) of the General Regulation and is also vitiated by an excess of power since a double fine was imposed on them. The applicant Hellenic suggests that the contested decision is vitiated by an incorrect interpretation of Articles 28(1) and 32(1) of the General Regulation, an error of fact since the applicant is not the processor and a lack of proper investigation since it was not taken into account that the applicant, before the websites were put into operation, carried out internal checks which did not reveal the need to implement additional technical measures. The letters of the defendant in the application dated 28.7.2021 to the three applicants have identical content and are as follows: "It has come to our attention, as reported in a publication on the sigmalive website, that there is a security gap in the platform http://tickets.stadium-360.net. This security gap allows an unauthorized person to have access and, if they wish, to extract personal data of fans who have used the said platform. 2. Verification / confirmation has already been carried out by our Office, and the security gap concerning the said platform has been identified, through the booking website (https://tickets.stadium-360.net/omonoia). Specifically, by studying the data exchange between the browser and the platform, the user can see the details of the persons who have already reserved a seat for the said match. The data displayed are the political identity number, the KMO registration number and the name of the fans in question. 3. In accordance with Article 33 of the General Data Protection Regulation (EU) 2016/679, in the event of a personal data breach, the controller shall notify the personal data breach to the supervisory authority competent in accordance with Article 55 without undue delay and, where feasible, not later than 72 hours after having become aware of it, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the notification to the supervisory authority is not made within 72 hours, it shall be accompanied by a justification for the delay. 4. Taking into account the above, we kindly ask you to: a) send us the relevant personal data breach notification form, which you can find on our website dataprotection.qov.cy), in the section “Information for organizations” - “Breach notification”. b) inform us if a penetration test was conducted on the platform and to share the results with us, c) send us the processing agreement with the company providing the said platform (based on Article 28 of the Regulation).” By a subsequent letter dated 29.7.2021, the respondent in the application clarified to the applicant Hellenic that the personal data breach notification form does not concern it because it is the processor but only concerns the applicants Omonia and Apoel (see Exhibit 3, document 6879958). On 29.7.2021, the applicants Omonia and Apoel responded by submitting a “Personal Data Breach Notification Form” (see Exhibit 1, document 6883350 and Exhibit 2 document 6883328 respectively). They also submitted the remaining documents requested by the respondent in the application and also answered clarifying questions asked of them. Article 33 of the General Regulation provides that: « 3. The notification referred to in paragraph 1 shall at least: a) describe the nature of the personal data breach, including, where possible, the categories and approximate number of data subjects affected, as well as the categories and approximate number of personal data files affected; b) state the name and contact details of the data protection officer or other contact point from which further information can be obtained; c) describe the potential consequences of the personal data breach; d) describe the measures taken or proposed to be taken by the controller to address the personal data breach, as well as, where appropriate, measures to mitigate its potential adverse effects. 4. Where and to the extent that it is not possible to provide the information simultaneously, it may be provided in stages without undue delay. 5. The controller shall document each personal data breach, consisting of the facts relating to the personal data breach, the consequences and the remedial measures taken. Such documentation shall enable the supervisory authority to verify compliance with this Article.” Given the above facts, it follows that the applicants Omonia and Apoel, by submitting the notification form, accepted both that there was a personal data breach and that they are both controllers for the purposes of the General Regulation, since in accordance with Article 33 the breach is notified by the controller. Consequently, grounds for annulment raised by the applicants in question and relating either to the admission of the breach or to their role as controller fall foul of the doctrine of approval and disapproval. Based on the above conclusion, the suggestion of the applicant Omonia that the defendant in the application should first have reached a prima facie finding of a violation and after hearing the applicant to finally rule on the violation since the applicant accepted the violation in advance by submitting the relevant notification is rejected. In any case, however, the defendant in the application in the decision dated 6.8.2021, after setting out the factual and legal background, gave the applicant the right to submit its positions, concluding as follows: «4.1. Bearing in mind that, based on the provisions of Article 58(2) of the GDPR, I have the authority to impose administrative sanctions for any violations of the GDPR, within the framework of the right to be heard granted to you by Article 43 of the General Principles of Administrative Law Law of 1999, Law 158(I)/1999, as amended, you are invited to as soon as possible and no later than 13/08/2021: (a) submit your positions in writing to my Office, for all of the above and in particular for those referred to in paragraphs 3.2.2, 3.2.3 and 3.2.4 and (b) indicate to us the reasons why you consider that there are no grounds for imposing any sanction and/or any mitigating factors, before I proceed to issue a Decision. As follows from the decision of the defendant in the application dated 6.9.2021, a violation by the applicants Omonia and Apoel of Articles 24(1), 25 and 32(1) of the General Regulation was found. The corresponding provisions of the said articles are as follows: « Article 24 Responsibility of the controller 1. Taking into account the nature, scope, context and purposes of the processing, as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, the controller shall implement appropriate technical and organizational measures in order to ensure and be able to demonstrate that the processing is carried out in accordance with this Regulation. Those measures shall be reviewed and updated when deemed necessary. Article 25 Data protection by design and by default 1. Taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of the processing, as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons resulting from the processing, the controller shall effectively implement, both at the time of determining the means of processing and at the time of processing, appropriate technical and organisational measures, such as pseudonymisation, designed to implement data protection principles, such as data minimisation, and to integrate necessary safeguards into the processing in such a way as to meet the requirements of this Regulation and to protect the rights of data subjects. 2. The controller shall implement appropriate technical and organisational measures to ensure that, by definition, only personal data which are necessary for the specific purpose of the processing are processed. This obligation applies to the scope of the personal data collected, the extent of their processing, the storage period and their accessibility. In particular, such measures shall ensure that, by definition, personal data are not made accessible without the intervention of the natural person to an indefinite number of natural persons. 3. An approved certification mechanism in accordance with Article 42 may be used as evidence of compliance with the requirements laid down in paragraphs 1 and 2 of this Article. Article 32 Security of processing 1. Taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of the processing, as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, the controller and the processor shall implement appropriate technical and organisational measures to ensure an appropriate level of security against the risks, including, inter alia, where applicable: a) pseudonymisation and encryption of personal data, b) the possibility of ensuring the confidentiality, integrity, availability and reliability of the processing systems and services on an ongoing basis, c) the possibility of restoring the availability and access to personal data in a timely manner in the event of a natural or technical incident, d) a procedure for regularly testing, assessing and evaluating the effectiveness of the technical and organisational measures to ensure the security of the processing. The invocation of the above provisions by the respondent in the application is made to demonstrate the high level of responsibility borne by all applicants. In all three articles, the responsibility borne by each controller and each processor to take such measures as to ensure an appropriate level of security against the risks that are constantly changing is pervasive. The measures provided for in Article 32 are indicative and not exhaustive because, precisely, it is the responsibility of the controller and the processor to take the appropriate measures in each case. The General Regulation allocates responsibility to both the controller and the processor precisely because it aims to ensure the highest level of protection for the data subject. Therefore, the applicant Apoel's suggestion that a violation was found for failing to take action that it was not its obligation to perform is not valid, as is the suggestion that it had no duty to perform a penetration test before the website was launched. All three applicants had the responsibility to take such technical measures so that the security of the data subjects' data was ensured. The applicant Apoel states on page 6 of the written statement, without prejudice to what she previously developed, that the application does not challenge the decision of the defendant in relation to the violation of Articles 24(1) and 32(1) resulting from her failure to use dummy data and to activate data hiding. As I explained above, Article 32(1) indicates some measures (“among others”) that the controller and the processor must take, and among these are pseudonymisation and encryption of data, but their obligation does not stop at what is indicated in Article 32(1) but extends to those “appropriate technical and organisational measures” in order to ensure the protection of personal data. In other words, the General Regulation places the general responsibility on the shoulders of the controller and the processor to constantly monitor the security of the system in operation. Before I proceed to examine the grounds for annulment raised in relation to the administrative fine imposed on the three applicants, I will examine the submissions of the applicant Hellenic on the correctness of the contested decision. The respondent in the application treated the applicant Hellenic for the purposes of the General Regulation as a processor. The relevant provisions of Article 28 are: « Article 28 Processor 1. Where processing is to be carried out on behalf of a controller, the controller shall use only processors who provide sufficient assurances to implement appropriate technical and organisational measures in such a way that the processing will meet the requirements of this Regulation and ensure the protection of the rights of the data subject. [.] 3. Processing by the processor shall be governed by a contract or other legal act governed by Union or Member State law, which is binding on the processor in relation to the controller and which specifies the subject matter and duration of the processing, the nature and purpose of the processing, the type of personal data and the categories of data subjects and the obligations and rights of the controller. That contract or other legal act shall provide in particular that the processor: a) shall process personal data only on the basis of recorded instructions from the controller, including as regards the transfer of personal data to a third country or an international organisation, unless required to do so by Union law or the law of the Member State to which the processor is subject; in that case, the processor shall inform the controller of that legal requirement prior to the processing, unless that law prohibits such information for overriding reasons of public interest; b) shall ensure that the persons authorised to process the personal data have undertaken a confidentiality undertaking or are subject to an appropriate regulatory obligation of confidentiality; c) shall take all necessary measures pursuant to Article 32; d) shall comply with the conditions referred to in paragraphs 2 and 4 for the recruitment another processor, (e) take into account the nature of the processing and assist the controller with appropriate technical and organisational measures, to the extent possible, to fulfil the controller's obligation to respond to requests for the exercise of the data subject's rights provided for in Chapter III, (f) assist the controller in ensuring compliance with the obligations arising from Articles 32 to 36, taking into account the nature of the processing and the information available to the processor, (g) at the controller's choice, erase or return all personal data to the controller after the end of the processing services and erase existing copies, unless Union or Member State law requires the storage of the personal data, (h) make available to the controller all information necessary to demonstrate compliance with the obligations laid down in this Article and allow and facilitate audits, including inspections, carried out by the controller or by another controller authorized by the controller. With regard to point (h) of the first subparagraph, the processor shall immediately inform the controller if, in its opinion, an instruction infringes this Regulation or other Union or national data protection provisions. [.]” As is apparent from the facts, the defendant in the application requested and received from the applicants Omonia and Apoel their contracts with the applicant Hellenic (Exhibit 1, part of document no. 6883350 and Exhibit 2, part of document no. 6885902). The content of the two contracts is identical and it is clear from them that the applicant Hellenic undertook “the processing of the fan’s personal data” (see preamble to the agreement). At the end of term 1 it is stated that: “For the purposes of this Agreement, the parties agree that [Omonoia / Apoel] acts as the Controller of Personal Data, and ΗΤΕ undertakes to process Personal Data on behalf of [Omonoia / Apoel] as the Processor of Personal Data within the framework of this Cooperation.” Also important is the content of term 3.6 of the agreement: “3.6. HT and [.] will implement appropriate technical and organizational measures to ensure an appropriate level of security against the risks, including, inter alia, where applicable: (a) the pseudonymization and encryption of Personal Data, (b) the ability to ensure the confidentiality, integrity, availability and reliability of the processing systems and services on an ongoing basis, (c) the ability to restore the availability and access to Personal Data in a timely manner in the event of a natural or technical incident, (d) a procedure for regularly testing, assessing and evaluating the effectiveness of the technical and organizational measures to ensure the security of the processing, (e) the provision of the necessary interfaces where applicable or support for other processing operations of the Company in the context of providing information to data subjects based on the law and the Regulation, (f) the updating, modification or rectification of Personal Data following written instructions from [.], (g) the suspension or interruption of access to Personal Data following written instructions from [.].” From the above it is clear that the applicant Hellenic was, for the purposes of the General Regulation, the processor which, as mentioned above, has the same increased obligations as the controller, therefore Articles 28(1) and 32(1) were not violated as the applicant suggested. Nor does its suggestion that the checks it carried out before the websites were put into operation change the result in any way since, as explained above, the obligation to take appropriate measures exists continuously and the measures depend on the case. Moreover, the applicant committed itself to this obligation also through clause 3.6 of the contract. Based on the above, it follows that the contested decision is correct in finding an infringement on the part of all three applicants. With regard to the grounds for annulment raised by the applicants and related to the administrative fine imposed on them, the provisions of Article 83 of the General Regulation are relevant: « 2. Administrative fines, depending on the circumstances of each individual case, shall be imposed in addition to or instead of the measures referred to in points (a) to (h) of Article 58(2) and point (j) of Article 58(2). When deciding on the imposition of an administrative fine, as well as on the amount of the administrative fine in each individual case, due account shall be taken of the following: a) the nature, gravity and duration of the infringement, taking into account the nature, scope or purpose of the processing concerned, as well as the number of data subjects affected by the infringement and the degree of damage suffered by them; b) the intent or negligence which caused the infringement; c) any action taken by the controller or processor to mitigate the damage suffered by data subjects; d) the degree of responsibility of the controller or processor, taking into account the technical and organisational measures implemented pursuant to Articles 25 and 32; e) any previous relevant infringements by the controller or processor; f) the degree of cooperation with the supervisory authority in remedying the breach and limiting its possible adverse effects, (g) the categories of personal data affected by the breach, (h) the manner in which the supervisory authority became aware of the breach, in particular whether and to what extent the controller or processor notified the breach, (i) where measures referred to in Article 58(2) have previously been ordered against the controller or processor concerned in relation to the same subject matter, compliance with those measures, (j) adherence to approved codes of conduct pursuant to Article 40 or approved certification mechanisms pursuant to Article 42, and (k) any other aggravating or mitigating factors arising from the circumstances of the specific case, such as the financial benefits gained or losses avoided, directly or indirectly, as a result of the breach. infringement. 3. Where the controller or processor, in respect of the same or related processing operations, infringes several provisions of this Regulation, the total amount of the administrative fine shall not exceed the amount laid down for the most serious infringement. 4. Infringements of the following provisions shall be subject, in accordance with paragraph 2, to administrative fines of up to EUR 10 000 000 or, in the case of undertakings, up to 2 % of the total worldwide annual turnover of the preceding business year, whichever is higher: (a) the obligations of the controller and the processor pursuant to Articles 8, 11, 25 to 39 and 42 and 43, [.] 8. The exercise by a supervisory authority of its powers under this Article shall be subject to appropriate procedural safeguards in accordance with Union and Member State law, including the exercise of an effective judicial remedy and the observance of due process. Having studied the contested decisions, the extent of the impact on personal data in each of the three cases and the imposition of an administrative fine, I find that the defendant in the application did not act proportionately. Specifically, in the case of the applicant Omonia, 3,652 persons were affected by the infringement (see page 2 of the decision) and a total administrative fine of €40,000 was imposed on it. In the case of the applicant Apoel, up to 100 persons were affected and the same administrative fine was imposed on it, while in the case of the applicant Hellenic, which was responsible as the processor of both infringements that occurred, the smaller administrative fine was imposed, namely €25,000. Given that in all three cases the actual facts are the same and given that the liability according to the General Regulation is shared equally between the controller and the processor, when imposing an administrative fine on the three applicants, the principle of proportionality was not observed, resulting in the finding of illegality in this part of the contested decisions. For the above reasons, I conclude that the appeals succeed partially as regards the imposition of the administrative fine as it is contested in each appeal and the contested decisions are annulled in this regard while the contested decisions are confirmed in the rest. Due to the partial success of the appeals, reduced costs of €650 plus VAT are awarded in favor of each applicant and against the defendant in the application. E. MICHAEL, D.D.D. cylaw.org: From KINOP/CyLii for the Cyprus Bar Association




