HDPA (Greece) - 10/2026

From GDPRhub
HDPA - 10/2026
Authority: HDPA (Greece)
Jurisdiction: Greece
Relevant Law: Article 5(1)(b) GDPR
Article 5(1)(c) GDPR
Article 5(1)(a) GDPR
Article 5(2) GDPR
Article 12(1) GDPR
Article 12(2) GDPR
Article 13(1) GDPR
Article 13(3) GDPR
Article 15(1) GDPR
Article 15(3) GDPR
Article 31 GDPR
Article 37(7) GDPR
Type: Complaint
Outcome: Upheld
Started: 22.06.2023
Decided: 12.06.2026
Published:
Fine: 160,000 EUR
Parties: MEDE S.A.
MARKET IN S.A.
National Case Number/Name: 10/2026
European Case Law Identifier: n/a
Appeal: n/a
Original Language(s): Greek
Original Source: HDPA (in EL)
Initial Contributor: ds

The DPA fined the operator of an exhibition centre and a supermarket chain €65,000 and €95,000 respectively for failures relating to the disclosure and further use of CCTV footage, responses to access requests and compliance with multiple data-protection principles and obligations.

English Summary

Facts

A data subject submitted access requests to “MEDE S.A.”, a company operating an exhibition centre (controller A), and “MARKET IN S.A.”, a supermarket chain (controller B). He requested information concerning the collection and processing of his personal data through their respective CCTV systems. In particular, he asked for the relevant privacy notices, information on the personal data processed, the recipients of those data and copies of CCTV material disclosed to third parties. He also submitted photographs which allegedly originated from the CCTV systems of both controllers.

Both controllers initially requested further clarification. After the data subject clarified and repeated his request, they made clarifications concerning their CCTV policies and stated that they had never disclosed CCTV photographs depicting the data subject to third parties. They maintained that they could not answer the remaining questions.

The data subject then lodged separate complaints with the Greek DPA (HDPA) against both controllers. He alleged that they had inadequately responded to his access requests, unlawfully processed his personal data through their CCTV systems and unlawfully disclosed CCTV material to third parties.

Controller A claimed that its only active cameras were located at the entrance and on the ground floor of the exhibition centre and that they did not record sound. It stated that no recording had taken place on the first floor, where the data subject worked. Controller A further argued that it had lawfully used CCTV photographs to legal proceedings involving controller A, a third party and the data subject, in order to defend its legal rights. It further argued that the third party had obtained the CCTV material through the court file in those proceedings and did not receive them directly from it.

According to controller B, following an incident outside its premises, its security guards manually turned the cameras towards the data subject’s vehicle, printed the resulting images and delivered them to the prosecutorial authorities without the controller’s involvement. It further claimed that its cameras did not permanently record public areas. Controller B also argued that the photographs did not contain the data subject’s personal data because they only showed his vehicle.

Holding

The DPA took into account that during the investigation, both controllers responded only after repeated contact requests. It pointed out that controller B displayed particular difficulty in cooperating with the DPA, as it responded after significant delay. The DPA also noted that both controllers had requested an extension to file further submissions but ultimately failed to submit them.

The DPA found that although the data subject’s access requests had been formulated clearly, both controllers nevertheless requested additional clarification, therefore making the exercise of his right of access more difficult.

Regarding controller A, the DPA noted that it had admitted using CCTV photographs in legal proceedings. It pointed out that although the purpose of defending legal claims appeared in its privacy policy, that policy did not specifically concern CCTV processing. It further held that the controller A’s CCTV signage referred only to the protection of persons and property and neither contained the information required by Article 13 GDPR nor referred data subjects to a second-level privacy notice.

The DPA concluded that controller A had disclosed the footage from its CCTV system without first informing the data subject and had processed it without ensuring that the processing was compatible with the originally specified purpose. It therefore found that the controller had infringed the principle of transparency, the principle of purpose limitation and the principle of accountability, since it failed to demonstrate its compliance with the GDPR. The DPA fined controller A €20,000 for the violations of Article 5(1)(a) GDPR, Article 5(1)(b) GDPR, Article 13(1) GDPR and Article 5(2) GDPR. In addition, it imposed a separate €20,000 fine for the infringements of Article 5(1)(b) GDPR and Article 13(3) GDPR.

Moreover, the DPA concluded that controller A did not facilitate the exercise of the data subject’s right of access, as it did not provide him with all the relevant information required under Article 15 GDPR nor provided a copy of the personal data undergoing processing. It therefore imposed a fine of €20,000 for the violations of Article 12(1) GDPR, Article 12(2) GDPR, Article 15(1) GDPR and Article 15(3) GDPR.

Finally, the DPA found that controller A appeared to have appointed a Data Protection Officer but failed to communicate its DPO’s contact details to the DPA. It subsequently fined it €5,000 for the violation of Article 37(7) GDPR.

Regarding controller B, the DPA rejected the argument that the vehicle depicted in the photographs could not constitute personal data. It clarified that a vehicle registration plate may constitute personal data where it enables the identification of the vehicle’s owner. It further rejected controller B’s argument that its security guards had acted entirely on their own initiative. The DPA stressed that controller B was responsible for ensuring that appropriate technical and organisational measures, including staff training and instructions concerning data protection, were in place to ensure compliance with the GDPR. In addition, it pointed out that the email address that controller B had publicly indicated as a privacy contact point was misleading since it appeared not to be managed by a natural person capable of responding to requests. The DPA also noted that no notification of controller B’s DPO contact details appeared in its records, as required under Article 37(7) GDPR where a DPO has been appointed.

The DPA found that controller B had disclosed CCTV material without properly informing the data subject in advance. It imposed a €50,000 fine for infringements of the principle of transparency under Article 5(1)(a) GDPR, the information obligations under Article 13 GDPR and the accountability principle under Article 5(2) GDPR. The DPA further found that controller B had failed to ensure that the personal data processed were relevant and limited to what was necessary for the intended purpose, therefore violating the principles of data minimisation and accountability. It fined it €20,000 for the violations of Article 5(1)(c) GDPR and Article 5(2) GDPR.

The DPA held that controller B had also failed to facilitate the data subject’s access request, as it did not provide all requested information concerning its CCTV policy and the disclosure of personal data, nor provided a copy of the personal data undergoing processing. The DPA found infringements of Article 12(1) GDPR, Article 12(2) GDPR, Article 15(1) GDPR and 15(3) GDPR and imposed a €20,000 fine.

In addition, it found that controller B had not cooperated adequately with the supervisory authority, contrary to Article 31 GDPR and imposed a further fine of €5,000.

Comment

Share your comments here!

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the Greek original. Please refer to the Greek original for more details.

Athens, 12-06-2026
No. Prot.: 2681

DECISION 10/2026

The Personal Data Protection Authority met, following

the invitation of its Acting President and Deputy President, Georgios

Batzalexis, following the resignation of its President Konstantinos Menudoudou, in a regular

meeting in a Department composition via videoconference, on Wednesday 04/02/2026,

in order to examine the case, which is mentioned below in the history of

this decision. Present were George Batzalexis, Deputy Chairman, and

the alternate members of the Authority, Dimosthenis Vougioukas and Maria Psalla, in

replacement of the regular members Konstantinos Lambrinoudakis, and Grigoris Tsolias, who

although legally summoned in writing, did not attend due to impediment.

Also present was Christos Kalloniatis, regular member, as rapporteur. Present without the right

to vote were Ioannis Lykotrafitis and Aikaterini Hadjidiakou, IT auditors,

as assistant rapporteurs and Irini Papageorgopoulou, employee of the

administrative affairs department, as secretary.

The Authority took into consideration the following:

With the nos. prot. C/ΕΙΣ/4677/22-06-2023 and C/ΕΙΣ/6496/15-09-2023 complaints,

A (hereinafter complainant) submitted complaints to the Authority against “MEDE SA” (hereinafter

complainant A) and “MARKET IN SA” (hereinafter

complainant B) respectively, for

the improper satisfaction of the right of access, the unlawful processing

of personal data through a video surveillance system and the

disclosure of the material from the video surveillance system to third parties. According to the above complaints, the complainant exercised his right of access to the defendants by sending e-mails on 21/07/2023, accompanied by photographic material from the respective video surveillance system of both defendants and letters asking a series of questions. Among other things,

he requested the disclosure to him of the company's privacy policy and

information as provided for in the right of access with emphasis on

the recipients of the data that were disclosed, as well as the provision of a copy

of the data that were disclosed to third parties, of the request on the basis of which

the unlawful disclosure was made, information on further processing, as well as the provision of

a copy of the evaluation of the above request, with which the disclosure was made without

his prior notification.

Both complainants responded to the above letters of the complainant on 03/08/2023 by notifying

their letters of 01/08/2023, in which they requested clarifications on the above issues and to which

the complainant responded with corresponding letters, stating that in any case

his request does not constitute a request from a third party and therefore repeats the above requests.

Both defendants responded again with their letters dated 07/08/2023,

in which there is a reference to clarifications regarding the protection policy regarding
the installed video surveillance system, while there is also the claim that

never has any of the defendants disclosed to third parties

photographs taken from the respective video surveillance system, in which

the plaintiff or other third parties are depicted, and therefore it is not possible

to respond to all the remaining relevant requests.

The Authority, in the context of examining the above relevant complaints, sent the letters no. prot. C/ΕΣΕ/3084/08-11-2024 and C/ΕΣΕ/3168/11-12-2023 documents to

complainant A and complainant B respectively for the provision of opinions, requesting

clarifications on the complaints regarding the insufficient satisfaction of the complainant's right of access, the failure to facilitate its exercise and the unlawful

transfer of personal data from the said system to

third parties. Furthermore, in view of the fact that complainant B did not respond to the above

request of the Authority, the Authority sent a reminder with no. proc. C/EXE/3062/05-11-2024

document, to which it also did not respond. Subsequently, the Authority sent a document under no.

proc. C/EXE/3503/09-12-2024, with which it requested the accused B

to respond within an exclusive period of five (5) days. Finally, each

of the accused A and B responded respectively with the documents under no. proc. C/EIS/988/04-02-

22025 and C/EIS/982/04-02-2025.

In his response, the accused A claims that:

1. The only cameras that have been installed are at the entrance of the exhibition

center and on the ground floor of the building, which do not record sound. The

accused notes that cameras were never installed in the offices

on the first floor, where the company where the

complainant works is housed. The first floor initially housed the offices of the

administration of the accused A, which, however, following incidents that took place

between the accused A and the complainant, were transferred to another

area of the exhibition center and since then the video surveillance system of the

entrance, which had been installed in the offices on the floor, was put into disuse and

stopped working. According to the same response, the

submitted photographs do not appear to capture an image from

the first floor of the exhibition center, a space in which

no recording ever took place.

2. The material from the video surveillance system came into the possession of a third party not

directly from the defendant but through a case file, in which
the parties are the said third party, defendant A and the complainant (joint

application for interim measures filed against the complainant by the

third party and defendant A).

3. The complainant also submits in his complaint photographs

collected by him, along with photographs that defendant A legally used

in the context of an interim measure trial against the complainant.

In his response, defendant B reiterates the allegations that were

set out in his initial letter to the complainant, while also stating the following:

1. In all the photographs submitted, there is no personal data of the complainant and therefore no issue arises

regarding their collection and processing. Furthermore, according to

his allegations, the photographs depict the complainant's car, which does not constitute personal data.

3 2. None of the cameras in the video surveillance system record a public

space on a fixed basis. Due to an incident that took place with the complainant outside the premises of defendant B, the security guards
manually turned the cameras without the intervention of defendant B,

in order to photograph the complainant's car. Subsequently,

the guards printed the above photographic material, which they handed over

to the prosecution authorities, and therefore there is no question of illegal

processing and disclosure to third parties without prior notification of

the data subject.

Following the above, the Authority sent the summons under no. prot. C/EXE/531/07-02-2025

to the accused A, the summons under no. prot. C/EXE/537/07-02-2025 to

the accused B and the summons under no. prot. C/EXE/538/07-02-2024 summons to the complainant to attend the meeting of the Department of the Authority on Wednesday 05

March 2025, in order to present their views on the case. At the meeting in question, which was held via videoconference, A

and his lawyer Dimitrios Verras with AM DS … were present. Also contacted on behalf of the two companies complained of above

are the lawyers Nikolaos Kakolias with AM

27061/DS…, Eleni Glekle with AM 19347/DS… and Antiopos Selianitis with AM

25336/DS…, in order to provide clarifications on the case. After the meeting, the parties involved were given a deadline to submit a memorandum, to develop the allegations they made during the meeting, as well as to provide clarifications on the issues for which questions were submitted during the meeting. Subsequently, the complainant submitted the no. prot.
C/ΕΙΣ/2364/21-03-2025 memorandum, in which he essentially repeated the allegations

he had previously raised before the Authority, in which he listed a series of

questions regarding the video surveillance system used by

both defendants, its legality and the fact that during

the meeting none of the specific questions were answered, as well as that

both defendants did not provide clarifications regarding their general
obligation regarding the principles of the GDPR. The two defendants requested

an extension for sending their memorandum with the no. prot. C/ΕΙΣ/2373/21-03-2025

4 document, without such a document being ultimately submitted to the Authority.

The Authority, after examining the elements of the file and the findings of

the hearing before it and the memorandum of the complainant alone, after

hearing the rapporteur and the clarifications from the assistant rapporteurs, who

attended without the right to vote, following a thorough discussion,

HAS DECIDED IN ACCORDANCE WITH THE LAW

1. Whereas, from the provisions of articles 51 and 55 of the General Data Protection Regulation

(hereinafter, GDPR) and article 9 of law 4624/2019

(Government Gazette A' 137) it follows that the Authority has the competence to supervise the implementation

of the provisions of the GDPR, this law and other regulations relating to

the protection of individuals from the processing of personal data. In particular,

from the provisions of articles 57 par. 1 letter f of the GDPR and 13 par. 1 letter g

of law 4624/2019 it follows that the Authority has the competence to handle the complaint in question,

therefore for processing falling within the regulatory scope

of articles 2 par. 1 of the GDPR and 2 of law 4624/2019.

2. Because the image of a person collected through the use of a video surveillance system constitutes personal data, to the extent that
1
it provides the possibility of identifying the specific natural person

directly or indirectly, while the capture and/or recording of the image which is stored
and maintained in a continuous-stream video surveillance mechanism, such as on the system's hard

disk, constitutes automated data processing. According to the definition in Article 4(1) of the GDPR, personal data is “any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, 34

5 genetic, psychological, economic, cultural or social identity of the natural person in question" and therefore, identification of a person through visual

material can be carried out based on his appearance or other specific

elements and the Authority has already considered that the vehicle registration number constitutes

personal data, since through it the natural person becomes identifiable

(see APD 91/2009 ) as well as that the collection and storage

of photographic or video material, which depicts the vehicle registration number, as it appears on its plate, in combination with

other elements which make the natural person identifiable, even

within the framework of a small group, constitutes the processing of personal

data, since the owner of the car can become

identifiable through his registration number as it appears on the vehicle's plate (see APD 34/2023 ).

3. Whereas, according to Article 4, item 2 of the GDPR, processing of personal data

is “any operation or set of operations which is performed upon personal data or sets of personal data, whether or not by automated means, such as

collection, recording, organisation, structuring, storage, adaptation

or alteration, retrieval, consultation, use, disclosure by

transmission, dissemination or otherwise making available, alignment or combination,

restriction, erasure or destruction”.

4. Whereas, according to Article 4, item 2 of the GDPR, 7 of the GDPR, a controller
is defined as “the natural or legal person, public authority, agency or other
body which, alone or jointly with others, determines the purposes and means
of the processing of personal data; and where the purposes and means
of such processing are determined by Union or Member State law
, the controller or the specific criteria for the designation
3See EDPB ΚΓ 3/2019 on the processing of personal data through video devices –
p. 7
4 https://www.dpa.gr/el/enimerwtiko/prakseisArxis/ypiresia-eikonikis-periigisis-stoys-dromoys-ellinikon-
periohon
5 https://www.dpa.gr/el/enimerwtiko/prakseisArxis/exetasi-kataggelias-fysikoy-prosopoy-kata-etaireias-gia-
epexergasia

6 of which may be provided for by Union law or the law of a Member State.

5. Whereas, in accordance with Article 4 para. 9 of the GDPR, a recipient is defined as “the

natural or legal person, public authority, agency or other body to which

personal data are disclosed, whether or not it is a third party.

However, public authorities which may receive personal data

in the context of a specific investigation in accordance with Union

or Member State law shall not be considered as recipients; the processing of such data

by such public authorities shall be carried out in accordance with

applicable data protection rules in accordance with the purposes of the

processing”.

6. Whereas, in accordance with Article 4(1)(a) 12 of the GDPR, a personal data

breach is defined as “a breach of security leading to

accidental or unlawful destruction, loss, alteration, unauthorised disclosure or

access to personal data transmitted,

stored or otherwise processed.”

7. Whereas the installation and operation of video surveillance systems with the capture

and/or recording of images and/or sound through the collection, retention, storage,

access and transmission of personal data, even from

a public space, constitute, as individual processing operations, an interference with

the individual rights to respect for private life under art. 9 of
7
the Constitution, 7th CPR and 8 ECHR as well as the protection of personal data under art. 9A of the Constitution, 8 ECHR and 8 CPR .

8. Whereas, under the GDPR, a new compliance model has been adopted, the central point of which is the principle of accountability, in the framework of which the controller of personal data is obliged to design, implement and generally take the necessary measures and policies in order to ensure that the processing of data is in accordance with the relevant legislative

6ECtHR Vukota-Bojic v Switzerland, 61838/10, 18.10.2016, § 52 et seq., Lopez Ribalda v Spain (GC), 1874/13 &
8567/13, 17.10.2019, §§ 89, 93, Antovic & Mirkovic v Montenegro, 70838/13, 28.11.2017, § 42, Uzun v.
Germany, 35623/05, 2.9.2010, §46, Peck v UK, 44647/98, 28.01.2003, §59
7DIC Digital Rights Ireland para. 29
8DIC Digital Rights Ireland para. 38

7 provisions, while the controller bears the further duty

to prove himself and at all times his compliance with the provisions

of the Regulation.

9. Whereas, according to Article 5 para. 1 lit. a’, b’ and c’: “Personal data:

shall be: (a) processed lawfully and fairly in a manner

transparent in relation to the data subject (‘lawfulness,

objectivity and transparency’),…, (c) adequate, relevant and

limited to what is necessary in relation to the purposes for which they are

processed (‘data minimisation’), (b) collected for

specified, explicit and legitimate purposes and not further

processed in a manner incompatible with those purposes; further

processing for archiving purposes in the public interest or for scientific or historical research purposes or statistical purposes shall not be considered to be

incompatible with the initial purposes in accordance with Article 89(1)

(‘purpose limitation’), (c) adequate, relevant and

limited to what is necessary in relation to the purposes for which they are

processed (‘data minimisation’) data»),…, and Article 5 para. 2 «The controller

shall be responsible for and able to demonstrate compliance with

paragraph 1 («accountability»)».

10. Because, in order for personal data to be lawful

processed, i.e. processed in accordance with the requirements of the GDPR, the conditions for the application and observance of

the principles of Article 5para. 1 GDPR must be met cumulatively, as follows from the recent judgment

of the Court of Justice of the European Union (CJEU) of 16-01-2019 in case
10
C496/2017 Deutsche Post AG v. Hauptzollamt Köln. The existence of a lawful

basis (art. 6 GDPR) does not exempt the controller from the

obligation to comply with the principles (art. 5 par. 1 GDPR) regarding the legitimate

9See also Authority decision 26/2019, paragraph 8, available on its website.
10«57. However, any processing of personal data must comply, on the one hand, with the principles to be observed in terms of data quality, which are set out in Article 6 of Directive 95/46 or Article 5 of Regulation 2016/679 and, on the other hand, with the basic principles of lawful data processing listed in Article 7 of that Directive or Article 6 of that Regulation (cf. judgments ...C-465/00, C-138/01, C-139/01, C-131/12)..

8 nature, necessity and proportionality and the principle of minimisation. In the event that any of the principles set out in Article 5(1) GDPR are infringed, the processing in question shall be deemed unlawful (subject to the provisions of the GDPR) and shall be deemed to be inadmissible. the

examination of the conditions for the application of the legal bases of Article 6

GDPR. Thus, the unlawful collection

and processing of personal data in violation of the principles of Article 5 GDPR is not cured by the

existence of a legitimate purpose and legal basis (cf. cf. ref. 26/2019, 12/2022, 25/2022). Furthermore, the CJEU, with its decision of 01-10-2015

in the context of case C-201/14 (Smaranda Bara), considered as a condition

of the fair and lawful processing of personal data

13
the information of the data subject before such processing.

11. Whereas, in accordance with Article 12(1) and (2) of the GDPR: “1. The controller shall take appropriate measures to provide the data subject with any information referred to in Articles 13 and 14 and any communication in the context of Articles 15 to 22 and Article 34 relating to the processing in a concise, transparent, intelligible and easily accessible form, using clear and plain language, in particular where it concerns information specifically addressed to children. The information shall be provided in writing or by other means, including, where appropriate, electronically. Where requested by the 

11 See L. Mitrou, The General Data Protection Regulation [New Law-New Obligations-New Rights], Sakkoulas Publishing House, 2017, pp. 58 and 69-70).
12
See CoE 517/2018 par. 12: “[...] in order for personal data to be lawfully processed, it is required in each case that the conditions of article 4 par. 1
of law 2472/1997 are cumulatively met, which, among other things, stipulates that the data must be collected and processed in a fair and lawful manner, for clear and legitimate purposes... If the conditions of article 4 par. 1 of law 2472/1997 (lawful collection and processing of data for clear and legitimate purposes) are met, it is further examined whether the conditions of the provision of article 5 par. 2 of law 2472/1997 [legal bases] are also met”. Also, cf. Council of Greece in Plenary 2285/2001 par. 10: “[...] Only if the above basic conditions are met, the provisions of Articles 5 and 7 of Law 2472/1997 apply, which impose as a further additional, in principle, condition for lawful processing of personal data of a specific person, the consent of that person”13“31. the controller or his representative are subject to an obligation to provide information, the content of which is defined in Articles 10 and 11 of Directive 95/46 and differs depending on whether the data are collected from the person to whom the data relate or not, and this is subject to the exceptions provided for in Article 13 of the said Directive [...] 34. Consequently, the requirement on the fair processing of data provided for in Article 6 of Directive 95/46 obliges the administrative authority to inform the data subjects of the transmission of the said data to another administrative authority for the purpose of their processing by the latter as recipient of the said data”.

9 data subject, the information may be given orally, provided that the identity of the data subject is

proven by other means. 2. The controller shall facilitate the exercise of the rights of data subjects set out in Articles 15 to 22. In the cases referred to in Article 11(2), the controller shall not refuse to act on a request from the data subject to exercise the rights set out in Articles 15 to 22, unless the controller demonstrates that it is unable to verify the identity of the data subject. 12. Whereas, pursuant to Article 13 of the GDPR, “1. Where personal data relating to a data subject are collected from the data subject, the controller shall, when receiving the personal data, provide the data subject with all of the following information: (a) the identity and contact details of the controller and, where applicable, of the controller's representative; (b) the contact details of the data protection officer, where applicable; (c) the purposes of the processing for which the personal data are intended and the legal basis for the processing; (d) where the processing is based on point (f) of Article 6(1), the legitimate interests pursued by the controller or by a third party; (e) the recipients or categories of recipients of the personal data, if any. 2. In addition to the information referred to in paragraph 1, the controller shall, when receiving the personal data, provide the data subject with the following information: additional information necessary to ensure fair and transparent processing: a) the period for which the personal data will be stored or, where that is not possible, the criteria determining that period, b) the existence of the right to request from the controller access to and rectification or erasure of personal data concerning the data subject or restriction of processing or the right to object to processing, as well as the right to data portability, c) where the processing is based on Article 6(1)(a) or Article 9(2)(a), the existence of the right to withdraw consent at any time, without affecting the lawfulness of the processing based on consent before its withdrawal, d) the right to lodge a complaint with a supervisory authority, e) whether the provision of personal data is a legal or contractual obligation or requirement for the entering into a contract, as well as

the extent to which the data subject is obliged to provide the personal data

and what the possible consequences of not providing those data would be,

f) the existence of automated decision-making,

including profiling, as referred to in Article 22

paragraphs 1 and 4 and, at least in such cases, significant

information about the logic involved, as well as the significance and

envisaged consequences of such processing for the data subject,

3. Where the controller intends to further process the personal data

for a purpose other than that for which the personal data were collected, the controller

shall provide the data subject, prior to such further processing, with information on that purpose and any other necessary

information, as referred to in paragraphs 2, 4.

Paragraphs 1, 2 and 3 shall not apply, where and to the extent that the data subject already has the information,”

13. Because, according to Article 15(1) and (3) of the GDPR: “1. The data subject shall have the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the personal data and to the following information: a) the purposes of the processing, b) the categories of personal data concerned, c) the recipients or categories of recipients to whom the personal data have been or are to be disclosed, in particular recipients in third countries or international organisations, d) where possible, the period for which the personal data will be stored or, where that is not possible, the criteria determining that period, e) the existence of the right to request from the controller rectification or erasure of personal data or restriction of processing of personal data concerning the data subject or the right to object to such processing, f) the right to lodge a complaint with a supervisory authority, (g) where the personal data are not collected from the data subject, any available information on their origin, (h) the existence of automated decision-making, including profiling, as referred to in Article 22(1) and (4) and, at least in such cases, meaningful information on the logic involved and the significance and the envisaged consequences of such processing for the data subject.” and “3. The controller shall provide a copy of the personal data being processed. For any additional copies that may be requested by the data subject, the controller may charge a reasonable fee for administrative costs. If the data subject makes the request by electronic means and unless the data subject requests otherwise, the information shall be provided in a commonly used electronic format. These provisions establish the right of access to personal data concerning him or her. In the context of this right, the data subject must, on the one hand, have access to personal data collected concerning him or her in order to ascertain the accuracy and nature of the processing of his or her data and to verify the lawfulness of the processing, and, on the other hand, be able to exercise this right easily and at reasonable intervals. The controller must provide remote access to a secure system through which the controller can access the personal data concerning him or her. 14 See Recital 63 of the GDPR

12 the data subject obtains direct access to the data relating to him

.5

14. Whereas, according to Article 31 of the GDPR “The controller and the

processor and, where applicable, their representatives shall cooperate,

upon request, with the supervisory authority in the performance of its tasks.”

15.Because, according to Article 37(7) of the GDPR “The controller or
the processor shall publish the contact details of the data protection officer and communicate them to the supervisory authority.”

16. In the cases under examination, as is apparent from the information in the files and

following what emerged during the hearing, it is established that the

complainant exercised the right of access to data concerning him/her to

the complainants A and B, who in this case are the controllers,

requesting information regarding the collection and processing of

personal data through the video surveillance system in operation,
requesting the disclosure of the controller's data protection policy,
as well as information regarding the personal data that

is processed by the controller in question and in particular the recipients of

this data. The complainant exercised the said right in a clear manner

in both cases. Both respondents did not fully respond to the above-mentioned requests of the complainant, but requested additional clarifications from him, thus making the exercise of the right of access difficult. Following relevant clarifications provided by the complainant, the two respondents replied to the complainant regarding the policy followed for the respective video surveillance system, stating that it is used for the purpose of protecting persons and property, while its operation is entirely legal, without providing all of the information as provided for in Article 13 of the GDPR, such as the identity and contact details of the controller, the contact details of the data protection officer, if one has been appointed, the legal basis for the processing, the recipients or categories of data. 15 See also recital 63 of the GDPR and Decision of the Authority 23/2020

13 recipients, any transfers, the retention period, the right

to submit a request for satisfaction of rights and the right to submit

a complaint to the Authority, while they also responded, through their letters, in

an identical manner that they did not disclose the respective material from the video surveillance system to a third party.

Furthermore, in his relevant response to the Authority, the complainant A

claimed that there are no cameras installed in the points mentioned

by the complainant. On the contrary, he claims that the only cameras that exist are

those installed at the entrance to the exhibition center, while their operation

is legal. According to what the accused A states,

the cameras to which the complainant refers are the ones that were initially

installed and then put into disuse and stopped working.

Furthermore, according to the allegations of the accused A, some of the

material (photographs) provided by the complainant is not related to the material
used by the accused A in the above litigation, but

results from others collected by the complainant himself. However,

the accused A admits that he used photographs from the video surveillance system

to defend his rights before the court.

As for the said processing purpose, it appears that it is included

among the stated processing purposes in the text of the personal data protection policy

posted by the defendant on his website

16
. However, the said personal data protection policy, although
is publicly accessible for the information of data subjects,

does not concern personal data processed by the video surveillance system.

Through the signs, which the accused A has posted

in the area supervised by the video surveillance system,

information is provided

on the purpose of processing for the protection of persons and goods,

without however providing appropriate information in accordance with

what is provided for in Article 13 of the GDPR, nor a reference to information

16
https://www.mec.gr/wp-content/uploads/2024/06/privacy-policy-mec.pdf

14 17 18
level 2 in accordance with the Guidelines 3/2019 .

In his response, the defendant claimed that there is no personal data of the complainant, as he considers that the complainant's vehicle does not constitute personal data, an argument which, as discussed above, is not accepted. He also states that the cameras are not fixed but can be swiveled and were modified to record the complainant's offending behavior by the security guards, who acted voluntarily and handed over the material directly to the judicial authorities, an argument that is put forward without further documentation. Therefore, it is considered that both defendants did not satisfy the right of access. 17. The Authority, in the context of investigating the first complaint, tried to

contact the complainant A through the contact details that

are available on his website (email address

info@mec.gr). This email address is also the

official point of contact, as the complainant A informs in

his personal data protection policy (see No. 17 Opinion –

last checked 8-11-2024), with the data protection officer that he has

appointed, who, however, has not been announced to the Authority. Accordingly, the Authority, in the

context of investigating the second complaint, attempted to contact

the complainant B through the contact details provided by the complainant in his complaint

against the complainant B, but also based on the details

listed on his website (email address

gdpr@market-in.gr), without success. In addition, following a search

it was found that there is no relevant communication of the DPO details of the complainant B to the Authority, as required by Article 37, paragraph 7 of the GDPR in

the case of the appointment of a DPO.

18. Both complainants responded to the Authority on the complaints subsequently

17
See section 7.2. Second level information p. 32 in the CG 3/2019 regarding the processing of personal data through video devices
https://www.edpb.europa.eu/sites/default/files/files/file1/edpb_guidelines_201903_video_devices_el.pdf
18 See the Authority's Recommendations in the section Video Surveillance Systems->Obligations of Controllers->Information Models on its website
https://www.dpa.gr/el/enimerwtiko/thematikes_enotites/eisagwgi_videoepitirisi

15 many communications and after a long period of time.

In particular, the complainant B responded in a period of more than one

year, thus demonstrating particular difficulty in his cooperation

with the Authority. Furthermore, both did not submit a memorandum following the

hearings despite the fact that they requested an extension for their submission (see

communications with no. protocol C/EXE/1033/24-03-2025 and with no.

protocol C/EXE/1034/24-03-2025).

19. According to the Guidelines 01/2022 on the rights of
19
data subjects and in particular the right of access, as

stated in paragraph 163 “What constitutes a complex request varies

depending on the specific circumstances of each case. Some of the

factors that could be considered relevant are, for example:

the volume of data processed by the controller,

the way in which the information is stored, in particular when it is difficult to retrieve the

information, for example when the data are processed

by different units of the organisation,

the need to erase information

where an exception applies, for example for information concerning other

data subjects or constituting a trade secret, and

where the information requires further work in order to be understandable”.

In

the case,

both complainants have not substantiated the delay

in satisfying the right of access in breach of Article 12

of the

GDPR by invoking any of the abovementioned suspending factors.

20. Also in accordance with the Guidelines 01/2022 on the rights of data subjects and in particular the right of access, as stated in paragraph 108 “The EDPB points out that it is part of the employer’s responsibility under Article 24 of the GDPR to use appropriate measures, ranging from training to disciplinary proceedings, to ensure that the processing of personal data is carried out in a way that is not harmful to the health and safety of the data subject.” complies with the GDPR and that no infringement is committed.” In this case

the defendant B claims in his response that the security guards

acted voluntarily and manually turned the cameras in order to

photograph the complainant’s car, material which they printed

without the intervention of the controller and therefore

processed illegally and disclosed to the judicial authorities, without

however, this being documented and without the manner of transmission to

the judicial authorities being apparent. Therefore, the defendant B as controller

did not take the appropriate technical and organizational measures

including the training and information of employees in order

to ensure the appropriate level of security of the processing and

its general compliance with the GDPR in accordance with the principle of

accountability.
21. According to the Guidelines 03/2019 on the rights of

data subjects and in particular the right to object, as

referred to in paragraph 106 “In the context of video surveillance, this

objection could be made upon entry into the monitored

space, during the stay in it and after leaving it.

In practice, this means that, unless the controller has overriding and legitimate grounds, surveillance of premises in which the identity of natural persons can be ascertained is lawful only if (1) the controller can immediately stop the camera from processing personal data upon receipt of a request, or (2) access to the premises being monitored is very strictly controlled so that the controller can ensure the consent of the data subject before the data subject enters the premises and it is not a premises to which the data subject has a right of access as a citizen. Furthermore, with regard to disclosure, it is stated that “each disclosure of personal data constitutes a separate type of disclosure” (21). See the grounds for the disclosure. 19 https://www.edpb.europa.eu/system/files/2023-
10/edpb_guidelines_202007_controllerprocessor_final_el.pdf
22https://www.edpb.europa.eu/sites/default/files/files/file1/edpb_guidelines_201903_video_devices_el.pdf

17 processing of personal data for which the controller

must have a legal basis in the context of Article 6”.

22. Therefore, based on the above, the Authority finds the following violations for the
complainant A:

a) Article 5 par.1 letters a’ and b’ of the GDPR in conjunction with paragraph 2 of

the same article of the GDPR, regarding the collection and processing of personal

data for a purpose other than that for which the subject was initially

informed. Specifically, while the personal data was used in a judicial manner, the information provided to the complainant did not include this purpose of processing but only the purpose of protecting persons and property.

b) Article 12(1) and (2) of the GDPR regarding the failure to facilitate the exercise of the right of access by the data subject, since the controller did not take appropriate measures to ensure that the information requested by the data subject regarding the video surveillance system is provided, which information constitutes elements provided for in Article 15 of the GDPR, in particular, it did not adequately respond to the issue of disclosure of the data subject's personal data.

c) Article 13 par. 1 and par. 3 of the GDPR regarding the fact that the controller
did not provide information to the data subject regarding
the further processing of the personal data collected.

d) Article 37 par. 7 of the GDPR, regarding the failure to communicate the contact details
of the data protection officer to the Authority.

23. Furthermore, based on the above, the Authority finds the following violations for

the accused B:
a) Article 5 par. 1 item. a’ and c’ of the GDPR in conjunction with i) paragraph 2

of the same article of the GDPR, regarding the collection and processing

of personal data for a purpose other than that initially specified, and ii)

with article 13 par. 1 and par. 3 of the GDPR regarding transparency in

informing the data subject, as the controller

did not provide information to the data subject regarding

the further processing of the personal data collected, while the

email address gdpr@market-in.gr announced on the website

of the accused B (https://www.market-in.gr/el-

gr/information/4820/Prosopika-dedomena/) is misleading, as

it appears that it is not managed by a natural person, in order to respond to

any requests such as that of the Authority.

b) Article 12, paragraph 1 and paragraph 2 of the GDPR, regarding the remote facilitation of the exercise of the right of access to the data subject, since the controller did not take appropriate measures to ensure that the information requested by the data subject regarding the video surveillance system, which constitutes information provided for in Article 15 of the GDPR, is provided, in particular, it did not adequately respond to the issue of the disclosure of the data subject's personal data.

c) Article 31 of the GDPR, regarding the difficulty demonstrated by the controller in cooperating with the Authority.

24. Since the above violations, as detailed above, entail the imposition of the administrative sanctions of Article 83, paragraph 5, subparagraph a of the GDPR.

According to the GDPR (Recital 148) in order to strengthen the
enforcement of the rules of this Regulation, sanctions,

including administrative fines, should be imposed

for any infringement of this Regulation, in addition to or instead of

appropriate measures imposed by the supervisory authority in accordance with

this Regulation.

25. Furthermore, the Authority took into account the criteria for measuring the fine

set out in Article 83(2) of the GDPR, paragraph 5 of the same article
which is applicable to the present case and the Guidelines

4/2022 of the European Data Protection Board on the calculation

of administrative fines for the purposes of Regulation 2016/679, which

were approved on 24/5/2023, as well as the actual data of the case under examination

and in particular the following:

23
https://www.edpb.europa.eu/system/files/2024-
01/edpb_guidelines_042022_calculationofadministrativefines_el_0.pdf

19As regards the accused A:

i. The following violations were identified:

a. the defendant A disclosed the material from the video surveillance system
without prior notification of
the data subject and therefore as controller
he violated the principle of transparency provided for in Article 5 para. 1

sub-paragraph a’, i.e. he violated a fundamental principle of
the GDPR for the protection of personal data,

Article 13 as well as Article 5 para. 2 since he failed to
prove his compliance with the GDPR.

b. the defendant A proceeded with processing without
ensuring that the processing is carried out in a manner compatible with
the initially specified purpose and therefore as controller
he violated the principle of transparency provided for in Article 5 para. 1

sub-paragraph b’ principle of purpose limitation, i.e. it violated
a fundamental principle of the GDPR for the protection of personal data

, Article 13 as well as Article 5 para. 2

as it failed to demonstrate its compliance with

the GDPR.

c. the complainant A did not facilitate, as provided for in
Article 12, paragraph 1 and paragraph 2, the exercise of the rights of the

subject, since he did not take appropriate measures to

ensure that all the information requested

by the data subject regarding the policy relating to the video surveillance system is provided, he did not adequately respond to the

issue of the disclosure of personal data of the

data subject, as well as he did not satisfy the

right of access to personal data and

information requested by the complainant, and did not

provide a copy of the personal data that

were processed and therefore, as a controller, he violated the provisions of Article 15, paragraph

20 1 and paragraph 3, i.e. he violated the provisions of the GDPR relating to

the rights of data subjects.

d. the defendant A appears to have appointed a data protection officer, but did not communicate his details to the supervisory authority as required, in accordance with Article 37(7), in breach of the GDPR provisions relating to the obligations of the controller. ii. the above infringements under a, b and c shall, in accordance with Article 83(2), be subject to administrative fines of up to EUR 20,000,000 or up to 4% of the total global annual turnover of the preceding financial year, while the above sub-infringement shall, in accordance with Article 83(2), be subject to administrative fines of up to EUR 10,000,000 or, in the case of undertakings, up to 2% of the total global annual turnover of the preceding financial year. iii. As regards the degree of seriousness of the above infringements:
a. the disclosure to the judicial authorities constitutes a processing,

of which the data subject

was not duly informed and which is related to the protection

purpose of the controller (infringements i. a and i. b above).

The processing in question does not fall within the core activities of

the controller, while its scope and duration appear

to be small. Furthermore, the number of

data subjects affected by the processing in question is

small, while any damage suffered by

the affected data subject cannot be determined. Furthermore,

it cannot be excluded or substantiated that the
unreported

person did not act fraudulently.

Finally,

it does not appear that

sensitive data covered by Articles 9 and

10 of the GDPR as well as data outside the scope of

these

articles are affected, the dissemination of which causes direct

damage/difficulty to the data subject (e.g. location

data, data relating to private communication, national

identification numbers or financial data, such as

transaction overviews or credit card numbers),

and

the volume of data does not appear to be large.

Therefore, the

seriousness of the breaches in question is considered medium.

b. the respondent A did not take appropriate measures to

limit the complainant's damage from the above i. c

breach, while the scope and duration of the breach is small

and the processing in question does not fall within its core

activities. Furthermore, the number of individuals affected is small with the potential for

more data subjects to be affected due to insufficient

information regarding the policy followed

regarding the video surveillance system in operation. It

cannot be established whether the respondent A acted with intent.

Finally, it does not appear that sensitive data covered by Articles 9 and 10 of the GDPR, as well as data outside the scope of these Articles, the dissemination of which would cause direct harm/difficulty to the data subject (e.g. location data, data relating to private communication, national identification numbers or financial data, such as transaction overviews or credit card numbers), are affected. Therefore, the severity of the breach is considered medium. c. the failure to disclose the controller's data does not entail any greater risks, therefore the extent of the breach is small. In addition, the processing in question does not

fall within its core activities, while its duration is

long, since the details of the data protection officer have not been communicated to the Authority by the time of the call.

Furthermore, the number of individuals affected is small.

It cannot be substantiated whether the complainant A acted with

deliberate intent. Finally, it does not appear that sensitive data

covered by Articles 9 and 10 of the GDPR, as well as data

22 outside the scope of these Articles, the dissemination of which

causes direct damage/difficulty to the data subject (e.g. location data, data relating to private

communication, national identification numbers or financial

data, such as transaction overviews or credit

card numbers) are affected. Therefore, the degree of seriousness of the violation

is considered minor.

iv. In all the above cases of violations by the accused A,

the
Authority takes into account the following as aggravating factors: The fact that the
accused A did not take action to limit the

consequences of the violation. Furthermore, there is potential harm to the

data subject since the accused A did not fulfill

his obligations under the GDPR. Finally, the fact that the accused

A did not submit a supplementary memorandum after the hearing

procedure, despite the prior communication and notification of the Authority

about its mission, constitute aggravating factors for

calculating the fine. However, the fact that no

recent relevant violations of the GDPR have been established by the

accused is taken into account.

v. The latest consolidated available turnover of the
complainant A (01/01/2024 - 31/12/2024) which amounts to

4,434,670.10.

Regarding the complainant B:

i. The following violations were identified:

a. The complainant B disclosed the material from the

video surveillance system without prior notification of the

data subject and therefore, as the

controller, he violated the principle of transparency provided for in Article 5, paragraph 1

subparagraph a’, i.e. he violated a fundamental principle of

the GDPR for the protection of personal data,

Article 13 as well as Article 5, paragraph 2, since he failed to

prove his compliance with the GDPR.

23 b. The accused B proceeded with processing without

ensuring that the data he processed are

relevant and limited to what is necessary for the purpose for

which they were processed for and therefore, as the controller, he violated the principle of minimization provided for in Article 5(1)(c), i.e. he violated a fundamental principle

of the GDPR for the protection of personal data, as well as Article 5(2), as he failed to

prove his compliance with the GDPR.

c. The complainant B did not facilitate, as provided for in

Article 12, paragraphs 1 and 2, the exercise of the rights of the

subject, since he did not take appropriate measures to

ensure that all the information requested

by the data subject regarding the policy relating to the video surveillance system is provided, he did not adequately respond to the

issue of the disclosure of personal data of the

data subject, as well as he did not satisfy

the right of access to personal data and

information requested by the complainant, and did not

provide a copy of the personal data that

was processed, consequently, as a controller, he violated the provisions of

Article 15, paragraphs 1 and 3, i.e. he violated the provisions of the GDPR relating to

the rights of data subjects.

d. The respondent B did not cooperate with the supervisory authority as it should have in accordance with Article 31, in breach of the provisions relating to the obligations of the controller.

ii. the above infringements under a, b, c shall, in accordance with paragraph 2 of

Article 83, be subject to administrative fines of up to EUR 20,000,000 or up to 4% of

the total worldwide annual turnover of the preceding

financial year, while the above infringement under d shall, in accordance with

paragraph 2 of Article 83, be subject to administrative fines of up to EUR 10,000,000

24 or, in the case of undertakings, up to 2% of the total worldwide annual turnover of the preceding financial year.

iii. As regards the degree of seriousness of the above infringements:
a. the disclosure to the judicial authorities constitutes a processing,

of which the data subject

was not duly informed, which is related to the protection purpose of

the controller (infringement i. a). The processing in question

does not fall within the core activities of the controller

and its scope and duration appear to be

small. Furthermore, the number of data subjects affected by the processing in question

is small, and it is not

possible to determine any damage suffered by the affected data subject. Furthermore, it cannot

be excluded or substantiated whether the accused B acted fraudulently. Finally, it does not appear that sensitive data covered by Articles 9 and

10 of the GDPR are affected, as well as data outside the scope of

these articles, the dissemination of which causes direct

damage/difficulty to the data subject (e.g. location data, data relating to private communication, national identification numbers or financial data, such as transaction overviews or credit card numbers), and the volume of data does not

appear to be large. Therefore, the

seriousness of the breaches in question is considered medium.

b. The complainant B did not take appropriate measures to

limit the complainant's damage, while the extent and

duration of the breach is minor and the processing in question does not

fall within its core activities. Furthermore, the number of affected

individuals is small with a potential

possibility that more data subjects may be affected due to insufficient

information regarding the policy followed

regarding the video surveillance system in operation.

It cannot be established whether the accused B acted with intent.

Finally, it does not appear that sensitive data covered

by Articles 9 and 10 of the GDPR, as well as data outside

the scope of application of these Articles, the dissemination of which

causes direct damage/difficulty to the data subject

(e.g. location data, data relating to private communication,

national identification numbers or financial data,

such as transaction overviews or credit card numbers), are affected.

Therefore,

the severity of the breach is considered medium.

iv. In all the above cases of violations by the accused B, the

Authority takes into account the following as aggravating factors: The fact that the

accused B did not take actions aimed at limiting the

consequences of the violation. Furthermore, there is potential harm to the

data subject, since the accused B did not fulfill

his obligations under the GDPR. Finally, the fact that the accused

B did not submit a supplementary memorandum after the hearing

procedure, despite the prior communication and information of the Authority

about its mission, constitute aggravating factors for

calculating the fine. However, the fact that no recent relevant violations of the GDPR have been established by the

accused is taken into account.

v. The latest consolidated available turnover of

the accused B (01/01/2024 - 31/12/2024) which amounts to

€171,179,897.19.

26. After taking into account the above criteria, as well as the turnover of

the controllers, the Authority unanimously decides that

the accused as controllers should be imposed the administrative sanctions referred to in

the operative part, which are deemed proportionate to the severity of

the violations.

26 FOR THESE REASONS

The Authority:

a) Imposes on “MEDE SA” as controller:

i. based on article 58 par. 2 sub. i’ of the GDPR, in accordance with Article 83

of the GDPR, an administrative fine of a total amount of twenty thousand (20,000) euros,

for the violation of Articles 5 par. 1 letter a’, 5 par. 1 letter b’, 13 par. 1 and

5 par. 2 of Regulation (EU) 2016/679.

ii. based on Article 58 par. 2 sentence i’ of the GDPR, in accordance with Article 83

of the GDPR, an administrative fine of a total amount of twenty thousand (20,000) euros,

for the violation of Articles 12 par. 1 and par. 2 and 15 par. 1 and par. 3 of

Regulation (EU) 2016/679.

iii. based on Article 58, paragraph 2, subparagraph i’ of the GDPR, in accordance with Article 83

of the GDPR, an administrative fine of a total amount of twenty thousand (20,000) euros,

for the violation of Article 5, paragraph b’ and 13, paragraph 3 of Regulation (EU)

2016/679.

iv. based on Article 58, paragraph 2, subparagraph i’ of the GDPR, in accordance with Article 83

of the GDPR, an administrative fine of a total amount of five thousand (5,000) euros, for

the violation of Article 37, paragraph 7 of Regulation (EU) 2016/679.

b) Imposes on “MARKET IN SA” as controller:

i. based on Article 58, paragraph 2, subparagraph i’ of the GDPR, in accordance with Article 83
of the GDPR, an administrative fine of a total amount of fifty thousand (50,000) euros,

for the violation of Article 5 par. 1 letter a’, in conjunction with Article 13

and Article 5 par. 2 of Regulation (EU) 2016/679.

Ii. based on Article 58 par. 2 letter i’ of the GDPR, in accordance with Article 83

of the GDPR, an administrative fine of a total amount of twenty thousand (20,000) euros,

for the violation of Article 5 par. 1 letter c’ in conjunction with Article 5 par.
2 of Regulation (EU) 2016/679.

iii. based on Article 58 par. 2 letter i’ of the GDPR, in accordance with Article 83

of the GDPR, an administrative fine of a total amount of twenty thousand (20,000) euros,

for the violation of Articles 12 par. 1 and par. 2 and 15 par. 1 and par. 3 of

Regulation (EU) 2016/679.

iv. based on Article 58 par. 2 sub. i’ of the GDPR, in accordance with Article 83

27 of the GDPR, an administrative fine of a total amount of five thousand (5,000) euros, for

the violation of Article 31 of Regulation (EU) 2016/679.

The Acting President The Secretary

Vice President

George Batzalexis Irene Papageorgopoulou

28