HDPA (Greece) - 33/2025
| HDPA - 33/2025 | |
|---|---|
| Authority: | HDPA (Greece) |
| Jurisdiction: | Greece |
| Relevant Law: | Article 5(1)(f) GDPR Article 25(1) GDPR Article 32(1) GDPR Article 33(1) GDPR Article 34(1) GDPR |
| Type: | Complaint |
| Outcome: | Upheld |
| Started: | |
| Decided: | 21.07.2025 |
| Published: | |
| Fine: | 9,000 EUR |
| Parties: | Bookstore of Hestia |
| National Case Number/Name: | 33/2025 |
| European Case Law Identifier: | n/a |
| Appeal: | Not appealed |
| Original Language(s): | Greek |
| Original Source: | HDPA (in EL) |
| Initial Contributor: | Le |
The DPA fined a publishing house €9,000 for revealing the real name and the gender identity of an author who published books using a pseudonym. The DPA found that the controller failed to implement appropriate security measures.
English Summary
Facts
The controller is a publishing company, Bookstore of Hestia. The data subject is a writer, contracted with the controller, who published books using a pseudonym due to his desire to hide his authorship form his immediate family and professional environment. The data subject belongs to a gender minority, the problems thereof are the focus of his writing.
In February 2024, the data subject received an email to his personal email address from the controller which was visible to the other recipients of the message, numbering approximately 55 people. This resulted in the disclosure of his real identity to all third parties.
The data subject lodged a complaint with the DPA (Hellenic Data Protection Authority-HDPA) alleging that the above breach resulted in the disclosure to the other recipients of the email of his personal data relating to his gender identity, which therefore constitutes a special category of personal data. He also claimed that the breach caused him shock and serious psychological problem and put his career in danger. Furthermore, the data subject stated that the controller did not take any of the actions required under the GDPR after the critical incident pursuant to Article 34 GDPR and that it failed to implement appropriate technical and organisational measures.
The controller on the other hand, claimed that the critical email message made no mention of the data subject’s name and it did not reveal any special category personal data. In any case, according to the controller, it had legitimate interest in the processing of the data which consisted in the smooth operation of its warehouse and distribution system and eventually its financial interests.
Holding
First, the DPA held that the controller disclosed special category of personal data to third parties by revealing to the recipients of the email the data subject’s real name and pseudonym.
Second, it found that the controller had not taken any technical and organisational measures to ensure an adequate level of security for the personal data, including any pseudonyms its contracted authors used. The controller could have prevented that risk by implementing organisational measures, such as using "blind carbon copy" (bcc) or sending individual messages, where possible. The controller failed to comply with the above obligation despite the fact that, according to the private agreement between it and the data subject, it had undertaken to use the data subject's artistic pseudonym in all public communications and to treat his legal name as confidential. Therefore, the DPA found a violation of Article 5(1)(f) GDPR in conjunction with Article 32(1) GDPR regarding the security of processing and Article 25(1) GDPR regarding data protection by design.
Third, the DPA ruled that the controller failed to notify the Authority and the data subject of the breach, despite the likability of risk to the rights of the natural persons concerned. The DPA found a violation of Article 33(1) GDPR and Article 34(1) GDPR.
Lastly, the DPA decided to impose a fine in the total amount of €9,000 for the aforementioned violations.
Comment
Share your comments here!
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the Greek original. Please refer to the Greek original for more details.
1 Kifissias Avenue 1-3, 11523 Athens T: 210 6475 600 E: contact@dpa.gr www.dpa.gr Athens, 21-07-2025 No. Prot.: 2613 DECISION 33/2025 The Personal Data Protection Authority (hereinafter "Authority") met, following an invitation by its President, in a meeting, via videoconference, on Tuesday 20-05-2025, following the meetings of 15-04-2025 and 16-04-2025, in order to examine the case referred to in the history of this case. The President of the Authority, Konstantinos Menudakos, and the regular members Konstantinos Lambrinoudakis, as rapporteur, Charalambos Anthopoulos, Grigoris Tsolias and Christos Kalloniatis were present. The regular member Aikaterini Iliadou and her alternate member Nikolaos Faldamis were absent due to impediment, although they were legally invited in writing. The alternate member Christos Papatheodorou was also present, replacing the regular member Spyros Vlachopoulos, who was not present, although he was legally invited in writing. Present, without the right to vote, were Fotini Karvela and Georgia Panagopoulou, experts, as rapporteur's assistants, and Irini Papageorgopoulou, an employee of the administrative affairs department, as secretary. The Authority took into account the following: With the complaint with no. prot. C/EIS/8977/20.11.2024, A is directed against the company with the name "BOOKSTORE OF ESTIAS, I.D. KOLLARO & SIA S.A." (hereinafter the defendant), complaining about a data breach incident and its unsatisfactory management. In particular, according to the complaint, on 02.02.2024 the complainant, who during the relevant period was contracted, as an author, with the defendant for the publication of his literary work, received a message from her at his personal email address, which was visible to the other recipients of the message, who amounted to approximately fifty-five (55) people. In more detail, in the “To” field, which contains the recipients of the message, the complainant’s email address, his full name, his artistic pseudonym (B) under which his books are published, his residential address and his VAT number were listed. According to the complaint under consideration, the complainant is … and at the same time a literary writer active under the pseudonym B, under which he has published two books (one of which has been published by the defendant), and has presented artistic works in Greece and abroad. According to the complaint, when he is active in his writing-artistic capacity, the complainant always appears covering his face, so that this is never apparent to the public. The use of the pseudonym and the concealment of the face is due, according to the complainant, to his desire to protect his personality as ... and not to reveal his gender identity to his immediate family and professional environment, as he belongs to a gender minority, the problems of which his writing activity focuses on. The complainant claims in particular that the above violation incident resulted in the disclosure to the other recipients of the message of his personal data relating to his gender identity and therefore constituting a special category of personal data. The complainant claims in this regard that the critical breach caused him shock and serious psychological problems, which were exacerbated when a user on a social networking site, on which the complainant is registered, mentioned the complainant’s surname in a public comment, thus, according to the complainant, putting his rights at greater risk, since the disclosure of his personal data 3 may affect his professional career and lead to the cancellation of his development, causing him further financial loss and moral harm. Furthermore, the complainant states that the defendant did not take any of the actions required under the GDPR after the critical incident, namely the notification of the personal data breach to the complainant in accordance with Article 34 of the GDPR, although the critical breach may put the complainant’s rights at high risk. On the contrary, according to the complaint under consideration, in her out-of-court statement to the complainant dated 30.9.2024, the defendant claims that the relevant e-mail message does not mention the complainant, his legal or artistic name, while there was no intention to disclose the above information to third parties, and in any case, the title of his book is not mentioned in the message, as a result of which it is not easy to identify the complainant's personal information with his written work. Moreover, according to the private agreement between the complainant and the defendant dated 03.09.2021 attached to the complaint under consideration, which regulated the relationship between them at the relevant time, the defendant committed to using the complainant's artistic name in all public communication and to treat his legal name as confidential. The Authority, in the context of examining the above complaint, with its document with no. prot. C/EX/3352/27-11-2024, invited the defendant to present its views on the defendants. The defendant provided clarifications on the defendants with its document with no. prot. C/EIS/125/08-01-2025, in which it argued the following: A) On the merits, no violation of the provisions on the protection of personal data occurred, but the complainant is targeting the defendant with the aim of causing her financial and psychological damage, driven by the judicial and procedural history between them. B) No explicit mention was made of the complainant's person, legal or artistic name in the said e-mail message 4. The complainant, according to the defendant, is one of the recipients of the message, which comes from an employee of the defendant's central warehouse and had as its exclusive purpose the disclosure of his details to the warehouse, so that the books to be returned could be sent to him. The mention of his legal name was necessary in order to identify the address to which the books were to be sent. C) There was no intention on the part of the defendant to disclose the complainant's name to third parties and to identify his work with his pseudonym, while, in any case, the identification of his personal details with his written work was not easy, because the message did not mention the name of the complainant's book, while, furthermore, it is not proven that the relevant message revealed the complainant's sexual orientation. D) In any case, there was a legitimate reason for processing, which consisted in the smooth operation of the defendant's warehouse, through which the financial interests of the complainant, who during the relevant period was contracted with the defendant, were also protected. E) It was not proven that the complainant suffered financial loss or moral harm from the relevant message, while it was also not proven that the reference, in a public comment by a third-party user, to the complainant's surname on a social networking site was due to an action by the defendant. F) There is no causal connection between the defendant's actions and the termination of the contract with the complainant. The defendant also referred to other issues that fall outside the competence of the Authority. Given the above, the Authority, with the summons no. C/EXE/1116/01-04-25 and C/EXE/1117/01-04-25, summoned the parties involved to a hearing at the Plenary Session of the Authority on 15-04-2025, in order to present their views on the case and to hold a hearing of the defendant on the possible violation of the applicable legislation on the protection of personal data. Due to the inability of the President of the Authority, the meeting of 15-04-2025 was postponed to 16-04-2025, when the hearing of the parties took place. At the adjourned meeting, the attorneys Stylianos Korres with AMDSA … and 5 Evangelia Vagena with AMDSA … attended on behalf of the complainant. The attorney Anna – Maria Asimogiorgou with AMDSA … attended on behalf of the defendant. Both parties orally presented their views. In particular, the complainant argued that what the defendant invokes in the no. prot. C/EIS/125/08-01-2025 written clarifications to the Authority focus on his legal dispute with the defendant and, moreover, are subsequent to the alleged data breach incident. The complainant was also given a deadline to submit a memorandum in further support of his allegations and submitted the memorandum under no. protocol C/EIS/3619/02-05-25 within the deadline, in which he presented the following in summary: A) The defendant's views, as expressed in protocol no. C/ΕΙΣ/125/08-01-2025 written clarifications to the Authority refer to the dispute between it and the complainant and in particular to events that followed the alleged violation by the defendant. That is, these are subsequent events, which cannot, according to the complainant, in any way affect the judgment as to whether or not there was a violation by the defendant. B) The defendant's claim that it had no intention of making the complainant's legal name known to third parties and of identifying it with the work and his pseudonym is not relevant in this case, because the alleged violation constitutes an objective fact independent of the intention of the infringer (objective tort liability) and the subjective element of the existence/absence of intent on the part of the infringer cannot be taken into account. C) The defendant's claim that the absence of reference to the title of the complainant's book in the relevant email results in it not being easy to identify his personal information with his work of writing is unfounded, because the complainant's pseudonym, which is mentioned in the relevant message, far exceeds the recognizability of the title of his book and, consequently, the mention or non-mention of the title of the book does not add anything to the already caused damage and disclosure of the complainant's personal data. D) The defendant's claim that the said e-mail message was not capable of causing the disclosure of the complainant's personal data to the general public due to the certain number of recipients is also unfounded, on the one hand because by law the disclosure of data to the "general public" is not a prerequisite for the assertion of the violation, on the other hand because the more than 50 recipients of the message, including journalists, bookstores, theaters, embassies of foreign states, publishers' associations, clubs, etc., could be considered the "general public". E) The defendant's claim that there was a legitimate reason for processing, which consisted in the smooth operation of its warehouse, is unfounded, because for the execution of the contract between the defendant and the recipients of the disputed message, either the sending of an individual message or, in the case of sending a group message, the hidden communication (bcc), F) The communication in the manner in which it was made, namely by incorporating all the personal data of the recipients in the "to" field of the electronic message, does not meet any of the principles of legality of processing that the defendant, as controller, is obliged to adhere to. G) The defendant's claim that the critical processing did not lead to the disclosure of the complainant's sexual orientation is unfounded, because the complainant's pseudonym arose from the need to protect both his sexuality and his gender identity as a person belonging to a gender minority and identified with a specific sexual identity, as is evident from a simple search for the specific pseudonym on the internet. Consequently, the said pseudonym, being declarative of sexual orientation, associated with other personal data and mainly the complainant's legal name, entails the disclosure of his sensitive personal data. H) The defendant has not taken any measures to comply with the legislation on personal data, i.e. it does not demonstrate either that it implements organizational measures so that the processing of personal data is carried out under specific conditions by appropriately trained personnel, nor that it takes measures to protect sensitive personal data, such as in the case of pseudonymous authors or authors belonging to a sexual minority. Furthermore, according to the complainant, the defendant, although informed of the violation (at the latest during the hearing of the interim order of the defendant's request for interim measures on 15.07.2024), did not take any corrective measures, such as withdrawing the message, sending a subsequent message asking the recipients of the original to ignore it and delete it, nor did it notify the Authority or the persons involved of the violation within 72 hours from the moment of being informed. The defendant also developed its views orally, and during this meeting it was given a deadline to submit a memorandum in further support of its claims and submitted within the deadline the memorandum under no. Γ/ΕΙΣ/3657/02-05-25 with the supplementary documents under no. Γ/ΕΙΣ/3655/02-05-25, with which it presented, among other things, the following, briefly mentioned: A) The defendant is one of the oldest publishing houses in Greece and, although it has the form of a limited company, it is not characterized as a cold commercial enterprise aimed exclusively at profit. On the contrary, the approach it takes towards its contracted authors is personal and they enjoy personal care and service from its employees, with the aim of the smooth execution of the contract between them and its adaptation to their particular wishes. Its legal representative personally undertakes the company's collaborations and activities and the wishes of those collaborating authors who wish to appear under a pseudonym or to have their image managed discreetly are fully respected. However, due to its limited turnover, there is no practical reason to establish a relevant standardized, cold procedure. B) The complainant received particularly personal and protective treatment from the defendant, however, their collaboration ended ingloriously. C) The defendant cites and invokes decision no. … of the Single-Member Court of First Instance of Athens which, judging during the interim measures procedure, considered it probable that the complainant publicly damaged her reputation and credibility through his postings on popular social networking platforms and insulted the dignity and personality of her legal representative, and prohibited the complainant from insulting the personality of the defendant's legal representative and the defendant's commercial reputation either orally before third parties or in writing by notifying third parties or by posting offensive content on social networks. The defendant also states that the Single-Member Court of First Instance did not take into account or take into account in forming its judgment the sending of the disputed message, even though the complainant invoked it before it as a violation of the legislation on personal data. D) In relation to the critical e-mail message, the defendant argues that all the recipients of the message appear in the same way, namely with a customer code each and then with the further details of each recipient. The sending of the said message took place exclusively for the execution of the contract between the defendant and the parties to it and the way in which the recipients are listed concerns the defendant's operational and accounting purposes, while no "publication" took place. The defendant also submitted, with document no. C/EIS/3655/02-05-25, the balance sheet for the tax year 2024, with a net annual turnover for 2024 of 1,025,505 euros. The Authority, after examining the elements of the file and what emerged from the hearing before it and the memoranda of the parties, after hearing the rapporteur and the clarifications from the assistant rapporteurs, who attended without the right to vote, following a thorough discussion, DECIDED IN ACCORDANCE WITH THE LAW 1. It follows from the provisions of articles 51 and 55 of the GDPR and article 9 of law 4624/2019 (Government Gazette A' 137) that the Authority has the competence to supervise the implementation of the provisions of the GDPR, this law and other regulations concerning the protection of individuals from the processing of personal data. 9 2. According to point 12 of Article 4 of the GDPR, a “personal data breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed. 3. According to point 1 of Article 4 of the GDPR, personal data are “any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, psychological, economic, cultural or social identity of that natural person”. 4. Article 5(1) of the GDPR sets out the principles governing the processing of personal data. These include the principle of integrity and confidentiality (paragraph f), according to which data shall be processed in a manner that ensures appropriate security of personal data, including their protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, by using appropriate technical or organisational measures. 5. In accordance with the principle of accountability introduced by the second paragraph of the aforementioned Article 5, it is expressly stated that the controller “shall be responsible for and able to demonstrate compliance with paragraph 1 (“accountability”)”. This principle, which constitutes a cornerstone of the GDPR, entails the obligation of the controller to design, implement and generally take the necessary measures and policies in order for the processing of data to be in accordance with the relevant legislative provisions and, in addition, to be able to demonstrate itself and at all times its compliance with the principles of Article 5(1) GDPR. 10 6. Based on Article 6(1) GDPR, “processing is lawful only if and to the extent that at least one of the following conditions applies: (…) a) the data subject has given consent to the processing of his or her personal data for one or more specific purposes, (…) f) the processing is necessary for the performance of a contract to which the data subject is a party or in order to take steps at the request of the data subject prior to entering into a contract.”. 7. According to the definitions of Article 25 of the GDPR: “1. Taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of the processing, as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons resulting from the processing, the controller shall effectively implement, both at the time of determining the means of processing and at the time of processing, appropriate technical and organisational measures, such as pseudonymisation, designed to implement data protection principles, such as data minimisation, and to incorporate necessary safeguards into the processing in such a way as to meet the requirements of this Regulation and to protect the rights of data subjects.” 8. Article 32(1) and (2) of the GDPR states that: “1. Taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of the processing, as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, the controller and the processor shall implement appropriate technical and organisational measures to ensure an appropriate level of security against the risks (…) 2. In assessing the appropriate level of security, particular account shall be taken of the risks presented by the processing, in particular accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to personal data transmitted, stored or otherwise processed.” 11 9. According to Article 32 of the GDPR, the use of electronic addresses to satisfy the purpose of the processing must be carried out in a manner that ensures the lowest possible risk in relation to the natural persons who are recipients of the messages. In this case, as is apparent from the information in the case file and what was submitted during the hearing and set out in the pleadings of the complainant and the defendant, the complainant received a message from the defendant to his electronic address, which included his full name and surname, his artistic pseudonym (B) under which his books are published, his residential address and his tax identification number, and these details were visible to the other fifty-five recipients of the message, with the result that his personal data was disclosed to all these recipients, including data relating to his gender identity and therefore constituting a special category of personal data. The inclusion of the complainant's email address in the "To" field of the email message made this address known to all recipients of the message, as well as his full name and his artistic pseudonym (B) under which his books are distributed, his residential address and his VAT number. Due to the mention of the complainant's pseudonym, whose writing-artistic activity is directly intertwined with his sexual orientation and his status as a member of a gender minority, the message in question disclosed special category personal data under Article 9 of the GDPR. 10. According to the definitions in Article 33 of the GDPR: "1. In the event of a personal data breach, the controller shall notify the personal data breach to the supervisory authority competent in accordance with Article 55 without undue delay and, where feasible, not later than 72 hours after having become aware of it, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the notification to the supervisory authority is not made within 72 hours, it shall be accompanied by a justification for the delay. (...) 3. The notification referred to in paragraph 1 shall at least: (a) describe the nature of the personal data breach, including, where possible, the categories and approximate number of data subjects affected, as well as the categories and approximate number of personal data files affected, (b) state the name and contact details of the data protection officer or other contact point from which further information can be obtained, (c) describe the potential consequences of the personal data breach, (d) describe the measures taken or proposed to be taken by the controller to address the personal data breach, as well as, where appropriate, measures to mitigate its potential adverse effects. 4. Where and to the extent that it is not possible to provide the information simultaneously, it may be provided in stages without undue delay. 5. The controller shall document each personal data breach, consisting of the facts relating to the personal data breach, the consequences and the remedial measures taken. That documentation shall enable the supervisory authority to verify compliance with this Article. ”. 11. According to Article 34 of the GDPR: “1. Where the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall communicate the personal data breach to the data subject without undue delay. 2. The communication to the data subject referred to in paragraph 1 of this Article shall clearly describe the nature of the personal data breach and shall contain at least the information and measures referred to in points (b), (c) and (d) of Article 33(3). 3. The communication to the data subject referred to in paragraph 1 shall not be required if any of the following conditions are met: (a) the controller has implemented appropriate technical and organisational protection measures, and those measures have been applied to the personal data affected by the breach, in particular measures making the personal data unintelligible to those not authorised to access them, such as encryption, (b) the controller has subsequently taken measures ensuring that the high risk to the rights and freedoms of data subjects referred to in paragraph 1 is no longer likely to arise, (c) it involves disproportionate effort. In such a case, a public communication shall be made instead or a similar measure is available whereby data subjects are informed in an equally effective manner. 4. If the controller has not already communicated the personal data breach to the data subject, the supervisory authority may, having examined the likelihood of a high risk arising from the personal data breach, require him to do so or may decide that any of the conditions referred to in paragraph 3 are met. 12. In the present case, as set out in paragraph 9, the complainant received a message from the defendant at his email address, which included his full name, his artistic pseudonym (B) under which his books are published, his residential address and his VAT number, which were visible to the other fifty-five recipients of the message, with the result that his personal data, including data relating to his gender identity and therefore constituting a special category of personal data, were disclosed to all those recipients. It also appears from all the information in the file that the defendant has not taken any technical and organizational measures to ensure the appropriate level of security of the personal data, including any pseudonym used, of the authors contracted with it, which it processes. Specifically, no appropriate technical and organizational measures and sufficient security measures had been taken from the outset in relation to the respective risks to the rights and freedoms of natural persons, nor had procedures been put in place to monitor the effectiveness of existing security measures in order to ensure compliance with the principles of integrity and confidentiality of the personal data affected by the data breach incident under consideration and which, according to the above, concern the email address, full name, residential address, VAT number and his artistic pseudonym (B) under which the complainant's books are distributed. Specifically, with regard to the incident under consideration of the violation of the inclusion of the complainant's email address and the above other details in the disputed email message, which the defendant does not dispute but on the contrary accepts in its memorandum under no. Γ/ΕΙΣ/3657/02.05.25, it appears that appropriate technical and organizational measures were not implemented from the outset in a way that guarantees the security of the personal data in question to protect them from unauthorized processing and to ensure compliance with the principle of integrity and confidentiality (Article 5, paragraph 1 of the GDPR), despite the fact that, as a publishing house, the defendant systematically managed such information and, therefore, was required to have measures in place that would protect the confidentiality of this personal data, taking into account in particular taking into account that these may, as in the present case, lead to the disclosure of special categories of personal data and therefore require special protection. In this specific case, in particular, given that many of the recipient addresses correspond to personal email addresses of natural persons, the controller should have prevented this risk, through organizational measures, such as the use of "hidden notification" or by sending individual messages, if possible. The defendant breached its above obligation despite the fact that, according to the private agreement dated 03-09-2021 between it and the complainant, it had committed to using the complainant's stage name in all public communication and to treat his legal name as confidential. 13. Furthermore, in the present case the defendant did not notify the incident of violation to the Authority, even though the said violation may cause a risk to the rights of the natural persons concerned. Similarly, the defendant did not notify the complainant of the breach, although the critical breach may put his rights at high risk, taking into account that it concerns personal data related to his sexual life and sexual orientation and the breach of their confidentiality may lead to material or moral damage, which may consist of discrimination against him, financial loss, damage to his reputation or disruption of his professional development.1 14. In accordance with the above, the Authority finds the following breaches by the defendant company, as controller: A) Violation of article 5 par. 1 letter f’ in conjunction with article 32 par. 1 of the GDPR regarding the security of processing. B) Violation of Article 25(1) of the GDPR regarding data protection by design, since measures to address various risks to personal data were not taken by design. C) Violation of Article 33(1) of the GDPR, since the incident of the breach was not notified to the Authority, as the defendant should have done. D) Violation of Article 34(1) of the GDPR, since the defendant did not notify the breach to the complainant. 15. Based on the above, the Authority considers that there is a case for exercising its corrective powers under Article 58, paragraph 2 of the GDPR in relation to the violations found. In particular, the Authority considers that, based on the violations found, an effective, proportionate and dissuasive administrative fine should be imposed, in accordance with the provision of Article 58, paragraph 2, subparagraph i of the GDPR, in accordance with Articles 83 of the GDPR and 39 of Law 4624/2019 on the controller. 1 See reason. p. 75 and 85 GDPR and Guidelines 9/2022 of the EDPB on the notification of personal data breaches under the GDPR, para. 102. 16 16. Furthermore, the Authority took into account the criteria for measuring the fine set out in article 83 para. 2 of the GDPR, paragraph 5 of this article which applies to the controller for the violation of article 5 para. 1 item. f of the GDPR and paragraph 4 of the same article 83 which applies to other violations of the controller, and the Guidelines 04/2022 of the European Data Protection Board2 on the calculation of administrative fines under the GDPR, which were adopted on 24-
5-2023, as well as the actual facts of the case under consideration and in particular the following: i) The established violation of article 5 par. 1 letter f of the GDPR by the controller falls, in accordance with the provisions of article 83 par. 5 sub. a of the GDPR, into the highest category provided for in the administrative fines grading system ("significant" violations with a maximum amount of 20,000,000 euros).
ii) The personal data breach is related to the main activities of the controller, since it concerns the management of relations with the authors contracted by him.
iii) The incident resulted in the disclosure of personal data relating to the complainant's gender identity and constitutes a special category of personal data, the breach of which may entail serious risks3.
iv) The defendant did not take any action to investigate the incident and mitigate its consequences, arguing that it did not consider that a personal data breach had occurred.
v) The number of data subjects affected by the breach cannot be considered small, as it amounts to approximately fifty (50) persons who received the controller’s email
2https://edpb.europa.eu/system/files/2023- 6/edpb_guidelines_042022_calculationofadministrativefines_en.pdf
3 See also in this regard Recital 57 of the EDPB Guidelines 4/2022.
17
processing. The lack of procedures and the handling of the incident concerns each
subject whose data is processed by the controller.
vi) The breach under consideration is potentially a reason for causing the complainant
mental shock and serious psychological problems.
vii) No previous corresponding breach by the controller has been established.
viii) The fact that the defendant is a publishing house that has the form of a public limited company but operates with the characteristics of a sole proprietorship with limited turnover. ix) The fact that the turnover (gross turnover) of the company for the financial year 2024 amounted to 1,025,505 euros. 17. The Authority also considers that, based on the violations found, an order should be imposed, pursuant to the provision of article 58 par. 2 subd. d of the GDPR, on the defendant to draw up, within a reasonable time from the notification of this decision, a policy for the management of personal data breach incidents and to inform the Authority. 18. The Authority considers that, based on the circumstances established and the above
criteria, the sanctions referred to in the operative part should be imposed on the defendant, which constitute an effective, proportionate and deterrent measure
both to restore compliance and to punish illegal
conduct.
FOR THESE REASONS
The Authority, taking into account the above:
a) Imposes, based on article 58 par. 2 sub. i’ of the GDPR, on the société anonyme with the name
“BOOKSTORE OF ESTIAS, I.D. KOLLARO & SIA S.A.” an administrative fine
18 of a total amount of 3,000 euros, for the violation of article 5 par. 1 sub. f’. in combination with Article 32(1) of Regulation (EU) 2016/679.
b) Imposes, on the basis of Article 58(2)(i) of the GDPR, on the société anonyme with the name
"BOOKSTORE OF HESTIAS, I.D. KOLLAROU & SIA S.A." an administrative fine
of a total amount of 2,000 euros, for the violation of Article 25(1) of Regulation
(EU) 2016/679.
c) Imposes, on the basis of Article 58(2)(i) of the GDPR, on the société anonyme with the name
"BOOKSTORE OF HESTIAS, I.D. KOLLAROU & SIA S.A." an administrative fine of a total amount of 4,000 euros, for the violation of articles 33 par. 1 and 34 par. 1 of Regulation (EU) 2016/679.
c) Addresses to the société anonyme with the name "BOOKSTORE OF ESTIAS, I.D.
KOLLAROU & SIA S.A.", as controller, based on article 58 par. 2 sub-paragraph d'
of the GDPR, an order to draw up, within a reasonable time from the notification of
this decision, a policy for the management of incidents of personal data breach, in the context of the defendant's compliance with the GDPR and to
inform the Authority.
The President The Secretary
Konstantinos Menuudakos Irini Papageorgopoulou




