HDPA (Greece) - 34/2023: Difference between revisions

From GDPRhub
 
(12 intermediate revisions by 3 users not shown)
Line 11: Line 11:


|Original_Source_Name_1=HDPA
|Original_Source_Name_1=HDPA
|Original_Source_Link_1=https://www.dpa.gr/sites/default/files/2023-11/34_2023%2520anonym.pdf
|Original_Source_Link_1=https://www.dpa.gr/sites/default/files/2023-11/34_2023%20anonym.pdf
|Original_Source_Language_1=Greek
|Original_Source_Language_1=Greek
|Original_Source_Language__Code_1=EL
|Original_Source_Language__Code_1=EL
Line 63: Line 63:
}}
}}


The Hellenic DPA imposed an administrative fine amounting to €20,000 on a leasing company, €10,000 for violating Article 5, paragraph 1(c), and an additional €10,000 for mishandling the data subject access request under Article 15, paragraph 1.
The Hellenic DPA imposed an administrative fine of €20,000 on a leasing company. They fined them €10,000 for violating [[Article 5 GDPR|Article 5(1)(c) GDPR]], and an additional €10,000 for violating [[Article 15 GDPR|Article 15(1) GDPR]].


== English Summary ==
== English Summary ==


=== Facts ===
=== Facts ===
The company [https://publicity.businessportal.gr/company/7480501000 PEIRAIOS LEASING] posted an advertisement for the property owned by CPB LEASING, in that advertisement there was a photo of the complainant's car parked next to it. The property was previously owned by the complainant's father before it was seized. The complainant claimed that the license plate of his car was visible in the photograph, causing his social circle to become aware of the loss of his family property.  
The company [https://publicity.businessportal.gr/company/7480501000 '''Piraeus Leasing'''] (the controller) posted an advertisement for the sale of property owned by CBP Leasing. In that advertisement there was a photo of the data subject's car parked next to the property. The property was previously owned by the data subject's father before it was seized. The data subject claimed that the license plate of his car was visible in the photograph, which allowed his social circle to become aware of the loss of his family property.  


The complainant submitted a request to object and for erasure of the personal data concerning him, i.e. the license plate, to the DPO of the PEIRAIOS LEASING. The DPO responded, stating the car's registration number is not visible, but in order to avoid any concern the photograph has already been removed from their website but it will remain in the company's archives as proof of the fact that the registration number of the car is not visible.
The data subject submitted a request for erasure of the personal data concerning him and an objection to processing to the controller's data protection officer ('DPO'), asking for his license plate to be removed from the advertisement. The DPO responded, stating the car's registration number was not visible, but in order to avoid any concern the photograph was removed from their website and would be retained in the company's archives as proof of the fact that the registration number of the car was not visible.


Later an acquaintance of the complainant shared emails with him, revealing that, as a potential buyer, Piraeus Real Estate S.A. had shared images of the property, including the photo previously posted in property advertisement on PEIRAIOS LEASING's website. The photo, presented was better resolution making the license plate number of the car clearly visible.
Later an acquaintance of the data subject who was a potential buyer of the property, shared emails with him revealing that the controller had shared images of the property with them, including the photo used in the advertisement, which clearly contained the data subject's car and his license plate.


These images were also seen by individuals familiar with the complainant, sparking discussions such as 'Is this not his car?... Is this not his father's house? Huge!!! What's going on? Did they eventually lose it?' These conversations occurred among mutual acquaintances and were subsequently shared with the complainant by one of his acquaintance.
After uncovering new evidence, the data subject filed a complaint on against [https://publicity.businessportal.gr/company/7480501000 Piraeus Leasing] and another similar complaint against CBP Leasing (which was renamed to [https://publicity.businessportal.gr/company/3877401000 PIRAEUS FINANCIAL LEASING SINGLE MEMBER S.A.]). However, since both of these companies ceased to exist, the beneficiary by formation for both companies for any pending lawsuits became [https://publicity.businessportal.gr/company/162425301000 PEIRAIOS LEASING M.A.E.] Therefore, the Hellenic DPA considered the controller to be PEIRAIOS LEASING M.A.E., and considered both complaints together as they were filed by the same data subject against what now was the same defendant company.


=== Holding ===
=== Holding ===
After reviewing the case, the Authority first concludes that since the complainant had originally submitted a complaint against Piraeus Leasing and another similar  complaint against CBP Leasing (which was renamed to [https://publicity.businessportal.gr/company/3877401000 PIRAEUS FINANCIAL LEASING SINGLE MEMBER S.A.]). However since both of these companies ceased to exist, the beneficiary by Formation for both companies for any pending lawsuits is now the [https://publicity.businessportal.gr/company/162425301000 PEIRAIOS LEASING M.A.E.] Therefore, the defendant party in this case becomes the PEIRAIOS LEASING M.A.E. and the two complaints are considered together because of their relevance and because they have been filed by the same complainant against the same now defendant company.
The Hellenic DPA found that the data controller (PEIRAIOS LEASING M.A.E.)  had processed the data subject's personal data in violation of [[Article 5 GDPR|Article 5(1)(c) GDPR]] and [[Article 15 GDPR|Article 15(1) GDPR]].


Then the Hellenic Data Protection Authority found that the data controller PEIRAIOS LEASING M.A.E.  has processed personal data of the complainant in violation of the GDPR. As such, the DPA issued a fine of:
Firstly, the DPA found a violation of [[Article 5 GDPR|Article 5(1)(c) GDPR]], as the controller had retained a photograph containing the data subject's personal data, through which he could be identified. Moreover, the controller had transferred the personal data to a third party. Both of these actions were in violation of the principle of data minimisation.


a) €10,000 for the breach of the data minimisation principle outlined in [[Article 5 GDPR|Article 5(1)(c)]] of the GDPR.
Secondly, the DPA found a violation of [[Article 15 GDPR|Article 15(1) GDPR]]. Under this Article, the data subject has the right to obtain from the controller confirmation as to whether or not personal data concerning them are being processed. In this instance, the DPA found a violation, as the controller alleged that it had already deleted the contested photograph from their website and had told the data subject that the photograph contained no personal data of his. Therefore, they falsely confirmed that no personal data of the data subject were being processed, when in actuality they were.


b) €10,000 for the violation of [[Articles 15(1)]] Right of access by the data subject.
As such, the DPA issued a fine of €20,000 in total. €10,000 for the breach of the principle of data minimisation ([[Article 5 GDPR|Article 5(1)(c)]] GDPR) and €10,000 for the violation of [[Article 15 GDPR|Article 15(1) GDPR]].


== Comment ==
== Comment ==
The unauthorised disclosure of personal data, even as basic as a car license plate, can have profound consequences, causing embarrassment, and disrupting one's peace of mind. This incident underscore the importance of safeguarding individual's privacy and the potential far-reaching impact of seemingly innocuous information.
The unauthorised disclosure of personal data, even as basic as a car license plate, can have profound consequences, causing embarrassment, and disrupting one's peace of mind. This incident underscores the importance of safeguarding individual's privacy and the potential far-reaching impact of seemingly innocuous information.


== Further Resources ==
== Further Resources ==

Latest revision as of 16:39, 9 January 2024

HDPA - 34/2023
LogoGR.jpg
Authority: HDPA (Greece)
Jurisdiction: Greece
Relevant Law: Article 5(1)(c) GDPR
Article 15(1) GDPR
Type: Complaint
Outcome: Upheld
Started: 09.11.2020
Decided: 10.11.2023
Published: 29.11.2023
Fine: 20000 EUR
Parties: ΠΕΙΡΑΙΩΣ ΧΡΗΜΑΤΟΔΟΤΙΚΕΣ ΜΙΣΘΩΣΕΙΣ ΜΟΝΟΠΡΟΣΩΠΗ ΑΝΩΝΥΜΗ ΕΤΑΙΡΕΙΑ (PEIRAIOS LEASING M.A.E)
National Case Number/Name: 34/2023
European Case Law Identifier: n/a
Appeal: Unknown
Original Language(s): Greek
Original Source: HDPA (in EL)
Initial Contributor: Inder-kahlon

The Hellenic DPA imposed an administrative fine of €20,000 on a leasing company. They fined them €10,000 for violating Article 5(1)(c) GDPR, and an additional €10,000 for violating Article 15(1) GDPR.

English Summary

Facts

The company Piraeus Leasing (the controller) posted an advertisement for the sale of property owned by CBP Leasing. In that advertisement there was a photo of the data subject's car parked next to the property. The property was previously owned by the data subject's father before it was seized. The data subject claimed that the license plate of his car was visible in the photograph, which allowed his social circle to become aware of the loss of his family property.

The data subject submitted a request for erasure of the personal data concerning him and an objection to processing to the controller's data protection officer ('DPO'), asking for his license plate to be removed from the advertisement. The DPO responded, stating the car's registration number was not visible, but in order to avoid any concern the photograph was removed from their website and would be retained in the company's archives as proof of the fact that the registration number of the car was not visible.

Later an acquaintance of the data subject who was a potential buyer of the property, shared emails with him revealing that the controller had shared images of the property with them, including the photo used in the advertisement, which clearly contained the data subject's car and his license plate.

After uncovering new evidence, the data subject filed a complaint on against Piraeus Leasing and another similar complaint against CBP Leasing (which was renamed to PIRAEUS FINANCIAL LEASING SINGLE MEMBER S.A.). However, since both of these companies ceased to exist, the beneficiary by formation for both companies for any pending lawsuits became PEIRAIOS LEASING M.A.E. Therefore, the Hellenic DPA considered the controller to be PEIRAIOS LEASING M.A.E., and considered both complaints together as they were filed by the same data subject against what now was the same defendant company.

Holding

The Hellenic DPA found that the data controller (PEIRAIOS LEASING M.A.E.) had processed the data subject's personal data in violation of Article 5(1)(c) GDPR and Article 15(1) GDPR.

Firstly, the DPA found a violation of Article 5(1)(c) GDPR, as the controller had retained a photograph containing the data subject's personal data, through which he could be identified. Moreover, the controller had transferred the personal data to a third party. Both of these actions were in violation of the principle of data minimisation.

Secondly, the DPA found a violation of Article 15(1) GDPR. Under this Article, the data subject has the right to obtain from the controller confirmation as to whether or not personal data concerning them are being processed. In this instance, the DPA found a violation, as the controller alleged that it had already deleted the contested photograph from their website and had told the data subject that the photograph contained no personal data of his. Therefore, they falsely confirmed that no personal data of the data subject were being processed, when in actuality they were.

As such, the DPA issued a fine of €20,000 in total. €10,000 for the breach of the principle of data minimisation (Article 5(1)(c) GDPR) and €10,000 for the violation of Article 15(1) GDPR.

Comment

The unauthorised disclosure of personal data, even as basic as a car license plate, can have profound consequences, causing embarrassment, and disrupting one's peace of mind. This incident underscores the importance of safeguarding individual's privacy and the potential far-reaching impact of seemingly innocuous information.

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the Greek original. Please refer to the Greek original for more details.

Summary
The Authority investigated a complaint by a natural person against a company related to the processing of a photo in which the license plate number of the complainant's car was visible and imposed a fine of €10,000 for a breach of Article 5 of the GDPR and a fine of €10,000 for a breach of Article 15 of the GDPR.