HDPA (Greece) - 7/2026

From GDPRhub
HDPA - 7/2026
Authority: HDPA (Greece)
Jurisdiction: Greece
Relevant Law: Article 5(1)(a) GDPR
Article 5(1)(b) GDPR
Article 5(1)(d) GDPR
Article 5(1)(e) GDPR
Article 28 GDPR
Article 29 GDPR
Article 32 GDPR
Article 11 L. 3471/2006
Type: Complaint
Outcome: Upheld
Started:
Decided: 02.06.2026
Published:
Fine: 880000.0 EUR
Parties: DEI S.A.
Service 800 Teleperformance Single-Member S.A. for the Provision of Services
CQS Customer-Centric Services S.A.
Mediatel Telephone Information Services S.A.
Prelude Group Limited Partnership
National Case Number/Name: 7/2026
European Case Law Identifier: n/a
Appeal: n/a
Original Language(s): Greek, Modern (1453-)
Original Source: HDPA (in )
Initial Contributor: ds

The DPA fined an energy supplier and four call-centre operators €880,000 in total for inadequate technical and organisational measures, mixed-purpose calls, insufficient processor oversight and unauthorised use of a subcontractor.

English Summary

Facts

The Greek DPA (HDPA) received twelve complaints filed against DEI, the Greek Public Power Corporation, (the controller) from telephone subscribers (data subjects) regarding the receipt of telephone calls for the purpose of promoting its products and services.

The controller had outsourced the telephone calls to four call-centre companies acting as processors: CQS S.A. (Processor A), Teleperformance (Processor B), Mediatel (Processor C) and Prelude Group (Processor D). Processor D stated that it had used the services of INFOBELL (subcontractor) for the operation of its outbound calling system. The controller stated that its processors made approximately two million calls per year to provide contract-related information and conduct customer-satisfaction surveys, as well as around 50,000 promotional calls per month.

The complaints concerned calls made on the controller’s behalf relating to billing and tariff information, the expiry of electricity supply contracts, customer-satisfaction surveys and other products or services. One complaint concerned an Air Miles programme, through which customers could collect airline miles. Several data subjects had either registered their telephone numbers in the national opt-out register or had expressly asked not to be contacted again. Under Article 11 of Greek Law 3471/2006, telephone subscribers may register their numbers in a national do not call register to indicate that they do not wish to receive unsolicited marketing calls.

In two cases, the controller acknowledged that calls had been made to numbers included in the Greek Do Not Call register and attributed this to a technical malfunction in the process used to compare and exclude telephone numbers from the calling lists. In another case, a request not to receive further calls was processed eleven days after it was first submitted. The case file also concerned calls described by the controller and the processors as informational or as surveys regarding customer-satisfaction, during which lower-rate tariffs, e-billing or other programmes offered by the controller were mentioned. One data subject submitted recordings obtained through an access request, which documented a call involving both a customer-satisfaction survey and information about a programme offering lower charges.

The DPA requested explanations from the controller and the processors. In their submissions, they argued, among other things, that the calls were linked to existing customer relationships and were intended to provide contractual or regulatory information, assess customer satisfaction or improve service quality rather than promote products. They also maintained that the calls made to numbers included in the do-not-call register resulted from isolated technical failures and referred to their contracts, opt-out procedures, staff training and quality-control measures.

Holding

Regarding the controller, the DPA held that it was responsible for determining the purposes of the processing and the essential means by which the telephone calls were carried out. It was therefore required to provide its processors with appropriate tools and instructions, ensure the effective consolidation of the applicable opt-out registers and adequately supervise the processors’ compliance.

Moreover, it found that the controller did not have a unified, automated and fully traceable mechanism for managing the different opt-out registers. Instead, it maintained separate subsystems that could lead to discrepancies or delays. The available arrangements also lacked complete audit trails capable of showing who had carried out a call, when a number had been checked and which data had been accessed or modified. The DPA considered that the controller relied mostly on manual or administrative supervision instead of technical monitoring.

The DPA further found that the controller’s agreements with its processors were insufficient to ensure the implementation of appropriate technical and organisational measures. The contracts did not contain specific periodic audits, continuous assessment mechanisms or measurable compliance requirements. They also lacked sufficiently detailed provisions regarding evidence of compliance, the prior approval of subprocessors, voice-transmission encryption, protection against internal threats and backup procedures.

Regarding certain calls described as customer-satisfaction surveys or as information about energy prices, the DPA held that such calls would fall outside the rules on unsolicited marketing only where they remained strictly limited to matters affecting the existing contractual relationship. The DPA found that the calls were not limited to providing information or conducting customer-satisfaction surveys, but also included direct commercial offers aimed at retaining customers or promoting new products. It therefore characterised them as “mixed-purpose” calls, in which the provision of information served as a pretext for making offers without first checking the opt-out register. The DPA concluded that these were not isolated incidents but a systematic and established practice, as the controller stated that the agents followed predefined scripts and did not act on their own initiative. The calls therefore fell within Article 11 of Law 3471/2006.

The DPA also examined the provided information relating to the Air Miles programme. It found that the policy did not clearly distinguish the relevant purposes and legal bases, used broad descriptions of the processing activities, did not explain how data accuracy would be maintained, failed to specify concrete retention periods and provided insufficiently clear information regarding the right to erasure.

The DPA fined the controller €190,000 for the infringement of Article 32 GDPR, €230,000 for the infringement of Article 11 of Law 3471/2006 and €130,000 for the infringement of Article 5 GDPR. It also ordered the controller, within six months, to amend its agreements with the processors by introducing explicit technical instructions, improve its technical and organisational procedures and establish a procedure for auditing the cooperating call centres.

Regarding processor A, the DPA found that it relied on manual procedures to remove telephone numbers from calling lists. This increased the risk of human error and did not provide reliable evidence of who had recorded an objection or when the relevant change had been made. It held that processor A therefore infringed Article 32 GDPR and fined it €20,000.

In addition, the DPA determined that processor A was also involved in a call presented as a customer-satisfaction survey during which a programme offered by the controller was mentioned. The DPA considered that the call included a direct commercial offer and therefore fell within Article 11 of Law 3471/2006, since it was directed to a subscriber who had opted out of marketing calls and imposed a €40,000 fine.

As regards processor B, the DPA found that its systems had produced mismatches between the controller’s customer lists and the applicable opt-out registers, resulting in calls being made to numbers that should have been excluded. The DPA considered that this demonstrated insufficient automation and a possible absence of complete records documenting the checks performed before each call. It concluded that processor B violated Article 32 GDPR and imposed a €50,000 fine. It also fined €40,000 processor B for violating Article 5 GDPR due to the shortcomings identified in the processing relating to the Air Miles programme.

Regarding processor C, the DPA pointed out that the method it used for the updates of its opt-out lists, created a gap between the submission of an objection and its addition to the updated list, during which the person could still receive a call. It therefore found the procedure insufficient under Article 32 GDPR and fined €45,000 processor C.

Furthermore, the DPA also examined a recording of a call made by processor C. Although the call was presented as a customer-satisfaction survey, the agent referred to a programme offering lower charges. The DPA therefore classified the call as a mixed-purpose communication falling within Article 11 of Law 3471/2006. It also rejected the argument that the subsequent calls had been requested by the data subject, since that explanation was not supported by the call records or the recording. It imposed €55,000 a fine for this.

As regards processor D, the DPA found that it had used a subcontractor to carry out telephone calling activities without obtaining the controller’s prior specific or general written authorisation. It held that this was contrary to the applicable contractual terms and fined it €30,000 for breaching Article 28 GDPR and Article 29 GDPR.

It further held that the technical and organisational measures governing its operations were outdated and incomplete. Processor D relied on manual exchanges of files and did not adequately address the risks associated with large-scale digital processing. Additionally, the DPA found that its subcontractor maintained separate calling lists outside the controller’s direct control. It fined €50,000 processor for violations of Article 32 GDPR.

Moreover, the DPA ordered all processors to improve their technical procedures within six months.

Comment

Share your comments here!

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the Greek, Modern (1453-) original. Please refer to the Greek, Modern (1453-) original for more details.

Athens, June 2, 2026

Ref. No. 2444

Decision 7/2026



       The Personal Data Protection Authority convened, following

an invitation from its President, in a teleconference meeting on December 17, 2025,

in order to examine the case referred to in the background of this decision

Present were Georgios Batzalexis, Deputy Chair; regular member Nikolaos

Livos, as rapporteur, and alternate members Demosthenes Vougioukas and Maria
Psalla, replacing regular members Konstantinos Lambrinoudakis and Grigoris

Tsolias, who, although duly summoned in writing, were unable to attend due to a conflict of interest.

The meeting was also attended, without the right to vote, at the Chairman’s request, by the expert

Panagiotis Tsopelas and Pantelis Kammas, IT auditors, attended as assistants

to the rapporteur. Finally, Eirini Papageorgopoulou attended as    Secretary and

Georgia Palaiologou as coordinator, both employees of the Administrative Affairs Department of the
Authority.

       The Authority took the following into account:


The Authority has received twelve (12) complaints filed against the company
Public Power Corporation S.A., trading as “DEI S.A.” (hereinafter

“DEH” or “the company”) from telephone subscribers regarding the receipt of telephone

calls for the purpose of promoting the company’s products and services. In

these cases, which are included in the appendix to this document, the Authority forwarded

each complaint to DEI so that the company could investigate the allegations and present
its views. Subsequently, the Authority reviewed PPC’s views to ensure the

facts of each case were complete, sending additional documents requesting

clarification, where deemed necessary. In cases where, following the

above-described review of each case, a potential violation of


                                         1of the applicable legislation on the protection of personal data, the Authority

grouped the relevant complaints so that they could be examined together. After the

complaint files and after taking into account PPC’s views on each
of these complaints, they were categorized, based on the responses of the

companies involved, as follows:


   Category A: Complaints not related to a sales call, but rather to information regarding
PPC’s charges.

   Category B: Complaints where the call was not made.

   Category C: Complaints not related to a sales call, but to information regarding

a third-party service.

   Category D: Complaints not related to a promotional call, but to information regarding

the expiration of the contract.
   Category E: Calls made due to a technical malfunction.

   Category F:    Complaints not related to a promotional call, but to a

customer satisfaction survey.



Analysis of complaints

Category A complaints (1, 3, 4):

       As part of the review of cases with ref. nos. Γ/ΕΙΣ/8816/14-11-2024 (No. 1),

G/EIS/6145/23-07-2024 (No. 3), and G/EIS/5386/20-06-2024 (No. 4), the Authority
sent to the Public Power Corporation (PPC) documents bearing ref. nos. Γ/ΕΞΕ/362/24-01-2025, Γ/ΕΞΕ/2119/05-08-2024, and

C/EXE/2107/02-08-2024, requesting its views on the complaints. PPC

responded with documents bearing reference numbers Γ/ΕΙΣ/1516/20-02-2025, Γ/ΕΙΣ/6678/23-08-2024, and

G/EIS/1648/25-02-2025, in which it states that the calls were made

by the partner companies “MEDIATEL Telephone Information Services

S.A.” (hereinafter “MEDIATEL”) and “SERVICE 800 TELEPERFORMANCE
SINGLE-MEMBER PUBLIC LIMITED SERVICE PROVIDER” (hereinafter “TP”) for the purpose of

providing information regarding the categories and charges on the bills, given that with the implementation

of the new rate schedules and price fluctuations via the energy exchange,

new charges may arise. In the case of complaint No. 1, the

complainant contacted the company in writing and stated his objection to receiving


                                          telephone calls, but the representative handling the matter did not realize that

the request was an objection and directed him to register in the registry under Article

11. The complainant followed up, and his request was granted after an 11-day delay.

In the case of complaint No. 3, the call concerned informing the

consumer about extreme wholesale prices. In the case of complaint No. 4,

, seven calls were made to the complainant, four of which went

unanswered, while during the last call, the complainant requested to be excluded from future

calls.


Category B(2) Complaint:

As part of the review of complaint ref. no. Γ/ΕΙΣ/6785/30-08-2024, the

Authority sent PPC document ref. no. Γ/ΕΞΕ/2643/02-10-2024 requesting its

views on the allegations. DEI responded with document no.

Γ/ΕΙΣ/8524/06-11-2024, in which it states that no communication has been made by

the partner company “PRELUDE GROUP E.E.” (hereinafter “PRELUDE”) to

the phone number listed in the complaint.



Category C(5) Complaint:

       As part of the review of complaint no. Γ/ΕΙΣ/1611/28-02-2024, the
Authority sent PPC document ref. no. Γ/ΕΞΕ/1059/05-04-2024 requesting its

views on the allegations. PPC responded with document no.

Γ/ΕΙΣ/3653/19-04-2024, in which it states that the complainant had registered for the

DEI myRewards miles program, through which, in collaboration with the Miles and Bonus program of

AEGEAN AIRLINES S.A., he can accumulate

miles for flights by purchasing products. To substantiate this claim, DEI

submitted hyperlinks    1 to the service’s terms and conditions and a relevant attached

file.



Complaint Category D(6):
 In the context of the review of complaint no. Γ/ΕΙΣ/8561/03-12-2023, the


1https://www.dei.gr/en/home/myrewards/myrewards-coupons/

https://www.dei.gr/en/home/myrewards/myrewards-miles/
                                            3Authority sent PPC a document bearing ref. no. Γ/ΕΞΕ/1208/22-04-2024 requesting its

views on the allegations. DEI responded with document no.

C/EIS/4020/02-05-2024, in which it states that the purpose of the calls was to
notify the complainant of the imminent expiration of his contracts.



Complaints in Category E(7,8):

As part of the review of Ref. No. Γ/ΕΙΣ/5490/30-08-2021 (No. 7), the Authority

sent PPC a document bearing ref. no. Γ/ΕΞΕ/2019/06-09-2021 requesting its

views on the allegations. PPC responded with document no.
Γ/ΕΙΣ/6030/22-09-2021, in which it confirms that the call in question

was made by a PPC representative for the purpose of providing information on personalized

products, lower prices, and payment plans. Furthermore, the response states that the

call to the complainant was due to a technical error, as the system incorrectly

failed to recognize that the complainant’s phone number is listed in the

registry under Article 11 of Law 3471/2006. Finally,DEI states that it is focusing its efforts
on optimizing its system in order to minimize, if not

eliminate, technical failures such as this one.

       In the context of the review of complaint no. Γ/ΕΙΣ/5344/18-08-2021 (item no. 8)

complaint, as supplemented by document Ref. No. Γ/ΕΙΣ/5784/15-09-2021,

the Authority sent PPC document Ref. No. Γ/ΕΞΕ/2987/22-12-2021 requesting
its views on the allegations. PPC responded with document no.

Γ/ΕΙΣ/46/05-01-2022, in which it states that following a relevant review,

it was confirmed that the customer is registered in the registry under Article 11 of Law No. 3471/2006.

Furthermore, it was determined that the complainant’s phone number had not been excluded

from promotional activities due to a technical malfunction. Finally, they confirm that the issue

that arose concerns an isolated incident, and that they have implemented the
necessary recommendations and technical checks to prevent similar failures in the

future.



Complaints in Category F (9–12):



As part of the review of complaint no. Γ/ΕΙΣ/4187/24-06-2021 (item no. 9)

                                          4, the Authority sent PPC a document bearing ref. no. Γ/ΕΞΕ/1695/13-07-2021

requesting its views on the allegations. DEI responded with document

No. Γ/ΕΙΣ/5019/July 30, 2021, in which it states that it is conducting a survey
on the satisfaction of existing customers, with the aim of improving the customer experience

, in the context of which the calls to the complainant were also made.

Specifically, eight (8) calls were made, five (5) of which

went to voicemail. According to PPC’s response, during the first

successful call, a third party answered and the call was terminated. During the second

successful call, the account holder answered and rated DEI with a score of five (5)
to PPC. During this call, mention was also made of the e-bill, which

the complainant found interesting and asked to be called back. When they called back,

the complainant’s husband answered and expressed his dissatisfaction with the

calls, as their phone number had been added to the registry under Article 11.

Following notification of the complaint by the Authority, DEI attempted to

contact the complainant again in order to provide an explanation. During
their last conversation, they explained that the initial calls were not made to promote

products, but to conduct a satisfaction survey, and at the end, the complainant’s

stated that he was satisfied with the discussion and convinced by the

explanations he was given.

       In the context of the review of complaints with ref. nos. Γ/ΕΙΣ/3872/11-06-2021 (serial no.
10) and Γ/ΕΙΣ/3287/19-05-2021 (No. 12), as supplemented by document ref. no.

C/EIS/3288/May 19, 2021, the Authority sent to PPC documents bearing ref. nos. C/EXE

1347/May 31, 2021 and Γ/ΕΞΕ/1992/September 2, 2021, requesting its views on the

allegations.PPC responded with document no. Γ/ΕΙΣ/5845/17-09-2021,

in which it states that two calls were made to the complainant as part of

a survey of existing customer satisfaction, with the aim of optimizing
their experience.Specifically, regarding the first call made on May 19, 2021,

it is reported that clear information was provided that the call was being made on behalf of DEI and

specifically for a customer satisfaction survey. During the call,

the complainant’s partner, who asked who was calling and was informed

that the call was being made on behalf of PPC by the company “CQS S.A. CUSTOMER SERVICE PROVIDER

CUSTOMER SERVICE CENTER” (hereinafter “CQS”). He then stated that the phone

 5number had been included in the registry under Article 11. The call then ended after

a farewell. Regarding the second call made on June 11, 2021,

after the information system indicated that the complainant, as an existing

customer, had not responded to the relevant survey, PPC reports that it contacted

with the complainant to thank her for her cooperation, as well as to discuss a

satisfaction survey they were conducting, since the relevant questionnaire had not been completed
during the first call. Furthermore, according to PPC’s response, mention was made of the new

“MY HOME ENTER” program, about which the complainant stated she was not

interested, and the call was ended. Finally, PPC states that the above calls do not

fall under the provisions of Article 11 of Law 3471/2006, as the purpose of the communication

was not to promote sales but to conduct a satisfaction survey; therefore, they do not constitute unsolicited

communication. 



       In connection with the review of complaint No. Γ/ΕΙΣ/3769/08-06-2021 (Ref. No. 11)
complaint, as supplemented by document Ref. No. Γ/ΕΙΣ/4011/17-06-2021,

the Authority sent PPC document Ref. No. Γ/ΕΞΕ/1598/28-06-2021 requesting

its views on the allegations. PPC responded with document no.

Γ/ΕΙΣ/4638/13-07-2021, in which it confirms that by signing the contract

for the supply of electricity on January 22, 2021, the complainant did not consent to receiving

information about new products and services through automated or non-automated means, nor

to participate in statistical surveys. Four months after

signing the contract, the PPC customer service system identified the
complainant as a candidate for a satisfaction survey. For this reason,

the complainant was contacted on May 28, 2021, during which the

complainant expressed his dissatisfaction with PPC regarding high charges.

Since then, PPC has not contacted the complainant again. However, on

June 1, 2021, the PPC call center received an incoming call from the

complainant—which was not completed—and a callback was scheduled for

the following day, during which instructions were given that, should the complaint concern

the charge for mailing a paper bill, the customer should be offered the option to sign up for

2
 A feature that allows a customer to ask a company to call them back, rather than
having to wait on hold.

                                          6. the e-billing service (e-bill) or an upgrade of the contract to

HomeEnter+.Communication regarding the above matter was completed on June 3, 2021. Consequently,

based on the above, PPC asserts that, out of respect for its customer’s privacy, it did not

engaged in any product promotion or statistical

surveys in any of these instances, except for those that constitute a contractual obligation. Specifically, the

first call was intended to conduct a satisfaction survey as provided for in

Article 11 of the contract entered into by its customers, while the calls made after June 2, 2021

do not constitute unsolicited communication, as they are a follow-up to the initial call
made by the complainant to PPC.

       Subsequently, the Authority sent PPC document no. Γ/ΕΞΕ/2157/28-09-

2021, which it also shared with the complainant, in order to obtain further

clarifications, such as how the customer is informed that they will participate in

a satisfaction survey upon signing the contract, as well as whether the customer

was given the opportunity to object to this during the telephone conversation.

It was also requested to clarify the difference between the purpose of “conducting a

satisfaction survey” and “conducting a survey to better understand the needs,

preferences, and experiences regarding PPC’s services,” for which the

data subject has stated in the consent form for natural persons regarding

the processing of their personal data by PPC, that they do not consent, and finally
because the instruction was given during the call scheduled for June 2, 2021, that in

the event the customer expresses a complaint regarding the billing of the

, they should be offered, among other things, an upgrade to the

HomeEnter+ plan, which includes the electronic billing service

(e-bill), even though the complainant has stated on the consent form that he does not consent to

receiving information via any means regarding new products and services. Furthermore, the

Authority sent the complainant document no. Γ/ΕΞΕ/2158/28-09-2021,

to which the PPC’s response was attached, and asked him to confirm the content

of the calls, bearing in mind that the company does not state in its response that

the course of the phone calls, any products or services were promoted.



3 Abbreviation for “electronic bill”: this is the digital version of a bill, which replaces the

traditional paper bill sent by mail.
 7 DEI responded with document no. Γ/ΕΙΣ/7005/29-10-2021, in which

it states, among other things, that the term “eligible for a satisfaction survey”

refers to a customer who has completed a billing cycle (issuance of a bill

and a settlement statement), or a customer who has called the customer service department more than

three times and is being contacted to determine the status of

request and their level of satisfaction with the service. It is also noted that the

key difference between this satisfaction survey and other surveys is that

it records customer satisfaction in relation to their specific contract on an individualized basis, and
the results are entered into each customer’s file to improve

service. In contrast, surveys conducted to better understand

needs, preferences, and experiences regarding PPC’s services

are conducted among the general public and are usually anonymous; the anonymous responses

are compiled and statistically analyzed to draw

draw conclusions and make recommendations to management. Another equally important difference is

that conducting a satisfaction survey is a contractual and regulatory obligation
 4
of the Public Power Corporation (PPC) toward the customer, in accordance with Article 11 of the General Terms and Conditions for the Supply

of Electricity to Residential Customers, whereas the other surveys require consent.

Finally, it states that the instruction to the partner regarding the referral to the

HomeEnter program was issued after the complainant’s dissatisfaction regarding the
charge on the paper bill was recorded, and that the complainant had called

the Public Power Corporation (DEI) the previous day; therefore, the call to him does not constitute unsolicited

contact.


       For his part, the complainant submitted to the Authority the documents bearing ref. nos.

Γ/ΕΙΣ/6610/13-10-2021, G/EIS/6701/16-10-2021, G/EIS/6702/16-10-2021, G/EIS/6703/16-10-

2021,     Γ/ΕΙΣ/6709/16-10-2021, Γ/ΕΙΣ/6710/16-10-2021,     Γ/ΕΙΣ/7047/01-11-2021,

C/EIS/7252/November 8, 2021, C/EIS/7266/November 8, 2021, C/EIS/8108/December 10, 2021, C/EIS/8141/13-12-
2021, and C/EIS/8158/14-12-2021 supplementary documents, in which it states, among



4, the Supplier undertakes to act in accordance with fair business practices to maintain the highest
quality of service for the Customer. The quality of service refers to the level of service provided for the
supply services under the Contract (e.g., response to supply requests, calculation of
Supply Charges, call center support, response to inquiries, complaints, replies to
letters, payment methods, documentation, and the adequacy of responses—particularly regarding charges,

staff conduct)
 8others, that he has been registered with the electronic billing service

(e-bill) service, that he did not contact the number 21242148250 on June 1, 2021, and that the

phone calls were made from the above phone number for the purpose of

conducting a satisfaction survey as well as promoting the myHomeEnter+ program.

As evidence of the above, it submits a breakdown of outgoing calls as well as the

recorded files of the calls in question. Upon review of the submitted
records, it appears that the calls were made by MEDIATEL for the purposes of

a satisfaction survey and to provide information about a program with lower rates, namely

myHomeEnter+. The recorded files came into the possession of the

complainant after he exercised his right of access with the Public Power Corporation (PPC),

and he was aware of their existence since he had been informed at the start of the

calls that the calls would be recorded for PPC, for security and

to ensure service quality, that the recording would be retained for

twenty-four (24) months, and that he could learn about his rights on the
PPC website. Specifically, he requested the recorded files of six (6) calls

in total, but ultimately received four of them. Regarding the two missing recordings, he was informed that

following a review, it was determined that while the two conversations were logged

in their systems, they were not recorded due to a technical malfunction.


Information on contractors and subcontractors

   PPC submitted to the Authority, under ref. nos. Γ/ΕΙΣ/2282/19-03-2025, Γ/ΕΙΣ/2675/01-

04-2025, a list of partner call centers dating back to

2021, including both active ones and those with which the respective contract has expired.

In addition, it submitted, in the same emails, the relevant service contracts

, which include the data processing agreements
regarding promotional telephone calls on behalf of DEI. Furthermore,

it submitted: (b) a power of attorney (Γ/ΕΙΣ/3458/25-04-2025) for the company TP,

c) a list (Γ/ΕΙΣ/2675/01-04-2025) of the telephone numbers

used by the executives and sub-executives of PRELUDE

and c) certificate of representation (Γ/ΕΙΣ/2675/01-04-2025) for the company MEDIATEL.


5
 Abbreviation for “electronic bill”: a digital version of a bill that replaces the
traditional paper bill sent by mail.

                                          9    According to the contracts submitted by the Public Power Corporation (PPC), the phone numbers

used to make calls are not included in the corresponding

contracts with the partner call centers. These telephone numbers

were disclosed only for the company PRELUDE through the submission of a signed

affidavit by its legal representatives.

Special “Do Not Call” List (Do Not Call List)

   PPC informed the Authority that partner companies are required to maintain an

opt-out list, which includes all subscribers or call recipients who have

indicated that they do not wish to receive telephone communications from or regarding their

PPC account. Regarding the notification and synchronization process, call centers

are required to promptly notify DEI of any new opt-out requests

and to update their own systems within 24 hours. The update is performed via

API 6 or a secure file transfer protocol (e.g., SFTP). PPC maintains the central

objection database, into which the records of all partners are integrated. Responsibility

for final updates and compliance remains with PPC, but the partner must

maintain local copies of the exclusion list. 

Technical Measures for Communications Security


In accordance with the relevant contracts, partner companies implement, among

other things, the following technical measures to enhance the security of procedures:

   •   Access control and authentication: All users have unique

 accounts and credentials for accessing the systems, with the implementation of

       least-privilege and role-based access policies. This includes

 an authentication and audit logging mechanism, as well as automatic

 account logout in case of inactivity.

   •   Physical and logical system security: Access to premises and to




6An API is a standardized interface that defines how an application or service can interact
with another through specific commands, parameters, and data exchange formats
7A secure protocol for transferring files over a network that allows for the encrypted exchange
files between two systems, without third parties being able to read or alter the content.

 10 Information    systems    are restricted  exclusively  to  authorized

       personnel.    Firewalls,    antivirus software,
 network segmentation, and mechanisms

       event monitoring mechanisms are implemented. Workstations are protected by

 password and screen lock policies, and the use of unauthorized

 devices is prohibited.


   •   Communications and data transfer security: Communications between

MEDIATEL and PPC take place via secure channels (VPN 9, SFTP, or

       equivalent), with data encrypted during transmission and, where

required, during storage. Telephone connections are made via

 an internal VoIP 10 system with controlled access, restrictions on outbound traffic,

 and data exchange only between authorized points.


   •   Logging and Traceability: All processing actions are logged

 (date, time, operator, action), with logs retained for
       a specified period and protected against modification. Provision is made for

 periodic review of the logs by the Security Officer or the

 DPO.


   •   Incident Management and Business Continuity: There is a procedure for reporting

security incidents and a response plan. The operator is required to

       notify PPC without delay of any incident and must have a

recovery plan in place with regular backups.


   •   Organizational and training measures: Ongoing training for the


8A firewall is a mechanism or software that monitors, filters, and controls
data traffic between networks, with the aim of allowing only authorized communication and
block malicious or unauthorized access.
Antivirus is security software that detects, prevents, and removes malicious software
(malware), such as viruses, Trojans, worms, spyware, or ransomware.
Network segmentation is the technique of dividing a single network into smaller,

isolated segments in order to restrict access and reduce the spread of threats or
unauthorized actions.
 Virtual Private Network (VPN): a network encryption and routing technology that allows
users or systems to securely connect to a private corporate network via the public
Internet.

10 VOIP (Voice Over Internet Protocol) refers to voice transmission via the Internet Protocol. It is the technology that
enables the transmission of voice (phone calls) over the Internet or a local network.

                                          11 Staff training on data protection and information security issues,

 confidentiality agreements for all employees who have access to data,

       as well as the appointment of a Security Officer/DPO to oversee compliance.

Consolidation of the Opt-Out Registry

   PPC maintains the central opt-out registry (unified opt-out), but each partner

is required to verify, before every outbound call, whether the phone number

is included in the Data Controller’s opt-out registry or in the registries of

telecommunications providers, and to block the number if it is listed.

Conducting Inspections at Partner Call Centers

   PPC reserves the right to conduct or commission third parties to conduct inspections, whether regular

or unscheduled, to verify the call center’s compliance with

the obligations set forth in the annex to the contracts and the provisions of Regulation (EU)

2016/679 (General Data Protection Regulation—hereinafter GDPR). Partner

call centers are required to provide full access to information, records, technical

data, and personnel, as well as any reasonable assistance required to
verify compliance. Consequently, they may not refuse an inspection, nor may they

invoke trade secrets, and must provide call logs,

dispute records, security reports, and allow for random call monitoring.

The types of audits provided for include regular compliance audits—annual or

semiannual—as well as special audits following a violation or complaint, internal
assessment of call quality and legality, technical system audits,

information security audits, annual audits of dispute files/registers, and cross-checking

DEI—provider—partner lists. Partners are required to maintain records

of all processing activities they perform on behalf of DEI and to

make them available upon request, including the results of internal

audits. Compliance reports must be submitted to PPC at least once
time per half-year and must include metrics such as the opt-out rate for verifications,

the number of failed call audits, security incidents, and the results of internal

audits. In the event of non-compliance, contractors are required to

immediately take the necessary corrective measures and notify PPC in writing within

five (5) business days; that is, contractors must immediately correct

 12any non-compliance and document in writing what has been corrected.

Summoning to a hearing and briefs following the summons

   In light of the above, the Authority, by letters ref. nos. Γ/ΕΞΕ/900/13-03-2025,

G/EXE/901/13-03-2025, G/EXE/903/13-03-2025, G/EXE/904/13-03-2025, C/EXE/905/13-03-

2025, summoned the companies TP, CQS, MEDIATEL, PRELUDE, and DEI, respectively, and

to appear before the Authority’s Division on April 2, 2025—a postponement from March 26, 2025—
in order to discuss the aforementioned jointly examined complaint cases. The following individuals were present at the

hearing:



1. On behalf of DEI, Ioanna Voulgaridou, with AMDS …, A, Director of Legal

   Support for Commercial Activities at PPC; B, Director of Customer

   Communications at PPC; C, the company’s Data Protection Officer; and D,
   Director of Alternative Channels and Small and Medium-Sized Enterprises,

2. on behalf of TP, Aikaterini Paida, with AMDS …, and E (Deputy Data Protection Officer),

   Data Protection Officer of the company,

3. on behalf of CQS, Asimakis – Konstantinos Alexopoulos, with Data Protection Officer ID …, and F,

   Director of Operations
4. on behalf of MEDIATEL, Artemia Milioti, with AMDS …, and Z, the

   Data Protection

5. On behalf of PRELUDE: Konstantinos Liannis, with AMDS …, and H.


During the hearing, the following points, among others, were raised:


PPC stated that it makes approximately 2,000,000 calls per year to

inform customers about their contracts and conduct satisfaction surveys, as well as

approximately 50,000 calls per month to promote products and services. These

calls are made by partner companies with which PPC has

entered into the appropriate contracts. Regarding the complaints, the company stated, among
other things, the following:


   •   Regarding complaint No. 1, the complainant was contacted for an informational meeting

in connection with receiving the first bill, in order to provide him with

       explanations regarding the charges; therefore, the provision of

Article 11(13) does not apply. Furthermore, whenever a customer is contacted by the Public Power Corporation (PPC), an

identification procedure is carried out first. In this particular case, when the representatives

realized they were speaking with the complainant’s son, the conversation

was terminated.

    •  Regarding complaint No. 2, it was reported that the complainant was never contacted by

       the partner company PRELUDE on the date he stated, a fact
confirmed by a relevant statement from the telephone provider.

    •  Regarding complaint No. 3, it was reported that the subscriber was called to participate in

 a satisfaction survey and to receive information regarding her first bill. During

       the call, the customer stated that she wished to be added to the (Do

 Not Call – hereinafter DNC) list,¹¹ and her request was granted immediately.

    •  Regarding complaint No. 4, it was reported that the call took place on

 June 10, 2024, to provide information regarding the first bill. During the

       call, the customer requested a callback, as he did not have time at that moment.

Subsequently, several calls were made that went unanswered, while the
       customer finally answered on June 25, 2024, at which time he stated that he wished to be added

to the DNC list. His request was granted immediately.

    •  Regarding complaint No. 5, it was reported that the customer was called on February 28, 2024,

 for informational purposes and that, during the call, she requested to be added

       the DNC list, a request that was granted immediately.

 •  Regarding complaints nos. 7 and 8, in which calls were made to

       subscribers registered in the registry under Article 11, it was reported that

this was due to a technical error in TP’s software, which controls

       which PPC customer phone numbers are included in the list of the

Article 11 registry, so that they can be excluded from the calls. Subsequently, the
phone numbers of the two customers were removed from the call list so that

they would not be called again. Since then, from 2019 to the present, there has been no other

       similar incident, even though approximately 2,500,000 outbound

calls have been handled for PPC’s campaigns. 



11
  List of telephone numbers whose owners have expressly stated that they do not wish to
receive sales calls or calls promoting products and services.

                                           14   •   Regarding complaints nos. 9 and 10, which are similar cases,

it was reported that the calls were answered by different individuals, who requested

       not to be called again. However, since they had not communicated with the customer directly,

it was deemed necessary to call back. These calls were made as part of

       the context of customer satisfaction surveys. It was also reported that during the call,

reference was made to the My Home Enter+ program. Furthermore, the requests not
to be called again were submitted by the spouses of the two customers. Finally,

it was noted that in many cases, phone numbers are provided that do not

belong to the customers themselves, but to members of their families.

   •   Regarding complaint No. 11, it was reported that the complainant was contacted as part of

 a PPC customer satisfaction survey. During the phone call

       , he expressed a complaint regarding the charge for the paper bill and
 12
 was directed to sign up for the e-bill service     ,

       so that he could receive his bills electronically. He asked for

 the call to be rescheduled, as he did not have time for that particular conversation. He
 then contacted the Public Power Corporation (PPC) himself on June 1, 2021, and June 3, 2021, and stated

       that he did not wish to receive calls. His request was granted immediately, and his

number was added to the DNC list so that he would not be called again. Furthermore,

       it was noted that during the first call, the customer rated PPC a 4 out of 5

due to the charge for the paper bill, and that during these calls,

       any mention of product promotion. Finally, it was noted that the customer

participated normally in the survey without expressing any further reaction.

   Regarding the questions posed by the Authority’s representatives

during the hearing, the following points are highlighted:


   •   In   response   to   the   Authority’s   question   as to why   so   many   and

       repeated calls, PPC responded that it is required to inform

consumers about specific issues explicitly provided for in the
Supply Code. Furthermore, for customers who have not provided an email

address or are not familiar with electronic means of communication, the


12
  Abbreviation for “electronic bill”: the digital version of a bill, which replaces the
traditional paper bill sent by mail.

                                         15   Notifications are provided by phone. At the same time, the Public Power Corporation (PPC) conducts satisfaction surveys

   for the benefit of its customers, in order to identify any issues of

   of dissatisfaction.   These   calls  are made    by   appropriately
   trained individuals who possess the necessary expertise to

   analyze the bills. It was also noted that if a large number of

   customers called the call center at the same time, it would result in wait times

   and delays in service. According to PPC, customers who receive

   proactive calls rate the company higher on average than

   those who call on their own.
•  When asked how PPC managed to notify such a

   large number of subscribers by phone regarding the rate adjustment clause, the company

   replied that it informed a sample of customers rather than the entire customer base, based on certain

   criteria that were not specified during the hearing.

•  When asked whether the content of the conversations—such as the questions asked

   during the calls—was predetermined, the response was that there are
   scripts that customer service representatives follow. These scripts

   include various branches, which are followed depending on the

   customer’s responses. Furthermore,checks are performed to ensure that

   agents adhere to the above scripts.

•  When asked whether the software can detect technical errors, the response was

   that in some cases the system generates an electronic trace.
   However, for the two cases of technical errors examined, no

   such trace was found in the report.

•  In response to a question regarding the methodology followed by partner

   companies for grouping provider registries, obtaining the list

   PPC customers, and the exclusion of telephone numbers

   included in the registry under Article 11 or on the DNC list, PPC replied that
   each call center receives updated lists on a monthly basis from

   the telecommunications providers. They then cross-reference these lists with the

   PPC’s customer list and inform the company that approximately

   50% of the numbers have been excluded due to the registry under Article 11. Regarding the DNC list,



                                      16, it was reported that PPC maintains its own request database, which is continuously updated

from all communication channels (email, retail locations, call centers

       of PPC or partner companies). Whenever PPC generates a new

call list, it excludes the phone numbers included in the

updated database.



   Finally, it was noted that a Customer

Relationship Management (CRM) system    1 has been under development for the past year, through which improvement initiatives will be implemented

once the project is completed, as all campaigns will be conducted through the CRM.

When a customer indicates their objection to receiving calls, the system will be updated

and will exclude them from all current campaigns. When asked whether partner companies

also have access to this system, PPC responded that partner

do not have access to it.

   Subsequently, PPC submitted the email with reference number Γ/ΕΙΣ/3470/25-04-2025

email, which included:


 •  The data protection policy,

 •  a copy of the electricity supply contract,

       •  the company’s data protection policy,

 •  a copy of the evaluation form,

 •  the complaint handling procedure,

 •  a guide to procedures for handling do-not-call lists,

       •  a copy of the form for exercising rights,

 •  a memorandum in which the company asserts, among other things, that:



 1. The phone calls were not advertising or promotional, but

              informative or service-related, within the context of an existing contractual relationship or

 customer satisfaction surveys. They do not fall under Article 11 of Law 3471/2006,


13 Customer Relationship Management (CRM) is both a strategy and
a set of processes, practices, and technologies that a business uses to
understand, manage, and improve its relationships with its customers, both existing and

potential
                                          17; therefore, they do not violate the provision regarding the Register under Article 11,

 2. only two isolated incidents involved technical failure,

          3. the processing is carried out within the framework of the following legal bases under Article 6
 of the GDPR:



              3.1. Performance of a contract (Article 6(1)(b)) — informing customers about

 bills, invoices, and product changes,

              3.2. legal obligation (Article 6(1)(c)) — e.g., obligation to provide notice

 prior to contract expiration (Article 19 of the Electricity Supply Code
                  ),

 3.3. legitimate interest (Article 6(1)(f)) — for satisfaction surveys and

 service improvement.



          4. PPC classifies calls into:


 4.1. Customer service calls (information on bills, price changes,

 contract expiration),

       4.2. customer satisfaction survey calls (not for marketing, but to evaluate

services),

 4.3. very limited instances of marketing due to technical issues
           with external partners.



 5. Telecommunications companies act as processors under processing agreements

 that include:



       5.1. Clauses under Articles 28 and 32 of the GDPR,
 5.2. obligations regarding confidentiality, security, and erasure,

 5.3. mechanisms for call quality control.



6. PPC implements the following procedures and compliance measures:

 6.1. It has updated its Data Protection Policy and customer

 information brochures,

                                          18 6.2. It provides ongoing training for staff and contractors,

 6.3. It maintains a do-not-call list mechanism that

 is immediately applied to customer requests,

       6.4. Makes approximately 2 million calls per year, with a

complaint rate of < 0.2%,

   7. Regarding complaints, PPC states that:
 7.1. For Category D complaints, calls regarding the first bill or the expiration

 of a contract are considered an obligation to provide information,

       7.2. For Category E complaints, technical glitches that led

 to customers being called again were addressed by immediately adding them to the DNC list,

       7.3. Regarding the complaint with ref. no. Γ/ΕΙΣ/161128-02-2024 (no. 5), the call was not

       was of a promotional nature, but rather concerned an update from the partner

company TP regarding the PPC myRewards Miles service. According to the information provided
 14
 in the relevant link    on the PPC website, this is a
 customer rewards program offered by PPC, in which participants can

       earn “miles” (Miles+Bonus) for electricity bills or

other transactions, through a partnership with AEGEAN Airlines and Olympic Air. 

       Specifically:

 •  The service is linked to telemarketing campaigns aimed at

 promoting the program and managing customer data

          (account number, contact information, Miles+Bonus code),

 •  The telephone calls were made by PPC partners, who

          who acted as data processors. During these calls, customers

were informed that their enrollment in the program required consent,

          and that miles were managed by AEGEAN Airlines, which

 acts as an independent data controller for its own data

          (Miles+Bonus ID, profile, flights, etc.),

 •  the data transferred included only what was strictly necessary for

          link the account (name, phone number, Miles+Bonus code),



14
  https://www.dei.gr/el/gia-to-spiti/myrewards/myrewards-miles/

                                          19 •   The purpose of the processing is to promote the program and to

 inform customers about the reward,


       •  the legal basis is the data subject’s consent (Article 6(1)(a)

 of the GDPR) upon registration. Consent is provided either via the
          DEH form or by telephone, following clear information regarding the purpose

 of the processing and the transfer of data to AEGEAN Airlines.


       •  In certain cases, customers received phone calls without

 prior valid consent or despite having exercised their right to object,

       •  Technical and organizational compliance measures are being implemented, such as the use of

the PPC DNC file prior to each call, technical separation of

          telemarketing campaigns related to “myRewards Miles” from

 other commercial activities, and informing customers about shared responsibility

          for data processing between PPC and AEGEAN Airlines regarding specific stages

of processing.

   8. PPC’s telephone communications constitute lawful actions for the purpose of providing information,

       customer service, and quality control, and do not constitute unsolicited commercial

promotion under Article 11 of Law 3471/2006. Therefore, there is no violation of the

       provisions of the General Data Protection Regulation (GDPR) or Law 3471/2006.



CQS submitted the email with reference number Γ/ΕΙΣ/3451/25-04-2025

, which included:
 15 16
 •  TÜV ISO/IEC 27001:2023 and 27701:2019 certification,

       •  a description of the employee training process,

 •  quality verification of the do-not-call list,
 •  information security policy,

       •  third-party privacy policy,

 •  description of the request and complaint management process,

 •  description of the process for managing underperforming representatives,



15International standard for information security.
16
  Privacy Information Management System. It is an extension of ISO 27001.
                                          20•  description of the training process,

•  a memorandum stating, among other things, that:



   1. As soon as an objection is filed, the system is updated and the
 number is excluded. The Public Power Corporation (PPC) is notified on a weekly basis,

   2. the quality department conducts random quality checks on

 calls marked as DNC,

   3. the checks are repeated when a failure or improper

       handling is identified,
   4. A monthly quality audit is conducted by listening to random calls. In the

 event of errors, targeted training is provided,

   5. Feedback records are maintained for each complaint or

callback,

   6. Regarding the complaints, CQS states that:


       6.1 Regarding complaint no. Γ/ΕΙΣ/4187/24-06-2021 (case no. 9), the

calls were made for a satisfaction survey, not for sales promotion. The customer

participated voluntarily and even rated the Public Power Corporation (PPC). The request

to contest the survey was submitted by her husband, not by her, and was completed

       immediately upon being submitted correctly,

 6.2 Regarding complaint no. Γ/ΕΙΣ/3287/19-05-2021 (item no. 10), the
       initial call was answered by a third party (her husband) who cited

Register 11. The complainant later participated normally in a

       satisfaction survey. No promotional or unsolicited calls were made,

       6.3 Regarding complaint no. Γ/ΕΙΣ/8561/03-12-2023 (item no. 6), the

 calls concerned notification of an upcoming contract expiration. The

 DNC request was submitted by a third party, not by the customer himself. It was entered
 into the system on the same day it was submitted.

   7. The telephone calls were made lawfully, did not constitute

 unsolicited advertising, and fully complied with DNC and

 quality control procedures.



                                   21   Company TP submitted email message No. Γ/ΕΙΣ/3458/25-04-2025,

which included:

    •  Training material regarding the handling of DNC calls,

 •  a memorandum in which it argues, among other things, that:
       1. The calls do not constitute a violation of Article 11 of Law 3471/2006, as they were not

 of an advertising nature. They were made at the request of the Public Power Corporation (PPC), within the

          the context of fulfilling an existing contractual relationship and legal obligations

to inform consumers (notification of changes in wholesale

          , information regarding the first bill, notification of
 the expiration of a supply contract, and information regarding the

 “myRewards Miles / Coupons” rewards program),

       2. TP operates exclusively under the instructions of the Data Controller (PPC),

 3. the technical protocol it implements includes the following stages:

          3.1 Provision of a consumer list: PPC periodically provides files containing

 contact information,
 3.2 Receipt of Register 11: TP receives a monthly updated list from

          telecommunications providers,

 3.3 Cross-checking: TP imports the lists into its software and automatically excludes

 those listed in Registry 11.

          3.4 Data Conversion: A technical encoding conversion is performed to

ensure correct matching. In the case of complaints .
          G/EIS/5490/08-30-2021    (No.   7)   and   G/EIS/5344/08-18-2021   (No.    8)

          , a coding error occurred during the conversion. After

 identifying the issue, TP re-examined the systems, implemented a permanent automatic exclusion

          DNC exclusion for such cases, and implemented an automatic

deactivation mechanism in cases of doubt,

3.5 Entry into the answering machine: The clean lists are imported into the
calling system with active DNC blocking,

3.6 technical fault detection,

4. staff training is conducted,

       5. Statistics for the 2019–2025 period are 2,500,000 outbound

 calls on behalf of the Public Power Corporation (PPC), two (2) recorded errors, an

                                          error rate of 0.00008%, and compliance accuracy: >99.99%,

 6. the calls were made lawfully, at the direction of DEI, and without any intent

          to violate Article 11 of Law 3471/2006. Any discrepancies were due to
 a technical error, which was corrected,

       7. TP complies with DNC procedures, holds ISO certifications, and implements best

practices for security and data verification.



   MEDIATEL submitted an email with reference number Γ/ΕΙΣ/3464/25-04-2025,

which includes:
       •  Training procedures,

 •  complaint handling procedures,

 •  a memorandum in which it asserts, among other things, that:



          1. MEDIATEL acts as a data processor on behalf of PPC, within the

 framework of a commercial partnership for making outbound calls to

 existing customers,
          2. The calls are for informational purposes and not for promotional purposes,

 3. The company was instructed by PPC to contact its customers to

          inform them about charges and details of their first bill,

 4. MEDIATEL’s actions do not violate Article 11 of Law 3471/2006, since

          these are not unsolicited promotional communications, but rather
 informational calls related to an existing contractual relationship,

          5. MEDIATEL acted exclusively on the instructions of DEI, without any

 initiative or use of its own data.

          6. Regarding the complaints, MEDIATEL states that:



 6.1 Regarding complaint no. Γ/ΕΙΣ/8816/24-06-2024 (item 1): The
              call was made on November 6, 2024, and the call was answered by another person

who explained that the complainant has a hearing impairment and has

              provided this number as his contact number. The caller requested that the information

 be sent via email, and the call ended

              without any request for objection. MEDIATEL did not receive a request for cancellation

 23 either in writing or verbally. The complainant subsequently submitted

              a request for objection directly to PPC, not through MEDIATEL,

6.2 regarding complaint no. Γ/ΕΙΣ/3769/08-06-2021 (item no. 11), The
complainant answered the questions, gave PPC a positive rating, and did not

express any objection. A few days later, he contacted the

              PPC call center, without success, and made two

follow-up calls. On the third call, he stated that he did not wish to receive any further communications,

              so the company immediately notified the Public Power Corporation to add his number

to the DNC list. 


PRELUDE submitted an email with reference number Γ/ΕΙΣ/2675/01-04-2025,

which included:

   •   A certificate from the company “INFOBEL SOFTWARE APPLICATION DEVELOPMENT &

       PROVISION OF TELECOMMUNICATIONS SERVICES, SINGLE-MEMBER COMPANY

       LIMITED LIABILITY” (hereinafter “INFOBELL”), stating that no calls were made
from its systems from the number 2109998681 to the number … (complainant’s

 number) on August 30, 2024,

   •   a list of numbers registered in the registry under Article 11,

   •   sworn statement regarding the exclusive use of the number 2109998681,

   •   a memorandum in which it asserts, among other things, that:



       1. It acts as a data processor on behalf of PPC, pursuant to the
 contract dated April 1, 2024, for the purpose of attracting prospective customers and

       brokering the conclusion of contracts for the supply of natural gas and

electricity,

       2. implements strict procedures for cross-checking lists of telephone

numbers against the Registry referred to in Article 11, in order to prevent any communication with
individuals who have opted out,

       3. maintains an internal compliance system and outbound

telephone call software (Dialer) managed by a partner company,

       4. Regarding the alleged incident, it states that no



 24 calls were made from the number it uses exclusively to the complainant.



       The Authority, after reviewing the evidence in the case file of the jointly examined
cases and the findings of the hearing before it, the

submissions and statements of the parties, having heard the rapporteur and the clarifications

from the assistant rapporteurs, who were present without the right to vote, following

thorough deliberation,




HAS DECIDED IN ACCORDANCE WITH THE LAW



1. The issue of telephone calls for the purpose of direct marketing of products or

services and for any kind of advertising purposes is regulated by Article 11 of Law

3471/2006, which introduces regulations concerning unsolicited communications (see

paragraphs 1 and 2). Specifically, Article 11, paragraph 1, of Law 3471/2006 states that: “The
use of automated calling systems, particularly via facsimile

(fax) or electronic mail, and, more generally, the sending of unsolicited

communications by any means of electronic communication, without human

intervention, for the purposes of direct marketing of products or services and for

any kind of advertising purposes, is permitted only if the subscriber gives
express prior consent,” while paragraph 2 of the same article stipulates that: “It is not

unsolicited communications involving human intervention

(calls) for the above purposes, provided that the subscriber has declared to the provider

of the publicly available service that he or she generally does not wish to receive such

calls. The provider is required to record these statements free of charge in a special

subscriber directory, which is available to any interested party.” Consequently,
telephone calls involving human intervention, for the purposes outlined above,

are permitted unless the called party has indicated that they do not wish to receive them (“opt-out” system).

Advertisers, when conducting telephone promotional activities involving

human intervention, must obtain from all providers

up-to-date copies of the registries referred to in Article 11 of Law 3471/2006 and

ensure that they have available the declarations of subscribers that have

                                        25up to thirty days prior to the telephone

call (see also the Authority’s Decisions Nos. 62–67/2016).

2. Furthermore, a natural person’s telephone number constitutes personal
data, since it can serve as a means of indirectly identifying its holder

(see Article 4(1) of Regulation (EU) 2016/679, hereinafter the GDPR), enabling

communication with that individual. Furthermore, according to Opinion 4/2007 of the EU Article

29 Working Party regarding the concept of personal data, particularly in the context of

electronic services, indirect identifiers may, in certain

cases, be sufficient to distinguish an individual from others within a specific group,
even if their name has not been verified.

3. Making telephone calls for the purpose of promoting products and services

is governed, in principle, by Article 11 of Law 3471/2006. It should be noted, however, that

Article 3(2) of this law specifies that “Law No. 2472/1997, as currently in force, and the

laws implementing Article 19 of the Constitution, as currently in force, apply to any

matter relating to the provision of electronic communications services that is not regulated
specifically by this Act.” Already, under Article 84 of Law 4624/2019 (Government Gazette A’ 137/August 29, 2019),

as currently in force pursuant to Article 44 of Law 5002/2022 (Government Gazette A’ 228/Dec. 9, 2022), Law

2472/1997 was repealed. Furthermore, following the entry into force of the General Data Protection Regulation (GDPR), any prior reference

to Law 2472/1997—which had been enacted to transpose Directive 95/46/EC—is deemed

as a reference to the GDPR (see also Article 94(1) of the GDPR). Consequently, for any matter relating
to the provision of electronic communications services to subscribers or users who are

natural persons and which is not specifically regulated in Law 3471/2006, the

GDPR shall apply (see also Article 95 of the GDPR as well as Recital No. 173).

4. Article 4(7) of the General Data Protection Regulation defines the controller as “…the natural or legal

person, public authority, agency, or other body which, alone or jointly with others,

determine the purposes and means of the processing of personal
data…”. The processor is defined in the following paragraph of the same

article as “the natural or legal person, public authority, agency, or other body that

processes personal data on behalf of the controller

.”

5. Article 28 of the GDPR, which governs matters concerning the processor,

provides in paragraph 1 that when processing is to be carried out

                                           26on behalf of a controller, the controller shall use only

processors that provide sufficient guarantees regarding the implementation

appropriate technical and organizational measures, so that the processing complies with
the requirements of this Regulation and ensures the protection of

rights of the data subject, while paragraph 3 stipulates that processing

by the processor shall be governed by a contract or other legal act

governed by Union or Member State law, which binds the processor

in relation to the controller and specifies the subject matter and

duration of the processing, the nature and purpose of the processing, the type of
personal data and the categories of data subjects, and

the obligations and rights of the data controller. Such a contract or

other legal act shall provide, in particular, that the processor shall process

personal data only on the basis of documented instructions from

the data controller and takes all necessary measures pursuant to Article 32

of the GDPR.
6. Article 29 of the GDPR stipulates that “The processor and any person

acting under the authority of the controller or the processor,

who has access to personal data, shall process such

data only on instructions from the controller, unless required to do

by Union or Member State law.” This provision imposes an obligation
on the processor to process data only on the instructions of

data controller, unless the law provides otherwise. Consequently, a violation

of this provision by processors constitutes a violation of the GDPR on

their part.

7. Article 32 of the GDPR stipulates, among other things, that both the controller and

the processor shall implement appropriate technical and organizational measures
to ensure a level of security appropriate to the risks,

taking into account the latest developments, the costs of implementation, and the nature, scope,

of application, the context, and the purposes of the processing, as well as the risks

of varying likelihood and severity to the rights and

freedoms of natural persons. The controller and the processor

shall take measures to ensure that any natural person who

                                         27acts under the supervision of the controller or the processor

and has access to personal data processes such data only on

instructions from the controller. It follows from these provisions that the responsibility for

maintaining appropriate security measures rests with both the controller

and the processor; consequently, liability for a breach of

security measures should be apportioned and attributed appropriately.

8. The EDPS Guidelines 07/2020 on the concepts of the controller and

processor under the GDPR, it is stated (Recital 127) that the level of instructions provided
by the controller to the processor regarding the measures to be taken

depends on the specific circumstances. In some cases, the

data controller may provide a clear and detailed description of the security measures

that must be implemented. In other cases, the data controller may

describe the minimum security objectives to be achieved, while at the same time

asking the data processor to propose the implementation of

specific security measures. In any case, the data controller must

provide the processor with a description of the processing activities and the

security objectives (based on the data controller’s risk assessment), as well as

approval of the measures proposed by the processor. 

9. Furthermore, paragraph 10 of Article 28 of the GDPR stipulates that “Subject to Articles
82, 83, and 84, if the processor determines, in violation of this

Regulation, the purposes and means of processing, the processor

shall be considered the controller for that specific processing.” Consequently, in

cases where a processor, even within the broader context of

collaboration with a data controller, carries out processing activities

for which it has no documented instructions (whether specific or general) from the data

, then the processor must be considered the controller, since

it determines the purposes and means of those activities, in accordance with the
 17
case law of the CJEU  .



17See, in this regard, the CJEU judgment of Dec. 5, 2023, Case C-683/21, paras. 35–36, 84–85, and, for a detailed analysis, G. Tsolia, “The
Delimitation of the Scope of Application of the GDPR Based on the Case Law of the Court of Justice of the European Union, on Lawspot dated
February 15, 2024


                                          2810. Paragraph 3 of Article 4 of Law No. 3471/2006 stipulates that the recording of

of conversations and related traffic data is permitted when they take place during

the course of lawful professional practice for the purpose of providing evidence
of a commercial transaction or other business-related communication, provided that

both parties, after being informed in advance of the purpose

of the recording, give their consent. By order of the Personal Data Protection

Authority, the manner in which the parties are informed and

consent is provided, as well as the manner and duration of retention of the

recorded conversations and related traffic data.

11. The information in the case files of the complaints under joint review indicates

that PPC, through a contract, entrusts partner call centers with making

telemarketing calls to promote its own products and
services. Through the contracts, written instructions, and other directives it provides to

these partner call centers, PPC establishes a series of

specifications that define the framework for the operations of each

partner, with the aim of meeting the requirements of the General Data Protection Regulation (GDPR) and Law 3471/2006. The

PPC fully defines the purpose of the processing, and thus its objective, while also specifying
the key characteristics of the processing methods.


   PPC’s responsibility, as the data controller, is to provide appropriate tools,

principles, and guidelines to prevent unauthorized calls. This includes
the consolidation of the individual registries of service providers into a single “Opt-out” Registry and the

maintenance of a special opt-out registry listing those who have specifically objected to receiving

telephone calls (pursuant to Article 21 of the General Data Protection Regulation). Furthermore, PPC’s responsibility concerns

the adequacy of the control and supervision of data processors, as well as

the actions it took as soon as it became aware of the complaints.

   The controller and the processor are responsible

for implementing appropriate measures to ensure an adequate

level of security against the risks. Liability for failure to implement appropriate

measures, in violation of Articles 28 and 32 of the GDPR, should be shared by the
data controller and the data processor. Consequently, in cases

where a failure occurs in the implementation of security measures by the


 29processor, the processor bears a greater degree of responsibility for implementing the

security measures. However, if in certain cases it turns out that the processor

violates the obligations imposed on it by the contract and processes

data beyond or in violation of the controller’s instructions, then

this constitutes a violation of Article 29 of the GDPR. Furthermore, any technical error must

be documented and substantiated. Based on the principle of accountability, such errors

are recorded and may also relate to data breach incidents under

Article 33 of the GDPR.

12. With regard to the processing activities related to the complaints under review

and the legal basis, the following points are noted:


       (a) With regard to the Public Power Corporation (PPC), it appears from the outcome (recurring technical

malfunctions, the placement of “mixed-type” calls, delayed fulfillment of

       of requests), taking into account Articles 24 and 32 of the General Data Protection Regulation (GDPR), there is insufficient
documentation of the procedures for consolidating objection registries and the absence of

       a comprehensive audit trail. The data indicate that

PPC maintains separate subsystems, without a unified,

       automated, and fully traceable mechanism, a situation that may

lead to discrepancies or delays. It is recommended that a central

       opt-out registry, with automated synchronization via a secure API 19 and

 mechanisms for logging every action, in order to ensure integrity and

 accountability. Furthermore, while the Public Power Corporation (PPC) stipulates in its relevant contracts with contractors

on-site inspections, physical monitoring, and “feedback,” there is

       is there any mention of electronic event logging or a system

for tracking user actions (e.g., who made the call, when, and what

       data they viewed or modified). In other words, compliance appears to be based on

manual or administrative controls rather than technical traceability controls. Therefore,

it is necessary to implement a clear policy for managing contractors and

conduct regular audits to ensure the proper implementation of contractual data protection clauses


18A documented record of actions within an information system that allows for the monitoring,
verification, and demonstration of the legitimacy and security of each data processing operation.
19An API is a standardized interface that defines how one application or service can interact
with another through specific commands, parameters, and data exchange formats

 30.


       b) With regard to CQS, it appears—taking into account Article 32 of the GDPR—

that the company relies on manual procedures to exclude numbers from

       call lists, resulting in an increased risk of human error and

incomplete documentation. Manual verification does not ensure full compliance and

       does not provide reliable evidence in the event of an audit. It is recommended that
manual procedures be replaced by automated checks

       and the implementation of a dual-confirmation system for any exception

entered manually. Furthermore, every action must be logged in an

       audit trail to document which user made the change and

 when.


 c) With regard to TP, taking into account Article 32 of the GDPR,

       an issue of failure has arisen concerning isolated instances of discrepancies between the
customer list and the blocking registers, resulting in

       calls to numbers that should have been blocked. This fact demonstrates

inadequate automation of the verification process and a possible lack of complete

       recording of the steps preceding each call. It is recommended to implement

 a mechanism for automatically cross-checking the lists before each telephone

       call, as well as maintaining a detailed log of actions documenting

which number was checked, when, and with what result. The procedure must be

integrated into a campaign quality control system, with accuracy and

compliance metrics.

       d) With regard to MEDIATEL, it appears—taking into account Article 32 of the

GDPR—that the company relies on daily synchronization via SFTP, which

       resulting in a time window during which calls may

be made before the blocking list is updated. This

       delay    constitutes  a  technical  and  organizational  weakness  regarding  the

updating of data. It is recommended to transition to a real-time


20A documented audit trail of actions in an information system, which allows for the monitoring,
verification, and proof of the legitimacy and security of every data processing operation.
21SFTP (Secure File Transfer Protocol) is a secure file transfer protocol that enables the
encrypted exchange of data between two computers on a network.

                                         31   in real time via a secure interface (API), or at least an increase in the frequency

   of synchronization with the corresponding reference files. At the same time,

   notification mechanisms for delayed entries and performance metrics
   that commit the company to specific levels of accuracy and

   update speed.


   e) With regard to PRELUDE, it appears that the company uses
   INFOBELL as a subcontractor to make telephone calls, without

   prior specific or general written authorization from the Data Controller (DEI),

   in violation of the terms of their contract and Articles 28 and 29 of the

   GDPR. The involvement of an undeclared subcontractor, within the meaning of Article 32

   of the GDPR, undermines the security of the processing and renders the

   data transfer chain opaque and uncontrollable. Furthermore, the technical and
   organizational measures described in the contract are deemed outdated and

   inadequate, as they focus on traditional, manual procedures

   for exchanging physical files, failing to address the risks

   associated with large-scale digital processing. Consequently, it becomes difficult to

   fully document the data verification process prior to each
   query. The lack of automated synchronization creates a direct risk

   of using outdated data, while making it difficult to verify compliance with the

   the retention limit (120 days), given that INFOBELL maintains independent lists

   outside the control of the Data Controller. It is imperative to improve

   the data exchange methodology and the establishment of an automated

   validity-checking mechanism that will reject, in real time,
   numbers included in the Article 11 Registry or other

   exclusion lists, while ensuring full traceability of these checks

  . 

   13. Taking all of the above into account, it is evident that the aforementioned shortcomings

   highlight the need for a unified and fully automated framework

   for managing telephone calls, which is proposed to be based on:

a. A central blocking registry accessible in real time by all

partners,


                                      32   b. automated checks and mechanisms to prevent calls to

   unauthorized numbers,


 c. continuous logging and monitoring of actions for accountability purposes,

   d. enforcement of the stipulated contractual terms through compliance metrics and

   audits of personnel,


 e. automatic blocking of outbound calls to numbers listed in the Registry under Article 11 of

   Law No. 3471/2006 (opt-out) or those on DNC lists.

   The implementation of these measures enhances transparency, integrity, and

compliance with the principles of security and accountability in the processing of personal

data. The necessity of adopting these measures is further reinforced by the reference, in
 22
context of the hearing, to the CRM software development process with the aim of

future improvement of the system.

14. Regarding the calls concerning the PPC myRewards Miles service, based on

review of the memoranda, the privacy policy accepted by the user upon

registration, and the relevant complaints, the following issues arose:


       •  There does not appear to be a clear distinction between the legal bases for processing and
 sufficient information regarding data use as defined in Article 5(1)(a)

 of the GDPR (lawfulness, transparency, integrity). Specifically, the policy

states that:


              o   “We will use your personal data only for

 the purposes for which we collect it, unless we reasonably determine

 that we will need to use it for another purpose and

                 that reason is compatible with the original purpose. If you would like to
receive an explanation regarding whether processing for the new purpose

                 is compatible with the original purpose, please contact us. If

we need to use your personal data



22CRM (Customer Relationship Management) is a system, process, or
software that enables an organization to collect, organize, and manage customer information
for the purpose of serving customers, analyzing data, and leveraging it for commercial purposes.
22Do Not Call: A list of phone numbers belonging to individuals who do not wish to
receive phone calls for advertising or promotional purposes.

                                          33 If we use your data for an unrelated purpose, we will notify you to explain

 the legal basis that allows us to do so,”


              o “Our website may include links to third-party websites,
distinct embedded web pages (microsites   2), plugins, and

applications. If you select or activate these links,

you grant third parties the right to collect or share

data about you. We do not control third-party websites and are not

                 are responsible for their own privacy policies; furthermore, in the

event that supplementary services are provided to you by

third parties through the booking process, you should be aware that the

                 AEGEAN Group may act as a data processor

on behalf of these third parties. Therefore, whenever you use
 14
                 these links or microsites    or when you leave our website,

 we recommend that you read the privacy statements of these third parties,”

       •  the policy is vague regarding the purposes of processing and the data

 that is collected (“I will receive informational and

          promotional material tailored to my interests and preferences,”

 “service improvement,” “marketing,” “Profiles,” etc.) without it appearing that

          the purpose limitation, as defined in Article

 5(1)(b) of the GDPR, is accurately ensured,

 •  there is no mention of mechanisms for updating data. Consequently,

          accuracy does not appear to be ensured as defined in Article 5(1)(d)

 of the GDPR, as defined in Article 5(1)(b) of the GDPR,

       •  the policy does not specify specific retention periods for

data. Consequently, the limitation on

          storage as defined in Article 5(1)(e) of the GDPR, as defined in

Article 5(1)(b) of the GDPR,




23A “microsite” is defined as a standalone online platform or website that operates under the
supervision of or on behalf of an entity, but independently of its main website, with a specific thematic

or operational purpose (e.g., promotion of a specific program, campaign, service, or initiative).
 34 •  The policy is vague regarding the exercise of the right to erasure.

          Specifically, it states that the exercise of this right is accepted when

 “there is no legitimate reason for us to continue processing the
 data.” Consequently, transparency does not appear to be ensured pursuant to

Article 5(1)(a) of the GDPR with regard to Article 17 of the GDPR,


15. Requests for information for the purposes of investigating, verifying, or providing updates regarding
wholesale prices constitute lawful processing only if they are limited to providing

information regarding changes that affect the existing contractual relationship. However,

based on the audio recording provided to the complainant by PPC and submitted

to the Authority (as an attachment to complaint No. Γ/ΕΙΣ/3769/08-06-2021 and email No.

C/EIS/8158/12-14-2021), in conjunction with PPC’s response bearing ref. no.

C/EIS/5845/09-17-2021, it is found that the partner companies
MEDIATEL and CQS deviated from the lawful purpose. Specifically, these companies did not

limit themselves to simply providing information or conducting satisfaction surveys; rather, the conversations

were accompanied by direct sales pitches aimed at retaining customers or

promote new products. In particular, in the conversation referenced in the complaint with

No. Γ/ΕΙΣ/3769/08-06-2021 (No. 11), the MEDIATEL representative can be heard, among other things,

stating: “(…) next, we’d like to inform you about a plan with lower
rates (…)”, while the Public Power Corporation (PPC) acknowledges in writing that the company CQS made

a similar call in the case of the complaint with ref. no. Γ/ΕΙΣ/3287/19-05-2021 (case no.

12). Consequently, these communications fall within the scope of

Article 11 of Law 3471/2006, as they constitute unsolicited communication involving human

for commercial promotion purposes to subscribers who have explicitly stated

in the Do Not Call Registry that they do not wish to receive such calls. These circumstances
indicate that the calls are of a “mixed nature,” where the information provided

serves as a pretext for making offers without prior verification against the

Register; and, in combination with the PPC’s statement that its representatives operate

based on predetermined scripts and do not act on their own initiative, it is evident that

“mixed-nature” calls are not isolated incidents, but constitute
a systematic and established practice of the partner companies. Finally, regarding the

claim by PPC (in complaint No. 11) that the calls were made at the



 35request of the complainant or as a result of his complaint, it should be noted that

this claim is not corroborated by the call log or the content of the

recorded conversation submitted to the Authority by the complainant.


16. Upon examination of the contracts with the partner telecommunications providers and other

documents submitted following the hearing—including those with reference numbers Γ/ΕΙΣ/2282/19-

03-2025 and Γ/ΕΙΣ/2675/01-04-2025, the following findings were made regarding the

conduct of audits and the implementation of appropriate technical and organizational measures

the following:

 •  The contracts include clauses regarding the processing of personnel data

       , which explicitly stipulate that contractors act only on the instructions of PPC,

 include provisions regarding confidentiality, technical security measures, and

       an obligation to report breaches, and state that PPC may

conduct audits or request inspections. However, the results

       it appears that the relevant contracts were not sufficient to ensure that

the partner companies implemented the appropriate technical and organizational

       measures to ensure an appropriate level of security against

 risks as defined in Article 32 of the GDPR, specifically:

              a) specific periodic audits are not documented (e.g., dates,

reports, audit logs; no mechanism for continuous

              assessment, and no measurable level of compliance is specified (e.g.,

 SLA 24 for updating the objection list, response time to requests

 from data subjects),


              b) the obligation to cooperate in the event of audits is

vague and does not include any reference to the specific
25
provision of evidence of compliance (such as penetration tests,




24A Service Level Agreement (SLA) is a contractual agreement between a provider and a customer that defines
specific, measurable performance metrics (service levels), as well as obligations, key performance indicators
(KPIs), control procedures, and penalties in the event of non-compliance. 
25A controlled security evaluation process for an information system through simulation
real-world attacks by malicious users, with the aim of identifying and confirming vulnerabilities
that can be exploited for unauthorized access or data tampering.
(Source: ISO/IEC 27001:2022 – Annex A.12, NIST SP 800-115)

                                          36 log audits or audit trail reports), 27

 28
 c) there is no mention of a subcontractor pre-approval process or a

 mechanism for notifying changes to subcontractors,

                                                                                                       29
 d) there is no provision for voice transmission encryption (SIP-TLS,
 30
 SRTP) for internal outgoing/incoming calls,


                  e) data encryption is limited solely to the

transport layer. With regard to storage, the lack of specific

                  specifications and the vague wording “where required” render the

 protection framework incomplete,


 f) no measures are provided for protection against internal threats,

                  (h) The methodology for maintaining backup copies is not specified, nor


are the type and number of media that should be used.

17. Based on the foregoing, the Authority finds that there are grounds to exercise its

corrective powers under Articles 58(2)(i) and 83 of the General Data Protection Regulation (GDPR) to impose fines with respect to


the infringements identified above and its corrective powers under Article 58(2)(d)

to order the data controller or the processor

to bring the processing operations into compliance with the provisions of

this Act. In determining the fines that the Authority deems effective,




26A process by which logs are examined and evaluated to

identify discrepancies, violations, or unauthorized actions, as well as to verify the proper
operation and compliance of the information system. (Sources: ISO/IEC 27001:2022 – Annex A.12.4,
NIST SP 800-92)
27A chronologically organized set of records documenting the sequence of actions that
affected a given piece of data, a process, or an information system at any stage. (Sources:
ISO/IEC 27001:2022, ISO/IEC 27701:2019, NIST SP 800-92)
28
  A person authorized by the principal data controller to perform specific processing operations
on behalf of the data controller, following prior specific or general
written authorization from the data controller.
29 SIP-TLS is the secure version of the SIP (Session Initiation Protocol) protocol
—a signaling protocol used to establish, manage, and terminate communication sessions

between two or more network participants), which is used to initiate, manage,
and terminate voice or video calls over the Internet. TLS (Transport Layer Security) adds
encryption and authentication to the communication.
30 SRTP is the secure version of RTP (Real-Time Transport Protocol—a network protocol
used to transmit audio and video in real time over networks), which carries

the audio stream itself during a VoIP call. While SIP-TLS
protects the signaling, SRTP protects the voice itself.

                                                    37. In a balanced and preventive manner, the assessment criteria set forth in

Article 83(2) of the GDPR that apply to the present case are taken into account, as

specifically interpreted by the EDPB’s Guidelines 4/2022 on the
 31
calculation of administrative fines     .

as well as the following:


I. The companies’ most recent available turnover, specifically:

 •  DEI: €8,978,607,000 (for the year 2024).

    •  CQS: €28,590,328.34 (for the year 2024).


    •  TP: €464,259,782 (for the year 2024).

 •  MEDIATEL: €28,506,803.09 (for the year 2024).


    •  PRELUDE: No financial statements were found on file in the General

Commercial Register of Enterprises.

 II. That the severity of the violations found is deemed, in all cases, to be

    minor, taking into account the number of complaints and phone calls

found to have been made in violation of the law, the time

    period, the small number of violations relative to the total number of

calls made, and the fact that the Authority’s
    Authority’s inspections that a small percentage of those receiving unlawful calls file

a complaint (see Authority Decisions 60–63/2018).


III. The Authority considers the following as mitigating factors:

 a. The gradual improvement of the measures implemented to ensure compliance with the

 GDPR and Law 3471/2006,

       b. The technical difficulties in integrating the Registry.


 c. The difficulty in implementing the Registry provision (for all companies).

    iv. The Authority considers the following to be aggravating factors:


 a. The fact that the data controller and the processors did not implement adequate

31
  https://edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-042022-calculation-
administrative-fines-under_en - version 2.1

                                            38 technical and organizational measures.


 b. That the controls exercised by the data controller over the processors, as well as

 those exercised by the processors over their subcontractors, were not sufficient to

       ensure compliance with the terms of their contracts with one another.

 c. The fact that, in certain cases, ambiguous explanations were provided to the Authority.


       d. The fact that consumer information calls regarding energy prices and

 satisfaction surveys were of a “mixed” nature.

       e. The fact that, in cases where consent is obtained, the applicable privacy policy

does not ensure sufficient clarity and transparency regarding the purposes and

legal bases for processing.




                               FOR THESE REASONS

The Authority:


a. Imposes the following on the PUBLIC ELECTRICITY CORPORATION S.A.:

   i. pursuant to Article 58(2)(i) of the General Data Protection Regulation (GDPR), the effective, proportionate, and

  deterrent administrative fine appropriate to the specific case

   in light of its specific circumstances, in the amount of €190,000     32, for the aforementioned

   established violation of Article 32 of the General Data Protection Regulation, as analyzed in recitals 11,

   12(a), 13, and 16 of this decision.

   ii. Pursuant to Article 58(2)(i) of the GDPR, the effective, proportionate, and

  deterrent administrative fine appropriate in this specific case

   in light of its specific circumstances, in the amount of €230,000 for the 33 established

   violation of Article 11 of Law 3471/2006, as detailed in recitals 11, 12(a), and

   15 of this decision.

   iii. Pursuant to Article 58(2)(i) of the General Data Protection Regulation (GDPR), the effective, proportionate, and

   deterrent administrative fine appropriate in this specific case




32This corresponds to 0.06% of the statutory maximum fine, or 0.00256% of the company’s turnover
33This corresponds to 0.07% of the statutory maximum fine, or 0.00145% of the company’s turnover

                                           39   in light of the specific circumstances of this case, in the amount of €130,000 34for the aforementioned

   established violation of Article 5 of the GDPR, as detailed in recital 14 of

   this decision,


   iv. pursuant to Article 58(2)(d) of the GDPR, orders that, within a

   six-month period, amend the contracts with the contractors so that

   they contain explicit instructions on how to technically improve their
   their procedures so that failures such as those

   described in recitals 13 and 16 of this decision are not permitted to occur,


   v. pursuant to Article 58(2)(d) of the General Data Protection Regulation (GDPR), orders that, within a

   period of six months from the notification of this decision, it implement

   an audit procedure for its partner call centers, which shall

   include, at least twice a year, a full or sample-based

   inspection of a large number of outbound calls from each partner company, and to
   notify the Authority following the implementation of this procedure, taking into account

   the provisions set forth in recital 16(a) of this decision,


 vi. pursuant to Article 58(2)(d) of the GDPR, it orders that, within a

   period of six months, it improve its technical and organizational procedures so that

   failures such as those described in recitals 12(b) and

   13–16 of this decision.

b. It orders CQS S.A., a customer-service provider:


   i. pursuant to Article 58(2)(i) of the General Data Protection Regulation (GDPR), the effective, proportionate, and

  deterrent administrative fine appropriate to the specific case
   in light of its specific circumstances, in the amount of €20,000 35 for the aforementioned

   established violation of Article 32 of the GDPR, as detailed in recital 12(b)

   of this decision,


   ii. pursuant to Article 58(2)(i) of the GDPR, the effective, proportionate, and

  deterrent administrative fine appropriate in this specific case




34This corresponds to 0.05% of the statutory maximum fine, or 0.00212% of the company’s turnover
35This corresponds to 3.50% of the statutory maximum fine, or 0.070% of the company’s turnover

                                           40   in accordance with the specific circumstances of this case, in the amount of €40,000     36 for the aforementioned

   established violation of Article 11 of Law 3471/2006, as detailed in recital

   15 of this decision,


   iii. pursuant to Article 58(2)(d) of the General Data Protection Regulation (GDPR), orders that, within a

   period of six months, to technically improve its procedures so as to prevent

   failures such as those detailed in recitals 12(b) and 13 of

   this decision. 

c. It orders SERVICE 800 - TELEPERFORMANCE SINGLE-MEMBER SOCIETE ANONYME

SERVICE PROVIDER:


   i. pursuant to Article 58(2)(i) of the General Data Protection Regulation (GDPR), the effective, proportionate, and

  deterrent administrative fine appropriate to the specific case
 37
   in accordance with the specific circumstances of the case, in the amount of €50,000, for the aforementioned

   established violation of Article 32 of the General Data Protection Regulation, as detailed in recital 12(c)
   of this decision.


   ii. Pursuant to Article 58(2)(i) of the GDPR, the effective, proportionate, and

  deterrent administrative fine appropriate in this specific case

   in light of its specific circumstances, in the amount of €40,000     38 for the aforementioned

   established violation of Article 5 of the GDPR, as detailed in paragraph 14 of

   present decision.

   iii. Pursuant to Article 58(2)(d) of the GDPR, it orders that, within a

   six-month period, it must technically improve its procedures so as to prevent

   failures such as those described in recitals 12(c), 13, and 14 of

   this decision.


d. It orders MENTIAL TELEPHONE INFORMATION SERVICES S.A.

to:

   i. pursuant to Article 58(2)(i) of the General Data Protection Regulation (GDPR), the effective, proportionate, and

  deterrent administrative fine appropriate in this specific case



36Corresponds to 3.50% of the statutory maximum fine, or 0.140% of the company’s turnover
37This corresponds to 0.54% of the statutory maximum fine, or 0.0108% of the company’s turnover
38This corresponds to 0.215% of the statutory maximum fine, or 0.0086% of the company’s turnover

                                          41   in accordance with the specific circumstances of this case, in the amount of €45,000     39 for the aforementioned

   established violation of Article 32 of the GDPR, as detailed in recital 12(d)

   of this decision.


   ii. pursuant to Article 58(2)(i) of the GDPR, the effective, proportionate, and

  deterrent administrative fine appropriate in this specific case
 40
   in light of the specific circumstances of the case, in the amount of €55,000 for the aforementioned
   established violation of Article 11 of Law 3471/2006, as detailed in recital

   15 of this decision,


 iii. pursuant to Article 58(2)(d) of the General Data Protection Regulation (GDPR), orders that, within a

   six-month period, to technically improve its procedures so as to prevent

   failures such as those detailed in recitals 12(d) and 13 of

   this decision.

e. Imposes on PRELUDE GROUP E.E.:


 i. pursuant to Article 58(2)(i) of the GDPR, an effective, proportionate, and
   deterrent administrative fine appropriate to the specific case

   in accordance with its particular circumstances, in the amount of €50,000 for the aforementioned

   established violation of Article 32 of the GDPR, as detailed in recital 12(e)

   of this decision,


   ii. pursuant to Article 58(2)(i) of the GDPR, the effective, proportionate, and

  deterrent administrative fine appropriate in this specific case

   in light of its specific circumstances, in the amount of €30,000 for the aforementioned

   established violation of Articles 28 and 29 of the GDPR, as detailed in recital
   12(e) of this decision,


 iii. pursuant to Article 58(2)(d) of the General Data Protection Regulation, orders that, within a

   period of six months, to technically improve its procedures so as to prevent

   failures such as those detailed in recitals 12(e) and 13 of

   this decision.




39This corresponds to 7.89% of the statutory maximum fine, or 0.1578% of the company’s turnover
40This corresponds to 4.82% of the statutory maximum fine, or 0.1929% of the company’s turnover

                                          42The Vice Chair The Secretary




Georgios Batzalexis Georgia Palaiologou




















































                              43