The Greek authority sanctions several companies for breaches related to telemarketing calls and data protection

The Greek Data Protection Authority sanctioned an energy provider and its four subcontracted call centers for conducting telemarketing campaigns under the guise of informational calls or satisfaction surveys, revealing systemic failures in consent management, subcontractor supervision, and data security.

Facts and context

The Personal Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα) issued a sanction decision against the energy company «Δ.Ε.Η Α.Ε.» (D.E.H.) and four of its subcontractors, the companies CQS, SERVICE 800 - TELEPERFORMANCE, MEDIATEL, and PRELUDE, imposing fines totaling €730,000 for breaches related to unsolicited telemarketing campaigns.

The case originated from twelve complaints filed by telephone subscribers who received commercial prospecting calls from D.E.H. or its partners, even though some had expressed opposition to such communications.

Grounds for the decision

The authority analyzed the practices of D.E.H. as the controller and its partners as processors, identifying several violations of the GDPR and national legislation transposing the ePrivacy Directive.

  • Violation of telemarketing rules (Article 11 of Law 3471/2006): The authority found that the calls, often presented as satisfaction surveys or informative communications about bills, actually had a "mixed character." They served as a pretext for promoting products and services. By not respecting the opposition of individuals listed on the do-not-call lists (opt-out register), MEDIATEL and CQS violated legislation requiring an opt-out system for calls involving human intervention.
  • Failure to comply with data processing principles (Article 5 of the GDPR): The authority found that D.E.H. and its subcontractor TELEPERFORMANCE failed to respect several fundamental principles. The purpose of processing was diverted, with informational calls turning into commercial solicitation, violating the purpose limitation principle (Article 5(1)(b)). Furthermore, D.E.H.'s privacy policy was deemed too general, lacking clarity on purposes, specific retention periods (violation of the storage limitation principle, Article 5(1)(e)), and data update mechanisms (violation of the accuracy principle, Article 5(1)(d)).
  • Failure to comply with processor obligations (Articles 28 and 29 of the GDPR): PRELUDE was sanctioned for processing data outside the documented instructions of D.E.H., the controller. By determining certain aspects of processing itself, it exceeded its role as a processor, thus incurring its own responsibility.
  • Failure to comply with security obligations (Article 32 of the GDPR): D.E.H. and all its subcontractors (TELEPERFORMANCE, MEDIATEL, PRELUDE) were sanctioned for failing to implement appropriate technical and organizational measures. The authority noted significant shortcomings, including the absence of encryption of voice communications (via SIP-TLS or SRTP), insufficient protection against internal threats, and lack of a defined methodology for backup management. The authority recalled that, according to the European Data Protection Board (EDPB) Guidelines 07/2020, the controller must provide clear instructions to its processors regarding security measures.

Authority's decision

Consequently, the authority imposed administrative fines totaling €730,000, distributed as follows:

  • A fine of €420,000 against D.E.H. S.A., as the controller.
  • A fine of €100,000 against MEDIATEL SERVICES D'INFORMATIONS TÉLÉPHONIQUES SOCIÉTÉ ANONYME.
  • A fine of €90,000 against SERVICE 800 - TELEPERFORMANCE SOCIÉTÉ ANONYMPERSONNELLE DE PRESTATION DE SERVICES.
  • A fine of €80,000 against PRELUDE GROUP S.E.N.C.
  • A fine of €40,000 against CQS.

Furthermore, the authority ordered all companies to bring their operations into compliance within six months, notably by improving technical procedures for managing opt-out lists, modifying subcontracting contracts to include sufficient guarantees, and implementing effective control and audit mechanisms.

Lessons learned

This decision confirms / specifies / recalls that:

  • Calls with a "mixed character," combining informational or service motives with promotional purposes, must be qualified as commercial prospecting and comply with applicable rules, especially regarding opposition management.
  • The controller has an obligation to actively supervise its processors, notably by ensuring through regular audits that they comply with its instructions and GDPR requirements, particularly centralized and up-to-date management of opt-out registers.
  • Processors incur their own responsibility and can be directly sanctioned for breaches of their specific obligations, such as processing security (Article 32) or strict compliance with the controller's instructions (Article 29).
  • Security measures must be concrete and adapted to risks. General contractual clauses are insufficient if not followed by the implementation of specific technical measures such as encryption of communications and stored data.
  • Management of opt-out lists in large-scale campaigns involving multiple actors requires a centralized, automated, and real-time updated system to ensure the effectiveness of individuals' rights.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire