The Greek authority sanctions TEIRESIAS A.E. for breach of the accuracy principle in debt management
Facts and context
The Hellenic Data Protection Authority today published a sanction decision against the company TΕΙΡΕΣΙΑΣ Α.Ε. for breaches related to the accuracy of personal financial data.
The case originated from a complaint by an individual concerning the company's refusal to rectify and erase inaccurate and obsolete data related to loans recorded in its credit files, following requests made on 4 October 2022 and 29 January 2023.
Reasons for the decision
- Accuracy obligation (Article 5(1)(d) of the GDPR): The authority found that the company, as data controller, had not taken all reasonable measures to ensure the accuracy of the personal data it processed. Several records concerning the complainant were found to be incorrect or obsolete, including a loan classified as non-existent and debts settled for several years under Law No. 3869/2010. Although the company had taken steps with the source financial institutions (Veraltis Asset Management, Intrum Greece, Piraeus Bank, Eurobank), the authority judged that significant delays in correcting and updating this information constituted a violation of the accuracy principle. The fact that the company had to temporarily suspend the transmission of certain data and delete others belatedly (on 8 October 2024) confirmed the persistence of the breach.
Authority's decision
Consequently, the authority issued a reprimand against TΕΙΡΕΣΙΑΣ Α.Ε., pursuant to Article 58(2)(b) of the GDPR.
Furthermore, the authority ordered the company to develop and implement an improved procedure to ensure compliance with the accuracy principle, notably by ensuring prompt and correct responses from the entities providing the data. The company must submit documentation relating to these new measures to the authority within six months.
Lessons learned
This decision reminds that:
- The data controller who centralizes data from multiple sources remains fully responsible for their accuracy and cannot shift this obligation onto the entities transmitting the data.
- The rectification of inaccurate data must be carried out within reasonable timeframes; prolonged delays, even justified by verifications with third parties, may constitute a breach of the accuracy principle.
- A data controller must have robust internal procedures to effectively handle rectification requests and verify the reliability of contested information, without imposing an excessive burden of proof on the data subject.
- The temporary suspension of the transmission of contested data is an appropriate protective measure, but it does not exempt the data controller from its obligation to correct or permanently delete inaccurate data as soon as possible.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire