The Greek authority imposes sanctions on ZeniΘ and Piraeus Bank for GDPR breaches related to the right of access

The Hellenic Data Protection Authority sanctioned an energy provider and a bank for breaches related to the management of direct debit orders and non-compliance with the right of access, highlighting the responsibility of each actor in the processing chain.

Facts and context

The Hellenic Data Protection Authority (APDPCH) today published a sanction decision against the company ZeniΘ (including the imposition of a fine of €100,000) and Piraeus Bank S.A. (including the imposition of a fine of €10,000) for breaches related to the management of direct debit orders and compliance with the right of access.

The case originated from two complaints by a customer contesting the establishment of automatic debits for which he had not consented and his inability to obtain copies of the corresponding orders.

Grounds for the decision

The authority found several violations against the two companies, each acting as a controller for the operations concerning them.

Regarding the company ZeniΘ:

  • Obligation of data accuracy (Article 5(1)(d) of the GDPR): The authority found that ZeniΘ had known since September 2020 that the direct debit orders for two of the complainant's three contracts had been recorded erroneously and did not reflect his will. Instead of correcting these inaccurate personal data, the company maintained the debits and placed the burden of correction on the complainant, violating the accuracy principle.
  • Obligation to respect the right of access (Article 15 of the GDPR) and its modalities (Article 12 of the GDPR): ZeniΘ responded to the complainant's access request beyond the one-month deadline provided in Article 12(3) of the GDPR. Moreover, its response was incomplete as it did not provide a copy of the only signed direct debit form nor the relevant telephone recording (which had meanwhile been deleted), thus failing its obligation to provide a copy of the processed data.
  • Obligation to use processors providing sufficient guarantees (Article 28(1) of the GDPR): The authority judged that ZeniΘ had not ensured that its processor, the company “Sigma et Kappa Import S.A.”, implemented appropriate measures. The processor did not properly record the partial revocation of the customer's consent and did not transmit the data as required by the contract. ZeniΘ did not exercise adequate control and subsequently modified its contract to reflect practices contrary to its own policies, constituting a breach of its obligation to choose a processor offering sufficient guarantees.

Regarding Piraeus Bank S.A.:

  • Obligation of data accuracy (Article 5(1)(d) of the GDPR): Although the bank acts as a payment intermediary, it is considered an independent controller for these operations. Once informed by the complainant that the data related to the debits were inaccurate (as unauthorized), it had the obligation to investigate this allegation. Its inaction and mere referral of the customer to ZeniΘ constitute a violation of the accuracy principle.
  • Obligation to respect the right of access (Article 15 of the GDPR): The bank refused to comply with the access request, claiming it held no documents and referring the complainant to ZeniΘ. The authority considered that, even if the bank did not hold the original direct debit mandate, it processed personal data via the electronic payment system. It was therefore required to provide the complainant with a copy of the electronic records related to the transactions it processed, which it did not do.

Authority's decision

Consequently, the authority imposed a fine of €100,000 on ZeniΘ and a fine of €10,000 on Piraeus Bank S.A.

Furthermore, the authority ordered a reprimand against Piraeus Bank S.A. for the violation of the accuracy principle.

Lessons learned

This decision confirms / specifies / recalls that:
  • A controller informed of the inaccuracy of data it processes cannot remain passive; it must take reasonable measures to verify and, if necessary, rectify this data, even if the initial error originates from a third party.
  • The right of access covers all personal data processed by a controller, regardless of their format or origin. An intermediary, such as a bank in a payment chain, cannot refuse access by merely stating it does not hold the original document; it must provide a copy of the data it actually processes, such as electronic transaction records.
  • The responsibility for choosing and supervising a processor is paramount. A controller must actively ensure that its processor complies with its instructions and the GDPR and cannot absolve itself of responsibility in case of failure by the latter.
  • In a processing chain involving multiple actors, such as a direct debit, each entity (the creditor, the bank) is a separate controller for the operations it carries out and must assume all its obligations under the GDPR for its processing scope.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire