NEWS

Greece: first GDPR fine imposed by the Hellenic Data Protection Authority

The Hellenic DPA issued on 26.7.2019 its first GDPR fine against the company “PRICEWATERHOUSECOOPERS BUSINESS SOLUTIONS SA” (PWC BS) for breach of art. 5 par 1 & 2, and art. 6 par 1 (a) of GDPR amounting to 150.000€ and accompanied with other corrective measures (Decision no. 26/2019).

DPA conducted an ex officio investigation of the lawfulness of the processing of personal data of the employees of PWC BS, upon receipt of a relevant complaint, according to which the employees were required to provide consent to the processing of their personal data. In nutshell, the findings of the audit were the following:

  •  PWC BS used the inappropriate legal basis of consent for the processing of employees’ personal data, which should have been avoided due to the clear imbalance between the parties.
  •  PWC BS processed the personal data of its employees in an unfair and non-transparent manner since it gave them the false impression that it was processing their data under the legal basis of consent, while in reality, it used a different legal basis about which the employees had never been informed.
  •  PWC BS transferred the burden of proof of its compliance to the employees by asking them to sign a statement of acknowledgment that the processing of their personal data was relevant and appropriate in the context of the employment relationship.


This decision is a useful guideline and undoubtedly has an educational aspect for all data controllers and other stakeholders of data protection field since it elaborates in detail the principles of transparency, lawfulness, fairness, and accountability.

Address

Address:
Omirou St. 18
10672,
Athens, Greece

Phone:
+30 21 036 75 100
+30 21 036 75 164
Email:
info@tsibanoulis.gr

Factsheet

Image

Useful Links