Hellenic Telecommunications Organization S.A. (OTE)
- Country
- Greece
- Fine
- 200,000 EUR
- Date
- 2019-09-13
- Sector
- Private / Telecommunications
- Articles
- Article 25 par. 3Article 5 par. 1(d) (also non-GDPR):Article 11 of Greek Law 3471/2006 (implementing ePrivacy Directive)
Violation of data protection by design and the principle of data accuracy
Article 11 of Law 3471/2006 mandates that every telecoms provider maintains a “subscriber directory” with the numbers of all the data subjects who wish to not receive unsolicited marketing calls. Consequently, companies that wish to make direct marketing calls should exclude these numbers from their lists. Due to a system error, OTE had failed to successfuly communicate the entire directory to the marketing companies resulting in many data subjects who had opted out of the marketing to receive unsolicited promotional calls. Following a series of complaints by individuals, the Hellenic DPA decided to impose an administrative fine due to the high number of data subjects affected (approximately 16.000) and the long duration of the violation (approximately 3 years). Authority: HELLENIC DATA PROTECTION AUTHORITY
Source: http://www.dpa.gr/APDPXPortlets/htdocs/documentDisplay.jsp?docid=239,201,128,61,30,141,174,220
Reported by: Zepos & Yannopoulos
