Hellenic Telecommunications Organization S.A. (OTE)
- Country
- Greece
- Fine
- 200,000 EUR
- Date
- 2019-09-30
- Sector
- Private / Telecommunications
- Articles
- Article 25 par. 3Article 21 par. 3
Breach of data protection by design and failure to effectively comply with data subject's right to object to processing for direct marketing purposes
Following complaints from the data subjects, the Greek data protection authority investigated whether OTE had sufficient technical and organisational measures to comply with the requests of the data subjects not to receive promotional material from OTE. The organisation had an 'unsubscribe' link in the e-mail sent to customers and on its website. However, due to a technical error, even when the data subjects clicked on the 'Unsubscribe' button, their contact details were not removed from the register and they received the promotional material. As OTE did not have the organisational and security measures necessary to identify and solve the technical problem, so that it could exist for a long period of time (since 2013) and affected a large number of people (approximately 8,000), the data protection authority imposed an administrative penalty. Authority: HELLENIC DATA PROTECTION AUTHORITY
Source: http://www.dpa.gr/APDPXPortlets/htdocs/documentDisplay.jsp?docid=47,129,81,44,214,237,129,37
Reported by: Zepos & Yannopoulos
