300,000 euros.
148
Α data protection officer who violates his/her duty of confidentiality shall be punished by a term of imprisonment between 1 and 5 years and by a
fine ranging from 10,000 to 100,000 euros.
2.5.3 Administrative Sanctions
Under the outgoing Law 2472/1997, the Personal Data Authority was empowered to
impose on the controllers the following administrative sanctions for breach of duties
arising out of the personal data protection legislation
149 : (a) A notice of violation
with an order to cease within a specified time limit
150 ; (b) a fine amounting between
c. 900 and c. 147,000 euros
151 ; (c) a temporary or definitive revocation of the permits
that have been granted by the Authority to the perpetrator in order to collect and
process sensitive personal data or to establish and operate the file or to interconnect
files containing sensitive data, or for the purpose of transborder transmission of data;
and (d) the destruction of the file or disruption of processing and destruction, return
or locking of the relevant data.
152 The sanctions under (c) and (d) shall only be
imposed in case of a particularly serious or repeated violation. A fine may be
imposed in conjunction with the sanctions under (c) and (d).The decisions issued
by the Authority imposing a fine constitute an enforceable instrument. They may be
challenged before the Council of State. The maximum fine imposed by the DPA to
148 The earlier legislation (L. 2472/1997) also imposed criminal sanctions for acts or omissions for
which the Authority has not yet issued a decision, such as the non-notification of the establishment
of a file or the operation of a file containing sensitive data without permit or in breach of the terms
and conditions referred to the Authority’s relevant permit. Moreover, for not complying with the
courts’ decisions ordering provisional measures as well as for not implementing decisions issued by
the Authority. Furthermore, for unlawful transfer of personal data as well as interconnection of files
without the Authority’s permit.
149 Art. 21 L. 2472/1997.
150 See, e.g., the DPA Decisions no. 61/2004 [notice addressed to employer to cease recording the
webpages visited by employees], no. 11/2005 [notice addressed to banks and to an insurance
company to apply the necessary procedures for the secure deletion of personal data after the
termination of the period required for the purposes for which such data were processed],
no. 17/2016 [notice to Mayor to delete postings in his Facebook containing references to third
party’s sensitive personal data].
151 See, e.g., the DPA decision no. 71/2017 [imposition of a fine of 10,000 euros on a telephone
company for failing to implement the right to access according to Art. 12 L. 2472/1997].
152 See, e.g., the decisions of the DPA: no. 38/2005 [prohibition to a TV station to re-broadcast and
use a transcribed text containing unlawful processing of personal data], no. 8/2016 [order against a
rehabilitation care center for disabled persons to uninstall video monitoring system that operated
unlawfully and to destruct of any relevant file containing personal data collected], no. 245/2000
[order against a Municipality to disrupt data processing that intended to monitor the entrance and
exit of employees at the workplace].
Data Protection in the Internet: Greece
235
Précédent

- 242/540

Suivant