{"id":1787,"date":"2025-09-12T17:41:04","date_gmt":"2025-09-12T14:41:04","guid":{"rendered":"https:\/\/sgklegal.gr\/?p=1787"},"modified":"2025-09-12T18:22:25","modified_gmt":"2025-09-12T15:22:25","slug":"gdpr-fine-e20000-for-recorded-phone-calls-key-takeaways-from-hdpa-decision-32-2025-sgk-legal","status":"publish","type":"post","link":"https:\/\/sgklegal.gr\/en\/gdpr-fine-e20000-for-recorded-phone-calls-key-takeaways-from-hdpa-decision-32-2025-sgk-legal\/","title":{"rendered":"GDPR Fine: \u20ac20,000 for Recorded Phone Calls \u2013 Key Takeaways from HDPA Decision 32\/2025"},"content":{"rendered":"<p class=\"whitespace-pre-wrap my-2\">The Hellenic Data Protection Authority (hereinafter the &#8220;HDPA&#8221; or the &#8220;Authority&#8221;) imposed a fine of \u20ac22,000 on an insurance company (NN Hellas &#8211; \u20ac20,000) and a cooperating dental company (MEDIADENT IKE &#8211; \u20ac2,000) for:<\/p>\n<ul class=\"list-disc pl-6 my-2 space-y-1\">\n<li class=\"pl-2\">Refusal to satisfy the right of access to recorded telephone calls,<\/li>\n<li class=\"pl-2\">Improper cooperation with the HDPA,<\/li>\n<li class=\"pl-2\">Lack of transparency in determining controller\/processor roles.<\/li>\n<\/ul>\n<h1 class=\"text-base font-semibold\">1. Background<\/h1>\n<p class=\"whitespace-pre-wrap my-2\">The complainant held an insurance policy with NN Hellas that included the &#8220;Dental Care&#8221; dental care program. For the service of policyholders, NN Hellas had a partnership with MEDIADENT company, which managed the program&#8217;s call center.<\/p>\n<p class=\"whitespace-pre-wrap my-2\">During telephone calls, policyholders were informed through a pre-recorded message that &#8220;for your safety and quality service, the call is being recorded,&#8221; while the service was presented as &#8220;Dental Care of NN HELLAS.&#8221;<\/p>\n<p class=\"whitespace-pre-wrap my-2\">On December 14, 2023, the policyholder submitted an access request via email to both companies, requesting transcripts of his telephone conversations that had taken place from July 24, 2023, to December 14, 2023, accurately specifying the date and time of each call.<\/p>\n<p class=\"whitespace-pre-wrap my-2\">Despite repeated communications (15\/12\/23, 20\/12\/23, 22\/12\/23, 27\/12\/23), neither company satisfied his request. NN Hellas referred the policyholder to MEDIADENT, while the latter completely ignored the request, although it had initially stated that it would provide the recordings.<\/p>\n<h2 class=\"text-base font-semibold\">2. Legal Framework<\/h2>\n<h3 class=\"text-sm font-semibold\"><span style=\"text-decoration: underline;\">2.1. Telephone Calls \u2013 Personal Data<\/span><\/h3>\n<p class=\"whitespace-pre-wrap my-2\">The complainant&#8217;s recorded telephone conversations constitute his personal data, according to Regulation 2016\/679 (General Data Protection Regulation \u2013 GDPR), to which he, as a data subject, has the right to gain access, according to the provisions of Article 15 GDPR.<\/p>\n<h3 class=\"text-sm font-semibold\"><span style=\"text-decoration: underline;\"><strong>2.2. Data Protection Principles &amp; Access Request<\/strong><\/span><\/h3>\n<p class=\"whitespace-pre-wrap my-2\">Specifically, according to the provisions of Article 15 paragraphs 1 and 3 GDPR:<\/p>\n<p class=\"whitespace-pre-wrap my-2\">&#8220;1. The data subject shall have the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed, and, where that is the case, access to the personal data [&#8230;] The controller shall provide a copy of the personal data undergoing processing [&#8230;].&#8221;<\/p>\n<p class=\"whitespace-pre-wrap my-2\">Furthermore, according to Article 12 paragraph 2 of the GDPR, the controller shall facilitate the exercise of data subject rights provided for in Articles 15 to 22 of the GDPR, while according to Article 12 paragraph 3 GDPR, the controller shall provide the data subject with information on action taken on a request under Articles 15 to 22 without undue delay and in any event within one month of receipt of the request.<\/p>\n<p class=\"whitespace-pre-wrap my-2\">The HDPA emphasized that the principle of accountability regarding transparency does not apply only at the point of data collection, but throughout the entire lifecycle of processing. Consequently, the rules that impose clear and transparent information also govern any response by the controller to a related access request.<\/p>\n<p class=\"whitespace-pre-wrap my-2\">In this context, the proper and timely satisfaction of the right of access constitutes a critical element for the transparency of processing and is directly connected to the principles of personal data protection.<\/p>\n<h2 class=\"text-base font-semibold\">2.3. Roles of the Parties<\/h2>\n<p class=\"whitespace-pre-wrap my-2\">One of the central issues of the case concerned determining the data controller for recording telephone calls. NN Hellas initially argued that MEDIADENT was the &#8220;processor,&#8221; while later changed position arguing that MEDIADENT was the &#8220;controller.&#8221;<\/p>\n<p class=\"whitespace-pre-wrap my-2\">The HDPA, examining the private agreement between the companies from 2015, found that:<\/p>\n<ul class=\"list-disc pl-6 my-2 space-y-1\">\n<li class=\"pl-2\">METLIFE (predecessor of NN Hellas) determined the purpose and means of processing consisting of recording telephone calls<\/li>\n<li class=\"pl-2\">Set specific operational specifications for the call center<\/li>\n<li class=\"pl-2\">Specified that it should have the capability of recording and sending calls to itself<\/li>\n<li class=\"pl-2\">Determined the purpose of processing (&#8220;for customer service and quality control of provided services&#8221;).<\/li>\n<\/ul>\n<p class=\"whitespace-pre-wrap my-2\">Therefore, NN Hellas acts as Data Controller and bears responsibility for processing the request, with the assistance of the Processor (MEDIADENT).<\/p>\n<h2 class=\"text-sm font-semibold\">2.4. Transparency Towards Data Subjects<\/h2>\n<p class=\"whitespace-pre-wrap my-2\">Despite the contract between the companies, the agreement and exact relationship were not transparent to the data subjects, who recognized only their contracting party NN Hellas as the controller. This emerged from:<\/p>\n<ul class=\"list-disc pl-6 my-2 space-y-1\">\n<li class=\"pl-2\">The fact that the telephone was answered as &#8220;Dental Care of NN HELLAS&#8221;<\/li>\n<li class=\"pl-2\">The insurance contract referred to &#8220;Provision of Dental Care within the HEALTH Network&#8221;<\/li>\n<li class=\"pl-2\">Policyholders were informed by NN Hellas about the program&#8217;s termination.<\/li>\n<\/ul>\n<h1 class=\"text-base font-semibold\">3. Imposed Sanctions<\/h1>\n<h2 class=\"text-sm font-semibold\">3.1. NN Hellas<\/h2>\n<p class=\"whitespace-pre-wrap my-2\">In this case, the HDPA imposed on NN Hellas an order to satisfy the Article 15 GDPR right of access of the complainant, providing the requested files within ten (10) days, and imposed an administrative fine of \u20ac20,000 for violation of his right of access.<\/p>\n<p class=\"whitespace-pre-wrap my-2\">For determining the fine, it took into account:<\/p>\n<ul class=\"list-disc pl-6 my-2 space-y-1\">\n<li class=\"pl-2\">Its degree of responsibility, as it has not implemented a specific procedure for responding to data subjects&#8217; access requests<\/li>\n<li class=\"pl-2\">The contradictory stance regarding MEDIADENT&#8217;s role<\/li>\n<li class=\"pl-2\">Indifference to proper satisfaction of the right for a long period<\/li>\n<li class=\"pl-2\">The impact of non-provision on the possibility of effective exercise of legal claims by the policyholder<\/li>\n<li class=\"pl-2\">The company&#8217;s turnover.<\/li>\n<\/ul>\n<h2 class=\"text-sm font-semibold\">3.2. MEDIADENT<\/h2>\n<p class=\"whitespace-pre-wrap my-2\">MEDIADENT was imposed a fine of \u20ac2,000 for violating the obligation to cooperate with the supervisory authority (Article 31 GDPR), as it:<\/p>\n<ul class=\"list-disc pl-6 my-2 space-y-1\">\n<li class=\"pl-2\">Did not respond to any of the two HDPA documents<\/li>\n<li class=\"pl-2\">Did not appear at the hearing on 21\/5\/2025<\/li>\n<li class=\"pl-2\">Processed health data of a significant number of subjects<\/li>\n<\/ul>\n<h1 class=\"text-base font-semibold\">4. Practical Advice for Public and Private Sector Organizations<\/h1>\n<p class=\"whitespace-pre-wrap my-2\">There are numerous organizations that proceed with recording telephone conversations, and most utilize external partners. The decision under examination confirms that particular attention should be given to the following (indicatively):<\/p>\n<ul>\n<li class=\"text-sm font-semibold\"><strong>Standardized Procedures:<\/strong><\/li>\n<\/ul>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul class=\"list-disc pl-6 my-2 space-y-1\">\n<li class=\"pl-2\">For receiving and processing requests (e.g., secure provision of access to recorded conversations, appointment of responsible persons for each stage)<\/li>\n<li class=\"pl-2\">For determining the &#8220;absolutely necessary time for keeping recorded conversations, based on the recording purpose.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul>\n<li class=\"text-sm font-semibold\"><strong>Data Processing Agreement (DPA) Drafting, <\/strong>where clear instructions are given regarding personal data management and any breach requests (in cases of external partners).<\/li>\n<li class=\"text-sm font-semibold\"><strong>Transparency to Callers <\/strong>about call recording as well as the purpose of such recording. It is noted that simple reference to purposes such as &#8220;transaction security&#8221; or &#8220;quality service&#8221; may not be deemed appropriate as they are not sufficiently specified.<\/li>\n<li class=\"text-sm font-semibold\"><strong>Full notice Provision<\/strong> (e.g., on the organization&#8217;s website) with the provisions of Article 13\/14 GDPR (e.g., retention time, recipients, source, rights, etc.) and referring callers to this information. It is noted that corresponding information should also be given to call center employees.<\/li>\n<li class=\"text-sm font-semibold\"><strong>Secure Retention of Recorded Conversations<\/strong><\/li>\n<li class=\"text-sm font-semibold\"><strong>Thorough Staff Training<\/strong><\/li>\n<\/ul>\n<p class=\"whitespace-pre-wrap my-2\">In case a document is transmitted from a supervisory authority, it is very important to:<\/p>\n<ul class=\"list-disc pl-6 my-2 space-y-1\">\n<li class=\"pl-2\">Comply with set deadlines<\/li>\n<li class=\"pl-2\">Provide complete requested elements as well as other supporting evidence<\/li>\n<li class=\"pl-2\">Not ignore any hearings<\/li>\n<\/ul>\n<p class=\"whitespace-pre-wrap my-2\">For the best possible safeguarding of an organization, communication with a professional who will undertake the organization&#8217;s representation is recommended.<\/p>\n<h1 class=\"text-base font-semibold\">5. Conclusion<\/h1>\n<p class=\"whitespace-pre-wrap my-2\">Decision 32\/2025 of the HDPA constitutes an important reminder of the obligations arising from the GDPR. The right of access is not optional but a fundamental right of every subject, and its non-satisfaction entails serious sanctions.<\/p>\n<p class=\"whitespace-pre-wrap my-2\">This decision also emphasizes the importance of transparency in business relationships and the need for clear information to subjects regarding the roles of involved companies. When a business appears to customers as the main controller, it cannot subsequently disclaim responsibility for satisfying their rights.<\/p>\n<p class=\"whitespace-pre-wrap my-2\">Finally, the case underlines that non-cooperation with the supervisory authority constitutes an independent violation that is strictly punished, regardless of the business size.<\/p>\n<p class=\"whitespace-pre-wrap my-2\">Businesses are called upon to review their procedures and ensure full compliance with GDPR obligations, in order to avoid similar sanctions and protect data subjects&#8217; rights.<\/p>\n<p class=\"whitespace-pre-wrap my-2\">Our Law Office contributes to shaping compliance policies and procedures with existing legislation and makes specific recommendations for timely and effective handling of subject requests.<\/p>\n<p>On behalf of the \u00ab<strong>Stergios Konstantinou &amp; Associates <\/strong><\/p>\n<p><strong>&#8211; SGKLegal\u00bb<\/strong><strong> Law Office<\/strong><\/p>\n<table>\n<tbody>\n<tr>\n<td width=\"312\"><strong>Stergios Konstantinou<\/strong><\/p>\n<p>Lawyer \u2013 Advanced LLM (IP &amp; ICT Law)<\/p>\n<p>CIPP\/E, CIPM, FIP<\/td>\n<td width=\"312\"><strong>Eva Pitsi<\/strong><\/p>\n<p>Trainee Lawyer, LLM<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n","protected":false},"excerpt":{"rendered":"<p>The Hellenic Data Protection Authority (hereinafter the &#8220;HDPA&#8221; or the &#8220;Authority&#8221;) imposed a fine of \u20ac22,000 on an insurance company (NN Hellas &#8211; \u20ac20,000) and a cooperating dental company (MEDIADENT IKE &#8211; \u20ac2,000) for: Refusal to satisfy the right of access to recorded telephone calls, Improper cooperation with the HDPA, Lack of transparency in determining [&hellip;]<\/p>\n","protected":false},"author":4,"featured_media":1789,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[20],"tags":[645,643,647,641,644,649,639,648,640,637,377,654,638,651,650,653,652,642,646,179],"class_list":["post-1787","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog-en","tag-article-15-gdpr","tag-call-center-compliance","tag-controller-vs-processor","tag-data-protection-fines-greece","tag-data-subject-access-request","tag-data-transparency-gdpr","tag-decision-32-2025-hdpa","tag-gdpr-compliance-greece","tag-gdpr-fines","tag-gdpr-greece","tag-gdpr-legal-advice","tag-gdpr-penalties","tag-hellenic-dpa-decision","tag-mediadent-fine","tag-nn-hellas-fine","tag-non-cooperation-supervisory-authority","tag-personal-data-greece","tag-recorded-phone-calls-gdpr","tag-right-of-access-gdpr","tag-sgk-legal-en"],"_links":{"self":[{"href":"https:\/\/sgklegal.gr\/en\/wp-json\/wp\/v2\/posts\/1787","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sgklegal.gr\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sgklegal.gr\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sgklegal.gr\/en\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/sgklegal.gr\/en\/wp-json\/wp\/v2\/comments?post=1787"}],"version-history":[{"count":2,"href":"https:\/\/sgklegal.gr\/en\/wp-json\/wp\/v2\/posts\/1787\/revisions"}],"predecessor-version":[{"id":1791,"href":"https:\/\/sgklegal.gr\/en\/wp-json\/wp\/v2\/posts\/1787\/revisions\/1791"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/sgklegal.gr\/en\/wp-json\/wp\/v2\/media\/1789"}],"wp:attachment":[{"href":"https:\/\/sgklegal.gr\/en\/wp-json\/wp\/v2\/media?parent=1787"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sgklegal.gr\/en\/wp-json\/wp\/v2\/categories?post=1787"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sgklegal.gr\/en\/wp-json\/wp\/v2\/tags?post=1787"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}