Hellenic Telecommunications Organization S.A. Rotten Score Breakdown
💼Corporate Misconduct
Rotten to the core
Avg Rating: 5.00Ratings: 1Severity Score: 6.00Evidence Count: 1Contribution: 30.0 pts
Misconduct: low 0 · medium 0 · high 1
Remediation: low 0 · medium 0 · high 0ⓘ cap: 25%
Greek privacy regulator fined OTE €3.25 million after subscriber call-data breach
After investigating the leakage of subscriber call data between 1 and 5 September 2020, the Hellenic Data Protection Authority found that OTE had infringed GDPR Article 32 because of inadequate security measures in infrastructure used in the breach. The authority fined OTE €3.25 million. The same decision separately fined COSMOTE €6 million; that subsidiary fine is not attributed to OTE in this record. Primary source: https://www.dpa.gr/en/enimerwtiko/news/fines-imposed-due-personal-data-breach-and-illegal-data-processing
📰Human Rights & Exploitation
No documented evidence
Avg Rating: —Ratings: 0Severity Score: 0.00Evidence Count: 0Contribution: 0.0 pts
🎭Fraud & Corruption
No documented evidence
Avg Rating: —Ratings: 0Severity Score: 0.00Evidence Count: 0Contribution: 0.0 pts
🧪Deceptive Practices
Toxic workplace vibes
Avg Rating: 5.00Ratings: 1Severity Score: 12.00Evidence Count: 2Contribution: 60.0 pts
Misconduct: low 0 · medium 0 · high 2
Remediation: low 0 · medium 0 · high 0ⓘ cap: 25%
Greek privacy regulator fined OTE €200,000 after unsubscribe requests failed for years
The Hellenic Data Protection Authority found that, from 2013 onward, a technical error prevented OTE marketing recipients who used an unsubscribe link from being removed and that OTE lacked an organisational procedure capable of detecting the failure. OTE subsequently removed about 8,000 people who had unsuccessfully attempted to opt out. The authority found infringements of the GDPR right to object to direct marketing and data protection by design and imposed a €200,000 fine in Decision 34/2019. Primary source: https://www.dpa.gr/en/enimerwtiko/press-releases/administrative-fines-imposed-telephone-service-provider
Greek privacy regulator fined OTE €200,000 over inaccurate do-not-call records
The Hellenic Data Protection Authority found that OTE deleted subscribers from its do-not-call register when they requested number portability but lacked a proper process to restore their entries when portability was cancelled. Because OTE's internal customer-service system and the register sent to advertisers diverged, affected subscribers received unsolicited marketing calls. The authority found GDPR accuracy and data-protection-by-design infringements affecting a large number of subscribers and imposed a €200,000 fine in Decision 31/2019. The authority's English notice does not state when the faulty processing began, so the decision date is used as the required event anchor rather than inventing an earlier date. Primary source: https://www.dpa.gr/en/enimerwtiko/press-releases/administrative-fines-imposed-telephone-service-provider
🚨Environmental Harm
No documented evidence
Avg Rating: —Ratings: 0Severity Score: 0.00Evidence Count: 0Contribution: 0.0 pts
🌱Sustainability Deception
No documented evidence
Avg Rating: —Ratings: 0Severity Score: 0.00Evidence Count: 0Contribution: 0.0 pts
💸Workplace Misconduct
No documented evidence
Avg Rating: —Ratings: 0Severity Score: 0.00Evidence Count: 0Contribution: 0.0 pts
⚠️Financial Misconduct
No documented evidence
Avg Rating: —Ratings: 0Severity Score: 0.00Evidence Count: 0Contribution: 0.0 pts