180 incidents on record · 2026 Headlights Incident reports by Ellie Harris · Melbourne
10 new this week Library last updated 30 August 2026
← The incident library
HD-INC-156
Government · Greece · 2024 · AI-enabled surveillance and biometric processing without adequate impact assessment

Greece's data protection authority fined the Migration Ministry 175,000 euros after finding that the impact assessments for the camera, behavioural analytics, drone and fingerprint systems at five island reception centres were substantially incomplete

By Ellie Harris · Filed Systems presented as operational from 2021; investigation opened by the authority on its own initiative

Alleged: Ministry of Migration and Asylum (Greece) developed or deployed the AI system implicated in this incident. Details are drawn from public reports; parties are presumed innocent of any wrongdoing not established by an official finding.

Greece's data protection authority fined the Migration Ministry 175,000 euros after finding that the impact assessments for the camera, behavioural analytics, drone and fingerprint systems at five island reception centres were substantially incomplete

What happened

It was reported that on 2 April 2024 the Hellenic Data Protection Authority issued Decision 13/2024 against the Greek Ministry of Migration and Asylum, and announced it the following day. The authority had opened the investigation itself, on its own initiative. It covered two systems running at Closed Controlled Access Centres and Reception and Identification Centres on Lesvos, Chios, Samos, Leros and Kos. The authority described Centaur as an integrated digital system for managing electronic and physical security, using motion analysis cameras with behavioural analytics, closed circuit television and drones that process image data. It described Hyperion as an integrated entry and exit control system, using readers together with fingerprint authentication, which processes biometric data. The fine came to 175,000 euros. The ministry was given three months to bring its processing into line with the GDPR.

It was reported that the authority found the ministry’s data protection impact assessments for the two systems substantially incomplete and limited in scope, and found a lack of cooperation on the part of the ministry in its capacity as data controller. Computer Weekly reported what that looked like in practice. The documents the ministry submitted were unclear, incomplete, confusing and contradictory, and it would not hand over its supply contracts with two private security companies, citing confidentiality clauses. The same reporting sets out the timeline. The migration minister unveiled a control room already connected to camp systems in September 2021. Ministry officials said in December 2021 that Centaur was operational in several camps. The impact assessments were completed in January 2022, more than three months after the ministry first advertised the programme as active. Neither the authority’s announcement nor the European Data Protection Board’s record of the decision, which lists provisions running from Article 4 to Article 83 of the GDPR together with Article 39 of Law 4624/2019, says which provision each individual finding rests on. The ministry told Computer Weekly that corrective measures had to a large extent already been implemented, that the authority had assessed the evidence incorrectly, and that it intended to assess the possibility of challenging the decision.

What an auditable version would have shown

The finding turned on what the ministry could show about systems already running over people living in its facilities. A record kept as the systems ran answers that. An investigation two years later can only reconstruct it. For Centaur the record would show each time the behavioural analytics raised an alert: what triggered it, how the system classified it, who received it and what they did next. For Hyperion it would show each time a fingerprint was enrolled or checked, the basis for collecting it, where the biometric template is held, how long it is kept, and what happened when a match failed or was disputed. Over time those records turn into figures the ministry does not otherwise have: how many people were processed, how many alerts were raised, how many came to nothing, and how often the biometric check failed the person standing in front of it. The impact assessment could then be written against what the systems were actually doing rather than what they were meant to do.

Where the gap was

It was reported that the authority found the impact assessments substantially incomplete and limited in scope, and that the ministry did not cooperate with it as controller. A ConstraintGate encodes the limits an assessment sets as checks that run before each processing action, so processing outside the assessed scope is refused when it is attempted rather than found years later. A ConductRecord preserves what the system did in each case, in enough detail to answer an authority asking what happened to a named person, or how often a class of alert was raised. The people living in these facilities cannot watch the system work and cannot put questions to it. That leaves accountability resting on the records the operator keeps.

What governance should have looked like

It was reported that the authority gave the ministry three months to bring its processing into line with the GDPR, and that it reached its findings through an investigation it began itself rather than through anything the ministry published. Where a public body runs automated surveillance over a population that cannot leave, good practice is for the impact assessment to be complete and specific before deployment, for the processing to be constrained to what that assessment covers, and for a record of each processing action to exist independently of the people operating the system. On the timeline Computer Weekly sets out, the assessments followed the deployment. The published material describes what the ministry could not show, and it says nothing about what the systems produced during the period under investigation.

Failure Pattern: automated surveillance and biometric systems were put into operation over people living in state accommodation, and the impact assessments required for them were completed late and found substantially incomplete and limited in scope.

Governance Principle: where the state runs automated surveillance over people in its care, the impact assessment should be complete before the system operates, and each processing action should be recorded so that what it actually did can be checked afterwards.

The reference implementation of ConstraintGate and ConductRecord is open source. It lives at github.com/saffronandindia/headlights-oss, Apache 2.0 licensed and free to install. The repository is public now.

Sources

The mailing list

Fresh incident reports every week. One email to match.

We add new incidents to the library regularly, and send a single short email each week with what's new. The library stays free and open; this is just how you keep up with it.

No tracking. Unsubscribe in one click.

The record

An auditable system would have produced a signed, tamper-evident record the moment this happened: what the system did, the version that did it, the basis it acted on, and the action taken, and Ministry of Migration and Asylum (Greece) could have produced it on demand.

This is the record the system as deployed did not produce in a signed, auditable form.

What this teaches
Capture what happened when it happens
What the system did, the version that did it, the basis it acted on, and the action taken, recorded at the moment, not reconstructed after.
Sign it, so no one has to trust the record-keeper
A tamper-evident entry. Edit it later and the signature breaks. The record does not ask for the benefit of the doubt.
Make it verifiable by anyone
A court, a regulator, a customer's lawyer can check the record themselves, without taking the company, or us, at our word.

Headlights summarises publicly reported AI incidents. All summaries are independently written, attributed to their original sources, and intended for research and educational purposes. Allegations are identified as such until established through official findings.

This report is based on the sources listed above and reflects information available at the time of review; later developments may not be captured. Where a person is described as charged with or alleged to have done something, that allegation is unproven unless a conviction or a court or regulatory finding is stated. Headlights publishes journalism and commentary, not legal advice.

Want to write back?

Direct to my inbox.

ellie@useheadlights.com →