{"id":35319,"date":"2017-10-01T02:04:10","date_gmt":"2017-09-30T23:04:10","guid":{"rendered":"http:\/\/koumentakislaw.gr\/prostasia-prosopikon-dedomenon-kai-epixeirhseis\/"},"modified":"2019-10-06T07:32:45","modified_gmt":"2019-10-06T04:32:45","slug":"personal-data-protection-and-companies","status":"publish","type":"post","link":"https:\/\/koumentakislaw.gr\/en\/articles\/personal-data-protection-and-companies\/","title":{"rendered":"Personal Data Protection And Companies"},"content":{"rendered":"<p>[vc_row][vc_column][vc_column_text]\u00a0<strong>European requirement the enforcement for Personal Data Protection. New compliance rules (Regulation 2016\/679) <\/strong><\/p>\n<p><strong>\u00a0<\/strong><\/p>\n<h3>Preamble: What Does Non-Compliance Mean<\/h3>\n<p>It is true that any new obligation created for a company burdens its operating costs. But could anyone suggest non-compliance with the obligations under this Regulation for Personal Data Protection?<\/p>\n<p>To this case we could not remain indifferent. European Regulation (2016\/679) is in force without the need for ratification by the Greek legislator.<\/p>\n<p>Sanctions threatened? Unsustainable! Without going into the details of criminal sanctions, the maximum penalties (fines) amount to \u20ac 10.000.000 or \u20ac 20.000.000 and at a percentage of 2% or 4% respectively of the infringer&#8217;s worldwide turnover (if the above amounts are below the respective percentages on its worldwide turnover!)<\/p>\n<p>Things are NOT simple &#8230;<\/p>\n<p>&nbsp;<\/p>\n<h3>The Existing Institutional Framework<\/h3>\n<p>The need to protect individuals from the constantly evolving (due to the rapid developments in technology) exposure of their Personal Data and the creation of a secure modus operandi of the data processors is underlined by the <strong>European Regulation 679 of 27 April 2016<\/strong>, which shall be in full effect for all Member States (among which our country, of course) on <strong>25.5.2018<\/strong>.<strong>\u00a0\u00a0<\/strong><\/p>\n<p>In accordance with <strong>Law 2472\/1997<\/strong> <em>on the Protection of Individuals with regard to the Processing of Personal Data (and its revisions)<\/em>, the Greek legislator has incorporated the European Directive <strong>95\/46 \/ EC<\/strong> <em>\u201cOn the protection of individuals with regard to the processing of personal data and the free movement of such data\u201d<\/em>.<\/p>\n<p>The key foundations for the Protection of Personal Data that had already been set twenty years ago referred to the identification of:<\/p>\n<p>(a) the basic concepts such as \u201crecord\u201d, \u201cdata subject\u201d, \u201csimple data\u201d, \u201csensitive data\u201d, \u201ccontroller\u201d, \u201cprocessor\u201d<\/p>\n<p>(b) the rights of the Subjects of Processing (<em>each of us<\/em>)<\/p>\n<p>(c) the obligations of Personal Data Controllers (<em>natural and legal persons, bodies and organizations with whom we are required to have transactions in our daily lives from our employer to the Register of a Taxation<\/em>); and<\/p>\n<p>(d) the establishment of the Personal Data Protection Authority, which would then function independently, as a supervising body and as an institutional guarantor for verifying compliance with the European requirements.<\/p>\n<p>The\u00a0<strong>Personal Data Protection Authority<\/strong>\u00a0has been set up and operating since then, it undertakes vigorous action while its decisions have become a serious item in the agenda of not only the legal world bit also of the public opinion, as for example in the case of identifying religion in identities.<\/p>\n<p>The European Parliament chooses in this Regulation a more dynamic position than the previous Directive, since the former is a law of increased formal validity (it raises upward the laws of each member \u2013 state) and is (unlike the Directive) directly applicable horizontally (its incorporation by the national legislator is not required).<\/p>\n<p>&nbsp;<\/p>\n<h3>The Tightening For The Protection Of Personal Data In The Context Of The European Regulation<\/h3>\n<p>The Regulation strengthens the protection framework and in particular:<\/p>\n<p><strong>(a)<\/strong> the Controller is required to choose the most secure, organizational and technical measures both at the time when the data collection and processing measures are defined and at the time of processing.<\/p>\n<p>The obligations of the Controller and the Processor expanded (: record-keeping \u2013 specifications &#8211; processing activities) and acquire specific responsibility <u>to receive and be able to demonstrate that it has taken all necessary measures<\/u> to ensure that processing is carried out in accordance with the Regulation.<\/p>\n<p><strong>(b)<\/strong>\u00a0The rights of the Subjects are enhanced, including: (i) the right of access, (ii) the right of correction (or completion) (iii) the right to be forgotten (conditionally, the right to erase data), (iv) the right to object (v) the portability of data.<\/p>\n<p><strong>(c)<\/strong>\u00a0It is specifically provided for cases of systematic, extensive and large-scale assessment of personal data or systematic monitoring on a large scale of public places, an obligation to carry out an impact assessment of potential risks and consequences for the rights and freedoms of individuals arising from the type, the framework, the scope and the purpose of processing.<\/p>\n<p><strong>(d)<\/strong>\u00a0the Controller is required to immediately inform the authority of any breach of the system security (within 72 hours as from the moment he becomes aware of such)<\/p>\n<p><strong>(e)<\/strong>\u00a0the Controller (in cases explicitly mentioned in the Regulation, indicatively large-scale processing of data and \/ or sensitive data) appoints a Data Protection Officer, an internal supervisor (employee or external partner) (such as a security technician) who will ensure compliance with the regulatory framework (in conjunction with any specific regulation, if any, envisaged by the national legislator in the scope of his discretion) and has direct contact, cooperation with and reporting obligation for any violation to the Personal Data Protection Authority.<\/p>\n<p><strong>(f)<\/strong>\u00a0There are provided considerably stricter sanctions than the existing administrative and criminal penalties, with fines of between \u20ac 10.000.000 or \u20ac 20.000.000, and a percentage of the company&#8217;s turnover, as the case and the offender may be (if that percentage exceeds the above amounts).<\/p>\n<p>A significant difference with the current legal framework is that no disclosure to the Authority is foreseen, rather than the availability of the material (: processing file) at the direct request of the Authority. <u>However, each national legislator may specify his requirements<\/u> and request for Disclosures or Licenses, especially in cases related to processing of sensitive personal data. In order to examine the possible adoption of legislative measures for the implementation of the Regulation, a Legislative Committee has been already set up (Government Gazette 1913 \/ 27.6.2016) whose work we expect to be completed before the implementation of the Regulation.<\/p>\n<p>It is imperative that each Controller reviews (with the appropriate collaborators) the security status of his technical systems and of its organizational structure so that he is ready to comply with the requirements of the Regulation.<\/p>\n<p>&nbsp;<\/p>\n<h3>However, Is There, Any Time?<\/h3>\n<p>As already mentioned, the date the new European Regulation comes into effect is 25.5.2018 \u2013 i.e. at first reading, we have enough time to act. Still, is that the case?<\/p>\n<p>Many factors are to be evaluated in order to provide the answer: \u201cOkay, we have a lot of time\u201d.<\/p>\n<p>The kind of business activity, compliance with the current institutional framework, the concentration (and \/ or handling) of sensitive, apart from simple, personal data, and so on.<\/p>\n<p>Let us not rush to answer that \u201cwe do not have sensitive personal data\u201d. Do we ask for criminal records for some of our employees? Do we have a record of the health status of some of them? Do we have security cameras for the security of our company?<\/p>\n<p>&nbsp;<\/p>\n<h3>Conclusion<\/h3>\n<p>While we expect what (also) the national legislator will impose, the institutional framework for the protection of personal data has already become more complex. Threatened sanctions not only are significant but also, in fact, dramatically high.<\/p>\n<p>Preparing the company, most of the time, is neither easy nor quick.<\/p>\n<p>The need for more detailed information, a first assessment and for the first procedural steps, is present.<\/p>\n<p>Today!<\/p>\n<p>&nbsp;<\/p>\n<p>[\/vc_column_text][\/vc_column][\/vc_row]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>[vc_row][vc_column][vc_column_text]\u00a0European requirement the enforcement for Personal Data Protection. New compliance rules (Regulation 2016\/679) \u00a0 Preamble: What Does Non-Compliance Mean It is true that any new obligation created for a company burdens its operating costs. But could anyone suggest non-compliance with the obligations under this Regulation for Personal Data Protection? To this case we could not&#8230;<\/p>\n","protected":false},"author":3,"featured_media":35899,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[206],"tags":[601,214,529,584,600,292],"class_list":["post-35319","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-articles","tag-european-regulation-679","tag-gdpr-en","tag-legal-advisors","tag-personal-data","tag-personal-data-protection","tag---en"],"_links":{"self":[{"href":"https:\/\/koumentakislaw.gr\/en\/wp-json\/wp\/v2\/posts\/35319","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/koumentakislaw.gr\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/koumentakislaw.gr\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/koumentakislaw.gr\/en\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/koumentakislaw.gr\/en\/wp-json\/wp\/v2\/comments?post=35319"}],"version-history":[{"count":6,"href":"https:\/\/koumentakislaw.gr\/en\/wp-json\/wp\/v2\/posts\/35319\/revisions"}],"predecessor-version":[{"id":36586,"href":"https:\/\/koumentakislaw.gr\/en\/wp-json\/wp\/v2\/posts\/35319\/revisions\/36586"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/koumentakislaw.gr\/en\/wp-json\/wp\/v2\/media\/35899"}],"wp:attachment":[{"href":"https:\/\/koumentakislaw.gr\/en\/wp-json\/wp\/v2\/media?parent=35319"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/koumentakislaw.gr\/en\/wp-json\/wp\/v2\/categories?post=35319"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/koumentakislaw.gr\/en\/wp-json\/wp\/v2\/tags?post=35319"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}