The Data Protection Authority constitutes an independent public authority, not
subjecting to administrative control, reports to the Minister of Justice and its seat is
in Athens.
31 Its members enjoy personal and functional independence. The Authority is entrusted with the task of supervising the implementation of any regulation
pertaining the protection of individuals from the processing of personal data. In
addition, it exercises the duties assigned to it, such as to issue guidelines and
recommendations for any matter regarding the processing of personal data, to give
opinions regarding any rules concerning the processing and protection of personal
data that will be included to a Law or regulation, to give its opinion to the data
controllers according to the procedure of prior consultation (art. 36 GDPR), to issue
forms for the notification of personal data breach (art. 33 GDPR) and the communication of breach to the data subject (art. 34 GDPR) and to issue certifications (art.
42 GDPR). Moreover, the Authority has the task to examine the lawfulness of
personal data processing and to inform the data subject concerned, to handle the
complaints lodged by data subjects, to announce to the Parliament any breach of the
rules regarding the protection of individuals from the processing of personal data and
to draw up annual reports on the performance of its duties.
The Authority is empowered to carry out ex officio or following a complaint
reviews regarding the implementation of the GDPR and other legislation on
processing of personal data. During the investigation, the Authority may obtain
access to the data protection equipment and means, as well as to data and information
necessary for the performance of its tasks. Moreover, the Authority may denounce
any breach of data protection law to the competent judicial authorities. It may impose
administrative sanctions.
1.4 The Self-Regulation Instruments
According to Law 2472/1997, the Data Protection Authority encouraged and
assisted the trade associations as well as the associations of natural and legal persons
keeping personal data files to draw up codes of conduct intended to secure wider and
more effective protection of the right to privacy and other rights and fundamental
liberties of individuals in their field.
32 Thus, already under the previous legislative
regime, Greek data protection law recognized the possibility of trade associations
and other bodies to prepare codes of conduct for their members, without providing
for approval procedures.
33
31 See the website of this Authority, at: www.dpa.gr/en.
32 Art. 19 § 1b L. 2472/1997.
33 See Papakonstantinou (2010), § 15.2.2.
216
V. Kourtis
Précédent

- 223/540

Suivant