dignity and the right to the free development of personality, respectively, and on the
articles 9 and 9A of the Constitution, which guarantees the right to privacy and the
protection of personal data, respectively.
59 The “right to be forgotten” was not
enshrined in any Greek specific provision regarding data protection in the way it is
provided for by the GDPR (article 17) and was recognized in the CJUE’s decision on
the Google Spain case.
60 However, one can trace the right to the erasure of personal
data processed in certain provisions of the older legal framework, which established
a right of the data subject to delete his/her own personal data. E.g., pursuant to Art.
4 §1d of Law 2472/1997, the personal data might be kept in a form permitting
identification of the data subject for no longer than the period required for the
purposes for which such data were collected or processed. Exceptionally, the
maintenance of personal data might be allowed under conditions for historical,
scientific or statistical purposes. In relation to the lawful duration of data processing,
the Data Protection Authority held that after the termination of a mobile contract or
the cancellation of a smart card, the personal data collected during the transaction
must be deleted.
61 Moreover, Article 12 §2e of Law 2472/1997 provided for the
right of the data subject to ask the controller to erase or lock of his/her data, when the
processing is not in accordance with the law, especially due to the incomplete or
inaccurate nature of data. Furthermore, Article 6 §1 of Law 3471/2006 recognized
the obligation of the providers of electronic communication services to erase or make
anonymous the traffic data relating to subscribers and users after the end of the
transmission of a communication.
62 Finally, worth to say is that the Data Protection
Authority examined during the last years certain requests concerning the deletion of
links from the Google search results, taking into account the Google Spain decision
and the relevant guidelines issued by the article 29 data protection working party.
63
2.1.4 Protection of Employees’ Personal Data Processed by Electronic
Means
Electronic personal data processing in the field of employment relationships is a
subject to the general personal data legal framework.
64 An exemption in respect to
the processing of employees’ personal data was introduced by Article 7A of Law
2472/1997 that has been added by an amendment in 2001. According to that
provision, the controller—who is usually identified with the employer or
59 See Iglezakis (2014), pp. 37 ff.; Panagopoulou-Koutnatzi (2016), p. 714.
60 CJEU, 13.05.2014, C-131/12, Google Spain v. Agencia Española, ECLI:EU:C:2014:317.
61 See DPA Decision no. 38/2002.
62 However, this obligation was subject to Law 3917/2011, which provided for the traffic data’s
retention for a period of 12 months.
63 WP 225/26.11.2014. See DPA decisions nos. 82/2016, 83/2016 and 84/2016.
64 For the protection of employees against the unlawful processing of their personal data, see Douka
(2005); Malagardi (2010); Mitrou (2016), pp. 191 ff.
Data Protection in the Internet: Greece
221
articles 9 and 9A of the Constitution, which guarantees the right to privacy and the
protection of personal data, respectively.
59 The “right to be forgotten” was not
enshrined in any Greek specific provision regarding data protection in the way it is
provided for by the GDPR (article 17) and was recognized in the CJUE’s decision on
the Google Spain case.
60 However, one can trace the right to the erasure of personal
data processed in certain provisions of the older legal framework, which established
a right of the data subject to delete his/her own personal data. E.g., pursuant to Art.
4 §1d of Law 2472/1997, the personal data might be kept in a form permitting
identification of the data subject for no longer than the period required for the
purposes for which such data were collected or processed. Exceptionally, the
maintenance of personal data might be allowed under conditions for historical,
scientific or statistical purposes. In relation to the lawful duration of data processing,
the Data Protection Authority held that after the termination of a mobile contract or
the cancellation of a smart card, the personal data collected during the transaction
must be deleted.
61 Moreover, Article 12 §2e of Law 2472/1997 provided for the
right of the data subject to ask the controller to erase or lock of his/her data, when the
processing is not in accordance with the law, especially due to the incomplete or
inaccurate nature of data. Furthermore, Article 6 §1 of Law 3471/2006 recognized
the obligation of the providers of electronic communication services to erase or make
anonymous the traffic data relating to subscribers and users after the end of the
transmission of a communication.
62 Finally, worth to say is that the Data Protection
Authority examined during the last years certain requests concerning the deletion of
links from the Google search results, taking into account the Google Spain decision
and the relevant guidelines issued by the article 29 data protection working party.
63
2.1.4 Protection of Employees’ Personal Data Processed by Electronic
Means
Electronic personal data processing in the field of employment relationships is a
subject to the general personal data legal framework.
64 An exemption in respect to
the processing of employees’ personal data was introduced by Article 7A of Law
2472/1997 that has been added by an amendment in 2001. According to that
provision, the controller—who is usually identified with the employer or
59 See Iglezakis (2014), pp. 37 ff.; Panagopoulou-Koutnatzi (2016), p. 714.
60 CJEU, 13.05.2014, C-131/12, Google Spain v. Agencia Española, ECLI:EU:C:2014:317.
61 See DPA Decision no. 38/2002.
62 However, this obligation was subject to Law 3917/2011, which provided for the traffic data’s
retention for a period of 12 months.
63 WP 225/26.11.2014. See DPA decisions nos. 82/2016, 83/2016 and 84/2016.
64 For the protection of employees against the unlawful processing of their personal data, see Douka
(2005); Malagardi (2010); Mitrou (2016), pp. 191 ff.
Data Protection in the Internet: Greece
221
