and stored in the hard disk of the computers used by the defendants.
76 The contents
of the e-mails infringed the employers’ rights protected by legislation on unfair
competition. The Court estimated that, in the circumstances of the case, the exercise
of the right to judicial protection by the employer
77 to secure his right to carry on
business activity
78 prevailed over the constitutional right of the employees to protect
their personal data
79
; thus, the contents of the harmful emails might be admitted as
evidence in court against the defendants.
The employees may exercise all remedies provided for by the Civil Code in
regard to the right to personality as well as those remedies provided for by the
legislation on personal data protection.
80 The waiving of the rights conferred to the
employee by Law 2472/1997 is void.
81 The exercise of the rights by the employee
cannot lead to unfavourable results for him/her. If an employee considers that the
infringement makes the performance of work intolerable, s/he may abstain from the
work for as long as the insult occurs; in that case the employer is in default and the
employee continues to have claims to wages.
2.1.5 Security Obligations and Data Breach Notifications Concerning
Data Processed by Electronic Means
Under Law 2472/1997, the data controller had the duty to take the appropriate
organisational and technical measures to ensure security and protection of personal
data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of or access to as well as any form of unlawful processing,
82 during the whole
data processing period, which was completed with the destruction of the data.
83
However, a controller was not obliged to give notice of data breach or an incident
concerning the security of personal data to the Data Protection Authority or the data
subject concerned, as a controller is obliged to do according to the General Data
Protection Regulation.
76 According to Areios Pagos, when an electronic correspondence has been terminated, it is no
longer protected by art. 19 of the Constitution, which guarantees the correspondence secrecy, but by
art. 9A of the Constitution on personal data protection. See also the Opinion no. 6/2008 of the
Attorney of Areios Pagos, according to which a hard disk is not a means of communication; hence,
the data stored in a hard disk do not fall within the protective scope of the communication secrecy.
77 Art. 20 § 1 of the Constitution.
78 Articles 5 and 106 § 2 of the Constitution.
79 Article 9A of the Constitution.
80 See Malagardi (2010), pp. 297 ff.
81 See DPA Directive no. 115/2001.
82 Art. 10 § 3 L. 2472/1997.
83 Art. 4 § 1 d L. 2472/1997. See also DPA Directive no. 1/2005 concerning the secure destruction
of personal data after the end of the period that is required for the accomplishment of the processing
purpose.
224
V. Kourtis
76 The contents
of the e-mails infringed the employers’ rights protected by legislation on unfair
competition. The Court estimated that, in the circumstances of the case, the exercise
of the right to judicial protection by the employer
77 to secure his right to carry on
business activity
78 prevailed over the constitutional right of the employees to protect
their personal data
79
; thus, the contents of the harmful emails might be admitted as
evidence in court against the defendants.
The employees may exercise all remedies provided for by the Civil Code in
regard to the right to personality as well as those remedies provided for by the
legislation on personal data protection.
80 The waiving of the rights conferred to the
employee by Law 2472/1997 is void.
81 The exercise of the rights by the employee
cannot lead to unfavourable results for him/her. If an employee considers that the
infringement makes the performance of work intolerable, s/he may abstain from the
work for as long as the insult occurs; in that case the employer is in default and the
employee continues to have claims to wages.
2.1.5 Security Obligations and Data Breach Notifications Concerning
Data Processed by Electronic Means
Under Law 2472/1997, the data controller had the duty to take the appropriate
organisational and technical measures to ensure security and protection of personal
data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of or access to as well as any form of unlawful processing,
82 during the whole
data processing period, which was completed with the destruction of the data.
83
However, a controller was not obliged to give notice of data breach or an incident
concerning the security of personal data to the Data Protection Authority or the data
subject concerned, as a controller is obliged to do according to the General Data
Protection Regulation.
76 According to Areios Pagos, when an electronic correspondence has been terminated, it is no
longer protected by art. 19 of the Constitution, which guarantees the correspondence secrecy, but by
art. 9A of the Constitution on personal data protection. See also the Opinion no. 6/2008 of the
Attorney of Areios Pagos, according to which a hard disk is not a means of communication; hence,
the data stored in a hard disk do not fall within the protective scope of the communication secrecy.
77 Art. 20 § 1 of the Constitution.
78 Articles 5 and 106 § 2 of the Constitution.
79 Article 9A of the Constitution.
80 See Malagardi (2010), pp. 297 ff.
81 See DPA Directive no. 115/2001.
82 Art. 10 § 3 L. 2472/1997.
83 Art. 4 § 1 d L. 2472/1997. See also DPA Directive no. 1/2005 concerning the secure destruction
of personal data after the end of the period that is required for the accomplishment of the processing
purpose.
224
V. Kourtis
