Unlike general Law 2472/1997, an obligation of the providers of publicly available electronic telecommunications services to notify the Data Protection Authority
as well as the Authority for Communication Security and Privacy (ADAE), when
data breach occurs, is imposed by Law 3471/2006.
84 Such a notification shall
include at least a description of the nature of the breach, the contact points from
which further information can be obtained, a description of the consequences of the
breach as well as the measures that were suggested or taken by the provider. If the
personal data breach is likely to affect the personal data or the private life of the
subscriber, the provider is also obliged to notify the subscriber, except if s/he has
proved that implemented appropriate technological security measures, which must at
least include secure data encryption. The Authorities, mentioned above, can jointly
issue guidelines concerning the circumstances in which providers are required to
notify personal data breaches.
2.1.6 Specific Legislation on Certain Sectorial Areas Regarding
the Processing of Personal Data by Electronic Means
Under the Code of Medical Ethics,
85 the doctors are obliged to maintain medical
records, in electronic form or other, containing data that are linked to the disease or
the health of their patients. The processing of medical records is subject to stricter
requirements provided for sensitive data.
86 A patient is entitled to access his/her
health data
87 and the national or international records where his/her personal data
have been added.
88
In virtue of Article 41 of Regulation 1987/2006 on Schengen Information System
(“SIS II”), the rights of the third-country nationals who are registered to Schengen
Information System II or/and to national catalogue of undesirable aliens (EKANA)
89
as concern their personal data are governed by the Greek legislation on personal data
protection. It follows that the Data Protection Authority applies national legislation
on personal data protection to relevant objections raised by third country nationals.
Finally, the processing of personal data collected by unmanned aerial vehicles
(“drones”) is governed by the general legislation on data protection in conjunction
with article 14 of Law 3917/2011 concerning the use of surveillance systems in
public areas. In addition, article 370A of Criminal Code is applicable, pursuant to
which intercepting “by monitoring using special technical means or taping
non-public conversations or video recording non-public acts of third parties” is
punishable. Furthermore, the directives and opinions issued by the Data Protection
84 Art. 12 §§ 5–10 L. 3471/2006.
85 Law 3418/2015, Government Gazette A 287.
86 See Latsiou (2016), p. 155.
87 Art. 12 L. 2472/1997 and art. 14 § 8 L. 3418/2005.
88 Art. 14 § 10 L. 3418/2005.
89 Papassiopi-Passia and Kourtis (2015), pp. 83 ff.
Data Protection in the Internet: Greece
225
as well as the Authority for Communication Security and Privacy (ADAE), when
data breach occurs, is imposed by Law 3471/2006.
84 Such a notification shall
include at least a description of the nature of the breach, the contact points from
which further information can be obtained, a description of the consequences of the
breach as well as the measures that were suggested or taken by the provider. If the
personal data breach is likely to affect the personal data or the private life of the
subscriber, the provider is also obliged to notify the subscriber, except if s/he has
proved that implemented appropriate technological security measures, which must at
least include secure data encryption. The Authorities, mentioned above, can jointly
issue guidelines concerning the circumstances in which providers are required to
notify personal data breaches.
2.1.6 Specific Legislation on Certain Sectorial Areas Regarding
the Processing of Personal Data by Electronic Means
Under the Code of Medical Ethics,
85 the doctors are obliged to maintain medical
records, in electronic form or other, containing data that are linked to the disease or
the health of their patients. The processing of medical records is subject to stricter
requirements provided for sensitive data.
86 A patient is entitled to access his/her
health data
87 and the national or international records where his/her personal data
have been added.
88
In virtue of Article 41 of Regulation 1987/2006 on Schengen Information System
(“SIS II”), the rights of the third-country nationals who are registered to Schengen
Information System II or/and to national catalogue of undesirable aliens (EKANA)
89
as concern their personal data are governed by the Greek legislation on personal data
protection. It follows that the Data Protection Authority applies national legislation
on personal data protection to relevant objections raised by third country nationals.
Finally, the processing of personal data collected by unmanned aerial vehicles
(“drones”) is governed by the general legislation on data protection in conjunction
with article 14 of Law 3917/2011 concerning the use of surveillance systems in
public areas. In addition, article 370A of Criminal Code is applicable, pursuant to
which intercepting “by monitoring using special technical means or taping
non-public conversations or video recording non-public acts of third parties” is
punishable. Furthermore, the directives and opinions issued by the Data Protection
84 Art. 12 §§ 5–10 L. 3471/2006.
85 Law 3418/2015, Government Gazette A 287.
86 See Latsiou (2016), p. 155.
87 Art. 12 L. 2472/1997 and art. 14 § 8 L. 3418/2005.
88 Art. 14 § 10 L. 3418/2005.
89 Papassiopi-Passia and Kourtis (2015), pp. 83 ff.
Data Protection in the Internet: Greece
225
