3.2 The Applicability of Data Protection Rules to Foreign
Entities
The rules of Law 2472/1997 were also applicable to personal data processing carried
out by a controller established in a third country, i.e. outside the EU/EEA territory,
who, for the purposes of processing, used of the equipment situated on the Greek
territory, except if the equipment was used only for data transfer through the Greek
territory. In the latter case, the controller should appoint, by a statement addressed to
the Data Protection Authority, a representative established in Greece, who
substituted the controller to all his/her rights and duties, without prejudice to legal
actions which might be initiated against the controller. The same applied when the
controller or processor was subject to immunities or other reason prohibiting criminal prosecution.
The Greek Law, like the Directive 95/46, did not explicitly enshrined as criterion
for its territorial scope the “market-place principle”,
158 so individuals domiciled in
Greece often deprived of the high protection in respect to their personal data
provided for by the harmonized EU legislation, when the controller was established
outside the EU and the data processing was related to offering of goods or services in
Greece by non-EU businesses (e-shops). The extended extraterritorial applicability
of the General Data Protection Regulation opens a promising perspective on this
matter.
According to the new Law, which has been enacted to implement the GDPR in
Greece, the Regulation as well as the new Law apply to the processing of personal
data carried out in Greece, as well as the processing carried out in the context of the
activities of an establishment in Greece, regardless of whether the processing takes
place in Greece or not.
3.3 The Specific Conditions Applicable to the Transfer
of Personal Data to a Foreign Jurisdiction
Until the entry into force of the GDPR, the article 9 of Law 2472/1997, following
article 25 of Directive 95/46, regulated the transborder flow of personal data. The
term transfer of personal data was not defined by the Greek legislation, as was not
defined by the Directive 95/46. With respect to the meaning of this term, important is
the decision rendered by the CJUE on the case Lindquist.
159
According to the outgoing Law 2472/1997, the transfer of personal data from
Greece to another EU Member State was freely allowed, while the transfer of
158 See the General Report, no. 4.2.
159 CJEU, 06.11.2013, C-101/2001, Lindquist, ECLI:EU:C:2003:596. On this matter, see
Yannopoulos (2001), pp. 733 ff.
Data Protection in the Internet: Greece
237
Entities
The rules of Law 2472/1997 were also applicable to personal data processing carried
out by a controller established in a third country, i.e. outside the EU/EEA territory,
who, for the purposes of processing, used of the equipment situated on the Greek
territory, except if the equipment was used only for data transfer through the Greek
territory. In the latter case, the controller should appoint, by a statement addressed to
the Data Protection Authority, a representative established in Greece, who
substituted the controller to all his/her rights and duties, without prejudice to legal
actions which might be initiated against the controller. The same applied when the
controller or processor was subject to immunities or other reason prohibiting criminal prosecution.
The Greek Law, like the Directive 95/46, did not explicitly enshrined as criterion
for its territorial scope the “market-place principle”,
158 so individuals domiciled in
Greece often deprived of the high protection in respect to their personal data
provided for by the harmonized EU legislation, when the controller was established
outside the EU and the data processing was related to offering of goods or services in
Greece by non-EU businesses (e-shops). The extended extraterritorial applicability
of the General Data Protection Regulation opens a promising perspective on this
matter.
According to the new Law, which has been enacted to implement the GDPR in
Greece, the Regulation as well as the new Law apply to the processing of personal
data carried out in Greece, as well as the processing carried out in the context of the
activities of an establishment in Greece, regardless of whether the processing takes
place in Greece or not.
3.3 The Specific Conditions Applicable to the Transfer
of Personal Data to a Foreign Jurisdiction
Until the entry into force of the GDPR, the article 9 of Law 2472/1997, following
article 25 of Directive 95/46, regulated the transborder flow of personal data. The
term transfer of personal data was not defined by the Greek legislation, as was not
defined by the Directive 95/46. With respect to the meaning of this term, important is
the decision rendered by the CJUE on the case Lindquist.
159
According to the outgoing Law 2472/1997, the transfer of personal data from
Greece to another EU Member State was freely allowed, while the transfer of
158 See the General Report, no. 4.2.
159 CJEU, 06.11.2013, C-101/2001, Lindquist, ECLI:EU:C:2003:596. On this matter, see
Yannopoulos (2001), pp. 733 ff.
Data Protection in the Internet: Greece
237
