personal data to third countries was subject to preventive control by the European
Commission or the Greek Data Protection Authority in respect to the adequate level
of data protection ensured by the third country in question.
Specifically, the transfer of personal data to a third country was allowed if the
European Commission confirmed on the basis of an adequacy decision that the
country in question guaranteed “an adequate level of protection”.
160 In the absence
of a Commission’s adequacy decision for a third country, the transmission of
personal data to that country might be done upon a permit granted by the Data
Protection Authority. For examining if the third country offered an adequate level of
protection, the Authority assessed the nature of the personal data, the purpose and
duration of the data processing, the relevant general and specific rules of law, the
codes of conduct, the security measures provided for the protection of personal data,
as well as the protection level in the countries of origin, transfer and destination of
the data.
Furthermore, the personal data might be exceptionally transmitted to a third
country not ensuring an adequate level of protection upon a permit issued by the
Authority on the basis of the data subject’s consent, unless the consent has been
deduced in a manner contrary to the law or the bonos mores, e.g., hiding the country
where the personal data would be really kept.
161 Other grounds which could make
the personal data transfer permissible was the protection of the vital interests of the
data subject, the conclusion or performance of a contract, important reasons of public
interest, the establishment or defence of a right in court, or that the transfer was
carried out by a public register intended to provide information to the public.
Moreover, if the data controller might ensure that the personal data would be
sufficiently protected by the recipient; this could be assured using contractual
clauses.
162
Among the changes which the GDPR brings to the system of international data
transfers established by the Directive 95/46 and the Law 2472/1997, as described
above, the most important are the adoption of new legal bases for the transborder
transfer of personal data and the abolition of the supervisory Authority’s power to
certify the adequate level of data protection of a third country or to decide if an entity
has adapted a satisfactory personal data protection control system. Under the GDPR,
this decision-making burden is largely transferred from the Authorities to the
controllers. However, this change raises doubts as to whether all the private and
public entities processing personal data provide sufficient guarantees for the purposes of reaching a proper decision.
163
160 Compare this to art. 45 GDPR; for more details regarding the procedure provided for by the
GDPR for the issuance of the Commission’s decision, see the General Report, no. 4.3.
161 DPA Decision no. 12/2003.
162 A permit was not required if the Commission had decided, based on art. 26 § 4 of Directive 95/46
that certain conventional clauses offered adequate safeguards for the protection of data.
163 See Vlachopoulos (2018).
238
V. Kourtis
Précédent

- 245/540

Suivant