3.4 The Law Applicable to Liability for Damages Caused by
the Unlawful Processing of Personal Data
The protection of personal data is deemed as a matter that falls within the scope of
the protection of privacy and rights related to personality, so the infringement of
personal data legislation is excluded from the material scope of the Regulation
864/2007 on applicable law to non-contractual obligations (“Rome II Regulation”).
Greek academics support the exclusion of civil liability for damages caused by
unlawful processing of personal data from the scope of Rome II Regulation.
164
Consequently, the liability for damages caused by the unlawful data processing is
governed by article 26 of the Civil Code, according to which lex loci delicti applies.
The academic discussion in Greece regarding the place where the wrongful act was
committed in case of the so called “offences at a distance” and the disseminated or
multiple-location offences never reached a conclusion, with some tendency to favour
conduct over effects or to give plaintiff the choice.
165 The Greek courts favour the
possibility of the injured party to choose the applicable law.
166 In absence of such a
choice, the courts usually apply the law of the state where the most significant
element or elements of the damage occurred.
The cases of infringement of rights of personality brought before the Greek courts
are usually defamation cases. The case law admitted that the location of the wrongful
act of defamation is the place where the defamatory material is received and read.
Based on this opinion, in a published judgment concerning defamation committed
by means of content posted on an internet website, the court considered that the
plaintiff’s reputation was harmed in Greece, where he had his habitual residence, as
well as in those countries where the defamatory content was accessible. It applied
Greek law based on the criterion that the damage has been suffered mostly in
Greece.
167
As regards the applicable law to delictual claims arisen out of the legal relationship between the provider of services provided at a distance and the recipient of the
service, in Greek theory it has been argued that the law designated by article 2 of the
Presidential Decree 131/2003, which transposed the article 3 of Directive 2000/31, is
applicable not only to contractual claims arisen out of an agreement for provision of
information society services but also to delictual claims arisen from the same legal
relationship.
168
164 See Grammatikaki-Alexiou (2016), p. 532; Christodoulou (2013), p. 142.
165 For the different theories that have been formulated on the issue see Vrellis (2008), pp. 249 ff.
166 See Areios Pagos no. 903/2010.
167 See Court of Appeals of Rhodes no. 220/2013.
168 See Christodoulou (2010).
Data Protection in the Internet: Greece
239
Précédent

- 246/540

Suivant