Data Protection and Privacy 2025

GREECE Law and Practice Contributed by: Natasha Mezini, Lambros Katsiamagkos and Jenny Georgountzou, Psarras, Georgountzou, Gavrilis - GKP Law Firm

3. Data Regulation on IoT Providers, Data Holders and Data Processing Services 3.1 Objectives and Scope of Data Regulation Regulation (EU) 2023/2854 of the European Par - liament and the Council, adopted on 13 Decem - ber 2023, establishes harmonised rules for fair access to and usage of data, commonly referred to as the Data Act. This regulation complements Regulation (EU) 2022/868, enacted on 30 May 2022, which focuses on European data gov - ernance, known as the Data Governance Act. Together with Regulation (EU) 2018/1807, which was adopted on 14 November 2018 and outlines a framework for the free flow of non-personal data within the EU, these regulations aim to cre - ate a comprehensive framework for data sharing and its utilisation. The Data Act sets the rights and obligations of users, data holders and data processing ser - vices. The main objective of the Data Act is to safeguard the fair allocation of the value of the data created from the use of connected prod - ucts and related services for the benefit of all factors of the digital economy and the promotion of access to data and their use. The Data Act aims to facilitate access to data and the users’ open use of data to create a well-functioning internal market for data. 3.2 Interaction of Data Regulation and Data Protection The Data Act mainly regulates access to non- personal data, while in the case of personal data, reference is made to the GDPR. The GDPR also applies to processing data generated from the use of connected products and related services. Insofar as the users are data subjects, they have the rights provided in the GDPR, while the rights

includes 440 related to the illegal processing of personal data, 411 concerning violations of data subject rights, 287 about unsolicited electronic communications (SPAM, emails, and SMS), and 275 regarding telephone harassment related to product and service promotions. The HDPA strictly safeguards the GDPR provisions and fol - lows the CJEU’s jurisprudence. 2.2 Recent Case Law The HDPA (decision 16/2024) imposed a fine of EUR400,000 on the Ministry of Internal Affairs for the unauthorised transfer of personal data of Greek nationals – voters living abroad – and a fine of EUR40,000 on a member of the EU Par - liament and candidate for the coming EU Parlia - ment elections of 2024 for the illegal collection and processing of the above personal data for the purposes of political communications. 2.3 Collective Redress Mechanisms Law 5019/2023 transposes the provisions of Directive (EU) 2020/1828 of the European Par - liament and of the Council of 25 November 2020 on representative actions for the protection of the collective interests of consumers. Actions may be brought against infringements by traders of the provisions, among others, of the GDPR and Law 3471/2006 for the protection of privacy and personal data in electronic communications. Domestic representative actions can be filed by consumers’ unions or organisations, including entities that have been qualified in other Mem - ber States to bring cross-border representative actions. Consumers’ unions or organisations must provide sufficient information about their members/consumers in order for the Court to decide on its jurisdiction and applicable law. The representative action may seek injunctive or redress measures.

154 CHAMBERS.COM

Powered by