GREECE Law and Practice Contributed by: Natasha Mezini, Lambros Katsiamagkos and Jenny Georgountzou, Psarras, Georgountzou, Gavrilis - GKP Law Firm
provided by the Data Act complement the right of access by the data subject and the right of portability provided in the GDPR. In the event of a conflict between the Data Act and the GDPR and EU law on the protection of personal data, the latter shall prevail. 3.3 Rights and Obligations Under Applicable Data Regulation The Data Act, which is directly applicable in Greece, regulates the use of IOT services and provides the following obligations. • Obligation to design, manufacture and pro - vide connected products and related services in a manner that product data and associated service data (including the relevant metadata necessary to interpret and use those data) are easily, securely, free of charge, in a compre - hensive, structured, commonly used and machine-readable format and directly acces - sible to the user. • If the user cannot directly access data from the connected product or related services, data holders are required to promptly make the data and any relevant metadata available to the user. This data must be of the same quality as what is accessible to the data hold - ers and should be easy to access, secure, free of charge, comprehensive, structured, commonly used, and in a machine-readable format. Additionally, where relevant and tech - nically feasible, this data should be provided continuously and in real-time upon a simple request through electronic means. • The seller or lessor of a connected product, as well as the service provider of a related service, is obligated to provide the user with clear and comprehensive information regard - ing the product data or service data prior to the sale, rental, or lease of the connected product, or the provision of the related ser -
vice. This information must include the type, format, and volume of data that the connect - ed product can generate, as well as details on how to access, retrieve, or erase this data. • Obligation of data holders not to make the exercise of the users’ right to restrict or pro - hibit accessing, using or further sharing data unduly difficult. • Data holders are obliged to take all neces - sary measures prior to the disclosure of trade secrets to preserve their confidentiality, par - ticularly regarding third parties. • Obligation of data holders to use only any readily available data that is non-personal data on the basis of a contract with the user; obligation of data holders not to use above data to derive insights about the economic situation, assets and production methods of, or the use by, the user in any other manner that could undermine the commercial position of that user on the markets in which the user is active. • Obligation of data holders not to make non-personal product data available to third parties for commercial or non-commercial purposes other than fulfilling their contract with the user; where relevant, data holders shall contractually bind third parties not to further share data received from them. The Data Act provides the following obligations for third parties receiving data at the request of the user in order to safeguard data processing, as outlined below. • Data may be processed only for the purposes and under the conditions agreed with the user and subject to EU and national law on the protection of personal data, including the rights of the data subject insofar as personal data are concerned.
155 CHAMBERS.COM
Powered by FlippingBook