Δευτέρα 6 Ιουνίου 2016

The Legal Regulation of Cyber Attacks


The Legal Regulation of Cyber Attacks provides a thorough analysis of the legal regulation of attacks against information systems in European, international, and comparative law contexts. Modern societies are to a great extent dependent on computers and information systems, but there is a negative side to the use of information and communication technology – the rise of a new kind of criminality not traditionally addressed by the law. Technological developments and the changing nature of cybercrime force legislators to deal with new objects and redefine concepts. Taking into account legislative and case law developments, this book covers legal issues not only pertaining to attacks arising in criminal law but also crucial problems such as the conflict of cybercrime investigation and prosecution with fundamental rights to privacy and freedom of expression.
What’s in this book:
The authors’ in-depth response to doctrinal and practical issues related to the application of cybercrime regulation includes elements, issues, and aspects such as the following:
  • legal harmonization of cybercrime law
  • jurisdictional issues in the investigation and prosecution of cybercrime;
  • prevention of cyber attacks;
  • personal data and privacy implications;
  • hacking of cell phones;
  • enforcement and forensics in cybercrime law;
  • states and legal persons as perpetrators of cybercrime;
  • European Programme for Critical Infrastructure Protection;
  • Cybercrime Convention of 2001;
  • Directive 2013/40/EU;
  • identity theft;
  • the Snowden revelations and their lessons;
  • principles, problems, and shortcomings of digital evidence;
  • legal status of the IP address;
  • the security and data breach notification as a compliance and transparency tool;
  • profile and motivation of perpetrators of cyber attacks;
  • cybercrime as a parallel economy; and
  • use of crypto-currency as a means for blackmail operations.
Technical definitions, case law, and analysis of both substantive law and procedural law contribute to a comprehensive understanding of cybercrime regulation and its current evolution in practice. Furthermore, this book evaluates the complex legal framework and the practical and legal challenges of the regulation of attacks against information systems.
How this will help you:
Being the first book to deal with the criminalization of cyber attacks, this book clarifies the nature of the conflict of cybercrime investigation and prosecution with fundamental rights to privacy and freedom of expression. Addressing a topic of growing importance in unprecedented detail, this book is an extremely useful reference tool for professionals and authorities dealing with cybercrime, including lawyers, judges, academics, security professionals, information technology experts, and law enforcement agencies.

Title Information

Title
The Legal Regulation of Cyber Attacks
Author(s) / Editor(s)
Ioannis Iglezakis
Publication Date
2016
ISBN
9789041169013
Page extent
pp: v - 230
Publisher
Kluwer Law International



TABLE OF CONTENTS:

  • pp. 163-168
    Conclusion
    Philippe Jougleux, Lilian Mitrou & Tatiana-Eleni Synodinou

Κυριακή 29 Μαΐου 2016

Είναι οι διευθύνσεις ΙΡ προσωπικά δεδομένα; Προτάσεις του Γεν. Εισαγγελέα στην υπόθεση C-582/14


Στις 12 Μαΐου 2016 δημοσιεύθηκαν οι προτάσεις του ΓΕΝΙΚΟΥ ΕΙΣΑΓΓΕΛΕΑ MANUEL CAMPOS SÁNCHEZ-BORDONA της 12ης Μαΐου 2016 στην υπόθεση C‑582/14 Patrick Breyer κατά Bundesrepublik Deutschland.

Η υπόθεση αυτή είναι πολύ σημαντική, καθώς αφορά το νομικό χαρακτηρισμό των διευθύνσεων ΙΡ στο Διαδίκτυο ως προσωπικών δεδομένων. 


Όπως σημειώνεται στην απόφαση, διεύθυνση πρωτοκόλλου του διαδικτύου (στο εξής: διεύθυνση ΙΡ) είναι μια ακολουθία δυαδικών αριθμών η οποία όταν αποδίδεται σε μια συσκευή (υπολογιστή, ταμπλέτα, έξυπνο τηλέφωνο), εξακριβώνει την ταυτότητά της και της παρέχει πρόσβαση στο δίκτυο ηλεκτρονικών επικοινωνιών. Για να συνδεθεί στο διαδίκτυο, η συσκευή πρέπει να χρησιμοποιήσει την αριθμητική ακολουθία που παρέχουν οι φορείς παροχής υπηρεσιών προσβάσεως στο διαδίκτυο. Η διεύθυνση IP διαβιβάζεται στον διακομιστή όπου είναι αποθηκευμένη η ιστοσελίδα αντικείμενο της αναζητήσεως.  Ειδικότερα, οι φορείς παροχής υπηρεσιών προσβάσεως στο διαδίκτυο (γενικά, οι τηλεφωνικές εταιρίες) παρέχουν στους πελάτες τους τις λεγόμενες «δυναμικές διευθύνσεις IP», προσωρινά, για κάθε σύνδεση στο διαδίκτυο, τις οποίες αλλάζουν επ’ ευκαιρία επόμενων συνδέσεων. Οι εν λόγω εταιρίες τηρούν μητρώο στο οποίο καταγράφεται η διεύθυνση IP την οποία αντιστοιχούν, ανά πάσα στιγμή, σε συγκεκριμένη συσκευή. Οι κάτοχοι των δικτυακών τόπων στους οποίους παρέχεται πρόσβαση μέσω των δυναμικών διευθύνσεων IP συνηθίζουν επίσης να τηρούν μητρώα στα οποία καταγράφονται οι σελίδες που προσπελάστηκαν, η διάρκεια της επισκέψεως και η δυναμική διεύθυνση IP από την οποία πραγματοποιήθηκε η προσπέλαση. Από τεχνική άποψη, τα εν λόγω μητρώα μπορούν να διατηρηθούν χωρίς χρονικούς περιορισμούς μετά το πέρας της συνδέσεως κάθε χρήστη στο διαδίκτυο. Η δυναμική διεύθυνση IP δεν αρκεί από μόνη της για να μπορέσει ο φορέας παροχής των υπηρεσιών να εξακριβώσει την ταυτότητα του χρήστη της σελίδας του στο διαδίκτυο. Εντούτοις, η εξακρίβωση της ταυτότητας είναι εφικτή εάν η δυναμική διεύθυνση IP συνδυαστεί με άλλα πρόσθετα δεδομένα τα οποία διαθέτει ο φορέας παροχής προσβάσεως στο διαδίκτυο. Στη διαφορά της κύριας δίκης αμφισβητείται κατά πόσον οι δυναμικές διευθύνσεις IP αποτελούν δεδομένο προσωπικού χαρακτήρα, κατά το άρθρο 2, στοιχείο α΄, της οδηγίας 95/46/ΕΚ (3). Η απάντηση προϋποθέτει να καθορισθεί προηγουμένως η λυσιτέλεια για τον σκοπό αυτό του γεγονότος ότι τα πρόσθετα δεδομένα που απαιτούνται για την εξακρίβωση της ταυτότητας του χρήστη δεν βρίσκονται στη διάθεση του κατόχου του δικτυακού τόπου, αλλά τρίτου (συγκεκριμένα, του φορέα παροχής της υπηρεσίας προσβάσεως στο διαδίκτυο).


Ειδικότερα τα πραγματικά περιστατικά της υπόθεσης έχουν ως εξής:

Iστορικό: Ο P. Breyer άσκησε κατά της Ομοσπονδιακής Δημοκρατίας της Γερμανίας αγωγή παραλείψεως σχετικά με την αποθήκευση διευθύνσεων IP. Πολλοί δημόσιοι φορείς στη Γερμανία διατηρούν ελεύθερα προσβάσιμες στο κοινό διαδικτυακές πύλες στις οποίες γνωστοποιούν πληροφορίες από την επικαιρότητα. Με σκοπό την αποτροπή επιθέσεων και τη διευκόλυνση της ποινικής διώξεως των επιτιθέμενων καταγράφεται στις περισσότερες από τις πύλες αυτές κάθε πρόσβαση σε αρχεία πρωτοκόλλου. Σε αυτά αποθηκεύονται, ακόμη και μετά τη λήξη της εκάστοτε χρήσεως, το όνομα του αρχείου ή της ιστοσελίδας που τηλεφορτώθηκε, οι έννοιες που αναζητήθηκαν, ο χρόνος της τηλεφορτώσεως, η ποσότητα των δεδομένων που μεταφέρθηκαν, η αναφορά κατά πόσον ήταν επιτυχής η τηλεφόρτωση και η διεύθυνση ΙΡ του υπολογιστή που πραγματοποίησε την πρόσβαση. Ο P. Breyer, ο οποίος επισκέφθηκε διάφορες τέτοιες σελίδες, ζήτησε με την αγωγή του να υποχρεωθεί η Ομοσπονδιακή Δημοκρατία της Γερμανίας να παύσει να αποθηκεύει ή να αναθέτει σε τρίτους να αποθηκεύουν μετά τη λήξη της εκάστοτε χρήσεως τη διεύθυνση ΙΡ του συστήματος υποδοχής («host system») από το οποίο είχε πρόσβαση, εφόσον η αποθήκευση δεν είναι αναγκαία για την αποκατάσταση της διαθεσιμότητας του τηλεμέσου σε περίπτωση βλάβης. 

Η αγωγή του P. Breyer απορρίφθηκε σε πρώτο βαθμό. Εντούτοις, η έφεσή του έγινε εν μέρει δεκτή, και η Ομοσπονδιακή Δημοκρατία της Γερμανίας υποχρεώθηκε να παύσει να αποθηκεύει [διευθύνσεις ΙΡ] μετά τη λήξη της εκάστοτε χρήσεως. Η διαταγή παραλείψεως τελούσε υπό την προϋπόθεση ότι ο ενάγων δηλώνει στο πλαίσιο της χρήσεως τα προσωπικά του στοιχεία, ακόμη και με τη μορφή διευθύνσεως ηλεκτρονικού ταχυδρομείου, και ότι η αποθήκευση δεν είναι αναγκαία για την αποκατάσταση της διαθεσιμότητας του τηλεμέσου.

Κατόπιν ασκήσεως αναιρέσεως από αμφοτέρους τους διαδίκους, το τμήμα VI του Bundesgerichtshof (Ανώτατο Αστικό και Ποινικό Δικαστήριο, Γερμανία) υπέβαλε τα ακόλουθα προδικαστικά ερωτήματα:


1)      Πρέπει το άρθρο 2, στοιχείο α΄, της οδηγίας 95/46/ΕΚ […] να ερμηνευθεί υπό την έννοια ότι η διεύθυνση πρωτοκόλλου του διαδικτύου (ΙΡ) την οποία αποθηκεύει φορέας παροχής υπηρεσιών στο πλαίσιο προσβάσεως στην ιστοσελίδα του αποτελεί ως προς εκείνον δεδομένο προσωπικού χαρακτήρα σε περίπτωση που τρίτος (εν προκειμένω ο φορέας παροχής υπηρεσιών προσβάσεως στο διαδίκτυο) διαθέτει τα πρόσθετα δεδομένα που απαιτούνται για την εξακρίβωση της ταυτότητας του θιγόμενου προσώπου;
2)      Αντιτίθεται το άρθρο 7, στοιχείο στ΄, της οδηγίας για την προστασία των δεδομένων προσωπικού χαρακτήρα σε εθνική κανονιστική ρύθμιση κατά την οποία ο φορέας παροχής υπηρεσιών δύναται να συλλέγει και να χρησιμοποιεί δεδομένα προσωπικού χαρακτήρα των χρηστών χωρίς τη συναίνεσή τους μόνο προκειμένου, εφόσον τούτο είναι αναγκαίο, να καταστεί δυνατή και να τιμολογηθεί η συγκεκριμένη χρήση του τηλεμέσου από τους εκάστοτε χρήστες, και κατά την οποία ο σκοπός της διασφαλίσεως της γενικής λειτουργικότητας του τηλεμέσου δεν μπορεί να δικαιολογήσει τη χρησιμοποίηση των δεδομένων μετά τη λήξη της εκάστοτε χρήσεως του τηλεμέσου;


Η απάντηση του Γεν. Εισαγγελέα 

Βάσει του άρθρου 2, στοιχείο α΄, της οδηγίας 95/46/ΕΚ του Ευρωπαϊκού Κοινοβουλίου και του Συμβουλίου, της 24ης Οκτωβρίου 1995, για την προστασία των φυσικών προσώπων έναντι της επεξεργασίας δεδομένων προσωπικού χαρακτήρα και για την ελεύθερη κυκλοφορία των δεδομένων αυτών, δυναμική διεύθυνση IP μέσω της οποίας χρήστης απέκτησε πρόσβαση στην ιστοσελίδα φορέα παροχής τηλεμέσων αποτελεί ως προς εκείνον “δεδομένο προσωπικού χαρακτήραˮ, στο μέτρο που φορέας παροχής υπηρεσιών προσβάσεως στο διαδίκτυο διαθέτει πρόσθετα δεδομένα τα οποία, σε συνδυασμό με τη δυναμική διεύθυνση IP, συμβάλλουν στην εξακρίβωση της ταυτότητας του χρήστη.




Το άρθρο 7, στοιχείο στ΄, της οδηγίας 95/46 έχει την έννοια ότι ο σκοπός της διασφαλίσεως της λειτουργικότητας του τηλεμέσου μπορεί, καταρχήν, να θεωρηθεί έννομο συμφέρον, του οποίου η επίτευξη δικαιολογεί την επεξεργασία του συγκεκριμένου δεδομένου προσωπικού χαρακτήρα, με την επιφύλαξη ότι το ως άνω συμφέρον προέχει του συμφέροντος ή των θεμελιωδών δικαιωμάτων και ελευθεριών του θιγόμενου προσώπου. Εθνική διάταξη η οποία δεν επιτρέπει να ληφθεί υπόψη το εν λόγω έννομο συμφέρον δεν συνάδει με το προμνησθέν άρθρο.»



Eιδικά όσον αφορά το ζήτημα του νομικού χαρακτηρισμού των διευθύνσεων ΙΡ, ο Γ. Εισαγγελέας διατυπώνει την κρίση ότι: 

"74. Ως εκ τούτου, φρονώ ότι, όπως αυτό διατυπώνεται από το Bundesgerichtshof, στο πρώτο ερώτημα πρέπει να δοθεί καταφατική απάντηση. Η δυναμική διεύθυνση IP πρέπει να χαρακτηρισθεί, ως προς τον φορέα παροχής υπηρεσιών διαδικτύου, δεδομένο προσωπικού χαρακτήρα λαμβανομένης υπόψη της υπάρξεως τρίτου (του φορέα παροχής προσβάσεως στο διαδίκτυο) στον οποίο μπορεί εύλογα αυτός να απευθυνθεί για να εξασφαλίσει άλλα πρόσθετα δεδομένα τα οποία, σε συνδυασμό με τη διεύθυνση ΙΡ, συμβάλλουν την εξακρίβωση της ταυτότητας ενός χρήστη."


Η αντίθεση λύση θα σήμαινε  ότι ο φορέας παροχής υπηρεσιών διαδικτύου "θα μπορούσε να τις διατηρεί επ’ αόριστον και μπορεί να ζητήσει, ανά πάσα στιγμή, από τον φορέα παροχής προσβάσεως στο διαδίκτυο τα πρόσθετα δεδομένα τα οποία θα συνδυάσει με τη διεύθυνση ΙΡ για να εξακριβώσει την ταυτότητα του χρήστη. Υπό τις συνθήκες αυτές, (....) η δυναμική διεύθυνση IP μετατρέπεται σε δεδομένο προσωπικού χαρακτήρα, οσάκις είναι διαθέσιμα τα έγκυρα πρόσθετα δεδομένα για την εξακρίβωση της ταυτότητας του χρήστη, εφαρμοζόμενης συναφώς της νομοθεσίας περί προστασίας των δεδομένων."


Η θέση αυτή, βεβαίως, έρχεται σε αντίθεση με την απόφαση του High Court της Ιρλανδίας στην υπόθεση Irish High Court in EMI Records & Ors -v-Eircom Ltd (2010), στην οποία έγινε δεκτό ότι οι διευθύνεις ΙΡ που συλλέγονται με σκοπό την ταυτοποίηση των ατόμων για την εφαρμογή της νομοθεσίας για την προστασία της πνευματικής ιδιοκτησίας, δεν είναι προσωπικά δεδομένα. Επίσης, συντάσσεται με την Γνώμη της ομάδας εργασίας του άρθρου 29 που δέχεται ότι οι διευθύνσεις ΙΡ είναι προσωπικά δεδομένα (βλ. http://ec.europa.eu/justice/data-protection/article-29/documentation/opinion-recommendation/files/2009/wp159_en.pdf).




Τετάρτη 20 Απριλίου 2016

ΟΔΗΓΟΣ ΓΙΑ ΤΗ ΣΥΓΓΡΑΦΗ ΟΡΩΝ ΧΡΗΣΗΣ ΙΣΤΟΧΩΡΟΥ (ΤERMS OF USE) & ΠΡΟΣΤΑΣΙΑΣ ΠΡΟΣΩΠΙΚΩΝ ΔΕΔΟΜΕΝΩΝ


Η δημιουργία ενός δικτυακού τόπου παρέχει πολλά πλεονεκτήματα σε έναν επαγγελματία και σε μια επιχείρηση που μπορούν, έτσι, να διευρύνουν τον κύκλο της πελατείας τους. Ωστόσο, πρέπει να γίνει σαφές ότι η παρουσία στο Διαδίκτυο ρυθμίζεται από κανόνες και μπορεί να συνεπάγεται ευθύνη του παρέχοντος υπηρεσίες. Οι χρήστες, ιδίως, μπορεί να ανησυχούν για την προστασία και την ασφάλεια των προσωπικών τους δεδομένων. Για αυτό είναι βασικό, σε κάθε ιστοχώρο να υπάρχουν διαμορφωμένοι όροι χρήσης και όροι προστασίας προσωπικών δεδομένων.

Βλ. περισσότερα εδώ 

Παρασκευή 15 Απριλίου 2016

The European Parliament adopts the Data Protection Reform Package

Press release - Brussels, 21 December 2015
Stronger data protection rules for Europe: the EU adopts the data protection reform package
The European Parliament and Council have reached agreement on the data protection reform proposed by the Commission. The reform is an essential step to strengthen citizens' fundamental rights in the digital age and facilitate business by simplifying rules for companies in the Digital Single Market.
The data protection reform package includes the General Data Protection Regulation ("Regulation") and the Data Protection Directive for the police and criminal justice sector.
Why did the Commission propose a reform of EU data protection rules? 
EU legislation on data protection has been in place since 1995. The Data Protection Directive guarantees an effective protection of the fundamental right to data protection. But differences in the way that each Member State implements the law have led to inconsistencies, which create complexity, legal uncertainty and administrative costs. This affects the trust and confidence of individuals and the competitiveness of the EU economy. The current rules also need modernising – they were introduced at a time when many of today's online services and the challenges they bring for data protection did not yet exist. With social networking sites, cloud computing, location-based services and smart cards, processing of personal data has grown exponentially. We need a robust set of rules to make sure people's right to personal data protection – recognised by Article 8 of the EU's Charter of Fundamental Rights – remains effective in the digital age.This will at the same time be beneficial for the development of the digital economy.  
What will change under the Regulation?
The Regulation updates and modernises the principles enshrined in the 1995 Data Protection Directive to guarantee privacy rights. It focuses on: reinforcing individuals' rights, strengthening the EU internal market, ensuring stronger enforcement of the rules, streamlining international transfers of personal data and setting global data protection standards. 
The changes will give people more control over their personal data and make it easier to access it. They are designed to make sure that people's personal information is protected – no matter where it is sent, processed or stored – even outside the EU, as may often be the case on the internet. 
What are the benefits for citizens? 
The reform provides tools for gaining control of one's personal data, the protection of which is a fundamental right in the European Union.
The data protection reform will strengthen citizens' rights and build trust. Nine out of ten Europeans have expressed concern about mobile apps collecting their data without their consent, and seven out of ten worry about the potential use that companies may make of the information disclosed.
The new rules address these concerns through:
  • A "right to be forgotten": When an individual no longer wants her/his data to be processed, and provided that there are no legitimate grounds for retaining it, the data will be deleted. This is about protecting the privacy of individuals, not about erasing past events or restricting freedom of the press.
  • Easier access to one's data: Individuals will have more information on how their data is processed and this information should be available in a clear and understandable way. A right to data portability will make it easier for individuals to transmit personal data between service providers.
  • The right to know when one's data has been hacked: Companies and organisations must notify the national supervisory authority of data breaches which put individuals at risk and communicate to the data subject all high risk breaches as soon as possible so that users can take appropriate measures.
  • Data protection by design and by default: ‘Data protection by design’ and ‘Data protection by default’ are now essential elements in EU data protection rules. Data protection safeguards will be built into products and services from the earliest stage of development, and privacy-friendly default settings will be the norm – for example on social networks or mobile apps.
  • Stronger enforcement of the rules: data protection authorities will be able to fine companies who do not comply with EU rules up to 4% of their global annual turnover.
Right to be forgotten: How will it work?
Already the current Directive gives individuals a possibility to have their data deleted, in particular when the data is no longer necessary.
For example, if an individual has given her or his consent to processing for a specific purpose, e.g. display on a social networking site, and does not want this service anymore, than there is no reason to keep the data in the system. In particular, when children have made data about themselves accessible, often without fully understanding the consequences, they must not be stuck with the consequences of that choice for the rest of their lives.
This does not mean that on each request of an individual all his personal data are to be deleted at once and forever. If for example, the retention of the data is necessary for the performance of a contract or for compliance with a legal obligation, the data can be kept as long as necessary for that purpose.
The proposed provisions on the "right to be forgotten" are very clear: freedom of expression, as well as historical and scientific research are safeguarded.
For example, no politician will be able to have their earlier remarks deleted from the web. This will thus allow, inter alia, news websites to continue operating on the basis of the same principles.
Is there specific protection for children?
Yes, the Regulation recognises that children deserve specific protection of their personal data, as they may be less aware of risks, consequences, safeguards and their rights in relation to the processing of personal data. For instance, they benefit from a clearer right to be forgotten.
When it comes to information society services offered directly to a child, the Regulation foresees that consent for processing the data of a child must be given or authorised by the holder of the parental responsibility over the child. The age threshold is for Member States to define within a range of 13 to 16 years.
The aim of this specific provision aims at protecting children from being pressured to share personal data without fully realising the consequences. It will not to stop teenagers from using the Internet to get information, advice, education etc. Moreover, the Regulation specifies that the consent of the holder of parental responsibility should not be necessary in the context of preventive or counselling services offered directly to a child.
What are the benefits for businesses?
The reform provides clarity and consistency of the rules to be applied, and restores trust of the consumer, thus allowing undertakings to seize fully the opportunities in the Digital Single Market.
Data is the currency of today's digital economy. Collected, analysed and moved across the globe, personal data has acquired enormous economic significance. According to some estimates, the value of European citizens' personal data has the potential to grow to nearly €1 trillion annually by 2020. By strengthening Europe’s high standards of data protection, lawmakers are creating business opportunities.
The data protection reform package helps the Digital Single Market realise this potential through:
  • One continent, one law: a single, pan-European law for data protection, replacing the current inconsistent patchwork of national laws. Companies will deal with one law, not 28. The benefits are estimated at €2.3 billion per year.
  • One-stop-shop: a 'one-stop-shop' for businesses: companies will only have to deal with one single supervisory authority, not 28, making it simpler and cheaper for companies to do business in the EU.
  • The same rules for all companies – regardless of where they are established: Today European companies have to adhere to stricter standards than companies established outside the EU but also doing business in our Single Market. With the reform companies based outside of Europe will have to apply the same rules when they offer goods or services on the EU market. This creates a level playing field.
  • Technological neutrality: the Regulation enables innovation to continue to thrive under the new rules. 
What is the one-stop shop? 
Within a single market for data, identical rules on paper are not enough. The rules must be applied in the same way everywhere. The 'one-stop-shop' will streamline cooperation between the data protection authorities on issues with implications for all of Europe. Companies will only have to deal with one authority, not 28. 
It will ensure legal certainty for businesses. Businesses will profit from faster decisions, from one single interlocutor (eliminating multiple contact points), and from less red tape. They will benefit from consistency of decisions where the same processing activity takes place in several Member States. 
Individuals will have more control. How will that help business? 
The new right to data portability will allow individuals to move their personal data from one service provider to another. Start-ups and smaller companies will be able to access data markets dominated by digital giants and attract more consumers with privacy-friendly solutions. This will make the European economy more competitive.  
Example: Benefits for individuals, benefits for businesses 
A new small company wishes to enter the market offering an online social media sharing website. The market already has big players with a large market share. Under the current rules, each new customer will have to consider starting over again with the personal data they    wish to provide to be established on the new website. This can be a disincentive for some people considering switching to the new business. 
With the Data Protection Reform: The right to data portability will make it easier for potential customers to transfer their personal data between service providers. This allows customers to exercise control over their personal data, and at the same time fosters competition and encourages new businesses in the marketplace.
What are the benefits for SMEs?
The data protection reform is geared towards stimulating economic growth by cutting costs and red tape for European business, also for small and medium enterprises (SMEs).
By having one rule instead of 28, the EU's data protection reform will help SMEs break into new markets. In a number of cases, the obligations of data controllers and processors are calibrated to the size of the business and/or to the nature of the data being processed. For example:
  • SMEs need not appoint a data protection officer unless their core activities require regular and systematic monitoring of the data subjects on a large scale or if they process special categories of personal data such as that revealing racial or ethnic origin or religious beliefs. Moreover, this will not need to be a full-time employee but could be an ad-hoc consultant, and therefore, would be much less costly. 
  • SMEs need not keep records of processing activities unless the processing they carry out is not occasional or likely to result in a risk for the rights and freedoms of data subject.
  • SMEs will not be under an obligation to report all data breaches to individuals, unless the breaches represent a high risk for their rights and freedoms. 
How will the new rules save money? 
The Regulation will establish a single, pan-European law for data protection meaning that companies can simply deal with one law, not 28. The new rules will bring benefits of an estimated €2.3 billion per year. 
Example: Cutting costsA chain of shops has its head office in France and franchised shops in 14 other EU countries. Each shop collects data relating to clients and transfers it to the head office in France for further processing. 
With the current rules: 
France’s data protection laws would apply to the processing done by head office, but individual shops would still have to report to their national data protection authority, to confirm they were processing data in accordance with national laws in the country where they were located. This means the company’s head office would have to consult local lawyers for all its branches to ensure compliance with the law. The total costs arising from reporting requirements in all countries could be over €12,000. 
With the Data Protection Reform: The data protection law across all 14 EU countries will be the same – one European Union – one law. This will eliminate the need to consult with local lawyers to ensure local compliance for the franchised shops. The result is direct cost savings and legal certainty. 
How will the Data Protection Reform encourage innovation and use of big data? 
According to some estimates, the value of European citizens’ personal data could grow to nearly €1 trillion annually by 2020. The new EU rules will offer flexibility to businesses all while protecting individuals' fundamental rights. 
‘Data protection by design and by default’ will become an essential principle. It will incentivise businesses to innovate and develop new ideas, methods, and technologies for security and protection of personal data.Used in conjunction with data protection impact assessments, businesses will have effective tools to create technological and organisational solutions.
The Regulation promotes techniques such as anonymisation (removing personally identifiable information where it is not needed),pseudonymisation (replacing personally identifiable material with artificial identifiers), and encryption (encoding messages so only those authorised can read it) to protect personal data. This will encourage the use of "big data" analytics, which can done using anonymised or pseudonymised data. 
Example: Driverless carsThe driverless cars technology requires important data flows, including the exchange of personal data. Data protection rules go hand in hand with innovative and progressive solutions. For example, in case of a crash, cars equipped with eCall emergency call system can automatically call the nearest emergency centre. This is an example of a workable and efficient solution in line with EU data protection principles. With the new rules, the function of eCall will become easier, simpler and more efficient in terms of data protection.
It is a data protection principle that when personal data is collected for one or more purposes it should not be further processed in a way that is incompatible with the original purposes. This does not prohibit processing for a different purpose or restrict 'raw data' for use in analytics. A key factor in deciding whether a new purpose is incompatible with the original purpose is whether it is fair. Fairness will consider factors such as; the effects on the privacy of individuals (e.g. specific and targeted decisions about identified persons) and whether an individual has a reasonable expectation that their personal data will be used in the new way. So in the example of the driverless cars, raw data can be used to analyse where the most accidents take place and how future accidents could be avoided. It can also be used to analyse traffic flows in order to reduce traffic jams.   
Businesses should be able to anticipate and inform individuals of the potential uses and benefits of big data - even if the exact specifics of the analysis are not yet known. Businesses should also think whether the data can be anonymised for such future processing. This will allow raw data to be retained for big data, while protecting the rights of individuals. 
The new data protection rules provide businesses with opportunities to remove the lack of trust that can affect people's engagement with innovative uses of personal data. Providing individuals with clear, effective information will help build trust in analytics and innovation. The information to be provided is not exactly how the data is to be processed, but the purposes for which it will be processed. 
The apparent complexity of innovated products and big data analytics is not an excuse for failing to seek consent of people where it is required. However, consent is not the only basis for processing. Companies are free to base processing on a contract, on a law or, on, in the absence of other bases, on a "balancing of interests". These 'formal requirements', such as consent, are set out in the rules to provide the necessary control by individuals over their personal data and to provide legal certainty for everyone. The new EU rules will provide flexibility on how to meet those requirements. 
How will the new rules work in practice?
Example: a multinational company with several establishments in EU Member States has an online navigation and mapping system across Europe. This system collects images of all private and public buildings, and may also take pictures of individuals.
With the current rules:The data protection safeguards upon data controllers vary substantially from one Member State to another. In one Member State, the deployment of this service led to a major public and political outcry, and some aspects of it were considered to be unlawful. The company then offered additional guarantees and safeguards to the individuals residing in that Member State after negotiation with the competent DPA, however the company refused to commit to offer the same additional guarantees to individuals in other Member States.
Currently, data controllers operating across borders need to spend time and money (for legal advice, and to prepare the required forms or documents) to comply with different, and sometimes contradictory, obligations.
With the new rules:The new rules will establish a single, pan-European law for data protection, replacing the current inconsistent patchwork of national laws. Any company - regardless of whether it is established in the EU or not - will have to apply EU data protection law should they wish to offer their services in the EU. 
Example: a small advertising company wants to expand its activities from France to Germany.
With the current rules:
Its data processing activities will be subject to a separate set of rules in Germany and the company will have to deal with a new regulator. The costs of obtaining legal advice and adjusting business models in order to enter this new market may be prohibitive. For example, some Member States charge notification fees for processing data.
With the new rules:
The new data protection rules will scrap all notification obligations and the costs associated with these. The aim of the data protection regulation is to remove obstacles to cross-border trade. 
What about the Data Protection Directive for the police and criminal justice sector? 
The Police Directive ensure the protection of personal data of individuals involved in criminal proceedings, be it as witnesses, victims, or suspects. It will also facilitate a smoother exchange of information between Member States' police and judicial authorities, improving cooperation in the fight against terrorism and other serious crime in Europe. It establishes a comprehensive framework to ensure a high level of data protection whilst taking into account the specific nature of the police and criminal justice field. 
How does the Data Protection Directive for the police and criminal justice sector impact law enforcement operations? 
Law enforcement authorities will be able to exchange data more efficiently and effectively. By further harmonising the 28 different national legislations, the common rules on data protection will enable law enforcement and judicial authorities to cooperate more effectively and more rapidly with each other by facilitating the exchange of personal data necessary to prevent crime under conditions of legal certainty, fully in line with the Charter of Fundamental Rights. 
Criminal law enforcement authorities will no longer have to apply different sets of data protection rules according to the origin of the personal data, saving time and money. The new rules will apply to both domestic processing and cross-border transfers of personal data. Having more harmonised laws in all EU Member States will make it easier for our police forces to work together. The rules in the Directive take account of the specific needs of criminal law enforcement and respect the different legal traditions in Member States.
How does the Directive affect citizens?
 
Individuals' personal data will be better protected.The Directive protects citizens' fundamental right to data protection when data is used by criminal law enforcement authorities. Everyone’s personal data should be processed lawfully, fairly, and only for a specific purpose. All law enforcement processing in the Union must comply with the principles of necessity, proportionality and legality, with appropriate safeguards for the individuals. Supervision is ensured by independent national data protection authorities and effective judicial remedies must be provided. 
The Directive also provides clear rules for the transfer of personal data by criminal law enforcement authorities outside the EU, to ensure that these transfers take place with an adequate level of data protection. The directive provides robust rules on personal data exchanges at national, European and international level. 
How does the Directive affect the work of criminal law enforcement? 
Having the same law in all EU Member States will make it easier for our criminal law enforcement authorities to work together in exchanging information. This will increase the efficiency of criminal law enforcement and thus create conditions for more effective crime prevention. 
This is also why the Data Protection Directive is considered a key element of the development of the EU's area of freedom, security and justice and a building block of the EU Agenda on Security. 
The Directive replaces Framework Decision 2008/977/JHA which previously governed data processing by police and judicial authorities. 
The entry into force of the Lisbon Treaty and, in particular, the introduction of a new legal basis (Article 16 TFEU) allow the establishment of a comprehensive data protection framework in the area of police and judicial cooperation in criminal matters. The new framework will cover both cross-border and domestic processing of personal data.
When will the new laws apply? 
The Regulation shall apply 2 years after its formal adoption by the European Parliament and Council. The Commission will work together with the Member States and the Data protection authorities – the future European Data Protection Board- to ensure a uniform application of the new rules. 
The Police Directive provides for a two-year implementation period. Member States are under an obligation to update their legal frameworks during this time. 

Παρασκευή 18 Μαρτίου 2016

Κύρωση της Σύμβασης για το έγκλημα στον Κυβερνοχώρο και του Προσθέτου Πρωτοκόλλου της – Μεταφορά της Οδηγίας 2013/40/ΕΕ

Μετά από πολυετή αδράνεια της Ελληνικής Πολιτείας, πρόκειται σύντομα να ψηφισθεί νόμος για την κύρωση της Σύμβασης για το Κυβερνοέγκλημα, αλλά και για τη μεταφορά της οδηγίας 2013/40/Ε για τις επιθέσεις κατά συστημάτων πληροφοριών.

Ειδικότερα, η ανακοίνωση του Υπουργού Δικαιοσύνης έχει ως εξής:

Τίθεται από σήμερα σε δημόσια διαβούλευση η νομοθετική πρωτοβουλία του Υπουργείου Δικαιοσύνης, Διαφάνειας και Ανθρωπίνων Δικαιωμάτων, υπό τον τίτλο: «Κύρωση της Σύμβασης του Συμβουλίου της Ευρώπης για το έγκλημα στον Κυβερνοχώρο και του Προσθέτου Πρωτοκόλλου της, σχετικά με την ποινικοποίηση πράξεων ρατσιστικής και ξενοφοβικής φύσης, που διαπράττονται μέσω Συστημάτων Υπολογιστών, καθώς και μεταφορά στο ελληνικό δίκαιο της οδηγίας 2013/40/ΕΕ του Ευρωπαϊκού Κοινοβουλίου και του Συμβουλίου της Ευρώπης για τις επιθέσεις κατά συστημάτων πληροφοριών και την αντικατάσταση της απόφασης – πλαισίου 2005/222/ΔΕΥ του Συμβουλίου και άλλες διατάξεις».
Δεδομένης της σπουδαιότητας της συγκεκριμένης πρωτοβουλίας, σας καλώ να συμμετάσχετε στη δημόσια ηλεκτρονική διαβούλευση, διατυπώνοντας τις απόψεις και τις παρατηρήσεις σας στις σχετικές ρυθμίσεις. Η διαβούλευση θα ολοκληρωθεί τη Δευτέρα, 28 Μαρτίου 2016 και ώρα 14:00.
Νικόλαος Παρασκευόπουλος
Υπουργός Δικαιοσύνης, Διαφάνειας και Ανθρωπίνων Δικαιωμάτων


Δείτε εδώ το σχέδιο νόμου:
http://www.opengov.gr/ministryofjustice/wp-content/uploads/downloads/2016/03/2016_03_16_Sxedio_Nomou_Min_Justice.pdf 


Και επίσης, τη διαβούλευση:

Τετάρτη 16 Μαρτίου 2016

Επιτηδευματίας που θέτει δωρεάν στη διάθεση του κοινού ένα ασύρματο τοπικό δίκτυο με πρόσβαση στο Διαδίκτυο


ΠΡΟΤΑΣΕΙΣ ΤΟΥ ΓΕΝΙΚΟΥ ΕΙΣΑΓΓΕΛΕΑ MACIEJ SZPUNAR της 16ης Μαρτίου 2016  Υπόθεση C‑484/14 Tobias Mc Fadden κατά Sony Music Entertainment Germany GmbH 
[αίτηση του Landgericht München I (Γερμανία) για την έκδοση προδικαστικής αποφάσεως]



Δημοσιεύθηκαν οι προτάσεις του Γεν. Εισαγγελέα του ΔΕΕ στην ως άνω υπόθεση, η οποία αφορά προδικαστική παραπομπή με την οποία ζητείται η έκδοση απόφασης που αφορά στο ζήτημα της ευθύνης του ιδιοκτήτη διαδικτυακής σύνδεσης που διατηρεί σε λειτουργία μέσω ασύρματου δικτύου (Wi-Fi). Μέσω αυτής της συνδέσεως, στις 4 Σεπτεμβρίου 2010, ένα μουσικό έργο προσφέρθηκε παράνομα προς τηλεφόρτωση. Η Sony Music, η οποία είναι παραγωγός φορέων ηχητικής εγγραφής και κάτοχος δικαιωμάτων επί του έργου αυτού, με έγγραφο της προέβη σε όχληση του ως άνω προσώπου για την προσβολή των δικαιωμάτων της. Ο εναγόμενος υποστήριξε, μεταξύ άλλων, ότι αποκλείεται η ευθύνη του δυνάμει των διατάξεων του γερμανικού δικαίου που μεταφέρουν στην εθνική έννομη τάξη το άρθρο 12, παράγραφος 1, της οδηγίας 2000/31. Ωστόσο, το αιτούν δικαστήριο εκθέτει ότι κλίνει προς την εφαρμογή κατ’ αναλογία της αποφάσεως του Bundesgerichtshof της 12ης Μαΐου 2010, Sommer unseres Lebens (I ZR 121/08), εκτιμώντας ότι η απόφαση αυτή, που αφορά ιδιώτες, ισχύει κατά μείζονα λόγο στην περίπτωση ενός επιτηδευματία ο οποίος διατηρεί σε λειτουργία ένα δίκτυο Wi‑Fi ανοικτό στο κοινό.


Τα βασικά ερωτήματα που τέθηκαν ήταν: παρέχει επιτηδευματίας, ο οποίος, στο πλαίσιο των δραστηριοτήτων του, διατηρεί σε λειτουργία ένα ασύρματο τοπικό δίκτυο με πρόσβαση στο Διαδίκτυο (στο εξής: δίκτυο Wi‑Fi), ανοικτό στο κοινό και δωρεάν, υπηρεσία της κοινωνίας της πληροφορίας κατά την έννοια της οδηγίας 2000/31/ΕΚ; Κατά πόσον περιορίζεται η ευθύνη του λόγω των προσβολών του δικαιώματος του δημιουργού εκ μέρους τρίτων χρηστών; Μπορεί ένα τέτοιο πρόσωπο που διατηρεί σε λειτουργία ένα δημόσιο δίκτυο Wi‑Fi να εξαναγκασθεί, μέσω διαταγής, να προστατεύει την πρόσβαση στο δίκτυό του με κωδικό προσβάσεως;


Καταρχήν, ο Γεν. Εισαγγελέας αναφέρει ότι τα άρθρα 2, στοιχεία αʹ, και βʹ, και 12, παράγραφος 1, της οδηγίας 2000/31 έχουν την έννοια ότι έχουν εφαρμογή σε πρόσωπο το οποίο, παρεπομένως σε σχέση με την κύρια οικονομική του δραστηριότητα, διατηρεί σε λειτουργία ένα δίκτυο Wi‑Fi με σύνδεση στο Διαδίκτυο, ανοικτό στο κοινό και δωρεάν.


Στη συνέχεια, κρίνει ότι το άρθρο 12, παράγραφοι 1 και 3, της οδηγίας 2000/31 αντιτίθεται στην καταδίκη ενός ενδιάμεσου φορέα παροχής υπηρεσιών απλής μεταδόσεως συνεπεία οποιουδήποτε αιτήματος που συνεπάγεται τη διαπίστωση αστικής ευθύνης του. Το άρθρο αυτό αντιτίθεται επομένως όχι μόνο στην επιβολή υποχρεώσεως αποζημιώσεως στον ενδιάμεσο φορέα παροχής υπηρεσιών, αλλά και στην καταδίκη του στα έξοδα οχλήσεως και στα δικαστικά έξοδα σε σχέση με την προσβολή του δικαιώματος του δημιουργού εκ μέρους τρίτου λόγω των διαβιβαζόμενων πληροφοριών. Το ίδιο άρθρο δεν αντιτίθεται στην έκδοση διαταγής επ’ απειλή χρηματικής ποινής.


Στη συνέχεια, εξετάζει το ζήτημα αν τα τρία μέτρα που μνημονεύονται στο ένατο ερώτημα, υπό βʹ, ήτοι η διακοπή της διαδικτυακής συνδέσεως, η προστασία της με κωδικό προσβάσεως ή ο έλεγχος κάθε επικοινωνίας που διεξάγεται μέσω αυτής, μπορούν να είναι συμβατά προς την οδηγία 2000/31. Ο Γεν. Εισαγγελέας θεωρεί ότι μέτρο που διατάσσει τη διακοπή λειτουργίας της διαδικτυακής συνδέσεως προδήλως δεν συμβιβάζεται με την απαίτηση δίκαιης εξισορροπήσεως των θεμελιωδών δικαιωμάτων, εφόσον θίγει το ουσιώδες περιεχόμενο του δικαιώματος της επιχειρηματικής ελευθερίας του προσώπου το οποίο, έστω και παρεπομένως, ασκεί οικονομική δραστηριότητα που συνίσταται στην παροχή προσβάσεως στο Διαδίκτυο. Ένα τέτοιο μέτρο θα ήταν αντίθετο προς το άρθρο 3 της οδηγίας 2004/48, δυνάμει του οποίου το δικαστήριο που εκδίδει τη διαταγή οφείλει να μεριμνά ώστε τα προσδιοριζόμενα μέτρα να μη παρακωλύουν το νόμιμο εμπόριο.


Όσον αφορά το μέτρο που υποχρεώνει τον ιδιοκτήτη της διαδικτυακής συνδέσεως να ελέγχει όλες τις επικοινωνίες που διεξάγονται μέσω αυτής, αυτό θα προσέκρουε προφανώς στην απαγόρευση γενικής υποχρεώσεως ελέγχου, που προβλέπεται στο άρθρο 15, παράγραφος 1, της οδηγίας 2000/31.


Όσον αφορά δε την προστασία της πρόσβασης σε ασύρματο δίκτυο, έχει τη γνώμη ότι η επιβολή υποχρεώσεως προστασίας της προσβάσεως στο δίκτυο Wi‑Fi, ως μέθοδος προστασίας του δικαιώματος του δημιουργού στο πλαίσιο του Διαδικτύου, δεν θα τηρούσε την απαίτηση δίκαιης ισορροπίας μεταξύ, αφενός, της προστασίας του δικαιώματος διανοητικής ιδιοκτησίας, της οποίας απολαύουν οι κάτοχοι του δικαιώματος του δημιουργού, και, αφετέρου, της προστασίας της επιχειρηματικής ελευθερίας η οποία ισχύει για τους φορείς παροχής των σχετικών υπηρεσιών. Περιορισμός της προσβάσεως σε νόμιμες επικοινωνίες θα συνεπαγόταν επιπλέον περιορισμό της ελευθερίας εκφράσεως και πληροφορήσεως. Υπό γενικότερο πρίσμα, η ενδεχόμενη γενίκευση της υποχρεώσεως προστασίας των δικτύων Wi‑Fi, ως μέθοδος προστασίας του δικαιώματος του δημιουργού εντός του Διαδικτύου, θα ήταν ικανή να επιφέρει ένα μειονέκτημα για όλη την κοινωνία, που θα εγκυμονούσε τον κίνδυνο να υπερβαίνει το ενδεχόμενο όφελός της για τους κατόχους αυτών των δικαιωμάτων. Αφενός, τα δημόσια δίκτυα Wi‑Fi που χρησιμοποιούνται από μεγάλο αριθμό ατόμων έχουν σχετικώς περιορισμένο εύρος ζώνης και, επομένως, δεν είναι πολύ εκτεθειμένα στις προσβολές των έργων και των αντικειμένων που προστατεύονται από το δικαίωμα του δημιουργού. Αφετέρου, τα σημεία προσβάσεως Wi‑Fi εμφανίζουν αναμφισβήτητα σημαντικό δυναμικό για την καινοτομία. Κάθε μέτρο που εγκυμονεί τον κίνδυνο να ανακόψει την εξέλιξη αυτής της δραστηριότητας πρέπει επομένως να εξετάζεται επιμελώς σε σχέση με το ενδεχόμενο όφελός του.


Καταλήγοντας, η πρόταση του Γεν. Εισαγγελέα είναι η εξής:

1) Τα άρθρα 2, στοιχεία αʹ και βʹ, και 12, παράγραφος 1, της οδηγίας 2000/31/ΕΚ του Ευρωπαϊκού Κοινοβουλίου και του Συμβουλίου, της 8ης Ιουνίου 2000, για ορισμένες νομικές πτυχές των υπηρεσιών της κοινωνίας της πληροφορίας, ιδίως του ηλεκτρονικού εμπορίου, στην εσωτερική αγορά (οδηγία για το ηλεκτρονικό εμπόριο), έχουν την έννοια ότι έχουν εφαρμογή σε κάθε πρόσωπο, το οποίο, παρεπομένως σε σχέση με την κύρια οικονομική του δραστηριότητα, διατηρεί σε λειτουργία ένα ασύρματο τοπικό δίκτυο Wi‑Fi με σύνδεση στο Διαδίκτυο, ανοικτό στο κοινό και δωρεάν.

2) Το άρθρο 12, παράγραφος 1, της οδηγίας 2000/31 αντιτίθεται στην καταδίκη ενός ενδιάμεσου φορέα παροχής υπηρεσιών απλής μεταδόσεως συνεπεία οποιουδήποτε αιτήματος που συνεπάγεται τη διαπίστωση αστικής ευθύνης του. Το άρθρο αυτό αντιτίθεται επομένως όχι μόνο στην επιβολή υποχρεώσεως αποζημιώσεως στον φορέα παροχής τέτοιων υπηρεσιών, αλλά και στην καταδίκη του στα έξοδα οχλήσεως και στα δικαστικά έξοδα σε σχέση με την προσβολή του δικαιώματος του δημιουργού εκ μέρους τρίτου λόγω των διαβιβαζόμενων πληροφοριών.

3) Το άρθρο 12, παράγραφοι 1 και 3, της οδηγίας 2000/31 δεν αντιτίθεται στην έκδοση διαταγής δικαστηρίου, συνοδευόμενης με απειλή χρηματικής ποινής.

Κάθε εθνικό δικαστήριο, όταν εκδίδει μια τέτοια διαταγή, οφείλει να βεβαιώνεται:

– ότι τα οικεία μέτρα συνάδουν προς το άρθρο 3 της οδηγίας 2004/48/ΕΚ του Ευρωπαϊκού Κοινοβουλίου και του Συμβουλίου, της 29ης Απριλίου 2004, σχετικά με την επιβολή των δικαιωμάτων διανοητικής ιδιοκτησίας, και, μεταξύ άλλων, ότι είναι αποτελεσματικά, σύμφωνα με την αρχή της αναλογικότητας και αποτρεπτικού χαρακτήρα·

– ότι σκοπό έχουν την παύση συγκεκριμένης προσβολής δικαιώματος ή την πρόληψή της και δεν συνεπάγονται γενική υποχρέωση ελέγχου, σύμφωνα με τα άρθρα 12, παράγραφος 3, και 15, παράγραφος 1, της οδηγίας 2000/31, και

– ότι η εφαρμογή των διατάξεων αυτών, καθώς και άλλων λεπτομερειών που προβλέπονται δυνάμει του εθνικού δικαίου, εξασφαλίζει δίκαιη ισορροπία μεταξύ των εφαρμοστέων εν προκειμένω θεμελιωδών δικαιωμάτων, ειδικότερα δε των προστατευόμενων, αφενός, από τα άρθρα 11 και 16 του Χάρτη των Θεμελιωδών Δικαιωμάτων της Ευρωπαϊκής Ένωσης καθώς και, αφετέρου, από το άρθρο 17, παράγραφος 2, αυτού.

4) Τα άρθρα 12, παράγραφος 3, και 15, παράγραφος 1, της οδηγίας 2000/31, ερμηνευόμενα υπό το πρίσμα των απαιτήσεων που απορρέουν από την προστασία των εφαρμοστέων θεμελιωδών δικαιωμάτων, δεν αντιτίθενται, κατ’ αρχήν, στην έκδοση διαταγής που αφήνει στον αποδέκτη της την επιλογή των συγκεκριμένων προς λήψη μέτρων. Εναπόκειται παρά ταύτα στον επιληφθέντα αιτήσεως εκδόσεως διαταγής εθνικό δικαστή να βεβαιωθεί για την ύπαρξη κατάλληλων μέτρων, σύμφωνα με τους περιορισμούς που απορρέουν από το ενωσιακό δίκαιο.

Οι εν λόγω διατάξεις αντιτίθενται στην έκδοση διαταγής που απευθύνεται σε διατηρούντα σε λειτουργία ασύρματο τοπικό δίκτυο Wi‑Fi με σύνδεση στο Διαδίκτυο, ανοικτό στο κοινό και δωρεάν, παρεπομένως σε σχέση με την κύρια οικονομική του δραστηριότητα, όταν ο αποδέκτης της διαταγής δεν μπορεί να συμμορφωθεί προς αυτή παρά μόνο:

– διακόπτοντας τη διαδικτυακή σύνδεση, ή

– προστατεύοντάς τη με κωδικό προσβάσεως, ή

– ελέγχοντας κάθε επικοινωνία που διεξάγεται μέσω αυτής ως προς το αν το συγκεκριμένο έργο που προστατεύεται από το δικαίωμα του δημιουργού μεταδίδεται εκ νέου παρανόμως.