Σάββατο 7 Νοεμβρίου 2015

Hate Speech on the Internet


Ioannis Iglezakis
Associate Professor, Faculty of Law, Aristotle University of Thessaloniki

Paper presented in the REDA Conference, Cyprus, 5-6/11/2015



Introduction

As is well known, the Internet is a decentralized international network of computer networks not owned by any government or private organization. Because of its particular characteristics, it is often depicted as a specific domain, called the ’Cyberspace’, which has no territorially-based boundaries and rises above the restrictions of national legislation. It is also praised as ‘the largest experiment in anarchy that we have ever had’ and as a network, in which ‘nobody knows if you’re a dog’.

The Internet is also a means of communication that allows the spreading of free expression globally and for that it is supported that it promotes a democratic culture. However, there is a tension between free expression and hate speech being disseminated on the Internet. In more particular, the anonymity and ability of communication of one-to-many and many-to-many has made it an ideal instrument for the widespreading of hate speech by extremists and hatemongers.

Thus, the Internet has become the ‘new frontier’ for spreading hate; it allows extremists and haters easier access to an expectedly big audience, which consists in a high degree of young and gullible persons. The Simon Wiesenthal Center’s Digital Hate and Terrorism project reported in 2011 that there existed over 14,000 problematic websites, forums, blogs and social media postings. Hate groups also exploit the Web 2.0 and gave developed their own sites such as New Saxon, “a Social Networking site for white singles” produced by the American Neo-Nazi group National Socialist Movement. Extremists are also represented on Facebook, so, e.g., Stormfront, National Socialist Life, Libertarian National Social Movement, Aryan Guard, FARC, Al Shabab Mujahideen, Hamas, Hezbollah, etc. Furthermore, Twitter is used as an online marketing tool for extremists, despite its efforts to remove terror postings, while online terrorist magazines proliferate in many languages.

Greece was also affected by the surge in hate speech, particularly in the time of economic crisis. It has been documented in a Report drafted by the European Commission against Racism and Intolerance for Greece in 2014, that speech attacking immigrants, Muslims, Roma, Jews, as well as homosexual and transgender persons is widespread in the mass media and on the Internet, particularly due to the lack of self-regulation mechanisms.

Tο respond to the wave of online hate, many countries and international organizations have enacted legislation, providing for criminal sanctions against such practices. The only exception is United States, which have a long constitutional tradition of protection of freedom of expression and the introduction of criminal sanctions against speech would violate this right. In my presentation, I will examine the peculiarities of regulating hate speech on the Internet on international level and, in more particular, its conflict with the right to freedom of expression.



Definition of Hate Speech

The definition of the term "hate speech" can be found in various international legal texts. In more particular, according to the Committee of Ministers of the Council of Europe, it covers all forms of expression which spread, incite, promote or justify racial hatred, xenophobia, anti-Semitism or other forms of hatred based on intolerance, including: intolerance expressed by aggressive nationalism and ethnocentrism, discrimination and hostility against minorities, migrants and people of immigrant origin.

This term is defined by the European Court of Human Rights, which refers to hate speech as covering all forms of expression which spread, incite, promote or justify hatred based on intolerance (including religious intolerance).

Greek law adopts a more comprehensive approach; Law 4285/2014 mentions acts or actions, which may provoke discrimination, hate or violence against a person or a group of persons, determined on the basis of race, color, religion, descent, national or ethnic origin, sexual orientation, gender identity or disability (Article 1 (1) and 2 (1)).



The international and EU legal framework against hate speech on the Internet

The Council of Europe introduced the Convention on Cybercrime in 2001, which is a milestone in this area and was signed by USA, also. Any provisions on cyber hate were excluded from the Convention, since USA would not accept them and so, the Council of Europe adopted the Additional Protocol to the Convention on Cybercrime concerning the criminalisation of acts of a racist and xenophobic nature committed through computer systems.

This protocol complements the provisions of the Convention and is a point of reference as regards the criminalization of online hate, as it is the first international legal act in this field.
In particular, it provides in Article 3 that each contracting Party shall adopt such legislative and other measures as may be necessary to establish as criminal offences under its domestic law, when committed intentionally and without right, the following conduct: distributing, or otherwise making available, racist and xenophobic material to the public through a computer system”.

Notably, "racist and xenophobic material" means, in accordance with Article 2 (1), any written material, any image or any other representation of ideas or theories, which advocates, promotes or incites hatred, discrimination or violence, against any individual or group of individuals, based on race, colour, descent or national or ethnic origin, as well as religion if used as a pretext for any of these factors. This definition differs from other international legal texts, such as the 12th protocol to the ECHR and the UN International Convention on the Elimination of All Forms of Racial Discrimination. The reason is that the additional protocol has a specific field of application and requires different treatment.

The Protocol provides in Art. 4 that each Party shall adopt such legislative and other measures as may be necessary to establish as criminal offences under its domestic law, when committed intentionally and without right, the following conduct: threatening, through a computer system, with the commission of a serious criminal offence as defined under its domestic law, (i) persons for the reason that they belong to a group, distinguished by race, colour, descent or national or ethnic origin, as well as religion, if used as a pretext for any of these factors, or (ii) a group of persons which is distinguished by any of these characteristics.

Furthermore, Art. 5 provides that each Party shall adopt such legislative and other measures as may be necessary to establish as criminal offences under its domestic law, when committed intentionally and without right, the following conduct: insulting publicly, through a computer system, (i) persons for the reason that they belong to a group distinguished by race, colour, descent or national or ethnic origin, as well as religion, if used as a pretext for any of these factors; or (ii) a group of persons which is distinguished by any of these characteristics.

And finally, it provides in Art. 6 that each Party shall adopt such legislative measures as may be necessary to establish the following conduct as criminal offences under its domestic law, when committed intentionally and without right: distributing or otherwise making available, through a computer system to the public, material which denies, grossly minimises, approves or justifies acts constituting genocide or crimes against humanity, as defined by international law and recognised as such by final and binding decisions of the International Military Tribunal, established by the London Agreement of 8 August 1945, or of any other international court established by relevant international instruments and whose jurisdiction is recognised by that Party.

The protocol intends only minimum harmonization of national law and so, it provides in Articles 3, 5 and 6 that any Party may reserve the right not to apply, in whole or in part, these provisions, or that it may require additional elements for the fulfilment of the offence. Reservations and declarations made by a Party to the Convention on Cybercrime may also apply to this Protocol (Art. 12 (1)).

The EU is also active in this field. The EU Council, namely, adopted the Joint Action of 15 July 1996 concerning action to combat and xenophobia (96/443/JHA), which provides that EU Member States must ensure an effective judicial cooperation and, if necessary, for that purpose, take steps to punish as criminal offence:
  • public incitement to discrimination, violence or racial violence or racial hatred in respect of a group of persons or a member of such a group defined by reference to colour, race, religion or national or ethnic origin;
  • public condoning, for a racist or xenophobic purpose, of crimes against humanity and human rights violations;
  • public denial of the crimes defined in Article 6 of the Charter of the International Military Tribunal appended to the London Agreement of 8 April 1945 insofar as it includes behaviour which is contemptuous of, or degrading to, a group of persons defined by reference to colour, race, religion or national or ethnic origin;
  • public dissemination or distribution of tracts, pictures or other material containing expressions of racism and xenophobia;
  • participation in the activities of groups, organisations or associations, which involve discrimination, violence, or racial, ethnic or religious hatred.

It also adopted the Council Framework Decision 2008/913/JHA on combating certain forms and expressions of racism and xenophobia by means of criminal law. This provides that EU Member States shall take the necessary measures to ensure the criminalization of the following acts:

(a) publicly inciting to violence or hatred directed against a group of persons or a member of such a group defined by reference to race, colour, religion, descent or national or ethnic origin;
(b) the commission of an act referred to in point (a) by public dissemination or distribution of tracts, pictures or other material;
(c) publicly condoning, denying or grossly trivialising crimes of genocide, crimes against humanity and war crimes as defined in Articles 6, 7 and 8 of the Statute of the International Criminal Court, directed against a group of persons or a member of such a group defined by reference to race, colour, religion, descent or national or ethnic origin when the conduct is carried out in a manner likely to incite to violence or hatred against such a group or a member of such a group;
(d) publicly condoning, denying or grossly trivialising the crimes defined in Article 6 of the Charter of the International Military Tribunal appended to the London Agreement of 8 August 1945, directed against a group of persons or a member of such a group defined by reference to race, colour, religion, descent or national or ethnic origin when the conduct is carried out in a manner likely to incite to violence or hatred against such a group or a member of such a group.

However, Member States are given the discretion to publish only conduct which is either carried out in a manner likely to disturb public order or which is threatening, abusive or insulting (Artile 1 (2)); and also, the Member States may opt to make punishable the act of denying or grossly trivialising the crimes referred to in paragraph 1(c) and/or (d) only if the crimes referred to in these paragraphs have been established by a final decision of a national court of this Member State and/or an international court, or by a final decision of an international court only (Article 1 (3)).

Both legal acts are not referring specifically to the Internet, as the Additional protocol to the Convention on Cybercrime, but they find application to acts committed in the online environment.


The conflict with constitutional rights

It is certain that the punishing of online hate speech is conflicting with the right to freedom of expression, which is enshrined in Article 10 (1) ECHR and other international acts, such as Article 11 (1) of the EU Charter of Fundamental Rights, Article 19 (20 of the International Covenant for Civil and Political Rights and Article 19 (2) of the Universal Declaration of human Rights. However, the exercise of this right can be restricted, such as when online hate speech is subjected to criminal sanctions.

The ECHR has stated in its decision of Gündüz v. Turkey that it may be considered necessary in certain democratic societies to sanction or even prevent all forms of expression which spread, incite, promote or justify hatred based on intolerance, including religious intolerance, provided that any “formalities”, “conditions”, “restrictions” or “penalties” imposed are proportionate to the legitimate aim pursued. The Court also noted in another case that there can be no doubt that concrete expressions constituting hate speech, which may be insulting to particular individuals or groups, are not protected by Article 10 of the Convention.

The importance of the Internet as a means to promote freedom of speech is recognized in ECHR’s case-law and in more particular, in the case Ahmet Yildirim v. Turkey. In this judgement, the Court held that the blocking of access to all Google Sites, which took place in order to restrict access to a particular web page that published content that insulted the memory of Atatürk, the founder of modern Turkey, which had the effect of also blocking access to the applicant’s website, constituted a breach of Article 10 f the Convention. The Court considered that the impugned measure amounted to “interference by public authority” with the applicant’s right to freedom of expression, of which the freedom to receive and impart information and ideas is an integral part. Such interference did not satisfy the requirement of ‘foreseeability’ and did not afford the applicant the degree of protection to which he was entitled by the rule of law in a democratic society.

In this decision, the Court highlights that the Internet has become one of the principal means by which individuals exercise their right to freedom of expression and information, providing as it does essential tools for participation in activities and discussions concerning political issues and issues of general interest. This means also that the dissemination of racial and hate speech through the Internet is far more effective than though traditional means. So, e.g., in the case of Willem v. France, a mayor in a French city was sentenced by a criminal court to a fine for announcing the boycott of Israeli products, to protest the anti-Palestinian policies of the Israeli Government. The mayor was prosecuted for incitement to discrimination on national, racial and religious grounds. The ECHR found no violation of his right to freedom of expression, since his prosecution and conviction had not been of his political opinions, but for calling on the municipal authorities to engage in act of discrimination. The Court noted that the announcement of the boycott was not only made orally at the council but it was also posted on the website of the municipality and thus, the discriminatory nature of the mayor’s decision was exacerbated.

In another case, an Internet publication was also given an important role. The case concerned the prohibition of the poster of the Raelian Movement, in which its website was mentioned. Τhe Court examined whether it was appropriate for the purposes of examining the necessity of the disputed measure to take into consideration, as the domestic courts did, the content of the Raelian Movement’s website, whose address was indicated on the poster in question. In the Court’s decision it is mentioned that:

Having regard to the principle that the Convention and its Protocols must be interpreted in the light of present-day conditions (see Tyrer v. the United Kingdom, 25 April 1978, § 31, Series A no. 26, and Vo v. France [GC], no.53924/00, § 82, ECHR 2004‑VIII), the Chamber took the view that the website did have to be considered because, as it was accessible to everyone, including minors, the impact of the posters on the general public would have been multiplied on account of the reference to the website address.

Subsequently, the Court noted that the impugned poster clearly had the aim of attracting people’s attention to the website, since the address of that site was given in bold type above the slogan “The Message from Extraterrestrials”. It would thus be illogical for the Court to look solely at the poster itself and thus, it was deemed necessary to examine the content of the website in question.


Conclusion


As it is evident, the prohibition and penalization of hate speech on the Internet should be without prejudice to the right of freedom of expression. The case law of the Strasburg Court provides guidance on how to strike a balance in cases of conflict.

Some of the countries that ratified the Additional Protocol to the Convention of Cybercrime adopted a restrictive approach in that they provided for that the act of disseminating racist and xenophobic material is only punishable if the perpetrator had the intention of committing a hate crime. The Greek law, for example, provides that the offence of public incitement to violence or hatred or other act of discrimination against a person or group or persons identified in reference to race, color, religion, genealogical origin, national or ethnic origin, sexual orientation, gender identity or disability, is punishable under the condition that there is an imminent danger of the public order or contain a threat for the life, the freedom or the bodily integrity of the above persons. Similarly, the offence of the denial of genocide and crimes against humanity and war crimes are punished in case this behaviour is presented in a way that can incite violence or hatred or has a threatening aim or aims at defaming a group or a member of this group.

Particularly, as regards the denial or condoning of crimes against humanity and genocides, a recent decision of the ECHR in the case of Perinçek v. Switzerland shows that a balance between conflicting rights should be struck. This case concerned the criminal conviction of a Turkish politician for publicly expressing the view, in Switzerland, that the mass deportations and massacres suffered by the Armenians in the Ottoman Empire had not amounted to genocide. The Court did not find necessary to subject Mr Perinçek to a criminal penalty in order to protect the rights of the Armenian community. To conclude to this decision it took into account that his statements touched upon a matter of public interest and did not amount to a call for hatred or intolerance and that those could not be regarded as affecting the dignity of the Armenian Community in the extent that a criminal law response in Switzerland was necessary.

It goes without saying that legal measures against hate speech may not prove sufficient to restraint the flood of such online publications. It would take also to work together with ISPs, who should adopt a policy of removing offensive content, and also use filtering techniques and other innovative technologies to detect and remove such content from the Web.



Τρίτη 13 Οκτωβρίου 2015

Ασφάλεια Συστημάτων Πληροφορικής και Δικτύων στην Ελλάδα


Στη Χώρα μας,μέτρα για ασφάλεια συστημάτων πληροφορικής και δικτύων προβλέπονται, σήμερα, μόνο σε σχέση με την προστασία προσωπικών δεδομένων και την προστασία του απορρήτου της επικοινωνίας. Ειδικότερα, σχετικές διατάξεις υφίστανται στο Ν. 2472/1997 και τον Ν. 3471/2006.
   Καταρχήν, στο Ν.2472/1997 (άρθρο 10 παρ. 3) που διέπει την προστασία προσωπικών δεδομένων, γενικά προβλέπεται η υποχρέωση του υπεύθυνου επεξεργασίας να λαμβάνει τα κατάλληλα οργανωτικά και τεχνικά μέτρα για την ασφάλεια των δεδομένων και την προστασία τους από τυχαία ή αθέμιτη καταστροφή, τυχαία απώλεια, αλλοίωση, απαγορευμένη διάδοση ή πρόσβαση και κάθε άλλη μορφή αθέμιτης επεξεργασίας. Σύμφωνα με την ίδια διάταξη, αυτά τα μέτρα πρέπει να εξασφαλίζουν επίπεδο ασφαλείας ανάλογο προς τους κινδύνους που συνεπάγεται η επεξεργασία και η φύση των δεδομένων που είναι αντικείμενο της επεξεργασίας.
   Παραπέρα, στο Ν.3471/2006, ο οποίος βρίσκει εφαρμογή κατά την επεξεργασία προσωπικών δεδομένων στο πλαίσιο της παροχής υπηρεσιών ηλεκτρονικών επικοινωνιών, προβλέπεται ότι «ο φορέας παροχής διαθεσίµων στο κοινό υπηρεσιών ηλεκτρονικών επικοινωνιών οφείλει να λαµβάνει τα ενδεδειγµένα τεχνικά και οργανωτικά µέτρα, προκειµένου να προστατεύεται η ασφάλεια των υπηρεσιών του, καθώς και η ασφάλεια του δηµοσίου δικτύου ηλεκτρονικών επικοινωνιών. Τα µέτρα αυτά, εφόσον είναι αναγκαίο, λαµβάνονται από κοινού µε τον φορέα παροχής του δηµοσίου δικτύου ηλεκτρονικών επικοινωνιών, πρέπει δε να εγγυώνται επίπεδο ασφαλείας ανάλογο προς τον υπάρχοντα κίνδυνο, λαµβανοµένων υπόψη αφ' ενός των πλέον προσφάτων τεχνικών δυνατοτήτων αφ' ετέρου δε του κόστους εφαρµογής τους» (άρθρο 12 παρ. 1).
Πιο ειδικά, στην περίπτωση που υφίσταται ιδιαίτερος κίνδυνος παραβίασης της ασφάλειας του δηµοσίου δικτύου ηλεκτρονικών επικοινωνιών, ο φορέας που παρέχει διαθέσιµη στο κοινό υπηρεσία ηλεκτρονικών επικοινωνιών οφείλει να ενηµερώσει τους συνδροµητές. Εφόσον ο κίνδυνος αυτός είναι εκτός του πεδίου των µέτρων που οφείλει να λαµβάνει ο πάροχος της υπηρεσίας, ο φορέας έχει την υποχρέωση να ενηµερώνει τους συνδροµητές και για όλες τις δυνατότητες αποτροπής του κινδύνου, καθώς και για το αναµενόµενο κόστος.
Σχετικές ρυθμίσεις προβλέπονται και στο Ν. 4070/2012 όσον αφορά την ασφάλεια και την ακεραιότητα δικτύων και υπηρεσιών ηλεκτρονικών επικοινωνιών. Ειδικότερα, σύμφωνα με το άρθρο 37 παρ. 1 του νόμου, «οι επιχειρήσεις που παρέχουν δημόσια δίκτυα επικοινωνιών ή υπηρεσίες ηλεκτρονικών επικοινωνιών που διατίθενται στο κοινό λαμβάνουν πρόσφορα τεχνικά και οργανωτικά μέτρα για την κατάλληλη διαχείριση του κινδύνου όσον αφορά στην ασφάλεια των δικτύων και υπηρεσιών. Τα μέτρα αυτά, λαμβάνοντας υπόψη τις πλέον πρόσφατες τεχνικές δυνατότητες, πρέπει να εξασφαλίζουν επίπεδο ασφάλειας ανάλογο προς τον υφιστάμενο κίνδυνο. Οι επιχειρήσεις αυτές λαμβάνουν ιδίως μέτρα για την αποτροπή και ελαχιστοποίηση των επιπτώσεων από περιστατικά ασφαλείας που επηρεάζουν τους χρήστες και τα διασυνδεμένα δίκτυα». Σημαντικό είναι ότι, σύμφωνα με άλλη διάταξη του ίδιου νόμου (άρθρο 37 παρ. 4), κάθε παραβίαση της ασφάλειας ή απώλεια της ακεραιότητας που είχε σημαντικό αντίκτυπο στη λειτουργία δικτύων ή υπηρεσιών, πρέπει να κοινοποιείται από τις επιχειρήσεις που παρέχουν πρόσβαση σε δίκτυα ή υπηρεσίες ηλεκτρονικών επικοινωνιών στην Εθνική Επιτροπή Τηλεπικοινωνιών και Ταχυδρομείων (Ε.Ε.Τ.Τ.), η οποία με τη σειρά της κοινοποιεί κάθε παραβίαση της ασφάλειας ή απώλεια της ακεραιότητας στην Αρχή Διασφάλισης του Απορρήτου των Επικοινωνιών (Α.Δ.Α.Ε.), η οποία ενημερώνει τις αρμόδιες εθνικές αρχές σε άλλα κράτη μέλη της ΕΕ και τον Ευρωπαϊκό Οργανισμό για την Ασφάλεια Δικτύων και Πληροφοριών (ENISA), όπως, ενδεχομένως και το κοινό.
Οι ρυθμίσεις της νομοθεσίας για τα προσωπικά δεδομένα και τις ηλεκτρονικές επικοινωνίες έχουν, ωστόσο, περιορισμένο πεδίο εφαρμογής και, ως εκ τούτου, εύλογα γίνεται η διαπίστωση ότι υφίσταται ρυθμιστικό έλλειμμα σε ό,τι αφορά την προστασία από τους κινδύνους και τις απειλές για την ασφάλεια των συστημάτων και των δικτύων πληροφορικής, στη Χώρα μας.
Για την αντιμετώπιση των σχετικών κινδύνων απαιτείται συντονισμένη προσπάθεια και ειδικότερα, η κατάρτιση εθνικής στρατηγικής κυβερνοασφάλειας και η θέσπιση μέτρων ασφάλειας δικτύων και πληροφοριών, όπως και αντιμετώπισης κινδύνων που να εμπλέκουν όλους τους φορείς, δηλ. τις δημόσιες αρχές, τους φορείς εκμετάλλευσης υποδομών ζωτικής σημασίας και τους ιδιώτες που παρέχουν υπηρεσίες της κοινωνίας της πληροφορίας.
Αξίζει να σημειωθεί ότι και στη Χώρα μας έχει συνταχθεί προσχέδιο Εθνικής Στρατηγικής Κυβερνοασφάλειας που προβλέπει μέτρα, ανάλογα με όσα προβλέπονται και σε αντίστοιχα ρυθμιστικά κείμενα της αλλοδαπής. Σε αυτό προβλέπονται ως στρατηγικές κατευθύνσεις: α) η δημιουργία ενός ασφαλούς, ανθεκτικού και αξιόπιστου διαδικτυακού περιβάλλοντος όπου θα διασφαλίζεται η ακεραιότητα, διαθεσιμότητα και η εμπιστευτικότητα της διακινούμενης πληροφορίας, β) η ανάδειξη της κυβερνοασφάλειας ως θέματος κοινού ενδιαφέροντος και υπευθυνότητας όλων των εμπλεκόμενων φορέων, δημόσιων και ιδιωτικών, γ) η ευαισθητοποίηση του πληθυσμού για την ευθύνη καθενός εντός του κυβερνοχώρου και δ) η δραστηριοποίηση της Ελληνικής Δημοκρατίας σε διεθνές επίπεδο και ειδικότερα μέσω της ανταλλαγής πληροφοριών, της διαμόρφωσης διεθνών στρατηγικών, της ανάπτυξης και υιοθέτησης κανονισμών, της συμμετοχής σε κοινές ασκήσεις και την ανάληψη πρωτοβουλιών ή κοινών έργων με άλλες χώρες. Ιδιαίτερα σημαντικό είναι ότι προβλέπεται η δημιουργία Εθνικής Αρχής Κυβερνοασφάλειας, με διευρυμένες αρμοδιότητες και με διοικητική και επιχειρησιακή δομή ανάλογη με ένα εθνικό κέντρο αντιμετώπισης έκτακτων περιστατικών ασφάλειας (CERT). H Aρχή αυτή θα φέρει την ευθύνη υλοποίησης της Εθνικής Στρατηγικής και θα παρακολουθεί, συντονίζει και αξιολογεί το έργο των εμπλεκόμενων φορέων με σκοπό την υλοποίηση της Εθνικής Στρατηγικής.  
Βεβαίως, πρέπει να αναφερθεί ότι ήδη λειτουργεί στη Χώρα μας, η Εθνική Αρχή Αντιμετώπισης Ηλεκτρονικών Επιθέσεων (Εθνικό CERT) – στο πλαίσιο της Εθνικής Υπηρεσίας Πληροφοριών –, η οποία   έχει ως αποστολή να μεριμνά για την πρόληψη και τη στατική και ενεργητική αντιμετώπιση ηλεκτρονικών επιθέσεων κατά δικτύων επικοινωνιών, εγκαταστάσεων αποθήκευσης πληροφοριών και συστημάτων πληροφορικής, καθώς και για τη συλλογή, την επεξεργασία δεδομένων και την ενημέρωση των αρμόδιων φορέων[1]. Η αρμοδιότητά της, ωστόσο, είναι περιορισμένη, καθ’ όσον αφορά μόνο τις ηλεκτρονικές απειλές προς τον Δημόσιο τομέα και τις κρίσιμες υποδομές της χώρας.
Σε επίπεδο Ευρωπαϊκής Ένωσης, έχουν ληφθεί μεμονωμένα νομοθετικά μέτρα για την αντιμετώπιση του ηλεκτρονικού εγκλήματος με πιο πρόσφατη, την οδηγία 2013/40/EE για τις επιθέσεις κατά συστημάτων πληροφοριών και την αντικατάσταση της απόφασης-πλαίσιο 2005/222/ΔΕΥ του Συμβουλίου.
 Στις 7.2.2013 κατατέθηκε από την Ευρωπαϊκή Επιτροπή Πρόταση Οδηγίας σχετικά με την εξασφάλιση κοινού υψηλού επιπέδου ασφάλειας δικτύωνκαι πληροφοριών, η οποία αναμένεται να εγκριθεί σύντομα και η οποία θα αποτελέσει ορόσημο για την αντιμετώπιση των σύγχρονων προκλήσεων στο ζήτημα της Κυβερνοασφάλειας.
Ειδικότερα, η ψήφιση της οδηγίας θα επιφέρει βελτίωση της ασφάλειας του διαδικτύου και των ιδιωτικών δικτύων και συστημάτων πληροφοριών που υποστηρίζουν τη λειτουργία των Ευρωπαϊκών κοινωνιών και των οικονομιών. Οι στόχοι αυτοί θα επιτευχθούν απαιτώντας από τα κράτη μέλη της ΕΕ να αυξήσουν την ετοιμότητά τους, να βελτιώσουν τη μεταξύ τους συνεργασία, και ζητώντας από τους φορείς εκμετάλλευσης των υποδομών ζωτικής σημασίας, όπως είναι η ενέργεια, οι μεταφορές, καθώς και από τους βασικούς παρόχους υπηρεσιών της κοινωνίας της πληροφορίας (πλατφόρμες ηλεκτρονικού εμπορίου, κοινωνικά δίκτυα κλπ), όπως και από τις δημόσιες διοικήσεις να θεσπίσουν κατάλληλα μέτρα για τη διαχείριση των κινδύνων για την ασφάλεια και να αναφέρουν τα σοβαρά συμβάντα στις αρμόδιες εθνικές αρχές. Η οδηγία είναι μέτρο ελάχιστης εναρμόνισης και αυτό σημαίνει ότι τα κράτη μέλη μπορούν να λάβουν μέτρα που να εξασφαλίζουν υψηλότερο επίπεδο ασφαλείας.
Μεταξύ των άλλων, προβλέπεται στο σχέδιο οδηγίας, κατά πρώτον, η κατάρτιση Εθνικής στρατηγικής για την ασφάλεια δικτύων και πληροφοριών και εθνικό σχέδιο συνεργασίας για την ασφάλεια δικτύων και πληροφοριών. Κατά δεύτερον, προβλέπεται η δημιουργία αρμόδιας εθνικής αρχής για την ασφάλεια των συστημάτων δικτύων και πληροφοριών, αλλά και η κατάρτιση ομάδας αντιμετώπισης έκτακτων αναγκών στην πληροφορική (“CERT”) που θα είναι υπεύθυνη για τον χειρισμό συμβάντων και κινδύνων. Περαιτέρω, ρυθμίζονται ζητήματα συνεργασίας μεταξύ αρμόδιων αρχών, στο πλαίσιο της οποίας προβλέπεται η δημιουργία δικτύου συνεργασίας και ενός ασφαλούς συστήματος ανταλλαγής πληροφοριών, η παροχή έγκαιρων ειδοποιήσεων κοκ. Ιδιαίτερα σημαντικές είναι οι ουσιαστικού δικαίου ρυθμίσεις (στο κεφάλαιο IV), όπου θεσπίζονται οι απαιτήσεις ασφάλειας που αφορούν τη δημόσια διοίκηση και τους φορείς της αγοράς κλπ. Τέλος, προβλέπεται η θέσπιση κυρώσεων σε περίπτωση παραβίασης των εθνικών διατάξεων που θεσπίζονται κατ’ εφαρμογή της οδηγίας, οι οποίες πρέπει να είναι ουσιαστικές, αναλογικές και αποτρεπτικές.




Τετάρτη 7 Οκτωβρίου 2015

Safe Harbor for U.S. Companies processing data of European Citizens Gone?


To enable the data transfer between U.S. and E.U., the Commission entered into an agreement with the U.S., which does not provide an adequate level of protection of personal data. In fact, according to Directive 95/46, the transfer of personal data to countries that do not guarantee an adequate level of protection (Article 25). Within the framework of this Agreement, the Commission Decision 2000/520/EC was issued, which allows personal data from the EU to be transferred to U.S.A., in case the organization receiving the data is committed to comply with the Safe Harbor Principles, included in Annex I of the Decision.

Practically, in order to join the Safe Harbor Framework, a company must self-certify to the Department of Commerce that it complies with EU standards. The FTC enforces the promise that companies make when they certify that they participate in the Safe Harbor Framework. The certified organizations are included in the U.S.-EU Safe Harbor List, It is reported that almost 3,500 organizations across a broad range of industries in USA are safe-harbor certified (see: here).

The situation changed with the revelations concerning the US government's covert surveillance programs. Notably, European Commission Vice-President Viviane Reding announced in July 2013 a European Commission (Commission) plan to review the Safe Harbor and publish the results before the end of 2013. She observed that the Safe Harbor "may not be so safe after all," noting that it "could be a loophole”for data transfers because "it allows data transfers from EU to US companies – although US data protection standards are lower than our European ones.

The breakthrough came with the Decision of the CJEU of 6 October 2015 in case C-362/14 Maximillian Schrems v. Data Protection Commissioner. The Court declared the Decision as invalid and opened up a Pandora's box, as far the data transfers from the EU to US are concerned.

In more particular, this case refers to a request for a preliminary ruling under Article 267 TFEU from the Hight Court of Ireland. The dispute in the main proceedings concerned a complaint of an Austrian citizen, Mr. Schrems. The complainant had been a Facebook user since 2008. As it happens with other subscribers residing in the EU, some or all of the data provided by Mr Schrems to Facebook is transferred from Facebook’s Irish subsidiary to servers located in the United States, where it is processed. Schrems lodged a complaint with the Irish supervisory authority, taking the view that, in the light of the revelations made in 2013 by Edward Snowden concerning the activities of the United States intelligence services (in particular the National Security Agency (‘the NSA’)), the law and practice of the United States do not offer sufficient protection against surveillance by the public authorities of the data transferred to that country. The Irish authority rejected the complaint, on the ground, in particular, that in a decision of 26 July 2000 the Commission considered that, under the ‘safe harbour’ scheme, the United States ensuresan adequate level of protection of the personal data transferred (the Safe Harbour Decision). The High Court of Ireland, before which the case had been brought, wished to ascertain whether that Commission decision had the effect of preventing a national supervisory authority from investigating a complaint alleging that the third country does not ensure an adequate level of protection and, where appropriate, from suspending the contested transfer of data.

 The CJEU held that the existence of a Commission decision finding that a third country ensures an adequate level of protection of the personal data transferred cannot eliminate or even reduce the powers available to the national supervisory authorities under the Charter of Fundamental Rights of the European Union and the directive. The Court stresses in this regard the right, guaranteed by the Charter, to the protection of personal data and the task with which the national supervisory authorities are entrusted under the Charter.

The Court stated that no provision of the directive 95/46 prevents oversight by the national supervisory authorities of transfers of personal data to third countries which have been the subject of a Commission decision. Thus, even if the Commission had adopted a decision, the national supervisory authorities, when dealing with a claim, must be able to examine, with complete independence, whether the transfer of a person’s data to a third country complies with the requirements laid down by the directive.

The Court alone has jurisdiction to declare that an EU act, such as a Commission decision, is invalid . Consequently, where a national authority or the person who has brought the matter before the national authority considers that a Commission decision is invalid, that authority or person must be able to bring proceedings before the national courts so that they may refer the case to the Court of Justice if they too have doubts as to the validity of the Commission decision. It is thus ultimately the Court of Justice which has the task of deciding whether or not a Commission decision is valid.
 
Consequently, the Court  investigated whether the Safe Harbour Decision is invalid. Consequently, it stated that the Commission was required to find that the United States in fact ensures, by reason of its domestic law or its international commitments, a level of protection of fundamental rights essentially equivalent to that guaranteed within the EU under the directive read in the light of the Charter. The Court observed that the Commission did not make such a finding, but merely examined the safe harbour scheme. Without needing to establish whether that scheme ensures a level of protection essentially equivalent to that guaranteed with in the EU, the Court found that the scheme is applicable solely to the United States undertakings which adhere to it, and United States public authorities are not themselves subject to it. Further more, national security, public interest and law enforcement requirements of the United States prevail over the safe harbour scheme, so that United States undertakings are bound to disregard, without limitation, the protective rules laid down by that scheme where they conflict with such requirements. The United States safe harbour scheme thus enables interference, by United States public authorities, with the fundamental rights of persons, and the Commission decision does not refer either to the existence, in the United States, of rules intended to limit any such interference or to the existence of effective legal protection against the interference.

The Court considered that that analysis of the scheme is borne out by two Commission communications, according to which the United States authorities were able to access the personal data transferred from the Member States to the United States and process it in a way incompatible, in particular, with the purposes for which it was transferred, beyond what was strictly necessary and proportionate to the protection of national security. Also, the Commission noted that the persons concerned had no administrative or judicial means of redress enabling, in particular, the data relating to them to be accessed and, as the case may be, rectified or erased. As regards a level of protection essentially equivalent to the fundamental rights and freedoms guaranteed within the EU, the Court finds that, under EU law, legislation is not limited to what is strictly necessary where it authorises, on a generalised basis, storage of all the personal data of all the persons whose data is transferred from the EU to the United States without any differentiation, limitation or exception being made in the light of the objective pursued and without an objective criterion being laid down for determining the limits of the access of the public authorities to the data and of its subsequent use.

The Court added that legislation permitting the public authorities to have access on a generalised basis to the content of electronic communications must be regarded as compromising the essence of the fundamental right to respect for private life. Likewise, the Court stated that legislation not providing for any possibility for an individual to pursue legal remedies in order to have access to personal data relating to him, or to obtain the rectification or erasure of such data, compromises the essence of the fundamental right to effective judicial protection, the existence of such a possibility being inherent in the existence of the rule of law. Finally, the Court found that the Safe Harbour Decision denied the national supervisory authorities their powers where a person calls into question whether the decision is compatible with the protection of the privacy and of the fundamental rights and freedoms of individuals. The Court held that the Commission did not have competence to restrict the national supervisory authorities’ powers in that way.

For all those reasons, the Court declared the Safe Harbour Decision invalid. As a result,  the Irish supervisory authority is required to examine Mr Schrems’ complaint with all due diligence and, at the conclusion of its investigation, is to decide whether, pursuant to the directive, transfer of the data of Facebook’s European subscribersto the United States should be suspended on the ground that that country does not afford an adequate level of protection of personal data.

The consequences from this decision are very important, since the practice of data flow between EU and USA will be influenced. However, the EU Commission and the Rat in Luxembourg find no reason to stop data flows (!) [see here].

The Vice-President of the EU Commission, Frans Timmermans, mentioned in a statement that this decision confirmed the EU Commission's approach for the renegotiation of the Safe Harbor.

 The Article 29 Working Party welcomed the Court's decision, which reaffirmed that data protection rights are an inherent part of the EU fundamental rights regime. It recognizes that the decision will have major consequences on all stakeholders and for this reason, it stated in a press release issued in 6 October 2015 that a first round of discussions between experts is organized this week in Brussels and that an extraordinary plenary meeting of the Working Party will be shortly scheduled.
.



 See Court of Justice of the European Uniion, PRESS RELEASE No 117/15



Πέμπτη 24 Σεπτεμβρίου 2015

Transfer of the data of European Facebook subscribers to servers located in the United States

The EU legal framework on electronic signatures

 

Electronic signatures and related services that allow data authentication can play an important role in ensuring security and trust in electronic transactions. Certainly, in open networks such as the Internet, security issues are emerging, which hinder the development of electronic services. In particular, concerns are raised on the confidentiality and security of electronic communications, which hold back the exploitation of the Internet as a platform for e-commerce.

To deal with the issues of security and trust in electronic transactions, the EU adopted in 1999 the eSignature Directive. This Directive (Directive 1999/93/EC) establishes the legal framework at EU level for electronic signatures and certification services. The aim is to make electronic signatures easier to use and help them become legally recognised within the Member States. The Directive does not favour any specific technology.
The Directive lays down the rule of legal recognition of electronic signatures;[1] it establishes a legal framework for electronic signatures and certification services and defines two levels of security that organizations may apply to e-signatures depending on the sensitivity of the transaction, that is: (a) simple e-signatures, which provide a minimum level of security and (b) advanced electronic signatures, which provide a higher level of security and can be used as a substitute for a handwritten signature.

In order for a signature to be qualified as an advanced signature, certain requirements have to be fulfilled (Article 5(1) of the Directive). These requirements concern the technical function of the signature software and the existence of a qualified certificate, which is provided by a certification service provider which meets certain criteria. As is obvious, apart from the regulation of the legal effect of electronic signatures, the legal regulations concerning the certification of e-signatures and the accreditation of service providers are also of great importance.

As already mentioned, the Directive adopts a technology neutral approach regarding the recognition of electronic signatures. It defines electronic signatures in an abstract manner, so that different technologies can be used to fulfil the legal requirements in order to be qualified as electronic signatures. However, advanced electronic signatures correspond essentially to digital signatures, since the requirements laid down are only met by public key crypto systems.

Regarding the legal effect of e-signatures, a two-tier system is created, in accordance with Article 5 of the directive. Firstly, advanced electronic signatures, which are based on a qualified certificate and are created by a secure signature creation device, are equal in their effect, that is legal validity and probative effect, to handwritten signatures in paper documents. Secondly, the rule of non-discrimination of e-signatures is laid down. Accordingly, EU Member States shall ensure that an electronic signature is not denied legal effectiveness and admissibility as evidence in legal proceedings solely on the grounds that it is:
— in electronic form, or
— not based upon a qualified certificate, or
— not based upon a qualified certificate issued by an accredited certification-service-provider, or
— not created by a secure signature-creation device.

Furthermore, the |Directive includes rules on market access (Article 3) and establishment of providers of e-signatures services (Article 4), which are in line with EU principles. The liability of certification service providers is regulated in Article 6, which provides for a strict liability regime; accordingly, as a minimum, by issuing a certificate as a qualified certificate to the public or by guaranteeing such a certificate to the public a certification service provider is liable for damage caused to any entity or legal or natural person who reasonably relies on that certificate.

The recognition of certificates issued by providers established in third countries is regulated in Article 7. Certification service providers are further under the obligation to comply with data protection requirements, laid down in directive 95/46 and more specifically, to collect personal data only directly from the data subject, or after the explicit consent of the data subject, and only insofar as it is necessary for the purposes of issuing and maintaining the certificate. The data may not be collected or processed for any other purposes without the explicit consent of the data subject.

On the basis of this Directive, Commission Decision 2003/511/EC of 14 July 2003 on the publication of reference numbers of generally recognised standards for electronic signature products was issued. The Annex of this legal act includes a list of standards in compliance with the requirements in Annex I f of the Directive, i.e., CWA 14167-1 (March 2003): security requirements for trustworthy systems managing certificates for electronic signatures - Part 1: System Security Requirements and CWA 14167-2 (March 2002): security requirements for trustworthy systems managing certificates for electronic signatures - Part 2: cryptographic module for CSP signing operations - Protection Profile (MCSO-PP) and a list of standards in compliance with the requirements in Annex III, i.e., CWA 14169 (March 2002): secure signature-creation devices.

Furthermore, the Commission Decision 2000/709 was issued, which lays down the minimum criteria to be taken into account by Member States when designating bodies in accordance with Article 3(4) of Directive 1999/93/EC, that is, when a national body is designated as responsible for the conformity assessment of signature-creation-devices.

A report on the operation of the Directive 1999/93 was issued in 2006.[2] The conclusions of this report concentrated on the legal aspect and the market effect of the Directive. Regarding the former, it is acknowledged that the directive introduced legal certainty with respect to the general admissibility of electronic signatures: the need for the legal recognition of electronic signatures has been met by the transposition of the EU-Directive into the legislation of the EU-Member States. As far as the market effect of e-signatures is concerned, this has been relatively low. In particular, it was found that the use of qualified electronic signatures had been much less than expected and the market was not very well developed. The main reason for the slow take-off of the market is that service providers had little incentive to develop multi-application electronic signature and preferred to offer solutions for their own services. The banking sector and e-government were the sectors where e-signatures were mostly used.

Consequently, extensive consultations on a review of the e-signatures directive took place, and also, on the initiative of the EU Commission, a number of studies were conducted in relation to electronic identification, authentication, signature and related trust services (eIAS). It was made clear that a large majority of stakeholders agreed on the need to review the current framework to fill the gaps left by the directive. It was concluded that this would better respond to challenges posed by the rapid development of new technologies (particularly online and mobile access) and by increased globalisation, while maintaining the technological neutrality of the legal framework.

Critics also highlight the fact that the e-Signatures Directive mistakenly combines identification and authentication with signing, while those should be treated separately.[3]  And also, the combining of PKI technology and the legal status of signatures seems frustrating. 

As a result, the e-Signatures Directive was replaced with the Regulation 910/2014 on electronic identification and trust services for electronic transactions in the internal market (eIDAS Regulation), adopted on 23 July 2014. The eIDAS Regulation shall apply from 1 July 2016, with the exception of certain provisions which will apply in different stages.

The eIDAS Regulation creates a European internal market for electronic identification and electronic trust services, including:
· electronic signatures; the rules related to the legal effect of e-signatures are provided for, as well as the requirements for qualified signature certificates, for qualified e-signature creation devices etc.
· Time stamping, i.e. the date and time on an electronic document which proves that the document existed at a point-in-time and that it has not changed since then;
· Electronic seal, i.e. the electronic equivalent of a seal or stamp which is applied on a document to guarantee its origin and integrity;
· Electronic delivery, i.e. a service that, to a certain extent, is the equivalent in the digital world of registered mail in the physical world;
· Legal admissibility of electronic documents to ensure their authenticity and integrity;
· Website authentication, i.e. trusted information on a website (e.g. a certificate) which allows users to verify the authenticity of the website and its link to the entity/person owning the website.

The Regulation obliges public bodies to accept cross-border identification/authentication services that are provided under a scheme that has been properly notified to the European Commission. Thus, it ensures that people and businesses can use their own national electronic identification schemes (eIDs) to access public services in the EU countries where eIDs are available.

It also creates a European internal market for electronic trust services in that it guarantees that they will operate across borders and have the same legal status as traditional paper based processes.

EU Member States should establish supervisory bodies that will supervise certification service providers, but also trust service and qualified trust service providers. The conditions for the supervision of those providers are laid down in the provisions of the Regulation.

The EU adopt measures for the implementation of the Regulation:

Commission Implementing Decision (EU) 2015/1505 of 8 September 2015 laying down technical specifications and formats relating to trusted lists pursuant to Article 22(5) of Regulation (EU) No 910/2014 of the European Parliament and of the Council on electronic identification and trust services for electronic transactions in the internal market (Text with EEA relevance) 


Commission Implementing Decision (EU) 2015/1506 of 8 September 2015 laying down specifications relating to formats of advanced electronic signatures and advanced seals to be recognised by public sector bodies pursuant to Articles 27(5) and 37(5) of Regulation (EU) No 910/2014 of the European Parliament and of the Council on electronic identification and trust services for electronic transactions in the internal market (Text with EEA relevance) 


Commission Implementing Regulation (EU) 2015/1501 of 8 September 2015 on the interoperability framework pursuant to Article 12(8) of Regulation (EU) No 910/2014 of the European Parliament and of the Council on electronic identification and trust services for electronic transactions in the internal market (Text with EEA relevance) 

Commission Implementing Regulation (EU) 2015/1502 of 8 September 2015 on setting out minimum technical specifications and procedures for assurance levels for electronic identification means pursuant to Article 8(3) of Regulation (EU) No 910/2014 of the European Parliament and of the Council on electronic identification and trust services for electronic transactions in the internal market (Text with EEA relevance) 

Commission Implementing Regulation (EU) 2015/806 of 22 May 2015 laying down specifications relating to the form of the EU trust mark for qualified trust services (Text with EEA relevance) 

Commission Implementing Decision (EU) 2015/296 of 24 February 2015 establishing procedural arrangements for cooperation between Member States on electronic identification pursuant to Article 12(7) of Regulation (EU) No 910/2014 of the European Parliament and of the Council on electronic identification and trust services for electronic transactions in the internal market Text with EEA relevance




[3]  See M. Voulon, “European Union introduces new legal framework for identity management”, online available at: http://www.idnext.eu/en/home/european-union-introduces-new-legal-framework-for-identity-management/

Τρίτη 22 Σεπτεμβρίου 2015

Το δικαίωμα της διανομής στο κοινό περιλαμβάνει και την προσφορά προστατευόμενων έργων, ακόμα και όταν δεν καταλήγει σε πώληση


Μια ενδιαφέρουσα απόφαση εξέδωσε το ΔικΕΕ στην υπόθεση C‑516/13, Dimensione Direct Sales Srl, Michele Labianca κατά Knoll International SpA, στις 13-5-2015 που αφορούσε το ζήτημα αν η διαφήμιση προστατευόμενων έργων εμπίπτει στο δικαίωμα της διανομής στο κοινό, υπό την έννοια του άρθρου 4 της οδηγίας 2001/29

Τα πραγματικά περιστατικά της υπόθεσης αυτής είχαν ως εξής:

Η Knoll ανήκει στον όμιλο Knoll του οποίου η μητρική εταιρία, η Knoll Inc., έχει έδρα στην Πενσυλβανία (Ηνωμένες Πολιτείες). Ο όμιλος αυτός κατασκευάζει και πωλεί σε ολόκληρο τον κόσμο έπιπλα αξίας. Η Dimensione είναι εταιρία περιορισμένης ευθύνης διαχειριστής της οποίας είναι ο M. Labianca. Διανέμει στην Ευρώπη με απευθείας πώληση έπιπλα σχεδιασμένα από δημιουργούς και προτείνει προς πώληση έπιπλα στον διαδικτυακό της τόπο. Κατά τα έτη 2005 και 2006, η Dimensione διαφήμισε την πώληση επίπλων που αντιστοιχούν σε προστατευόμενες δημιουργίες στον διαδικτυακό της τόπο, ο οποίος είναι διαθέσιμος στη γερμανική γλώσσα, σε διάφορες γερμανικές εφημερίδες και περιοδικά καθώς και σε διαφημιστικό φυλλάδιο το οποίο ανέφερε: «Αγοράστε τα έπιπλά σας στην Ιταλία και πληρώστε μόνο κατά την ανάληψη ή κατά την παράδοση από εξουσιοδοτημένο για την είσπραξη μεταφορέα (υπηρεσία παρεχόμενη κατόπιν αιτήσεώς σας)».  Εκτιμώντας ότι τα προτεινόμενα από την Dimensione προς πώληση έπιπλα ήσαν απομιμήσεις ή παρομοιώσεις προστατευόμενων δημιουργιών, η Knoll ενήγαγε την Dimensione και τον M. Labianca ενώπιον του Landgericht Hamburg (περιφερειακού δικαστηρίου του Αμβούργου) ζητώντας να τους απαγορευθεί να προσφέρουν προς πώληση τα έπιπλα αυτά στη Γερμανία. Προς στήριξη της αγωγής της, η Knoll ισχυρίστηκε ότι τα εν λόγω έπιπλα προστατεύονται από το δικαίωμα του δημιουργού ως έργα εφαρμοσμένης τέχνης. Το γερμανικό Ακυρωτικό (Bundesgerichtshof) επισήμανε ότι η ευδοκίμηση του εν λόγω ενδίκου μέσου εξαρτάται από την ερμηνεία του άρθρου 4, παράγραφος 1, της οδηγίας 2001/29 και ιδίως από το αν το δικαίωμα διανομής που προβλέπει η διάταξη αυτή περιλαμβάνει το δικαίωμα προσφοράς προς πώληση στο κοινό του πρωτοτύπου ή αντιγράφου ενός προστατευόμενου έργου.  

Συνακόλουθα, το Γερμανικό Ακυρωτικό υπέβαλε στο Δικαστήριο τα ακόλουθα ερωτήματα:
1) Περιλαμβάνει το δικαίωμα διανομής, κατά το άρθρο 4, παράγραφος 1, της οδηγίας 2001/29, το δικαίωμα προσφοράς, προς πώληση στο κοινό, του πρωτοτύπου ή αντιγράφου ενός έργου; 
Σε περίπτωση καταφατικής απαντήσεως στο πρώτο ερώτημα: 
2) Περιλαμβάνει το δικαίωμα προσφοράς, προς πώληση στο κοινό, του πρωτοτύπου ή αντιγράφου ενός έργου μόνο προτάσεις για τη σύναψη συμβάσεως ή και διαφημιστικές πράξεις;
3) Υπάρχει προσβολή του δικαιώματος διανομής αν η προσφορά δεν κατέληξε στην απόκτηση του πρωτοτύπου ή αντιγράφου ενός έργου;»

Το Δικαστήριο απάντησε θετικά σε όλα τα ερωτήματα. Ειδικότερα, δέχθηκε ότι μπορεί να συντρέχει προσβολή του αποκλειστικού δικαιώματος διανομής, προβλεπόμενου στο άρθρο 4, παράγραφος 1, της οδηγίας 2001/29, όταν έμπορος, ο οποίος δεν είναι κάτοχος δικαιώματος του δημιουργού, πωλεί προστατευόμενα έργα ή αντίγραφά τους, μέσω του διαδικτυακού του τόπου, με ταχυδρομικές διαφημίσεις ή με δημοσιεύσεις στον Τύπο, σε καταναλωτές εγκατεστημένους στο έδαφος κράτους μέλους εντός του οποίου τα εν λόγω έργα προστατεύονται για να τους παροτρύνει να τα αποκτήσουν (σκέψη αρ. 31). Από το συμπέρασμα αυτό προκύπτει ότι, για να διαπιστωθεί προσβολή του δικαιώματος διανομής, δεν ασκεί επιρροή το γεγονός ότι τη διαφήμιση αυτή δεν επακολούθησε μεταβίβαση της κυριότητας του προστατευόμενου έργου ή αντιγράφου του στον αποκτώντα (σκ. αρ. 32).

Το Δικαστήριο απέκλινε από την προηγούμενη νομολογία του και συγκεκριμένα, έκρινε διαφορετικά από ό,τι στην απόφαση Peek & Cloppenburg (C‑456/06, EU:C:2008:232, σκέψεις 33, 36 και 41), η οποία αφορούσε τη δυνατότητα χρήσεως των αντιγράφων προστατευόμενου έργου, ότι η έννοια της διανομής στο κοινό προστατευόμενου έργου ή αντιγράφου του, κατά το άρθρο 4 παρ. 1 της οδηγίας 2001/29, συνεπάγεται μεταβίβαση της κυριότητας του αντικειμένου αυτού, μπορεί εντούτοις να διαπιστωθεί προσβολή του δικαιώματος διανομής εφόσον προσφέρεται, μέσω στοχευμένης διαφημίσεως, σε καταναλωτές εγκατεστημένους στο έδαφος κράτους μέλους εντός του οποίου το έργο αυτό προστατεύεται, η απόκτηση της κυριότητας του πρωτοτύπου ή αντιγράφου του. Σϋμφωνα με το Δικαστήριο, η ερμηνεία αυτή είναι σύμφωνη με τους σκοπούς της εν λόγω οδηγίας, κατά τις οποίες η εναρμόνιση του δικαιώματος του δημιουργού πρέπει να βασίζεται σ’ ένα υψηλό επίπεδο προστασίας, οι δημιουργοί πρέπει να λαμβάνουν εύλογη αμοιβή για τη χρήση των έργων τους και το σύστημα προστασίας του δικαιώματος του δημιουργού πρέπει να είναι αποτελεσματικό και αυστηρό (βλ. απόφαση Peek & Cloppenburg, C‑456/06, EU:C:2008:232, σκέψη 37).

Κατ' ακολουθία, το ΔικΕΕ έκρινε ότι το άρθρο 4 παρ. 1 της οδηγίας 2001/29 έχει την έννοια ότι παρέχει σε κάτοχο αποκλειστικού δικαιώματος διανομής προστατευόμενου έργου τη δυνατότητα να απαγορεύει την προσφορά πωλήσεως ή στοχευμένη διαφήμιση αφορώσα το πρωτότυπο ή αντίγραφο του έργου αυτού, ακόμα και όταν δεν αποδεικνύεται ότι η εν λόγω διαφήμιση κατέληξε στην απόκτηση του προστατευόμενου έργου από αγοραστή της Ένωσης, καθόσον η διαφήμιση αυτή παροτρύνει τους καταναλωτές κράτους μέλους, εντός του οποίου το έργο αυτό προστατεύεται από το δικαίωμα του δημιουργού, να το αποκτήσουν.

Το συμπέρασμα από την απόφαση αυτή του ΔικΕΕ είναι τα όρια του δικαιώματος διανομής είναι ευρεία και φτάνουν να εκτείνονται και σε πράξεις που καλύπτονταν μέχρι πρότινος από το δικαίωμα επιγραμμικής διάθεσης (άρθρο 3 της οδηγίας 2001/29).