Παρασκευή 15 Απριλίου 2016

The European Parliament adopts the Data Protection Reform Package

Press release - Brussels, 21 December 2015
Stronger data protection rules for Europe: the EU adopts the data protection reform package
The European Parliament and Council have reached agreement on the data protection reform proposed by the Commission. The reform is an essential step to strengthen citizens' fundamental rights in the digital age and facilitate business by simplifying rules for companies in the Digital Single Market.
The data protection reform package includes the General Data Protection Regulation ("Regulation") and the Data Protection Directive for the police and criminal justice sector.
Why did the Commission propose a reform of EU data protection rules? 
EU legislation on data protection has been in place since 1995. The Data Protection Directive guarantees an effective protection of the fundamental right to data protection. But differences in the way that each Member State implements the law have led to inconsistencies, which create complexity, legal uncertainty and administrative costs. This affects the trust and confidence of individuals and the competitiveness of the EU economy. The current rules also need modernising – they were introduced at a time when many of today's online services and the challenges they bring for data protection did not yet exist. With social networking sites, cloud computing, location-based services and smart cards, processing of personal data has grown exponentially. We need a robust set of rules to make sure people's right to personal data protection – recognised by Article 8 of the EU's Charter of Fundamental Rights – remains effective in the digital age.This will at the same time be beneficial for the development of the digital economy.  
What will change under the Regulation?
The Regulation updates and modernises the principles enshrined in the 1995 Data Protection Directive to guarantee privacy rights. It focuses on: reinforcing individuals' rights, strengthening the EU internal market, ensuring stronger enforcement of the rules, streamlining international transfers of personal data and setting global data protection standards. 
The changes will give people more control over their personal data and make it easier to access it. They are designed to make sure that people's personal information is protected – no matter where it is sent, processed or stored – even outside the EU, as may often be the case on the internet. 
What are the benefits for citizens? 
The reform provides tools for gaining control of one's personal data, the protection of which is a fundamental right in the European Union.
The data protection reform will strengthen citizens' rights and build trust. Nine out of ten Europeans have expressed concern about mobile apps collecting their data without their consent, and seven out of ten worry about the potential use that companies may make of the information disclosed.
The new rules address these concerns through:
  • A "right to be forgotten": When an individual no longer wants her/his data to be processed, and provided that there are no legitimate grounds for retaining it, the data will be deleted. This is about protecting the privacy of individuals, not about erasing past events or restricting freedom of the press.
  • Easier access to one's data: Individuals will have more information on how their data is processed and this information should be available in a clear and understandable way. A right to data portability will make it easier for individuals to transmit personal data between service providers.
  • The right to know when one's data has been hacked: Companies and organisations must notify the national supervisory authority of data breaches which put individuals at risk and communicate to the data subject all high risk breaches as soon as possible so that users can take appropriate measures.
  • Data protection by design and by default: ‘Data protection by design’ and ‘Data protection by default’ are now essential elements in EU data protection rules. Data protection safeguards will be built into products and services from the earliest stage of development, and privacy-friendly default settings will be the norm – for example on social networks or mobile apps.
  • Stronger enforcement of the rules: data protection authorities will be able to fine companies who do not comply with EU rules up to 4% of their global annual turnover.
Right to be forgotten: How will it work?
Already the current Directive gives individuals a possibility to have their data deleted, in particular when the data is no longer necessary.
For example, if an individual has given her or his consent to processing for a specific purpose, e.g. display on a social networking site, and does not want this service anymore, than there is no reason to keep the data in the system. In particular, when children have made data about themselves accessible, often without fully understanding the consequences, they must not be stuck with the consequences of that choice for the rest of their lives.
This does not mean that on each request of an individual all his personal data are to be deleted at once and forever. If for example, the retention of the data is necessary for the performance of a contract or for compliance with a legal obligation, the data can be kept as long as necessary for that purpose.
The proposed provisions on the "right to be forgotten" are very clear: freedom of expression, as well as historical and scientific research are safeguarded.
For example, no politician will be able to have their earlier remarks deleted from the web. This will thus allow, inter alia, news websites to continue operating on the basis of the same principles.
Is there specific protection for children?
Yes, the Regulation recognises that children deserve specific protection of their personal data, as they may be less aware of risks, consequences, safeguards and their rights in relation to the processing of personal data. For instance, they benefit from a clearer right to be forgotten.
When it comes to information society services offered directly to a child, the Regulation foresees that consent for processing the data of a child must be given or authorised by the holder of the parental responsibility over the child. The age threshold is for Member States to define within a range of 13 to 16 years.
The aim of this specific provision aims at protecting children from being pressured to share personal data without fully realising the consequences. It will not to stop teenagers from using the Internet to get information, advice, education etc. Moreover, the Regulation specifies that the consent of the holder of parental responsibility should not be necessary in the context of preventive or counselling services offered directly to a child.
What are the benefits for businesses?
The reform provides clarity and consistency of the rules to be applied, and restores trust of the consumer, thus allowing undertakings to seize fully the opportunities in the Digital Single Market.
Data is the currency of today's digital economy. Collected, analysed and moved across the globe, personal data has acquired enormous economic significance. According to some estimates, the value of European citizens' personal data has the potential to grow to nearly €1 trillion annually by 2020. By strengthening Europe’s high standards of data protection, lawmakers are creating business opportunities.
The data protection reform package helps the Digital Single Market realise this potential through:
  • One continent, one law: a single, pan-European law for data protection, replacing the current inconsistent patchwork of national laws. Companies will deal with one law, not 28. The benefits are estimated at €2.3 billion per year.
  • One-stop-shop: a 'one-stop-shop' for businesses: companies will only have to deal with one single supervisory authority, not 28, making it simpler and cheaper for companies to do business in the EU.
  • The same rules for all companies – regardless of where they are established: Today European companies have to adhere to stricter standards than companies established outside the EU but also doing business in our Single Market. With the reform companies based outside of Europe will have to apply the same rules when they offer goods or services on the EU market. This creates a level playing field.
  • Technological neutrality: the Regulation enables innovation to continue to thrive under the new rules. 
What is the one-stop shop? 
Within a single market for data, identical rules on paper are not enough. The rules must be applied in the same way everywhere. The 'one-stop-shop' will streamline cooperation between the data protection authorities on issues with implications for all of Europe. Companies will only have to deal with one authority, not 28. 
It will ensure legal certainty for businesses. Businesses will profit from faster decisions, from one single interlocutor (eliminating multiple contact points), and from less red tape. They will benefit from consistency of decisions where the same processing activity takes place in several Member States. 
Individuals will have more control. How will that help business? 
The new right to data portability will allow individuals to move their personal data from one service provider to another. Start-ups and smaller companies will be able to access data markets dominated by digital giants and attract more consumers with privacy-friendly solutions. This will make the European economy more competitive.  
Example: Benefits for individuals, benefits for businesses 
A new small company wishes to enter the market offering an online social media sharing website. The market already has big players with a large market share. Under the current rules, each new customer will have to consider starting over again with the personal data they    wish to provide to be established on the new website. This can be a disincentive for some people considering switching to the new business. 
With the Data Protection Reform: The right to data portability will make it easier for potential customers to transfer their personal data between service providers. This allows customers to exercise control over their personal data, and at the same time fosters competition and encourages new businesses in the marketplace.
What are the benefits for SMEs?
The data protection reform is geared towards stimulating economic growth by cutting costs and red tape for European business, also for small and medium enterprises (SMEs).
By having one rule instead of 28, the EU's data protection reform will help SMEs break into new markets. In a number of cases, the obligations of data controllers and processors are calibrated to the size of the business and/or to the nature of the data being processed. For example:
  • SMEs need not appoint a data protection officer unless their core activities require regular and systematic monitoring of the data subjects on a large scale or if they process special categories of personal data such as that revealing racial or ethnic origin or religious beliefs. Moreover, this will not need to be a full-time employee but could be an ad-hoc consultant, and therefore, would be much less costly. 
  • SMEs need not keep records of processing activities unless the processing they carry out is not occasional or likely to result in a risk for the rights and freedoms of data subject.
  • SMEs will not be under an obligation to report all data breaches to individuals, unless the breaches represent a high risk for their rights and freedoms. 
How will the new rules save money? 
The Regulation will establish a single, pan-European law for data protection meaning that companies can simply deal with one law, not 28. The new rules will bring benefits of an estimated €2.3 billion per year. 
Example: Cutting costsA chain of shops has its head office in France and franchised shops in 14 other EU countries. Each shop collects data relating to clients and transfers it to the head office in France for further processing. 
With the current rules: 
France’s data protection laws would apply to the processing done by head office, but individual shops would still have to report to their national data protection authority, to confirm they were processing data in accordance with national laws in the country where they were located. This means the company’s head office would have to consult local lawyers for all its branches to ensure compliance with the law. The total costs arising from reporting requirements in all countries could be over €12,000. 
With the Data Protection Reform: The data protection law across all 14 EU countries will be the same – one European Union – one law. This will eliminate the need to consult with local lawyers to ensure local compliance for the franchised shops. The result is direct cost savings and legal certainty. 
How will the Data Protection Reform encourage innovation and use of big data? 
According to some estimates, the value of European citizens’ personal data could grow to nearly €1 trillion annually by 2020. The new EU rules will offer flexibility to businesses all while protecting individuals' fundamental rights. 
‘Data protection by design and by default’ will become an essential principle. It will incentivise businesses to innovate and develop new ideas, methods, and technologies for security and protection of personal data.Used in conjunction with data protection impact assessments, businesses will have effective tools to create technological and organisational solutions.
The Regulation promotes techniques such as anonymisation (removing personally identifiable information where it is not needed),pseudonymisation (replacing personally identifiable material with artificial identifiers), and encryption (encoding messages so only those authorised can read it) to protect personal data. This will encourage the use of "big data" analytics, which can done using anonymised or pseudonymised data. 
Example: Driverless carsThe driverless cars technology requires important data flows, including the exchange of personal data. Data protection rules go hand in hand with innovative and progressive solutions. For example, in case of a crash, cars equipped with eCall emergency call system can automatically call the nearest emergency centre. This is an example of a workable and efficient solution in line with EU data protection principles. With the new rules, the function of eCall will become easier, simpler and more efficient in terms of data protection.
It is a data protection principle that when personal data is collected for one or more purposes it should not be further processed in a way that is incompatible with the original purposes. This does not prohibit processing for a different purpose or restrict 'raw data' for use in analytics. A key factor in deciding whether a new purpose is incompatible with the original purpose is whether it is fair. Fairness will consider factors such as; the effects on the privacy of individuals (e.g. specific and targeted decisions about identified persons) and whether an individual has a reasonable expectation that their personal data will be used in the new way. So in the example of the driverless cars, raw data can be used to analyse where the most accidents take place and how future accidents could be avoided. It can also be used to analyse traffic flows in order to reduce traffic jams.   
Businesses should be able to anticipate and inform individuals of the potential uses and benefits of big data - even if the exact specifics of the analysis are not yet known. Businesses should also think whether the data can be anonymised for such future processing. This will allow raw data to be retained for big data, while protecting the rights of individuals. 
The new data protection rules provide businesses with opportunities to remove the lack of trust that can affect people's engagement with innovative uses of personal data. Providing individuals with clear, effective information will help build trust in analytics and innovation. The information to be provided is not exactly how the data is to be processed, but the purposes for which it will be processed. 
The apparent complexity of innovated products and big data analytics is not an excuse for failing to seek consent of people where it is required. However, consent is not the only basis for processing. Companies are free to base processing on a contract, on a law or, on, in the absence of other bases, on a "balancing of interests". These 'formal requirements', such as consent, are set out in the rules to provide the necessary control by individuals over their personal data and to provide legal certainty for everyone. The new EU rules will provide flexibility on how to meet those requirements. 
How will the new rules work in practice?
Example: a multinational company with several establishments in EU Member States has an online navigation and mapping system across Europe. This system collects images of all private and public buildings, and may also take pictures of individuals.
With the current rules:The data protection safeguards upon data controllers vary substantially from one Member State to another. In one Member State, the deployment of this service led to a major public and political outcry, and some aspects of it were considered to be unlawful. The company then offered additional guarantees and safeguards to the individuals residing in that Member State after negotiation with the competent DPA, however the company refused to commit to offer the same additional guarantees to individuals in other Member States.
Currently, data controllers operating across borders need to spend time and money (for legal advice, and to prepare the required forms or documents) to comply with different, and sometimes contradictory, obligations.
With the new rules:The new rules will establish a single, pan-European law for data protection, replacing the current inconsistent patchwork of national laws. Any company - regardless of whether it is established in the EU or not - will have to apply EU data protection law should they wish to offer their services in the EU. 
Example: a small advertising company wants to expand its activities from France to Germany.
With the current rules:
Its data processing activities will be subject to a separate set of rules in Germany and the company will have to deal with a new regulator. The costs of obtaining legal advice and adjusting business models in order to enter this new market may be prohibitive. For example, some Member States charge notification fees for processing data.
With the new rules:
The new data protection rules will scrap all notification obligations and the costs associated with these. The aim of the data protection regulation is to remove obstacles to cross-border trade. 
What about the Data Protection Directive for the police and criminal justice sector? 
The Police Directive ensure the protection of personal data of individuals involved in criminal proceedings, be it as witnesses, victims, or suspects. It will also facilitate a smoother exchange of information between Member States' police and judicial authorities, improving cooperation in the fight against terrorism and other serious crime in Europe. It establishes a comprehensive framework to ensure a high level of data protection whilst taking into account the specific nature of the police and criminal justice field. 
How does the Data Protection Directive for the police and criminal justice sector impact law enforcement operations? 
Law enforcement authorities will be able to exchange data more efficiently and effectively. By further harmonising the 28 different national legislations, the common rules on data protection will enable law enforcement and judicial authorities to cooperate more effectively and more rapidly with each other by facilitating the exchange of personal data necessary to prevent crime under conditions of legal certainty, fully in line with the Charter of Fundamental Rights. 
Criminal law enforcement authorities will no longer have to apply different sets of data protection rules according to the origin of the personal data, saving time and money. The new rules will apply to both domestic processing and cross-border transfers of personal data. Having more harmonised laws in all EU Member States will make it easier for our police forces to work together. The rules in the Directive take account of the specific needs of criminal law enforcement and respect the different legal traditions in Member States.
How does the Directive affect citizens?
 
Individuals' personal data will be better protected.The Directive protects citizens' fundamental right to data protection when data is used by criminal law enforcement authorities. Everyone’s personal data should be processed lawfully, fairly, and only for a specific purpose. All law enforcement processing in the Union must comply with the principles of necessity, proportionality and legality, with appropriate safeguards for the individuals. Supervision is ensured by independent national data protection authorities and effective judicial remedies must be provided. 
The Directive also provides clear rules for the transfer of personal data by criminal law enforcement authorities outside the EU, to ensure that these transfers take place with an adequate level of data protection. The directive provides robust rules on personal data exchanges at national, European and international level. 
How does the Directive affect the work of criminal law enforcement? 
Having the same law in all EU Member States will make it easier for our criminal law enforcement authorities to work together in exchanging information. This will increase the efficiency of criminal law enforcement and thus create conditions for more effective crime prevention. 
This is also why the Data Protection Directive is considered a key element of the development of the EU's area of freedom, security and justice and a building block of the EU Agenda on Security. 
The Directive replaces Framework Decision 2008/977/JHA which previously governed data processing by police and judicial authorities. 
The entry into force of the Lisbon Treaty and, in particular, the introduction of a new legal basis (Article 16 TFEU) allow the establishment of a comprehensive data protection framework in the area of police and judicial cooperation in criminal matters. The new framework will cover both cross-border and domestic processing of personal data.
When will the new laws apply? 
The Regulation shall apply 2 years after its formal adoption by the European Parliament and Council. The Commission will work together with the Member States and the Data protection authorities – the future European Data Protection Board- to ensure a uniform application of the new rules. 
The Police Directive provides for a two-year implementation period. Member States are under an obligation to update their legal frameworks during this time. 

Παρασκευή 18 Μαρτίου 2016

Κύρωση της Σύμβασης για το έγκλημα στον Κυβερνοχώρο και του Προσθέτου Πρωτοκόλλου της – Μεταφορά της Οδηγίας 2013/40/ΕΕ

Μετά από πολυετή αδράνεια της Ελληνικής Πολιτείας, πρόκειται σύντομα να ψηφισθεί νόμος για την κύρωση της Σύμβασης για το Κυβερνοέγκλημα, αλλά και για τη μεταφορά της οδηγίας 2013/40/Ε για τις επιθέσεις κατά συστημάτων πληροφοριών.

Ειδικότερα, η ανακοίνωση του Υπουργού Δικαιοσύνης έχει ως εξής:

Τίθεται από σήμερα σε δημόσια διαβούλευση η νομοθετική πρωτοβουλία του Υπουργείου Δικαιοσύνης, Διαφάνειας και Ανθρωπίνων Δικαιωμάτων, υπό τον τίτλο: «Κύρωση της Σύμβασης του Συμβουλίου της Ευρώπης για το έγκλημα στον Κυβερνοχώρο και του Προσθέτου Πρωτοκόλλου της, σχετικά με την ποινικοποίηση πράξεων ρατσιστικής και ξενοφοβικής φύσης, που διαπράττονται μέσω Συστημάτων Υπολογιστών, καθώς και μεταφορά στο ελληνικό δίκαιο της οδηγίας 2013/40/ΕΕ του Ευρωπαϊκού Κοινοβουλίου και του Συμβουλίου της Ευρώπης για τις επιθέσεις κατά συστημάτων πληροφοριών και την αντικατάσταση της απόφασης – πλαισίου 2005/222/ΔΕΥ του Συμβουλίου και άλλες διατάξεις».
Δεδομένης της σπουδαιότητας της συγκεκριμένης πρωτοβουλίας, σας καλώ να συμμετάσχετε στη δημόσια ηλεκτρονική διαβούλευση, διατυπώνοντας τις απόψεις και τις παρατηρήσεις σας στις σχετικές ρυθμίσεις. Η διαβούλευση θα ολοκληρωθεί τη Δευτέρα, 28 Μαρτίου 2016 και ώρα 14:00.
Νικόλαος Παρασκευόπουλος
Υπουργός Δικαιοσύνης, Διαφάνειας και Ανθρωπίνων Δικαιωμάτων


Δείτε εδώ το σχέδιο νόμου:
http://www.opengov.gr/ministryofjustice/wp-content/uploads/downloads/2016/03/2016_03_16_Sxedio_Nomou_Min_Justice.pdf 


Και επίσης, τη διαβούλευση:

Τετάρτη 16 Μαρτίου 2016

Επιτηδευματίας που θέτει δωρεάν στη διάθεση του κοινού ένα ασύρματο τοπικό δίκτυο με πρόσβαση στο Διαδίκτυο


ΠΡΟΤΑΣΕΙΣ ΤΟΥ ΓΕΝΙΚΟΥ ΕΙΣΑΓΓΕΛΕΑ MACIEJ SZPUNAR της 16ης Μαρτίου 2016  Υπόθεση C‑484/14 Tobias Mc Fadden κατά Sony Music Entertainment Germany GmbH 
[αίτηση του Landgericht München I (Γερμανία) για την έκδοση προδικαστικής αποφάσεως]



Δημοσιεύθηκαν οι προτάσεις του Γεν. Εισαγγελέα του ΔΕΕ στην ως άνω υπόθεση, η οποία αφορά προδικαστική παραπομπή με την οποία ζητείται η έκδοση απόφασης που αφορά στο ζήτημα της ευθύνης του ιδιοκτήτη διαδικτυακής σύνδεσης που διατηρεί σε λειτουργία μέσω ασύρματου δικτύου (Wi-Fi). Μέσω αυτής της συνδέσεως, στις 4 Σεπτεμβρίου 2010, ένα μουσικό έργο προσφέρθηκε παράνομα προς τηλεφόρτωση. Η Sony Music, η οποία είναι παραγωγός φορέων ηχητικής εγγραφής και κάτοχος δικαιωμάτων επί του έργου αυτού, με έγγραφο της προέβη σε όχληση του ως άνω προσώπου για την προσβολή των δικαιωμάτων της. Ο εναγόμενος υποστήριξε, μεταξύ άλλων, ότι αποκλείεται η ευθύνη του δυνάμει των διατάξεων του γερμανικού δικαίου που μεταφέρουν στην εθνική έννομη τάξη το άρθρο 12, παράγραφος 1, της οδηγίας 2000/31. Ωστόσο, το αιτούν δικαστήριο εκθέτει ότι κλίνει προς την εφαρμογή κατ’ αναλογία της αποφάσεως του Bundesgerichtshof της 12ης Μαΐου 2010, Sommer unseres Lebens (I ZR 121/08), εκτιμώντας ότι η απόφαση αυτή, που αφορά ιδιώτες, ισχύει κατά μείζονα λόγο στην περίπτωση ενός επιτηδευματία ο οποίος διατηρεί σε λειτουργία ένα δίκτυο Wi‑Fi ανοικτό στο κοινό.


Τα βασικά ερωτήματα που τέθηκαν ήταν: παρέχει επιτηδευματίας, ο οποίος, στο πλαίσιο των δραστηριοτήτων του, διατηρεί σε λειτουργία ένα ασύρματο τοπικό δίκτυο με πρόσβαση στο Διαδίκτυο (στο εξής: δίκτυο Wi‑Fi), ανοικτό στο κοινό και δωρεάν, υπηρεσία της κοινωνίας της πληροφορίας κατά την έννοια της οδηγίας 2000/31/ΕΚ; Κατά πόσον περιορίζεται η ευθύνη του λόγω των προσβολών του δικαιώματος του δημιουργού εκ μέρους τρίτων χρηστών; Μπορεί ένα τέτοιο πρόσωπο που διατηρεί σε λειτουργία ένα δημόσιο δίκτυο Wi‑Fi να εξαναγκασθεί, μέσω διαταγής, να προστατεύει την πρόσβαση στο δίκτυό του με κωδικό προσβάσεως;


Καταρχήν, ο Γεν. Εισαγγελέας αναφέρει ότι τα άρθρα 2, στοιχεία αʹ, και βʹ, και 12, παράγραφος 1, της οδηγίας 2000/31 έχουν την έννοια ότι έχουν εφαρμογή σε πρόσωπο το οποίο, παρεπομένως σε σχέση με την κύρια οικονομική του δραστηριότητα, διατηρεί σε λειτουργία ένα δίκτυο Wi‑Fi με σύνδεση στο Διαδίκτυο, ανοικτό στο κοινό και δωρεάν.


Στη συνέχεια, κρίνει ότι το άρθρο 12, παράγραφοι 1 και 3, της οδηγίας 2000/31 αντιτίθεται στην καταδίκη ενός ενδιάμεσου φορέα παροχής υπηρεσιών απλής μεταδόσεως συνεπεία οποιουδήποτε αιτήματος που συνεπάγεται τη διαπίστωση αστικής ευθύνης του. Το άρθρο αυτό αντιτίθεται επομένως όχι μόνο στην επιβολή υποχρεώσεως αποζημιώσεως στον ενδιάμεσο φορέα παροχής υπηρεσιών, αλλά και στην καταδίκη του στα έξοδα οχλήσεως και στα δικαστικά έξοδα σε σχέση με την προσβολή του δικαιώματος του δημιουργού εκ μέρους τρίτου λόγω των διαβιβαζόμενων πληροφοριών. Το ίδιο άρθρο δεν αντιτίθεται στην έκδοση διαταγής επ’ απειλή χρηματικής ποινής.


Στη συνέχεια, εξετάζει το ζήτημα αν τα τρία μέτρα που μνημονεύονται στο ένατο ερώτημα, υπό βʹ, ήτοι η διακοπή της διαδικτυακής συνδέσεως, η προστασία της με κωδικό προσβάσεως ή ο έλεγχος κάθε επικοινωνίας που διεξάγεται μέσω αυτής, μπορούν να είναι συμβατά προς την οδηγία 2000/31. Ο Γεν. Εισαγγελέας θεωρεί ότι μέτρο που διατάσσει τη διακοπή λειτουργίας της διαδικτυακής συνδέσεως προδήλως δεν συμβιβάζεται με την απαίτηση δίκαιης εξισορροπήσεως των θεμελιωδών δικαιωμάτων, εφόσον θίγει το ουσιώδες περιεχόμενο του δικαιώματος της επιχειρηματικής ελευθερίας του προσώπου το οποίο, έστω και παρεπομένως, ασκεί οικονομική δραστηριότητα που συνίσταται στην παροχή προσβάσεως στο Διαδίκτυο. Ένα τέτοιο μέτρο θα ήταν αντίθετο προς το άρθρο 3 της οδηγίας 2004/48, δυνάμει του οποίου το δικαστήριο που εκδίδει τη διαταγή οφείλει να μεριμνά ώστε τα προσδιοριζόμενα μέτρα να μη παρακωλύουν το νόμιμο εμπόριο.


Όσον αφορά το μέτρο που υποχρεώνει τον ιδιοκτήτη της διαδικτυακής συνδέσεως να ελέγχει όλες τις επικοινωνίες που διεξάγονται μέσω αυτής, αυτό θα προσέκρουε προφανώς στην απαγόρευση γενικής υποχρεώσεως ελέγχου, που προβλέπεται στο άρθρο 15, παράγραφος 1, της οδηγίας 2000/31.


Όσον αφορά δε την προστασία της πρόσβασης σε ασύρματο δίκτυο, έχει τη γνώμη ότι η επιβολή υποχρεώσεως προστασίας της προσβάσεως στο δίκτυο Wi‑Fi, ως μέθοδος προστασίας του δικαιώματος του δημιουργού στο πλαίσιο του Διαδικτύου, δεν θα τηρούσε την απαίτηση δίκαιης ισορροπίας μεταξύ, αφενός, της προστασίας του δικαιώματος διανοητικής ιδιοκτησίας, της οποίας απολαύουν οι κάτοχοι του δικαιώματος του δημιουργού, και, αφετέρου, της προστασίας της επιχειρηματικής ελευθερίας η οποία ισχύει για τους φορείς παροχής των σχετικών υπηρεσιών. Περιορισμός της προσβάσεως σε νόμιμες επικοινωνίες θα συνεπαγόταν επιπλέον περιορισμό της ελευθερίας εκφράσεως και πληροφορήσεως. Υπό γενικότερο πρίσμα, η ενδεχόμενη γενίκευση της υποχρεώσεως προστασίας των δικτύων Wi‑Fi, ως μέθοδος προστασίας του δικαιώματος του δημιουργού εντός του Διαδικτύου, θα ήταν ικανή να επιφέρει ένα μειονέκτημα για όλη την κοινωνία, που θα εγκυμονούσε τον κίνδυνο να υπερβαίνει το ενδεχόμενο όφελός της για τους κατόχους αυτών των δικαιωμάτων. Αφενός, τα δημόσια δίκτυα Wi‑Fi που χρησιμοποιούνται από μεγάλο αριθμό ατόμων έχουν σχετικώς περιορισμένο εύρος ζώνης και, επομένως, δεν είναι πολύ εκτεθειμένα στις προσβολές των έργων και των αντικειμένων που προστατεύονται από το δικαίωμα του δημιουργού. Αφετέρου, τα σημεία προσβάσεως Wi‑Fi εμφανίζουν αναμφισβήτητα σημαντικό δυναμικό για την καινοτομία. Κάθε μέτρο που εγκυμονεί τον κίνδυνο να ανακόψει την εξέλιξη αυτής της δραστηριότητας πρέπει επομένως να εξετάζεται επιμελώς σε σχέση με το ενδεχόμενο όφελός του.


Καταλήγοντας, η πρόταση του Γεν. Εισαγγελέα είναι η εξής:

1) Τα άρθρα 2, στοιχεία αʹ και βʹ, και 12, παράγραφος 1, της οδηγίας 2000/31/ΕΚ του Ευρωπαϊκού Κοινοβουλίου και του Συμβουλίου, της 8ης Ιουνίου 2000, για ορισμένες νομικές πτυχές των υπηρεσιών της κοινωνίας της πληροφορίας, ιδίως του ηλεκτρονικού εμπορίου, στην εσωτερική αγορά (οδηγία για το ηλεκτρονικό εμπόριο), έχουν την έννοια ότι έχουν εφαρμογή σε κάθε πρόσωπο, το οποίο, παρεπομένως σε σχέση με την κύρια οικονομική του δραστηριότητα, διατηρεί σε λειτουργία ένα ασύρματο τοπικό δίκτυο Wi‑Fi με σύνδεση στο Διαδίκτυο, ανοικτό στο κοινό και δωρεάν.

2) Το άρθρο 12, παράγραφος 1, της οδηγίας 2000/31 αντιτίθεται στην καταδίκη ενός ενδιάμεσου φορέα παροχής υπηρεσιών απλής μεταδόσεως συνεπεία οποιουδήποτε αιτήματος που συνεπάγεται τη διαπίστωση αστικής ευθύνης του. Το άρθρο αυτό αντιτίθεται επομένως όχι μόνο στην επιβολή υποχρεώσεως αποζημιώσεως στον φορέα παροχής τέτοιων υπηρεσιών, αλλά και στην καταδίκη του στα έξοδα οχλήσεως και στα δικαστικά έξοδα σε σχέση με την προσβολή του δικαιώματος του δημιουργού εκ μέρους τρίτου λόγω των διαβιβαζόμενων πληροφοριών.

3) Το άρθρο 12, παράγραφοι 1 και 3, της οδηγίας 2000/31 δεν αντιτίθεται στην έκδοση διαταγής δικαστηρίου, συνοδευόμενης με απειλή χρηματικής ποινής.

Κάθε εθνικό δικαστήριο, όταν εκδίδει μια τέτοια διαταγή, οφείλει να βεβαιώνεται:

– ότι τα οικεία μέτρα συνάδουν προς το άρθρο 3 της οδηγίας 2004/48/ΕΚ του Ευρωπαϊκού Κοινοβουλίου και του Συμβουλίου, της 29ης Απριλίου 2004, σχετικά με την επιβολή των δικαιωμάτων διανοητικής ιδιοκτησίας, και, μεταξύ άλλων, ότι είναι αποτελεσματικά, σύμφωνα με την αρχή της αναλογικότητας και αποτρεπτικού χαρακτήρα·

– ότι σκοπό έχουν την παύση συγκεκριμένης προσβολής δικαιώματος ή την πρόληψή της και δεν συνεπάγονται γενική υποχρέωση ελέγχου, σύμφωνα με τα άρθρα 12, παράγραφος 3, και 15, παράγραφος 1, της οδηγίας 2000/31, και

– ότι η εφαρμογή των διατάξεων αυτών, καθώς και άλλων λεπτομερειών που προβλέπονται δυνάμει του εθνικού δικαίου, εξασφαλίζει δίκαιη ισορροπία μεταξύ των εφαρμοστέων εν προκειμένω θεμελιωδών δικαιωμάτων, ειδικότερα δε των προστατευόμενων, αφενός, από τα άρθρα 11 και 16 του Χάρτη των Θεμελιωδών Δικαιωμάτων της Ευρωπαϊκής Ένωσης καθώς και, αφετέρου, από το άρθρο 17, παράγραφος 2, αυτού.

4) Τα άρθρα 12, παράγραφος 3, και 15, παράγραφος 1, της οδηγίας 2000/31, ερμηνευόμενα υπό το πρίσμα των απαιτήσεων που απορρέουν από την προστασία των εφαρμοστέων θεμελιωδών δικαιωμάτων, δεν αντιτίθενται, κατ’ αρχήν, στην έκδοση διαταγής που αφήνει στον αποδέκτη της την επιλογή των συγκεκριμένων προς λήψη μέτρων. Εναπόκειται παρά ταύτα στον επιληφθέντα αιτήσεως εκδόσεως διαταγής εθνικό δικαστή να βεβαιωθεί για την ύπαρξη κατάλληλων μέτρων, σύμφωνα με τους περιορισμούς που απορρέουν από το ενωσιακό δίκαιο.

Οι εν λόγω διατάξεις αντιτίθενται στην έκδοση διαταγής που απευθύνεται σε διατηρούντα σε λειτουργία ασύρματο τοπικό δίκτυο Wi‑Fi με σύνδεση στο Διαδίκτυο, ανοικτό στο κοινό και δωρεάν, παρεπομένως σε σχέση με την κύρια οικονομική του δραστηριότητα, όταν ο αποδέκτης της διαταγής δεν μπορεί να συμμορφωθεί προς αυτή παρά μόνο:

– διακόπτοντας τη διαδικτυακή σύνδεση, ή

– προστατεύοντάς τη με κωδικό προσβάσεως, ή

– ελέγχοντας κάθε επικοινωνία που διεξάγεται μέσω αυτής ως προς το αν το συγκεκριμένο έργο που προστατεύεται από το δικαίωμα του δημιουργού μεταδίδεται εκ νέου παρανόμως.











Σάββατο 20 Φεβρουαρίου 2016

ΕΤΗΣΙΑ ΕΚΘΕΣΗ ΓΙΑ ΤΗ ΔΙΑΘΕΣΗ ΚΑΙ ΠΕΡΑΙΤΕΡΩ ΧΡΗΣΗ ΤΩΝ ΑΝΟΙΚΤΩΝ ΔΕΔΟΜΕΝΩΝ

Στις 19/2/2016 τέθηκε σε δημόσια διαβούλευση από το Υπουργείο Εσωτερικών και Διοικητικής Ανασυγκρότησης η Ετήσια Έκθεση για τη διάθεση και περαιτέρω χρήση ανοικτών δεδομένων (βλ.: http://www.opengov.gr/ypes/?p=3541). 

Σύμφωνα με την έκθεση, οι πολιτικές ανοιχτών δεδομένων, οι οποίες ενθαρρύνουν την ευρεία διαθεσιμότητα και την περαιτέρω χρήση πληροφοριών του δημόσιου τομέα για προσωπικούς ή εμπορικούς σκοπούς, με ελάχιστους ή καθόλου νομικούς, τεχνικούς ή οικονομικούς περιορισμούς, και οι οποίες προωθούν την κυκλοφορία των πληροφοριών όχι μόνο για τους οικονομικούς φορείς αλλά και για το κοινό, μπορούν να διαδραματίσουν σημαντικό ρόλο στην ταχεία ανάπτυξη υπηρεσιών που βασίζονται σε νέους τρόπους συνδυασμού και χρησιμοποίησης αυτών των πληροφοριών και τόνωσης της οικονομικής ανάπτυξης. Το προσδοκώμενο ωφέλιμο αποτέλεσμα έγκειται στην ενίσχυση τόσο της διαφάνειας και της συμμετοχής, όσο και στην δημιουργία νέων ευκαιριών για φορείς της κοινωνίας των πολιτών και (νεοφυών) επιχειρήσεων, ώστε να παράσχουν υπηρεσίες προστιθέμενης αξίας, αξιοποιώντας τα δεδομένα που προσφέρονται ανοικτά από τους δημόσιους φορείς.
Την παρούσα χρονική περίοδο, έχει συνταχθεί σχέδιο έκθεσης το οποίο αφορά την περιγραφή του ισχύοντος θεσμικού πλαισίου, το σύνολο των ενεργειών οι οποίες ανελήφθησαν το 2015 από το Υπουργείο και τα βασικά σημεία του σχεδιασμού ως προς την πολιτική των ανοικτών δεδομένων για το έτος 2016. Ειδικότερα, η έκθεση διαρθρώνεται στα εξής κεφάλαια:

1. Εισαγωγή – Ιστορική εξέλιξη (Θεσμικό πλαίσιο του Ν. 3448/2006 (Α’ 57) – Επιχειρησιακή διάσταση
2. Διεργασίες σε επίπεδο Ευρωπαϊκής Ένωσης για την πολιτική των ανοικτών δεδομένων
3. Ανοικτή διάθεση και περαιτέρω χρήση εγγράφων, πληροφοριών και δεδομένων του δημόσιου τομέα: το κεφ. Α του Ν. 4305/2014 (237/Α’) (Θεσμικό πλαίσιο – Επιχειρησιακή διάσταση – ποσοτική και ποιοτική αποτίμηση αποτελεσμάτων – σχέσεις με διεθνείς οργανισμούς)
4. Γενική Αποτίμηση Πολιτικής
5. Σχέδιο δράσης για το έτος 2016 (Εντοπισμός κρίσιμων φορέων της Διοίκησης για την εφαρμογή της πολιτικής των ανοικτών δεδομένων – Διάσταση υποδομών – Συμμετοχή μετόχων εκτός της Διοίκησης: αξιολόγηση αναγκαιότητας/δυνατότητας/οφέλους – Ενδυνάμωση της περαιτέρω χρήσης από φορείς του δημοσίου τομέα και λοιπούς ενδιαφερόμενους – Πτυχές οικονομικής αποτίμησης)


Τα συμπεράσματα της έκθεσης είναι τα εξής:

- Ως προς το ισχύον θεσμικό πλαίσιο: Το αναθεωρημένο θεσμικό πλαίσιο, το οποίο υιοθετήθηκε με το Ν. 4305/2014, τροποποιώντας το αντίστοιχο το οποίο είχε εγκαθιδρυθεί με το Ν. 3448/2006, συνιστά άμεση και πλήρη ανταπόκριση και ευθυγράμμιση αφενός στην ευρωπαϊκή πολιτική και αφετέρου στη διεθνή πρακτική. Τα ανοικτά δεδομένα συνιστούν προτεραιότητα στη δημόσια διοίκηση, αποτελώντας μια οριζόντια πρόβλεψη την οποία όλοι οι φορείς οι οποίοι εμπίπτουν στο πεδίο εφαρμογής του Νόμου καλούνται να εφαρμόσουν, καταγράφοντας και αξιολογώντας μέσω συγκεκριμένης διαδικασίας τα σύνολα εγγράφων, πληροφοριών και δεδομένων τα οποία έχουν στην κατοχή τους και να αναρτήσουν στο κεντρικό αποθετήριο, το data.gov.gr. Η κατοχύρωση της εξ ορισμού αρχής της ανοικτής διάθεσης αποτελεί μία καινοτομία, η οποία διασφαλίζει την εφαρμογή του Νόμου, μεταθέτοντας το βάρος απόδειξης για πιθανή άρνησης πρόσβασης σε δεδομένα στον εκάστοτε φορέα, καλώντας τον να θεμελιώσει την άρνηση παροχής δεδομένων σε συγκεκριμένη νομική βάση απορρήτων, προσωπικών δεδομένων και λοιπών περιορισμών. 

- Ως προς το βαθμό υιοθέτησης της πολιτικής: Το Υπουργείο Εσωτερικών και Διοικητικής Ανασυγκρότησης, μέσω της Διεύθυνσης Ηλεκτρονικής Διακυβέρνησης, υιοθέτησε άμεσα μία σειρά ενεργειών για τη διάχυση της πολιτικής και τη γνωστοποίηση των υποχρεώσεων που απορρέουν από την υιοθέτηση του Ν. 4305/2014, τόσο μέσω εγκυκλίων, όσο και μέσω συναντήσεων και λοιπών άμεσων επικοινωνιών. Ωστόσο, η ανάλυση των αποτελεσμάτων, τόσο σε ποιοτικό όσο και σε ποσοτικό επίπεδο, καταδεικνύει περιορισμένη ανταπόκριση των φορέων στην εφαρμογή της πολιτικής των ανοικτών δεδομένων. 

Ειδικότερα, τα προβλήματα τα οποία εντοπίζονται θα μπορούσαν να συνοψιστούν ως ακολούθως: 

  • Η ανταπόκριση κρίσιμων φορέων της δημόσιας διοίκησης θα μπορούσε να χαρακτηριστεί ως εξαιρετικά περιορισμένη. Μεγάλη υστέρηση εντοπίζεται στα Υπουργεία, τα οποία λόγω του θεσμικά κατοχυρωμένου, επιτελικού ρόλου τους, διαθέτουν πλήθος δεδομένων, βάσει των οποίων θα μπορούσαν να αναπτυχθούν εφαρμογές υψηλής προστιθέμενης αξίας. Θεματικές ενότητες όπως η Παιδεία, η Υγεία, η Εργασία, η Κοινωνική Ασφάλιση, η Οικονομία, οι Μεταφορές δεν έχουν ανοίξει τα δεδομένα τους. Επομένως, η ενεργοποίηση των καθ’ύλην αρμόδιων Υπουργείων συνιστά προτεραιότητα για την ουσιαστική πραγμάτωση της πολιτικής. 
  • Οι υποδομές οι οποίες έχουν αναπτυχθεί για να υποστηρίξουν το Μητρώο Ανοικτών Δεδομένων του Δημοσίου χρήζουν περαιτέρω βελτιώσεων για να είναι σε θέση να υποστηρίξουν τις ανάγκες οι οποίες απορρέουν από την εφαρμογή του Ν. 4305/2014. Ο υφιστάμενος διαδικτυακός τόπος www.data.gov.gr υλοποιήθηκε σε πολύ σύντομο χρονικό διάστημα και με περιορισμένες λειτουργικές δυνατότητες, με σκοπό την άμεση κάλυψη των απαιτήσεων της σχετικής νομοθεσίας, χωρίς όμως να μπορεί να υποστηρίξει τεχνολογικά την πλήρη εφαρμογή της στο σύνολο του δημοσίου τομέα και την αναμενόμενη μελλοντική ζήτηση χρήσης των διαθέσιμων ανοικτών δεδομένων. Για το λόγο αυτό, είναι αναγκαίος ο περαιτέρω ανασχεδιασμός του. 
  • Η συμμετοχή μετόχων εκτός της Διοίκησης κρίνεται περιορισμένη. Δεδομένης της εξωστρεφούς φύσης της πολιτικής των ανοικτών δεδομένων, κρίνεται αναγκαία η συμμετοχή φορέων εκτός της Δημόσιας Διοίκησης, οι οποίοι λόγω της τεχνογνωσίας στο πεδίο των ανοικτών δεδομένων, δύνανται να συνεισφέρουν σε κάθε στάδιο εφαρμογής της πολιτικής, ιδίως ως προς τα δεδομένα στα οποία εκδηλώνεται ενδιαφέρον για την ανάπτυξη εφαρμογών. 
  • Ακόμα και στις περιπτώσεις οπού φορείς έχουν προβεί σε άνοιγμα των δεδομένων τους, η περαιτέρω χρήση τόσο από φορείς του δημόσιου τομέα όσο και από κάθε πιθανό ενδιαφερόμενο παραμένει περιορισμένη. Παρατηρείται ότι ιδίως φορείς, εκτός του δημοσίου τομέα, δε γνωρίζουν την πολιτική των ανοικτών δεδομένων και των ωφελειών που μπορούν να αντληθούν από τη διάχυση της πολιτικής. Επομένως, η γνωστοποίηση της πολιτικής και η παροχή εργαλείων τα οποία διευκολύνουν την περαιτέρω χρήση συνιστούν πεδία προς βελτίωση. 
  • Ο όγκος των συνόλων εγγράφων, πληροφοριών και δεδομένων τα οποία έχουν αναρτηθεί στο data.gov.gr δεν έχει καταστήσει ακόμα εφικτή την αποτίμηση των οικονομικών ωφελειών από την πολιτική των ανοικτών δεδομένων. Κρίνεται αναγκαία η προσπάθεια για ποσοτικοποίηση των ωφελειών από τα ανοικτά δεδομένα, με σκοπό την επίτευξη συγκεκριμένων εξοικονομήσεων. 
  • Η ποιότητα των συνόλων εγγράφων, πληροφοριών και δεδομένων τα οποία έχουν αναρτηθεί στο data.gov.gr απέχει από την ιδανική εφαρμογή των προβλέψεων της σχετικής νομοθεσίας τόσο σε ότι αφορά το περιεχόμενο όσο και τον μορφότυπο τους χωρίς ωστόσο να λείπουν και παραδείγματα καλής εφαρμογής. Καταληκτικά, η προσπάθεια που έχει καταβληθεί από το Υπουργείο, η οποία στόχευσε κατ’ αρχήν στην σώρευση μίας κρίσιμης μάζας δεδομένων στο portal και η οποία αντανακλάται στον εικοσιαπλασιαμό των αναρτηθέντων datasets καταδεικνύει την ύπαρξη μίας δυναμικής η οποία, κυρίως λόγω της περιορισμένης ανταπόκρισης κρίσιμων φορέων, παραμένει ανεκμετάλλευτη. 


Η προαναφερόμενη περιορισμένη ανταπόκριση, ιδίως μεγάλων διοικητικών σχηματισμών, όπως τα Υπουργεία, ασφαλώς υποδηλώνει αδυναμία ή/και απροθυμία υιοθέτησης θεμελιωδών έστω στοιχείων κουλτούρας ανοικτής διοίκησης, η οποία συνιστά ένα από τα μείζονα βήματα για την πραγμάτωση της διοικητικής μεταρρύθμισης. Έχοντας εντοπίσει τα συγκεκριμένα πεδία τα οποία χρήζουν περαιτέρω βελτίωσης, ο σχεδιασμός του Υπουργείου για το έτος 2016 επικεντρώνεται στις ενέργειες που απαιτούνται για την ειδικότερη αντιμετώπισή τους ώστε, εφόσον επιτευχθεί ένας ικανός αριθμός σημαντικών ποιοτικά datasets να είναι εφικτή η διερεύνηση διαστάσεων που αφορούν αφενός την περαιτέρω χρήση αυτών και αφετέρου το όφελος της εξεταζόμενης πολιτικής στην πραγματική οικονομία.






Δευτέρα 15 Φεβρουαρίου 2016

Παραβίαση προσωπικών δεδομένων από Τράπεζα κατά τη διαβίβαση δεδομένων σε Εταιρία Ενημέρωσης Οφειλών

ΕιρΑθ 96/2016



Συγκροτήθηκε από την Ειρηνοδίκη Ανθούλα Δήμητσα, την οποία όρισε η Πρόεδρος του Τριμελούς Συμβουλίου Διοικήσεως του Ειρηνοδικείου Αθηνών και τη Γραμματέα Ζ. Δερμεντζόγλου.

Συνεδρίασε δημόσια στο ακροατήριο του, στις 10.11.2015, για να δικάσει την υπόθεση μεταξύ:

ΤΟΥ ΕΝΑΓΟΝΤΑ: ... Δικηγόρου, ο οποίος παραστάθηκε αυτοπροσώπως.

ΤΗΣ ΕΝΑΓΟΜΕΝΉΣ: Ανώνυμης Τραπεζικής Εταιρείας με την επωνυμία «... Α.Ε.», νομίμως εκπροσωπούμενης, που εδρεύει στην Αθήνα, η οποία παραστάθηκε δια της πληρεξούσιας δικηγόρου της Θ. Π.

Ο ενάγων με την από 8.9.2015 με αρ. κατ. 1103/2015 αγωγή του, η συζήτηση της οποίας προσδιορίσθηκε για την ανωτέρω δικάσιμο, αιτείται τα αναφερόμενα σ' αυτή.

Ακολούθησε συζήτηση, όπως σημειώνεται στα Πρακτικά.

ΑΦΟΥ ΜΕΛΕΤΗΣΕ ΤΗ ΔΙΚΟΓΡΑΦΙΑ
ΣΚΕΦΘΗΚΕ ΣΥΜΦΩΝΑ ΜΕ ΤΟ ΝΟΜΟ


Με την κρινόμενη ο ενάγων εκθέτει ότι, στις 17.2.2015, η εναγόμενη διαβίβασε,- χωρίς προηγούμενη ενημέρωση του ως όφειλε, κατά την διάταξη του άρθρου 11 παρ. 1 και 3 του Ν. 2472/1997 και χωρίς την λήψη της ρητής και σαφούς συγκατάθεσης του, κατά την διάταξη του άρθρου 5 του Ν. 2472/1997,- τα συλλεγέντα, στις 22.8.2008, κατά την κατάρτιση σύμβασης χορήγησης πιστωτικής κάρτας, αναφερόμενα προσωπικά του δεδομένα, στην Εταιρεία Ενημέρωσης Οφειλετών για ληξιπρόθεσμες Απαιτήσεις με την επωνυμία «Pano Inform Α.Ε.», υπάλληλος της οποίας τον κάλεσε, στις 17.2.2015, για να τον ενημερώσει για την ληξιπρόθεσμη οφειλή του και να διαπραγματευθεί τον τρόπο και χρόνο αποπληρωμής της. Ότι από την ως άνω παράνομη πράξη και παράλειψη της εναγόμενης, που, δια των προστηθέντων της, διαβίβασε τα προσωπικά του δεδομένα σε απροσδιόριστο αριθμό τρίτων ατόμων, κατά παράβαση των διατάξεων του ως άνω Νόμου, υπέστη ηθική βλάβη και για τους λόγους αυτούς αιτείται να υποχρεωθεί (η εναγόμενη), με απόφαση προσωρινά εκτελεστή, να του καταβάλλει ως χρηματική ικανοποίηση το, κατ' ελάχιστον οριζόμενο από την διάταξη του άρθρου 23 παρ. 2 του ως άνω Νόμου, ποσόν των 5.869, 40 ευρώ, με τον νόμιμο τόκο από της επιδόσεως της κρινόμενης και να καταδικασθεί στην δικαστική του δαπάνη.

Η αγωγή αρμόδια και παραδεκτά εισάγεται προς συζήτηση ενώπιον του παρόντος Δικαστηρίου (άρθρα 14 παρ. 1α, 25, 37 ΚΠολΔ), κατά την διαδικασία των άρθρων 664επ. ΚΠολΔ (άρθρο 23 παρ. 3 Ν 2472/1997), είναι επαρκώς ορισμένη, απορριπτόμενου του περί του αντιθέτου ισχυρισμού της εναγόμενης και παρεπόμενα νόμιμη στηριζόμενη στις κατωτέρω αναφερόμενες διατάξεις του Ν. 2472/1997 και σ' αυτές των άρθρων 345, 346 ΑΚ, 907, 908, 176 ΚΠολΔ και θα πρέπει να ερευνηθεί περαιτέρω ως προς την ουσιαστική της βασιμότητα καθόσον καταβάλλεται το νόμιμο τέλος δικαστικού ενσήμου με τις ανάλογες υπέρ τρίτων προσαυξήσεις (υπ' αρ. 249409 και 254425 αγωγόσημα).

Από την εκτίμηση της ένορκης κατάθεσης του μάρτυρα και της ανώμοτης εξέτασης του ενάγοντα (417 ΚΠολΔ), που περιλαμβάνονται στα ταυτάριθμα με τη παρούσα Πρακτικά, του συνόλου (671 ΚΠολΔ) των προσκομιζόμενων με επίκληση εγγράφων σε συνδυασμό με τα διδάγματα της Κοινής πείρας και λογικής (336 παρ. 4 ΚΠολΔ) και τις ομολογίες, που συνάγονται από το σύνολο των ισχυρισμών των διαδίκων (261 ΚΠολΔ), αποδείχθηκαν τα ακόλουθα ουσιώδη πραγματικά περιστατικά: Ο ενάγων, με την από 22.8.2008 αίτηση του, υποβληθείσα στην εναγόμενη, ζήτησε την χορήγηση πιστωτικής κάρτας και γνωστοποίησε στην τελευταία τα απλά προσωπικά δεδομένα του, που ήταν αναγκαία για την κατάρτιση της αντίστοιχης σύμβασης, ήτοι το όνομα, επώνυμο, πατρώνυμο, ημερομηνία γέννησης, αριθμό δελτίου ταυτότητας, διεύθυνση κατοικίας, αριθμό τηλεφώνου και επάγγελμα. Περαιτέρω αποδείχθηκε ότι η εναγόμενη, που είχε υπογράψει με την ανώνυμη εταιρεία του άρθρου 7 Ν. 3758/2009 με την επωνυμία «ΡΑΝΟ INFORM Α.Ε.», την από 2.11.2009 σύμβαση παροχής υπηρεσιών,- λόγω ανώμαλης εξέλιξης της ενοχής από την ως άνω πιστωτική κάρτα, ήτοι υπερημερίας του ενάγοντα-, διαβίβασε, χωρίς την προηγούμενη οφειλόμενη, κατ' άρθρο 11 Ν. 2472/1997 και της, κατ' εξουσιοδότηση αυτού, εκδοθείσας υπ' αρ. 1/1999 κανονιστικής πράξης της Αρχής Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (ΦΕΚ 555 Β76.5.1999), ενημέρωση του, τα ως άνω (απλά) προσωπικά δεδομένα του ως και το ύψος της ληξιπρόθεσμης οφειλής του, στην ως άνω εταιρεία, η οποία προέβη σε χρήση αυτών, καλώντας τον τηλεφωνικά, δια προστηθέντος υπαλλήλου της, στις 17.2.2015. Όπως προκύπτει από τον όρο 23 της ως άνω σύμβασης, το περιεχόμενο του οποίου έχει ως εξής: «Καθυστέρηση ολοσχερούς εξόφλησης από τον κάτοχο των ελαχίστων καταβολών ή του ποσού που αναφέρεται ως άμεσα πληρωτέο...και να αναθέσει την είσπραξη των οφειλομένων σε τρίτα, προς την Τράπεζα, φυσικά ή νομικά πρόσωπα, γνωστοποιώντας για τον σκοπό αυτό όσα προσωπικά στοιχεία του κατόχου ή/και του εγγυητή κρίνει απαραίτητο», ως και των υπ' αρ. 19 και 21.1 «επικαιροποιημένων όρων χρήσης, που του απεστάλησαν μαζί με το αντίγραφο κίνησης του λογαριασμού της κάρτας του», η παράθεση του περιεχομένου των οποίων παρέλκει καθόσον προσιδιάζουν στο ανωτέρω ήδη εκτιθέμενο (περιεχόμενο), η υποχρέωση της εναγόμενης-υπεύθυνου επεξεργασίας, όπως διαγράφεται από την διάταξη του άρθρου 11 Ν. 2472/1997 και την κατ' εξουσιοδότηση του νόμου αυτού εκδοθείσα υπ' αρ. 1/1999 κανονιστική πράξη της Αρχής Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (ΦΕΚ 555 Β76.5.1999), για ενημέρωση του υποκειμένου-ήδη ενάγοντα, ανεξαρτήτως συγκατάθεσης του, ουδόλως τηρήθηκε, προ της διαβίβασης, στις 17.2.2015, των προσωπικών του δεδομένων στην ως άνω μη διάδικο ανώνυμη εταιρεία. Τέλος αποδείχθηκε ότι, από την ως άνω παράνομη και υπαίτια συμπεριφορά της εναγόμενης, που όφειλε να γνωρίζει τον κίνδυνο επέλευσης ζημίας λόγω των παρανόμων παραλείψεων και πράξεων της, ο ενάγων  υπέστη αιτιωδώς συνυφασμένη ηθική βλάβη για την αποκατάσταση της οποίας, δεδομένων των συνθηκών τέλεσης, της έντασης της προσβολής της έννομης τάξης, του βαθμού πταίσματος της, του κοινωνικού ρόλου, που οφείλει να επιτελεί, πέραν του οικονομικού/ κερδοσκοπικού, του οικονομικού μεγέθους της και της κοινωνικής και οικονομικής θέσης του ενάγοντα, η καταβλητέα εύλογη χρηματική ικανοποίηση πρέπει να οριστεί στο ποσό των 5.869, 40 ευρώ (ΑΠ 1740/2013, ΕφΑΘ 1437/2014, 3833/2003 ΤΝΠ Νόμος). Ο ισχυρισμός της εναγόμενης ότι δεν είχε δυνατότητα πρόβλεψης της βλάβης του ενάγοντος (άρθρο 23 παρ. 1 εδ. 3 Ν. 2472/1997) και σε κάθε περίπτωση ότι η ως άνω συμπεριφορά της οφείλεται σε αμέλεια (άρθρο 23 παρ. 2 Ν. 2472/1997) τυγχάνει απορριπτέος καθόσον μόνη η νόμιμη συλλογή των προσωπικών δεδομένων από την εναγομένη-υπεύθυνο επεξεργασίας, κατά την κατάρτιση της ως άνω σύμβασης, δεν αίρει την υποχρέωση της προς τήρηση και των λοιπών διατάξεων του Ν. 2472/1997, ήτοι του άρθρου 11 και συνεπώς και την δυνατότητα πρόβλεψης της, εκ της παραβάσεως της, βλάβης του ενάγοντα η δε ευθύνη της είναι νόθος αντικειμενική και ουδόλως αποδείχθηκε από την ίδια, φέρουσα το σχετικό βάρος, ότι ανυπαίτια αγνοούσε τα ως άνω θεμελιωτικά   της   υπαιτιότητας της πραγματικά γεγονότα. Ωσαύτως απορριπτέος τυγχάνει ο επικουρικά προβαλλόμενος από την εναγόμενη ισχυρισμός ότι το δικαίωμα του ενάγοντα ασκείται καθ' υπέρβαση των τιθέμενων από την διάταξη του άρθρου 281 ΑΚ ορίων, καθόσον μόνον το γεγονός ότι ο τελευταίος (ενάγων), όπως προκύπτει από την ΑΠ …/9.3.2015 αίτηση του προς την εναγόμενη, εξ' αφορμής σχετικής πρότασης, που του έγινε από την ως άνω εταιρεία «ΡΑΝΟ INFORM Α.Ε.», ρύθμισε επωφελώς και τελικώς εξόφλησε την οφειλή του από την κατά τα ανωτέρω χορηγηθείσα πιστωτική κάρτα ουδόλως καθιστά την άσκηση του δικαιώματος του καταχρηστική.

Κατόπιν αυτών η κρινόμενη θα πρέπει να γίνει δεκτή ως ουσιαστικά βάσιμη και να υποχρεωθεί η εναγόμενη να καταβάλλει στον ενάγοντα, κατά στρογγυλοποίηση, το ποσόν των 5.869 ευρώ με τον νόμιμο τόκο από την επίδοση της κρινόμενης.. Το παρεπόμενο αίτημα περί κήρυξης της παρούσας προσωρινά εκτελεστής θα πρέπει να απορριφθεί καθόσον, κατά την εκτίμηση του Δικαστηρίου, δεν συντρέχουν εξαιρετικοί λόγοι προς τούτο (907, 908 ΚΠολΔ). Η εναγόμενη θα πρέπει, λόγω της ήττας της (176 ΚΠολΔ) να καταδικασθεί στην δικαστική δαπάνη του ενάγοντα, κατά τα οριζόμενα στο διατακτικό.


ΓΙΑ ΤΟΥΣ ΛΟΓΟΥΣ ΑΥΤΟΥΣ

ΔΙΚΑΖΕΙ με παρόντες τους διαδίκους.

ΔΕΧΕΤΑΙ την αγωγή.

ΥΠΟΧΡΕΩΝΕΙ την εναγόμενη να καταβάλλει στον ενάγοντα το ποσόν των πέντε χιλιάδων οκτακοσίων εξήντα εννέα (5.869) ευρώ, με τον νόμιμο τόκο από την επίδοση της αγωγής.

(...)




Σχόλιο:

Με το ν. 3758/2009, ο οποίος τροποποιήθηκε με το άρθρο 36 του ν. 4038/2012, θεσπίσθηκαν αρχές συναλλακτικής συμπεριφοράς, κανόνες λειτουργίας και κρατικής εποπτείας των Εταιριών Ενημέρωσης οφειλών (εφεξής: εταιρίες) για ληξιπρόθεσμες απαιτήσεις, καθώς και άλλα θέματα. Η νομοθέτηση μηχανισμών ελέγχου της υπηρεσίας οφειλετών έγινε, καθώς προηγήθηκαν καταγγελίες πολιτών για καταχρηστικές πρακτικές εκ μέρους των εν λόγω εταιριών [βλ. και πρόσφατα, λ.χ. http://www.tovima.gr/finance/article/?aid=536944]. 

Με τον ίδιο νόμο προβλέπεται - σχεδόν αυτονοήτως - ότι οι Εταιρείες λειτουργούν σύμφωνα με τον παρόντα νόμο και υποχρεούνται να τηρούν τις διατάξεις της κείμενης νομοθεσίας περί προστασίας του καταναλωτή, περί προστασίας της ιδιωτικής ζωής, του τραπεζικού απορρήτου, της καλής πίστης και των συναλλακτικών ηθών, ώστε να διασφαλίζεται η νομιμότητα της δράσης τους στην αγορά με ταυτόχρονη διασφάλιση του σεβασμού της προσωπικότητας και της οικονομικής ελευθερίας των οφειλετών.

Πιο ειδικά, οι αρχές που διέπουν την ενημέρωση των οφειλετών προβλέπονται στο άρθρο 4. Συγκεκριμένα προβλέπεται ότι "η παρέμβαση των Εταιρειών αφορά αποκλειστικά και μόνο στην ενημέρωση των οφειλετών για την ύπαρξη ληξιπρόθεσμων οφειλών τους έναντι δανειστών και τη διαπραγμάτευση του χρόνου, του τρόπου και των λοιπών όρων αποπληρωμής αυτών, κατ' εντολή και για λογαριασμό των δανειστών. " και απαγορεύεται η είσπραξη από τις εταιρίες ληξιπρόθεσμων οφειλών (παρ. 2).

Πιο πέρα προβλέπεται ότι "πριν από κάθε ενέργεια Ενημέρωσης απαιτείται η από τον δανειστή προς τον οφειλέτη επιβεβαίωση των οφειλών με κάθε διαθέσιμο τρόπο και η ταυτοποίηση του οφειλέτη, καθώς και η ενημέρωσή του για τη διαβίβαση των δεδομένων του στην Εταιρεία συμφώνως και προς το άρθρο 11 του ν. 2472/1997, ως εκάστοτε αυτός ισχύει".

Η ως άνω απόφαση του Ειρηνοδικείου Αθηνών δέχθηκε ότι η εναγόμενη Τραπεζική εταιρία, με το να διαβιβάσει σε εταιρία ενημέρωσης οφειλών  λόγω ανώμαλης εξέλιξης της ενοχής από την ως άνω πιστωτική κάρτα, ήτοι υπερημερίας του ενάγοντα, τα απλά προσωπικά του δεδομένα και το ύψος της ληξιπρόθεσμης οφειλής του, στην ως άνω εταιρεία, η οποία προέβη σε χρήση αυτών, καλώντας τον τηλεφωνικά, δια προστηθέντος υπαλλήλου της, στις 17.2.2015, παραβίασε τη διάταξη του άρθρου 11 Ν. 2472/1997 και της, κατ' εξουσιοδότηση αυτού, εκδοθείσας υπ' αρ. 1/1999 κανονιστικής πράξης της Αρχής Προστασίας Δεδομένων Προσωπικού Χαρακτήρα και ως εκ τούτου, υπέστη ηθική βλάβη.

 Ορθώς, βεβαίως, έκρινε έτσι η απόφαση, ωστόσο, εν προκειμένω έχουμε παραβίαση της διάταξης του άρθρου 4 παρ. 4 εδ. α΄ ν. 3758/2009, στην οποία προβλέπεται ρητά η υποχρέωση ενημέρωσης του οφειλέτη για τη διαβίβαση των δεδομένων προς εταιρία ενημέρωσης οφειλών. Όσον αφορά τη νομιμότητα της διαβίβασης δεδομένων, αυτή καλύπτεται από τον σχετικό συμβατικό όρο (υπ' αριθ. 23 όρο), όπως δέχθηκε η απόφαση, δίχως να αιτιολογεί, ωστόσο, την κρίση της αυτή με επίκληση του ν. 2472/1997.

Κατά την άποψή μας, ο συμβατικός όρος βάσει του οποίου γίνεται γνωστοποίηση προσωπικών δεδομένων σε τρίτο πρόσωπο, δεν μπορεί να καταστήσει καθεαυτός νόμιμη την επεξεργασία, ιδίως διότι ο ν. 2472/1997 δεν προβλέπει ότι η επεξεργασία μπορεί να νομιμοποιείται με σύμβαση, ενώ η διάταξη του άρθρου 5 παρ. 2 α΄ δεν δύναται να καλύψει το σχετικό κενό. Το κενό αυτό μπορεί να καλυφθεί με τη διάταξη του άρθρου 5 παρ. 1 του ίδιου νόμου, καθ' ότι ο συμβατικός όρος καλύπτεται από τη συγκατάθεση του υποκειμένου των δεδομένων.


Ιωάννης Ιγγλεζάκης, Αν. Καθηγητής Νομ. Σχολής ΑΠΘ





Πέμπτη 4 Φεβρουαρίου 2016

EU Commission and United States agree on new framework for transatlantic data flows: EU-US Privacy Shield


Press release

The European Commission and the United States have agreed on a new framework for transatlantic data flows: the EU-US Privacy Shield.
Today, the College of Commissioners approved the political agreement reached and has mandated Vice-President Ansip and CommissionerJourová to prepare the necessary steps to put in place the new arrangement. This new framework will protect the fundamental rights of Europeans where their data is transferred to the United States and ensure legal certainty for businesses. 
The EU-US Privacy Shield reflects the requirements set out by the European Court of Justice in its ruling on 6 October 2015, which declared the old Safe Harbour framework invalid. The new arrangement will provide stronger obligations on companies in the U.S. to protect the personal data of Europeans and stronger monitoring and enforcement by the U.S. Department of Commerce and Federal Trade Commission (FTC), including through increased cooperation with European Data Protection Authorities. The new arrangement includes commitments by the U.S. that possibilities under U.S. law for public authorities to access personal data transferred under the new arrangement will be subject to clear conditions, limitations and oversight, preventing generalised access. Europeans will have the possibility to raise any enquiry or complaint in this context with a dedicated new Ombudsperson. 
Vice-President Ansip said: "We have agreed on a new strong framework on data flows with the US. Our people can be sure that their personal data is fully protected. Our businesses, especially the smallest ones, have the legal certainty they need to develop their activities across the Atlantic. We have a duty to check and we will closely monitor the new arrangement to make sure it keeps delivering. Today's decision helps us build a Digital Single Market in the EU, a trusted and dynamic online environment; it further strengthens our close partnership with the US. We will work now to put it in place as soon as possible."
Commissioner Jourová said: "The new EU-US Privacy Shield will protect the fundamental rights of Europeans when their personal data is transferred to U.S. companies. For the first time ever, the United States has given the EU binding assurances that the access of public authorities for national security purposes will be subject to clear limitations, safeguards and oversight mechanisms. Also for the first time, EU citizens will benefit from redress mechanisms in this area. In the context of the negotiations for this agreement, the US has assured that it does not conduct mass or indiscriminate surveillance of Europeans. We have established an annual joint review in order to closely monitor the implementation of these commitments."
The new arrangement will include the following elements: 
  • Strong obligations on companies handling Europeans' personal data and robust enforcement: U.S. companies wishing to import personal data from Europe will need to commit to robust obligations on how personal data is processed and individual rights are guaranteed. The Department of Commerce will monitor that companies publish their commitments, which makes them enforceable under U.S. law by the US. Federal Trade Commission. In addition, any company handling human resources data from Europe has to commit to comply with decisions by European DPAs. 
  • Clear safeguards and transparency obligations on U.S. government access: For the first time, the US has given the EU written assurances that the access of public authorities for law enforcement and national security will be subject to clear limitations, safeguards and oversight mechanisms. These exceptions must be used only to the extent necessary and proportionate. The U.S. has ruled out indiscriminate mass surveillance on the personal data transferred to the US under the new arrangement. To regularly monitor the functioning of the arrangement there will be an annual joint review, which will also include the issue of national security access. The European Commission and the U.S. Department of Commerce will conduct the review and invite national intelligence experts from the U.S. and European Data Protection Authorities to it. 
  • Effective protection of EU citizens' rights with several redress possibilities: Any citizen who considers that their data has been misused under the new arrangement will have several redress possibilities. Companies have deadlines to reply to complaints. European DPAs can refer complaints to the Department of Commerce and the Federal Trade Commission. In addition, Alternative Dispute resolution will be free of charge. For complaints on possible access by national intelligence authorities, a new Ombudsperson will be created. 
Next steps
The College has today mandated Vice-President Ansip and Commissioner Jourová to prepare a draft "adequacy decision" in the coming weeks, which could then be adopted by the College after obtaining the advice of the Article 29 Working Party and after consulting a committee composed of representatives of the Member States. In the meantime, the U.S. side will make the necessary preparations to put in place the new framework, monitoring mechanisms and new Ombudsman. 
Background
On 6 October, the Court of Justice declared in the Schrems case that Commission’s Decision on the Safe Harbour arrangement was invalid. The judgment confirmed the Commission's approach since November 2013 to review the Safe Harbour arrangement, to ensure in practice a sufficient level of data protection as required by EU law.
On 15 October, Vice-President Ansip, Commissioners Oettinger and Jourová met business and industry representatives who asked for a clear and uniform interpretation of the ruling, as well as more clarity on the instruments they could use to transfer data.
On 16 October, the 28 national data protection authorities (Article 29 Working Party) issued a statement on the consequences of the judgment.
On 6 November, the Commission issued guidance for companies on the possibilities of transatlantic data transfers following the ruling until a new framework is put in place.
On 2 December, the College of Commissioners discussed the progress of the negotiations. Commissioner Jourová received a mandate to pursue the negotiations on a renewed and safe framework with the US.

Δευτέρα 1 Φεβρουαρίου 2016

Δίκαιο της πληροφορικής - Συμπλήρωμα



προτείνετε αυτό το προϊόν

Ο κλάδος του δικαίου πληροφορικής δεν είναι μόνο ένας νεότευκτος κλάδος του δικαίου, αλλά είναι και ταχύτατα αναπτυσσόμενος. Στα πλαίσιά του εντάσσεται μια ποικιλία νομικών ζητημάτων, με επίκεντρο τις νέες τεχνολογίες. Λόγω, δε, της εξέλιξης της τεχνολογίας, καθίστανται αναγκαίες οι συχνές αναθεωρήσεις της νομοθεσίας, όπως και η έκδοση δικαστικών αποφάσεων που αφορούν επίκαιρα ζητήματα.
Το πρώτο συμπλήρωμα στη δεύτερη έκδοση του βιβλίου (2008) κυκλοφόρησε το 2013, με σκοπό να παρέχει ενημέρωση για τις νομοθετικές αλλαγές που εμφιλοχώρησαν στο διάστημα που μεσολάβησε από την έκδοση αυτή. Ωστόσο και στη συνέχεια, ανέκυψαν νέες νομοθετικές και νομολογιακές εξελίξεις, γεγονός που επέβαλε την έκδοση νέου συμπληρώματος. Στο παρόν συμπλήρωμα περιλαμβάνεται η ύλη του πρώτου συμπληρώματος, στο βαθμό που η σχετική νομοθεσία δεν έχει τροποποιηθεί, ενώ παρέχεται ενημέρωση και για τις πλέον τρέχουσες εξελίξεις. Σημειώνεται ότι οι παραπομπές στο βιβλίο γίνονται με αναφορά στον αριθμό περιθωρίου.





ISBN/ISSN:978-960-568-370-2
Σελίδες:IV + 46
Copyright:2016














Τρίτη 12 Ιανουαρίου 2016

ECHR Bărbulescu v. Romania (61496/08)


In the Chamber's judgement in the case of  Bărbulescu v. Romania, the European Court of Human Rights held, by six votes to one, that there had been: no violation of Article 8 (right to respect for private and family life, the home and correspondence) of the European Convention on Human Rights. The case concerned Mr Bărbulescu’s dismissal by his employer, a private company, for having used the company’s Internet for personal purposes during working hours in breach of internal regulations. The Court found, in particular, that Mr Bărbulescu’s private life and correspondence had been engaged. However his employer’s monitoring of his communications had been reasonable in the context of disciplinary proceedings.

Facts of the case

The applicant, Bogdan Mihai Bărbulescu, is a Romanian national who was born in 1979 and lives in Bucharest. From 1 August 2004 until 6 August 2007 Mr Bărbulescu was employed by a private company as an engineer in charge of sales. At his employers’ request, he created a Yahoo Messenger account for the purpose of responding to clients’ enquiries. On 13 July 2007 Mr Bărbulescu was informed by his employer that his Yahoo Messenger communications had been monitored from 5 to 13 July 2007 and that the records showed he had used the internet for personal purposes. Mr Bărbulescu replied in writing that he had only used the service for professional purposes. He was presented with a transcript of his communication including transcripts of messages he had exchanged with his brother and his fiancée relating to personal matters such as his health and sex life. On 1 August 2007 the employer terminated Mr Bărbulescu’s employment contract for breach of the company’s internal regulations that prohibited the use of company resources for personal purposes. Mr Bărbulescu challenged his employer’s decision before the courts complaining that the decision to terminate his contract was null and void as his employer had violated his right to correspondence in accessing his communications in breach of the Constitution and Criminal Code. His complaint was dismissed on the grounds that the employer had complied with the dismissal proceedings provided for by the Labour Code and that Mr Bărbulescu had been duly informed of the company’s regulations. Mr Bărbulescu appealed claiming that e-mails were protected by Article 8 (right to respect for private and family life, the home and correspondence) of the European Convention and that the first-instance court had not allowed him to call witnesses to prove that his employer had not suffered as a result of his actions. In a final decision on 17 June 2008 the Court of Appeal dismissed his appeal and, relying on EU law, held that the employer’s conduct had been reasonable and that the monitoring of Mr Bărbulescu’s communications had been the only method of establishing whether there had been a disciplinary breach. Furthermore, the Court of Appeal held that the evidence before the first-instance court had been sufficient.

Decision of the Court 

Article 8
The Court considered that the fact that the employer had accessed Mr Bărbulescu’s professional Internet account and that the record of his communications had been used in the domestic litigation to prove the employer’s case was sufficient to engage the applicant’s “private life” and “correspondence”. It therefore found that Article 8 was applicable. Firstly, however, it did not find it unreasonable that an employer would want to verify that employees were completing their professional tasks during working hours and noted that the employer had accessed Mr Bărbulescu’s account in the belief that it contained client-related communications. Secondly, Mr Bărbulescu had been able to raise his arguments related to the alleged breach of his private life and correspondence before the domestic courts and there was no mention in the ensuing decisions of the actual content of the communications. Notably, the domestic courts had used the transcript of his communications only to the extent that it proved that he had used the company’s computer for his own private purposes during working hours and the identity of the people with whom he had communicated was not revealed. The Court therefore concluded that the domestic courts had struck a fair balance between Mr Bărbulescu’s right to respect for his private life and correspondence under Article 8 and the interests of his employer. There had therefore been no violation of Article 8 of the European Convention.


Article 6
The Court declared this complaint manifestly ill-founded as Mr Bărbulescu’s concerns had been considered by the Court of Appeal which found them, in a sufficiently reasoned decision, to be irrelevant.