Skip to content

News with true faith

World

Greek Court Rules Diavgeia Employee Data Post Illegal

A Greek court has upheld sanctions against a public body for illegally publishing identifiable employee conduct details on the Diavgeia portal.

Greek Court Rules Diavgeia Employee Data Post Illegal

A Greek court has ruled that a public law entity unlawfully processed employee personal data by posting a board decision on the Diavgeia portal.

The Hellenic Data Protection Authority had previously ordered the deletion of the decision from the national transparency platform and imposed administrative fines on the organization for privacy breaches under the General Data Protection Regulation.

The case centered on a resolution adopted by the board of directors of a legal entity governed by public law in Greece. The board resolution granted authorization to an executive body to take administrative measures regarding the workplace conduct of an employee.

Following a complaint, the data protection regulator found that the public body engaged in illegal personal data processing under Article 6 of the GDPR, failed to answer a formal request submitted by the employee under Article 12, and failed to satisfy a request for data erasure under Article 17.

Crucially, the published decision did not state the full name of the employee. However, the text included information closely linked to the individual, including his name initials, specific details of his employment status, and references to his workplace behavior.

When evaluated as a whole and published on a freely accessible website, these details enabled the employee to be identified by colleagues, professional acquaintances, and members of his social circle.

The regulator and the court concluded that identification was also possible without disproportionate effort by an unlimited number of internet users, owing to employment contract records on Diavgeia and available online search tools. The legal standard established that proving third parties actually identified the worker was unnecessary, as it was sufficient that the data subject was identifiable under the processing circumstances.

Legal Basis and Scope of Public Transparency

The court determined that uploading the decision constituted automated processing of personal data, incorporating evaluative assessments and opinions regarding employee conduct rather than neutral administrative facts.

In its defense, the public authority cited Article 6(1)(c) of the GDPR, asserting that it had a legal obligation to publish administrative acts on the Diavgeia portal.

However, the ruling established that the specific board resolution did not fall within the categories of documents that public entities are required by law to publish.

Under Article 2, paragraph 4 of Law 3861/2010, the Greek statute governing the Diavgeia system, mandatory public uploads are explicitly and exhaustively listed. These include fixed-term private law employment contracts, contract renewals, and contract terminations. Other documents linked to employment procedures require a specific legal provision to justify publication, which was absent in this case.

Legal analyst and attorney Souzana Klimentidi highlighted that when personal data processing relies on a statutory obligation rather than consent, the legal basis must be interpreted strictly. The governing provision must be clear, precise, and predictable, meaning a general notion in favor of administrative transparency cannot create a publishing duty.

The court also held that advisory opinions from the State Legal Council concerning different categories of administrative acts cannot establish a publishing obligation for unrelated decisions. Furthermore, any excusable error by public officials regarding their duties does not negate the breach, as processing lawfulness is judged objectively at the time of publication.

Rejection of Alternative GDPR Legal Grounds

The public authority was barred from relying on Article 6(1)(f) of the GDPR regarding legitimate interests, as this ground does not apply to public authorities performing their official duties.

Similarly, the entity could not justify the publication under Article 6(1)(b) of the GDPR regarding contractual obligations. The existence of an employment relationship does not grant a public employer authority to publish employee details on Diavgeia without specific statutory authorization.

The public body also claimed the employee had consented to the publication, but it failed to present evidence demonstrating free, specific, explicit, and fully informed consent as required by the GDPR.

Court Upholds Fines and Refers Erasure Fine Issue

The court upheld the legality of administrative fines imposed for breaches of Article 6 regarding unlawful processing and Article 12 regarding the failure to respond to the data subject's request.

The court also confirmed the regulator's order requiring the removal of the decision from Diavgeia under the corrective powers of Article 58(2) of the GDPR.

However, the court raised an ex officio question regarding the legality of the fine imposed for violating Article 17, the right to erasure. Under Article 83(7) of the GDPR, member states may determine whether public authorities can be fined for data protection breaches.

In Greece, Article 39 of Law 4624/2019 established public sector fines for specific violations, including Articles 5, 6, and 12, but omitted Article 17. Consequently, the court referred the issue of the Article 17 fine to a seven-member panel to determine whether a statutory basis exists for fining public bodies under that provision.

Background on Greek Transparency and Privacy Rules

The Diavgeia portal was created under Law 3861/2010 to enforce transparency across Greek public administration by requiring state bodies, ministries, and municipalities to publish executive acts, decisions, and public contracts online.

Supervision of data protection across public institutions in Greece is conducted by the Hellenic Data Protection Authority, an independent constitutional authority responsible for enforcing national privacy legislation and EU data regulations.

As Klimentidi noted, the ruling reinforces the boundary between administrative transparency and individual privacy rights, ensuring that public portals cannot operate as unrestricted repositories for identifiable employee conduct records without clear statutory mandates.

Related

Leave a comment

Your email address will not be published. Required fields are marked *