{"id":1444,"date":"2025-02-17T16:07:02","date_gmt":"2025-02-17T14:07:02","guid":{"rendered":"https:\/\/sgklegal.gr\/?p=1444"},"modified":"2025-02-17T16:12:49","modified_gmt":"2025-02-17T14:12:49","slug":"telework-in-the-public-sector-instructions-and-responsibilities-for-greece","status":"publish","type":"post","link":"https:\/\/sgklegal.gr\/en\/telework-in-the-public-sector-instructions-and-responsibilities-for-greece\/","title":{"rendered":"Telework in the Public Sector: Instructions and Responsibilities for Greece"},"content":{"rendered":"<p data-start=\"61\" data-end=\"355\">The Government Gazette published the <a href=\"file:\/\/\/C:\/Users\/sterg\/Downloads\/20250100019.pdf\">Presidential Decree 13\/2025<\/a>, entitled Protection of Personal Data during Telework in the Public Sector, in accordance with the provisions of paragraph 1 of Article 19 of Law 4807\/2021, as currently in force.<\/p>\n<p data-start=\"357\" data-end=\"895\">In general, the use of telework in the public sector requires that public bodies ensure not only the smooth functioning of services but also the protection of the personal data they process.<br data-start=\"547\" data-end=\"550\" \/>It is recalled that telework in the public sector is primarily governed by the provisions of Law 4807\/2021, as currently in force, by Presidential Decree 13\/2025, as well as by Regulation (EU) 2016\/679 (GDPR) and Law 4624\/2019, as currently in force, with the Guidance 1\/2022 of the Hellenic Data Protection Authority (HDPA) also proving useful.<\/p>\n<h3 data-start=\"897\" data-end=\"936\">I. Obligations of the Public Bodies<\/h3>\n<p data-start=\"938\" data-end=\"1017\">Public bodies, as data controllers, must, prior to issuing a telework decision:<\/p>\n<p data-start=\"1019\" data-end=\"1318\">a. <strong data-start=\"1022\" data-end=\"1077\">Conduct a Data Protection Impact Assessment (DPIA).<\/strong> In the event that the public body utilizes a time-tracking system, the DPIA must demonstrate that no less intrusive measures were available and that this system will not pose a high risk to the rights and freedoms of the body\u2019s teleworkers.<\/p>\n<p data-start=\"1320\" data-end=\"1472\">b. <strong data-start=\"1323\" data-end=\"1472\">Establish policies on proper application usage, operational security of applications, and incident response for mitigating and remedying threats.<\/strong><\/p>\n<p data-start=\"1474\" data-end=\"1732\">c. <strong data-start=\"1477\" data-end=\"1591\">It is advisable to have a policy outlining the minimum criteria that the teleworkers\u2019 \u201cWorkstation\u201d must meet.<\/strong> In cases where it is not possible to provide an appropriate workstation, it is recommended to adopt a \u201cBring Your Own Device\u201d (BYOD) policy.<\/p>\n<p data-start=\"1734\" data-end=\"1925\">They must promptly and appropriately inform the data subjects (for example, teleworkers, managers, third parties) in accordance with at least the provisions of Articles 13 and 14 of the GDPR.<\/p>\n<p data-start=\"1927\" data-end=\"2240\">They must be aware of the countries in which service providers\u2019 servers are located, so as to apply the provisions of Chapter V of the GDPR in combination with the relevant case law of the European Data Protection Board (EDPB) and the corresponding acts of the European Data Protection Board (hereinafter \u201cEDPB\u201d).<\/p>\n<p data-start=\"2242\" data-end=\"2525\">They must provide clear instructions and training to teleworkers (in an accessible and understandable format) regarding the proper configuration and security of the workstation (e.g., policies, procedures, workspace arrangement, etc.), as well as offer specialized technical support.<\/p>\n<p data-start=\"2527\" data-end=\"2726\">They must implement secure access systems (such as VPNs), keep security software (e.g., antivirus, firewalls, etc.) up to date, and take measures to prevent unauthorized access or alteration of data.<\/p>\n<p data-start=\"2728\" data-end=\"3068\">They must equip teleworkers with an appropriate \u201cWorkstation\u201d or approve the use of personal equipment (BYOD). However, it is essential that a risk assessment be carried out to ensure that the approved device meets the necessary specifications. Furthermore, the public body may restrict access to systems it deems \u201cCritical\u201d or \u201cSensitive.\u201d<\/p>\n<p data-start=\"3070\" data-end=\"3375\">They must establish procedures for time tracking and recording (e.g., teleconferences). It is worth noting that the Presidential Decree allows bodies to take measures under \u201cproportionate\u201d monitoring of work. The monitoring tools should be included in the DPIA and accompanied by appropriate notification.<\/p>\n<p data-start=\"3377\" data-end=\"3561\">In the case of approving a teleworker\u2019s request to work from a country outside the European Economic Area (EEA), the public body must, beforehand, conduct a Transfer Impact Assessment.<\/p>\n<h3 data-start=\"3563\" data-end=\"3602\">II. Measures during Teleconferences<\/h3>\n<p data-start=\"3604\" data-end=\"3856\">The recording of teleconferences is, as a general rule, prohibited. By exception, recording is permitted when the content is likely to cause legal consequences for the participants and there is a corresponding obligation to keep minutes. In such cases:<\/p>\n<ul data-start=\"3858\" data-end=\"4686\">\n<li data-start=\"3858\" data-end=\"3952\">There must be prior notification to the participants (particularly via an information memo).<\/li>\n<li data-start=\"3953\" data-end=\"4036\">The confidentiality of the recordings must be ensured (e.g., through encryption).<\/li>\n<li data-start=\"4037\" data-end=\"4188\">The storage of teleconference recordings on employees\u2019 personal devices is prohibited if those devices have been approved by the body (BYOD devices).<\/li>\n<li data-start=\"4189\" data-end=\"4338\">The retention period of the recording must be defined by the body, with the principle of limiting the storage period being a fundamental criterion.<\/li>\n<li data-start=\"4339\" data-end=\"4452\">Metadata (e.g., participant\u2019s full name, connection time and date, IP address) shall be retained for 12 months.<\/li>\n<li data-start=\"4453\" data-end=\"4686\">At the teleworker\u2019s responsibility, any recordings made on a BYOD device must be deleted according to the relevant procedure established by the body. Such deletion must be accompanied by a written certificate addressed to the body.<\/li>\n<\/ul>\n<h3 data-start=\"4688\" data-end=\"4723\">III. Obligations of Teleworkers<\/h3>\n<p data-start=\"4725\" data-end=\"4753\">Teleworkers are required to:<\/p>\n<p data-start=\"4755\" data-end=\"5377\">\u2022 Follow strictly the policies established by the body, ensuring the confidentiality and security of the data they process.<br data-start=\"4878\" data-end=\"4881\" \/>\u2022 Use exclusively the equipment provided for work or apply the prescribed measures when using personal devices.<br data-start=\"4992\" data-end=\"4995\" \/>\u2022 Ensure that their telework environment meets the security and ergonomic standards.<br data-start=\"5079\" data-end=\"5082\" \/>\u2022 Safeguard the confidential nature of the information they handle. This means taking specific measures to prevent the disclosure of sensitive information to unauthorized persons. An illustrative example is printing documents outside the body\u2019s premises, for which the teleworker is responsible.<\/p>\n<p data-start=\"5384\" data-end=\"5917\">The implementation of telework in the public sector is accompanied by strict obligations regarding the protection of personal data. The proper application of security measures, along with the training and awareness of both the bodies and the employees, are crucial factors for the effective management of data and the protection of data subjects\u2019 rights. By adopting these measures, it is ensured that telework is carried out in a secure environment, in compliance with the requirements of the GDPR and the relevant legal provisions.<\/p>\n<p data-start=\"5919\" data-end=\"6101\">In any case, the implementation of the above measures and ensuring compliance with the existing legal framework is a necessary step for protecting personal data in the public sector.<\/p>\n<p data-start=\"6103\" data-end=\"6436\"><strong data-start=\"6103\" data-end=\"6436\">&#8220;Stergios Konstantinou &amp; Associates \u2013 SGKLegal&#8221; Law Office provides specialized legal services in the field of personal data protection, the application of the GDPR, and telework. With extensive experience and in-depth knowledge of the regulatory framework, we offer comprehensive legal advice, representation, and support for:<\/strong><\/p>\n<ul data-start=\"6438\" data-end=\"6839\">\n<li data-start=\"6438\" data-end=\"6493\">Providing DPO for public bodies,<\/li>\n<li data-start=\"6494\" data-end=\"6559\">Conducting DPIAs as well as Transfer Impact Assessments (DTIA),<\/li>\n<li data-start=\"6560\" data-end=\"6664\">Ensuring that bodies comply with the EU and national regulatory framework on personal data protection,<\/li>\n<li data-start=\"6665\" data-end=\"6727\">Drafting and revising security and data protection policies,<\/li>\n<li data-start=\"6728\" data-end=\"6839\">Addressing legal issues arising from the use of personal equipment (BYOD) and remote access to critical data.<\/li>\n<\/ul>\n<p data-start=\"6841\" data-end=\"7085\">If you require further legal guidance on implementing data protection measures or on addressing any legal issues in the field of personal data protection, our law firm is at your disposal to provide you with specialized and effective solutions.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Government Gazette published the Presidential Decree 13\/2025, entitled Protection of Personal Data during Telework in the Public Sector, in accordance with the provisions of paragraph 1 of Article 19 of Law 4807\/2021, as currently in force. In general, the use of telework in the public sector requires that public bodies ensure not only the [&hellip;]<\/p>\n","protected":false},"author":4,"featured_media":1442,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[20],"tags":[138,111,137,136],"class_list":["post-1444","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog-en","tag-employees","tag-gdpr-en","tag-personal-data","tag-telework-in-the-public-sector"],"_links":{"self":[{"href":"https:\/\/sgklegal.gr\/en\/wp-json\/wp\/v2\/posts\/1444","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sgklegal.gr\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sgklegal.gr\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sgklegal.gr\/en\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/sgklegal.gr\/en\/wp-json\/wp\/v2\/comments?post=1444"}],"version-history":[{"count":2,"href":"https:\/\/sgklegal.gr\/en\/wp-json\/wp\/v2\/posts\/1444\/revisions"}],"predecessor-version":[{"id":1446,"href":"https:\/\/sgklegal.gr\/en\/wp-json\/wp\/v2\/posts\/1444\/revisions\/1446"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/sgklegal.gr\/en\/wp-json\/wp\/v2\/media\/1442"}],"wp:attachment":[{"href":"https:\/\/sgklegal.gr\/en\/wp-json\/wp\/v2\/media?parent=1444"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sgklegal.gr\/en\/wp-json\/wp\/v2\/categories?post=1444"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sgklegal.gr\/en\/wp-json\/wp\/v2\/tags?post=1444"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}