Selling Land at Kapedes

Field in Kapedes, Nicosia for sale

Clients of our firm are interested in selling land with the potential to build in Kapedes, Nicosia with Registration number 0/10212, Sheet/Plan 39/26, Location MAYROGIA, Plot Number 799 and with parcel area 13 decares and 301 sq.m.

The area is predominantly flat and surrounded by pine trees. There is a small orchard of citrus trees, pomegranate, a large olive tree and mature vine which are appealing features for the gardens of any residential home.

The land falls within two planning zones: H2 building density of 90% and H3 building density of 60%. There is an existing electricity supply and bore hole for water. There is direct access to the land from the main road to Machairas, with an attractive stone wall boundary and pavement.

Price: 700.000 euro

Estate agents are welcomed.

For more information, please send us an email at info@markoullc.com

 

Πωλείται χωράφι στους Καπέδες Λευκωσίας

Πελάτες της εταιρείας μας ενδιαφέρονται να πουλήσουν χωράφι (αγροτεμάχιο) με πεύκα στους Καπέδες, Λευκωσία, με αριθμό εγγραφής 0/10212, Φύλλο/Σχέδιο 39/26, Θέση ΜΑΥΡΟΓΙΑ, Αριθμός τεμαχίου 799 και με εμβαδόν αγροτεμαχίου 13 δεκάρια και 301 τ.μ.

Τιμή: 700.000 ευρώ

Οι κτηματομεσίτες είναι ευπρόσδεκτοι.

Για περισσότερες πληροφορίες, στείλτε μας ένα email στο info@markoullc.com.

When can pseudonymized data be considered anonymized/anonymous, thus falling outside the GDPR?

When pseudonymized data can no longer directly or indirectly identify a physical person and thus fall outside of the scope of the GDPR?

This is the question the General Court of the European Union (EGC) deals with in its ruling of 26 April 2023, case reference: T-557/20. The EGC in its verdict adopts a practical approach which should give relief to modern industry, e-economy and online services.

The EGC held that the answer depends on whether a recipient of pseudonymized data, holds or may reasonable likely acquire information that eventually can identify a natural person.

Background to the decision

The case was brought before the EGC, which can serve as the first instance to the CJEU, by an action of the Single Resolution Board (SRB) based on Article 263 TFEU against the revised decision of the European Data Protection Supervisor (EDPS) following five complaints about the transfer of data collected by the SRB to a third party, which was a consulting company, without informing the complainants, prior to the transfer.

The SRB, namely the central resolution authority within the Banking Union of the EU and under Regulation (EU) No 806/2014 for the framework of a Single Resolution Mechanism, adopted a resolution scheme for a Spanish bank which was bankrupted. In this procedure the SRB called via its website shareholders and creditors that may be affected by the resolution of the bank to register online and provide proof of their ID and their capacity as shareholders or creditors in order to exercise their right to be heard. A relevant privacy notice was also published on its website. At a second stage, the SRB sent an email to those considered to be affected and asked them to complete a form with their opinions. After their names had been replaced with an alphanumeric code consisting of a 33-digit randomly generated identification number, the responses were forwarded to a consultancy firm, which undertook to analyse them. However, the privacy notice on the website had no information about this transfer or other recipients except the SRB itself.

On that ground the EDPS, after receiving five complaints, found that the transfer of these coded responses was in violation of Art. 15 (1) (d) of Regulation (EU) 2018/1725 (analogous to GDPR Art. 13 (1)(e) obligation to inform the recipients).

The SRB argued that there was no obligation to provide information, because the transmitted data to the consulting firm did not constitute personal data, but were anonymous data for the consulting firm, even if the information allowing re-identification is not irrevocably eliminated and resides with the original processor of data (i.e. SRB); this is so because the consultancy firm had had no access to the database with original collected data and thus there was no possibility of data subjects being reidentified by the consulting firm.

The judgment

The EGC adopted the SRB’s arguments and annulled the EDPS’s decision.

The criteria according to the Court that Article 3(1) of Regulation 2018/1725 sets to define ‘personal data’ are two:

–             the information ‘relates’ to a natural person, meaning that by reason of its content, purpose or effect is linked to a particular person (with ref. to Nowak case C‑434/16)

–             the information relates to an ‘identified or identifiable’ natural person (with ref. to Breyer case C‑582/14).

As it was stated by the EDPS during the hearing of the case, the additional information necessary to identify the authors of the comments (respondents in the forms) consisted of the alphanumeric code and the identification database of the SRB.

The EGC held that first, the EDPS in his decision had not examined whether opinions within a form, transmitted to the consultancy company, could relate to a particular natural person by their content, purpose and effect. Second, the EDPS wrongfully considered the transmitted data as pseudonymized data (i.e. information related to an identifiable natural person) because he took for granted, that additional information existed, which could identify natural persons. In that respect, he did not take into account that the necessary additional information for re-identification of respondents was in the hands of the SRB and not in the hands of the consulting firm, which had no access to the SRB’s database, which included names and IDs.

The decisive factor for the Court was if the recipient of the disclosed coded data could in a reasonably possible manner or with means likely reasonably to be used, to identify the data subject and not generally, if additional information that could led to identification existed somewhere.

In other words, the possibility of combining additional information for the identification of a natural person is not sufficient on its own; such possibility must not have been prohibited by law or be practically impossible in the sense that it would have required a disproportionate effort in terms of time, cost and man-power effectively rendering the risk of identification  insignificant (see judgment Breyer, C‑582/14 para. 46).

Further and most notably, that possibility according to the EGC must be examined by reference to the position of the recipient of the data and not just by reference to the position of the exporter of the data.

The EGC concluded that the transmitted data was not information relating to an ‘identifiable natural person’; in his decision the EDPS had not examined from the perspective of the consulting firm if the firm “had legal means available to it which could in practice enable it to access the additional information necessary to re-identify the authors of the comments” (see EGC judgment T-557/20 para. 105), which was not the case as the firm was not allowed by law to have access to the identification database of the SRB.

As the EDPS has lodged an appeal against the judgment of the EGC, it remains to be seen if the bold step of the EGC will be endorsed by the CJEU.

Date: 9 October 2024
Author of the Article: Eleni Zafeiri, Lawyer & Legal Consultant at Markou & Co LLC

 

References:

Regulation (EU) 2018/1725 (http://data.europa.eu/eli/reg/2018/1725/oj )

Regulation (EU) 2016/679 (GDPR) (http://data.europa.eu/eli/reg/2016/679/oj )

EGC judgment T-557/20 (62020TJ0557 (europa.eu)

CJEU Case Nowak C-434/16 (EUR-Lex – 62016CJ0434 – EN – EUR-Lex (europa.eu))

CJEU Case Breyer C-582/14 (EUR-Lex – 62014CJ0582 – EN – EUR-Lex (europa.eu))

Οδηγός Συμμόρφωσης με τον ΓΚΠΔ/GDPR

Αναρτήθηκε στην ιστοσελίδα του Γραφείου της Επιτρόπου Προστασίας Προσωπικών Δεδομένων  Οδηγός συμμόρφωσης με τον Γενικό Κανονισμό για την Προστασία Δεδομένων [(ΕΕ) 2016/679 (ΓΚΠΔ)(GDPR)]  (δείτε τον Οδηγό εδώ:  Οδηγός Συμμόρφωσης με τον ΓΚΠΔ) ο οποίος για να είναι πιο κατανοητός και απλός στη χρήση του έχει την μορφή ερωτηματολογίου.
Η κίνηση αυτή της Επιτρόπου είναι πολύ καλή για την καθοδήγηση του κοινού, καθώς οι επιχειρήσεις είτε ενεργούν ως Υπεύθυνοι Επεξεργασίας είτε ως Εκτελούντες μπορούν πλέον να χρησιμοποιούν τον συγκεκριμένο Οδηγό ως ένα εργαλείο για την συμμόρφωση τους με τον Κανονισμό και ταυτοχρόνως και ως ένα μέτρο αυτοαξιολόγησης της συμμόρφωσης τους για να προβαίνουν σε διορθώσεις των πρακτικών/ πολιτικών τους και σε επικαιροποιήσεις όπου χρειάζεται, ώστε να διασφαλίζουν την αποτελεσματική προστασία των προσωπικών δεδομένων που διαχειρίζονται στο πλαίσιο των δραστηριοτήτων τους.
Τονίζεται ότι οι ερωτήσεις δεν είναι εξαντλητικές ούτε εφαρμόζονται όλες σε όλες τις περιπτώσεις επεξεργασίας δεδομένων, αλλά πρέπει να λαμβάνεται υπόψη η κατηγορία  των δεδομένων και η εκάστοτε επεξεργασία που γίνεται, κάτι που διευκρινίζεται και στην ανακοίνωση της Επιτρόπου για τον Οδηγό (δείτε την ανακοίνωση εδώ).

Selling a House in Kaimakli

Clients of our firm are interested in selling a house in Kaimakli of Municipality of Lefkosia /Nicosia, in District of Lefkosia/Nicosia, with registration number 1/645, Block 01, Sheet/Plan 21/1000V01, Location inside the village, Parcel Number 827 and with parcel area 681 sq.m

Price: 200,000 euros

Estate agents are welcomed.

For more information, please send us an email at info@markoullc.com

Tεχνητη νοημοσύνη, καταναλωτές και απάτη

H δικηγόρος του γραφείου μας, Χριστιάνα Μαρκου ήταν καλεσμένη στην εκπομπή του ΡΙΚ, “Επικοινωνίες” με τον δημοσιογράφο Πάρη Ποταμίτη, όπου έγινε συζήτηση για την τεχνητή νοημοσύνη και τις διαδικτυακές άπατες και απαντήθηκαν ερωτήματα τηλεθεατών. Ολόκληρη η εκπομπή μπορεί να ευρεθεί εδώ:

Νωρίτερα, συγκεκριμένα στις 15/3/2024, Παγκόσμια Ημέρα Καταναλωτή, συμμετείχε σε εκδήλωση με θέμα “τεχνητή νοημοσύνη και καταναλωτές” κατόπιν πρόσκλησης του διοργανωτή, συγκεκριμένα της Υπηρεσίας  Προστασίας Καταναλωτή του Υπουργείου Ενέργειας, Εμπορίου και Βιομηχανίας. Ακολουθούν φωτογραφίες από την εκδήλωση:

1 2 3 5
error: Content is protected !!