General Data Protection Regulation

The law firm “Yiannis & Maria Nicolaides & Associates”, hereinafter referred to as the “Firm”, strictly adheres to the applicable legislation in relation to the protection of personal data of natural persons. For this reason, in the context of the current national and EU legal framework governing the protection of personal data, in particular the EU General Data Protection Regulation – Regulation 2016/679 (GDPR) and Law 4624/2019, herein follows a full update in relation to the collection and processing of your personal data by our Firm in general and regarding our website (www.noalaw.gr).

This Policy, in no way, replaces or alters the obligation to maintain legal confidentiality. It should be noted that the confidentiality obligations deriving from the principle of security, as specified in particular in Article 32 of the GDPR, converge with the provisions of the Code of Conduct on confidentiality governing the legal profession.

ARTICLE 1 Our Firm as a Data Controller and as a Processor

Our Firm, in the context of exercising its activity, acts either in the capacity of the Data Controller or in the capacity of the Data Processor.

Indicatively, our Firm acts as a Data Controller with regard to the personal data of our staff and associates, as well as in cases where it represents its clients before judicial and other authorities, while it is a Processor in those cases where it provides legal advice and/or services of a Data Protection Officer as an external partner of legal entities under private or public law and in this context personal data is transmitted to us by the These legal entities are our clients..

ARTICLE 2 – General Principles for the Processing of Personal Data

When our Firm processes personal data, either in the capacity of the Data Controller or in the capacity of the Data Processor, it ensures:

    1. To have legally collected and processed such data, by virtue of the provisions of the existing legislation and the conditions it sets.
    2. To process the necessary personal data and only for specified, explicit and legitimate purposes.
    3. Not to share personal data with third parties, except when necessary and permissible under existing legislation. In this case, it discloses only the data that is strictly necessary in relation to the purpose of the disclosure, and ensures that the data subjects are informed before proceeding with it.
    4. Taking appropriate technical and organisational measures to ensure that personal data are processed in a way that guarantees the appropriate security of personal data, including their protection against unauthorised or unlawful processing and accidental loss, destruction or damage. In addition, to periodically review the adequacy and effectiveness of these measures.
    5. Making the necessary efforts to ensure that the personal data it maintains and processes is always accurate and up-to-date.
    6. Not retaining the personal data it collects for a longer period than required by the purposes for which it was collected and processed. However, it may also retain them for a longer period of time if the processing of such data is necessary:a) for the establishment, exercise or support of legal claims of our Firm’s clients in the context of the exercise of the legal function by our partners and associates.b) for compliance with a legal obligation that imposes the processing based on a provision of law) for reasons of public interest.

ARTICLE 3 – Data that may be collected

Our Firm, in the context of its activities and in accordance with the Lawyers’ Code, may collect personal data of both our associate lawyers and other associates, as well as the principals and/or opponents of our clients, as well as other natural persons with whom we transact in the context of the exercise of the legal function. These individuals may be principals and/or adversaries, external partners, owners of sole proprietorships, legal or other representatives of legal entities, as well as employees or interested third parties, but also in general associates of those with whom the Firm transacts.

Specifically, the information collected directly or indirectly may include full names, father’s names, maiden names, years of birth, places of birth, gender, nationality, home addresses, work addresses, email address, telephone numbers and contact fax, Identity Card Numbers (ID), Tax Identification Numbers (TIN), Business Identification Numbers (if any), Social Security Numbers and other information of social security fund registers, bank account number and/or details credit/debit bank cards, marital status data, education and vocational training data.

Also, it is possible that this data do not always belong to direct traders with our Firm but also to third parties, adversaries or not.

ARTICLE 4 – Special Categories of Personal Data

On a case-by-case basis, in the context of handling cases and always within the framework of the exercise of the legal function, our Firm may collect and process data belonging to special categories of personal data, such as data relating to health, copies of criminal records and other relevant judicial data.

ARTICLE 5 – Lawful bases for processing

The processing of personal data made available to our Firm takes place:

  1. in the context of each mandate provided to us to represent and defend the rights and interests of our clients,
  2. in the context of fulfilling contractual terms for the provision of legal services.
  3. in the context of compliance with a legal obligation, and
  4. in the context of defending the legitimate interests of our Firm or its clients and partners.

In particular, in cases of special categories of personal data (sensitive personal data), our Firm carries out the appropriate processing that is necessary for the establishment, exercise and/or support of legal claims of its clients or associates.

ARTICLE 6 – Purposes of Processing

Pursuant to the GDPR, in conjunction with the Lawyers’ Code, as well as its statutory purpose, the activity of our Firm lies in the provision of legal services in general.

In this context, our Firm may collect and process personal data, in order to represent and defend its clients in any court, authority or service or out-of-court settlement, to provide legal advice and opinions and to take any legal action in the context of exercising the duties it has undertaken towards its clients;  on the basis of the provisions of the current legislation.

Furthermore, our Firm, in the context of fulfilling its employer obligations, collects and processes personal data of its employees, while at the same time, it collects and processes personal data of its partners in general in the context of the business relationships it develops.

 

ARTICLE 7 – Cookie Policy

Our Firm guarantees the respect of the privacy of the visitors of our website (www.noalaw.gr ) during their browsing on it. In this context, we inform you that cookies are not used.

ARTICLE 8 – Disclaimer for Third Party Websites

The Firm’s website (www.noalaw.gr) may contain links that redirect the visitor to third-party websites. The Firm does not control these third-party websites and is not responsible for the content posted on them. The Firm is not responsible for the privacy practices of third parties or for the content of third-party websites.

ARTICLE 9 – Transfer to Third Parties

It is possible that the Firm will transmit the above data to third parties, especially when this is provided for by the existing legislation as its obligation or, alternatively, in accordance with the guarantees provided for in the existing legislation. In such cases, it shall adequately inform data subjects before making such a transfer.

In the event that the transfer concerns a country outside the European Union (EU) or the European Economic Area (EEA), the Firm must check whether:

  • The Commission has adopted a relevant adequacy decision for the third country to which the transfer will take place.
  • The appropriate safeguards are respected in accordance with the Regulation for the transmission of such data.

Otherwise, the transfer to a third country is prohibited and the Firm may not transfer personal data to it, unless one of the special derogations provided for by the relevant regulatory framework applies.

ARTICLE 10 – Data Retention Period

The personal data we collect in the context of exercising our activity are kept for a predetermined and limited period of time, depending on the purpose of the processing, after which the data are deleted from the Firm’s records, unless a different retention period is provided for or permitted by the applicable legislation.

ARTICLE 11 – Rights of Personal Data Subjects

The Firm, in addition to the strict observance of legal confidentiality, ensures that data subjects can exercise the rights recognized by the applicable legislation. These rights are as follows:

  1. The Right to access and be informed about the data.
  2. The Right to rectification of data.
  3. The Right to delete data.
  4. The Right to Restriction of Data Processing
  5. The Right to object to the processing of data
  6. The Right to Data Portability

In case it is provided for by the GDPR, our Firm may refuse to satisfy your request regarding your personal data.

ARTICLE 12 – Exercising your rights

In case you wish to exercise your rights deriving from the existing legislation, according to the above, you may submit your request in any of the following ways, by contacting the Firm’s Data Protection Officer (DPO).

By post

GIANNIS & MARIA NIKOLAIDIS & ASSOCIATES Law Firm Address: 24 Alexandrou Soutsou Street, P.C. 106 74, Athens

By FAX

Fax: 210 3618006

By email

Email: noath@otenet.gr

In addition, if you believe that any right or legal obligation of our Firm regarding the protection of your personal data is violated, you have the right to contact the competent supervisory authority, i.e. the Personal Data Protection Authority (DPA) (www.dpa.gr).

1-3 Kifisias Street, 115 23 Athens, Greece

Tel: +302106475600Fax:+302106475628E-mail: contact@dpa.gr

ARTICLE 13 – Update of Policy

Our Firm reserves the right to amend this Personal Data Protection Policy from time to time and at its discretion. Updated versions of this Personal Data Protection Policy will be posted on our Firm’s website with a date indication.