Interview with the Senior Director Government Affairs of Symantec, Ilias Chantzos

His title merely impresses:  “Senior Director Government Affairs EMEA and APJ, Global CIP and Privacy Advisor” for Symantec, a leader company in the Cybersecurity sector.

In other words, Mr Ilias Chantzos is the person responsible for the intergovernmental relations of Symantec for almost every state of the globe (apart from America), regarding Cybersecurity and data protection issues. Symantec, is one of the leading companies of Cyber Security software worldwide, with hundreds of millions users.

After all, who is not familiar with ‘Norton Internet Security’, Symantec’s most popular and No 1 product for customer protection?

Our first contact was at Data Privacy & Protection Conference where he vividly presented the topic of security breaches and the notification of such breaches. We kindly asked him to share his views on the contemporary developments on the sector as well as the role of NGOs. Despite his busy schedule, he ardently accepted our invitation. We thank him thus, for this extremely interesting interview.

In Greece, entire generations have been brought up in the framework of ‘Rightsism’ and ‘politically correctness’ Τhe crisis we experience is both economical as well as moral.

– HD:The implementation of GDPR and NIS renders Europe as a pioneer in the creation of an integrated, prescriptive setting for Cybersecurity and data protection. What are the next steps?

IC: Initially, the first step is the full implementation of GDPR. And this will become viable through the adaptation of individual rules, such as the guidelines set by the European Data Protection Board (EBPB), the imposition of fines functioning as impediments to the non abidant organisations and through solving issues arising from data transmission, especially to America. The latter acting as a sticking point to mutual interests of great, private companies.Then, adequacy decision with other countries, such as Korea will follow, which will eventually create a great secure flow space and, of course, the final decisions regarding e-privacy Regulation.

-HD: On that occasion, let me ask you about the efforts and the enormous funds that are allegedly spent within lobbying settings from giants in the technology sector such as Google and Apple on favorable e-privacy conformation towards them. 

ΙC: Well, isn’t it reasonable for the companies to be interested about rules that concern and directly regulate them? The industry’s interests are not common, rather than different and dissenter. If, for example, a regulatory context  is favorable for company X, the same context will be less favorable for company Y which operates in a similar but not the same sector. The same happens with e-privacy.

Companies are ‘fighting’ each other because their interests are not common. Ιn Greece there is neither the conscience nor the full picture of the entrepreneurship interest due to the demonising of profit and entrepreneurship that emerges from the past’s ideological stiffness. We should not face the industry as a caricature of a bad capitalist, but realistically through the prism of complicated relations and existing interests. Τhis is the only way that bodies will perform correctly. Let’s give an example that everyone in Greece will easily understand. The legislature regarding dual tanks in sea-going tankers is supposed to protect the environment from oil leaks. This type of legislature is supported by environmental NGOs and shipyards (an industry that mostly pollutes. . . Can you spot the paradox already?) because it can be translated into brand new orders. Ιt will be supported by the coastal states of European Union but it is not useful to Greece (which has the greatest coastline and tremendous tourism), which has mostly sea-going shipping since it augments its costs while having zero income from its shipping.

Can you spot how many contradictions there are in one simple example and we haven’t even discussed about local communities that have suffered sea contamination and the tourism industry.

-HD: You mentioned fine imposition earlier. Recently, we watched huge companies such as Google, British Airways and Marriott being imposed tremendous fines leaving everyone believing that no one is immune within the Cybersecurity and protection of privacy sector. Thus, if the ultimate protection and secure processing of personal data is impossible, then what is at stake here? Why all this is happening?

IC: In the companies that you mentioned, fines were imposed for different reasons. Regarding the Google case, fines were imposed for lawfulness of data processing , and more specifically their collection and processing, whereas in Marriott and British Airlines cases fines were imposed due to restricted data protection measures. There is no absolute security to anything in life, the same stands for security. The authorities though, did evaluate that those companies should have protected data much more attentively. Unfortunately, that was not applied this way and this is the reason that fines were imposed, indicating that privacy protection is a top priority.

-HD: In Greece, why do you believe that fines are not equally high?

IC:There are many factors implicated.Up to date greek companies invested in highly essentials. In state of economic crisis you do what is necessary to ensure smooth operation. Current fines are calling for the national companies which want to sell products and services abroad to answer a critical question that every foreign client will ask: “ Can you protect my personal data effectively? ”. Ι understand that small and medium sized enterprises comprehend security mainly as a cost. It is like car insurance which you may never use.

Nevertheless, security can become a competitive advantage. Even if we are kind of left behind, middle sized enterprise should keep up and improve its products and services quality. Quality will make you competitive. I understand that this quality might increase your cost but you belong in the European Union. You have to play according to these rules!

-HD: How do you perceive the NGOs role in this sector? What would you advise an organisation such as Homo Digitalis in order to make their action more effective?

Do not act as ‘rightsists’. In Greece, entire generations have been brought up in the framework of ‘Rightsism’ and ‘politically correctness’ Τhe crisis we experience is both economical as well as moral.This, of course, does not mean we have to stop fighting for our rights. We ought though, with every enquiry that we make to be well informed of its losses and its gains.Which are the consequences of our choices. Not blindly ask just because we can.

It’s the so called ‘occassional cost’. Namely, you should be informed as far as possible which are the other options, that you rejected, before the finally chosen. It is not possible, for example, based on the current business model, to ask for free internet without accepting advertisements (it should be noted that I do not like them).

You don’t like advertisements? No problem, can you afford to pay for the service you receive or to ensure the share of privacy you want? Ιt’s not enough to ask. You also have obligations. Unfortunately, we are victims of the trend “I need X at all costs”, without having thought what we lose or what we accept. It is indicator of maturity and resistance to populism to be able to distinguish easy rightsism from the one that is really in our interest. This is the biggest challenge in my opinion for all NGOs.


Homo Digitalis in DOCUMENTO newspaper

Today, Sunday 15th September 2019, Homo Digitalis’s members, Mr. Konstantinos Kakavoulis and Mr.  Panagiotis Gialis gave an interview in Documento newspaper.

The two members of our organization had an interesting discussion with Documento’s  journalist Ms. Labrini Papadopoulou about our organisation, our goals, the level of Greek residents’ awareness regarding personal data and the new Greek Law on the  processing of personal data. They also set out Homo Digitalis’s upcoming actions seeking to raise awareness, knowledge and dissemination of information.

The interview can be found on page 26 of the newspaper.


Homo Digitalis participates in the Working Party of CEPS on Artificial Intelligence and Cybersecurity

Our organisation has the great pleasure and honour to be invited to participate in the Working Party of Centre for European Policy Studies (CEPS) on Artificial Intelligence and Cybersecurity. CEPS is a well known think tank with a great amount of research activity and impact on issues related to European Union.

The Working Party will hold its first meeting on 10 September 2019 in Brussels, while  4 more meetings will follow in the upcoming months. Its work will be completed with the publication of a study during the first months of 2020.

Members of the Scientific Council of the Working Party are:

-Joanna Bryson, tenured Associate Professor, University of Bath

-Jean-Marc Rickli, Head of Global Risk and Resilience, Geneva Centre or Security Policy (GCSP)

-Marc Ph. Stoecklin, Principal Research Scientist and Manager of Cognitive Cybersecurity Intelligence (CCSI) group, IBM T.J. Watson Research Center

-Mariarosaria Taddeo, Assistant Professor, Oxford Internet Institute, University of Oxford

We would like to thank the Head of the Working Party Mr. Lorenzo Pupillo and its Rapporteur Mr. Stefano Fnatin for such a gentle invitation. Our organisation will be represented by Mr. Lefteris Helioudakis.

You can learn more about the Working Party and its program of activities here.


Homo Digitalis in Netweek journal

In the newest Netweek issue, Homo Digitalis’s Stefanos Vitoratos gives an interview on the recent draft legislation relating to personal data implementing GDPR, which was adopted on the 26th of August 2019 by the Greek Parliament. Netweek is the monthly business journal of the modern Information Society.

The said draft law is quite carelessly drafted and Mr. S. Vitoratos points out many adverse effects that could be arisen by both the Greek State and Greek citizens.

You can find and read the interview in electronic format here (in Greek).


How to strengthen the protection of children's rights in the digital environment?

Written by Anastasia Karagianni*

One year after the entry into force of the General Regulation on the Protection of the Personal Data of the European Union.

Some may argue that the adoption of the new regulation has contributed to the effective protection of children’s rights in the digital environment, as parental consent is required for the collection, storage, processing and dissemination of the children’s personal data in order to be able to take part in the information society.

On the other hand, others can argue that the Regulation has indeed laid some groundwork for child protection in the digital world.

However, the challenges are still many and the path for the effective enforcement and protection of the children’s rights in the digital world is long.

Firstly, one of the fundamental rights of the child, that is in need of protection in the digital environment is the right to take part in the decision and the right to be heard and to take into account the child’s opinion in the decision making process. Children, even though they are active on the Internet and in general in the digital environment, are not able to participate in the decision-making process. In other words, the child is not given the opportunity to express his / her views, desires and experiences before making the political decisions that will significantly affect his / her life.

For example, Eurochild organizes and manages an annual conference for children aged 11-16, which represents each EU Member State, and expresses its views on specific issues that are being raised.

Thus, children interact with each other, as well as with specialists and politicians who, while not taking part in the council, their opinions are taken into account in the decision making process.

Unicef also sets up meetings and seminars, in which children can participate and interact with each other as well as with Unicef specialists. The material resulting from these meetings is used by Unicef in the political decision-making process.

Exercising the right of participation does not necessarily mean securing a seat, a “chair”, at the political conference. On the contrary, it means strengthening the active role of the child in issues that concern him/her and, consequently, his/her digital social responsibility in the democratic society.

The participation of children in political decisions also determines the degree of participation efficiently. Policy makers have to consult children, and to be genuinely willing to interact with them and actually listen carefully to their opinions.

The parent or the custodian” has to listen “to the child’s social and psychological needs in order to train/educate him/her properly.

In this way, the establishment of a friendly and open culture for interaction with the children enhances the reduction of digital literacy. More specifically, digital literacy is not only the learning of technical knowledge, but also the proper use of these skills. The parent or parental carer/custodian should listen to the child’s social and psychological needs in order to train/educate him/her properly. For example, if a child uses a fitness or weight loss application that needs biometric data, they should inform the child about the risks of violating their personal data handled by this application. Digital literacy, therefore, is not just information but also useful information.

Many times, due to limited access to information and lack of technical equipment or limited access to the Internet, discriminatory behavior in the digital world, such as racist, xenophobic, homophobic and sexist events, appears.

For this reason, equal opportunities for access to digital literacy, the implementation of training/educating programs and the increase of resources for all children, for every minority group and vulnerability to access to the necessary tools and equipment contributes to the enhancement of the digital literacy.

However, it should be noted that adults, parents and parental carers also need to be trained and educated in order to familiarize themselves with the digital space and the challenges it poses.

Speaking of familiarity and parents, of course, we could refer to the role of parents and parental carers. In particular, it is important for parents to overcome the ideology of ‘protectionism’, over-reaction and one-dimensional decision-making, in essence protecting the best interests of the child, thus, leading to the fulfillment of their primary role as parents and parental carers.

Parents and guardians are called upon to meet the child’s physical, mental, spiritual and social needs by actually listening to his needs and desires.

Children have now grown up within the digital age. They are citizens of the internet and parents are also required to act under the parental care.

For this reason, parents and guardians should adapt to the digital environment, be aware of the dangers they face by asking for support from the state and civil society.

Parents and legal guardians should familiarize children with the concept of privacy and personal data from an early age and control their inexorable exposure to social media.

Of course, as long as the parents or guardians have to be attentive to the dangers of the internet, so careful they must be with their own digital behavior, for example with photos and children’s information they publish on social media and in general on the Internet. This also means that parents and parents should familiarize children with the concept of privacy and personal data from an early age and control their inexplicable exposure to social media. Only in this way can the child be protected in the digital environment.

To summarize, both the states and the private sector, marketing and advertising companies should consider children as rights holders, restrict manipulation and exploitation practices and violations of their privacy and rights.

On the other hand, children should be aware of and understand the regular and misleading forms of digital marketing in order to develop critical thinking and protect their rights as consumers.

Recognizing children as subjects of digital rights significantly determines the recognition and protection of their rights as digital workers, digital citizens, digital students, digital consumers, digital patients, digital librarians or defendants.

The regulation of an appropriate legal framework for children’s digital rights is essential for the holistic and effective protection of children’s rights.

Learn more about Homo Digitalis’s actions at the schools of the Evangelical School of Nea Smyrna here and at the Greek-French School of Piraeus “Saint Paul” here.

* Anastasia Karayanni is a lawyer with a specialization in the digital rights of children. She is a member of Homo Digitalis and co-founder of ChildAct, which aims to protect children’s digital rights. On November 8, 2018 he represented Homo Digitalis at a meeting on “Facebook and other social risks”, which took place in the European Parliament.


Schrems II Case before the CJEU

On Tuesday, 9 and Wednesday 10 of July 2019, a very important case for the protection of personal data was heard before the Grand Chamber of the European Court of Justice in Luxembourg.

The case is known as “Schrems II”, having received the name of plaintiff Max Schrems. Max Schrems is the founder of one of Europe’s largest digital rights organizations, NOYB-European Center for Digital Rights, based in Vienna, Austria. This is not the first time a case is heard by the European Court of Justice with Mr Schrems. In the case of Schrems I (C-362/14), the Court of Justice found that the US Safe Harbor Transfers of Personal Data did not provide an adequate level of security. Consequently, data transfers under this regime was illegal.

In response to this decision, the European Commission, in cooperation with the US government, has created a new framework for data transfer between the EU and the US. This box was called “Privacy Shield”.

Mr Schrems again turned against the Privacy Shield, arguing that this also does not provide a sufficient level of security for personal data transferred between the EU and the US.

Mr. Schrems makes statements to the media after the end of the case’s hearing

What are the main points of the case?

– Does the case concern all data transfers between the EU and the US?  No, it only concerns data transfers subject to “mass monitoring”. In most cases, there are simple ways to avoid mass surveillance and many productive sectors (banking, aviation, commerce) are not subject to such legislative framework. Mr Schrems’ complaint is related exclusively to Facebook, which, according to the documents published by Edward Snowden in 2013, contributes to the mass surveillance carried out by the US NSA, based on the PRISM program.

– Are all data transfers in the US problematic? No. Both US and EU law make it clear that there is a significant difference between the necessary transfers and unnecessary transfers, which are done for business purposes only (outsourcing).

– What does this mean? Can we continue sending emails to the US or buying air tickets? Of course! Article 49 of the General Data Protection Regulation (GDPR) provides for “exemptions” which allow all data transfers, for example, if they are necessary for the performance of a contract or if the user has explicitly consented to the transfer.

For example, an email must be sent to the US if the recipient is there but it is not necessary to send emails via the US if both the sender and the recipient are located in the EU simply because the server is in the US.

– So what kind of transfers should be stopped? Basically, the outsourcing should be ceased if such processing takes place in the EU or in other countries that provide a high level of protection for personal data.

Background of the case

The case focuses on a complaint by Max Schrems, a lawyer specialised in personal data protection against Facebook in 2013. Six years ago, Edward Snowden revealed that Facebook allows US intelligence services to access Europeans’ personal data under surveillance programs such as PRISM. The complaint seeks to stop EU-US Facebook data transfers.

So far, the Irish Data Protection Commissioner has not taken any concrete steps to stop these transfers.

First refusal and decision of the European Court of Justice on Safe Harbor

The case was first dismissed by the Irish Data Protection Commissioner (DPC) in 2013, then subjected to judicial review in Ireland and referred to the Court of Justice of the European Union. The CJEU ruled in 2015 that the so-called Safe Harbor agreement allowing the transfer of EU-US data was void and that the Irish Commissioner had to investigate the case, which he had initially refused.

Information on the use of “standard contractual clauses”

Surprisingly, the Irish Commissioner informed Mr Schrems in late 2015 that Facebook has in fact never been based on the Safe Harbor agreement which was canceled but was already based in 2013 on “standard contractual clauses” (another data transfer mechanism from EU to the US). This development made the first CJEU’s decision irrelevant to the case.

Second research and education

Mr Schrems adapted his complaint to the transfers made under “standard contractual clauses” and called for the termination of data transfers to Facebook USA, based on the argument that the company gives access to data to the US NSA. The Irish Commissioner’s investigation lasted only two months: from December 2015 to spring 2016.

Instead of deciding on the complaint, the Commissioner filed a lawsuit against Facebook and Mr Schrems (both now charged) at the Irish Supreme Court in 2016, in order to put further questions to the CJEU. After more than six weeks of hearings mainly held in 2017, the Irish Supreme Court found that the US government is dealing with the “mass processing” of European citizens’ personal data and has submitted eleven questions to the CJEU for the second time in 2018. The CJEU is now called upon to answer these questions.

Next steps

The CJEU reported the case in case C-311/18 and a second hearing was held on 9 and 10 July 2019 – about six years after the filing of the original complaint. The decision is expected  to be issued before the end of the year. Following the CJEU’s decision, the Irish Commissioner will eventually have to decide on Mr Schrems’s complaint. The decision can again be contested by Facebook or Mr. Schrems.

Homo Digitalis is particularly happy, as Ms. Mariliza Baka, a member of our organization and trainee lawyer at noyb, is currently in the European Court of Justice in Luxembourg and is attending the case.

We will provide you with news on this important case.

The noyb team at the Court of Justice of the European Union. First from the right is Ms. Mariliza Baka


Homo Digitalis at European Commission’s 1st Alliance Assembly for Artificial Intelligence

On Wednesday 26 June 2019, Homo Digitalis had the great honor and pleasure to participate in European Commission’s first AI Alliance Assembly in Brussels.

The Alliance enables actors from the world over to interact with the European Commission’s High Level Expert Group on AI, to comment on the deliverables of this group and to engage in educational and social events throughout Europe.

Our organization has been a member of the Alliance since its early days in June 2018.

During the event, the launch of the Piloting Process of the Expert Group’s Artificial Intelligence Guidelines was announced, while its new deliverable, “Policy and Investment Recommendations for trustworthy Artificial Intelligence” was published.

Our organization recognizes the contribution of these deliverables for the development of the systems that use technologies that are part of the broad and vague term of “Artificial Intelligence”. However, we seek the immediate resolution of the issues arising from the use of such systems in favor of the Rights and Freedoms of EU residents through concrete actions and implementation of legislative measures.

You can learn more about the event and watch videos recorded in the event here.


Homo Digitalis on PARAPOLITICA 90,1 FM radio

On June 26 2019, Homo Digitalis’s Katerina Pouliou, had an interview on PARAPOLITICA 90,1 FM radio with the journalist G. Houdalakis from “Noris” (Early) radio broadcast and discussed the currently interesting issues arisen from elections and the processing of personal data!

You can now listen to the interview on our YouTube channel here (in Greek).


The GDPR is applicable to all

Written by Konstantinos Kakavoulis

At the end of May, the Belgian Authority for the Protection of Personal Data [“L’Autorité de protection des données” (APD)] imposed a fine for violating the provisions of the General Data Protection Regulation (“GDPR”) for the first time.

You want probably to stop reading this article. If you hear the amount of the fine, you will probably stop immediately: just 2.000 euros.

However, this decision is very interesting. That’s because the Belgian Personal Data Protection Authority imposed this fine on a mayor!

The mayor had sent 2 emails to two city residents about his campaign. The two citizens had sent firstly e-mail to the mayor, in which they analyzed their idea of a project in their city. The mayor one day before the local elections responded to the emails of the two citizens by sending them his political campaign.

The Belgian Authority considered that the use of the e-mail addresses of the two citizens was abusive and imposed a fine.

“Public officials are the first to comply with the law. A mayor is expected and must know the legislation and comply with it.”

As noted by Hielke Hijmans, the President of the Belgian Authority, “the use of personal data by politicians for electoral purposes is an important issue for citizens. Public servants are the first to comply with the law. A mayor is expected and must know the legislation and comply with it. “

Personal data “are collected for specified, explicit and legitimate purposes and are not further processed in a manner incompatible with these purposes” (Article 5 (b) GDPR).

In this case, the mayor had received the email addresses of the two citizens for a very specific purpose. But he chose to use them for a completely different purpose. This behavior is a violation of the GDPR. Indeed, it is particularly interesting that the Belgian Authority has focused its attention on the provisions of the GDPR and not on national legislation on electronic communications.

So what did the Belgian authorities say with this decision?

That privacy is everyone’s responsibility!

The obligation to protect and correctly process personal data is not only for companies and organizations. Public servants and public officials also have a serious responsibility. They must realize that personal data that they have gathered in the exercise of public authority can not in any way be used for personal gain.

Clearly, we already knew from the scope of the GDPR that public officials also have to comply with the rules. However, this is the first time that a national authority enforces it in practice.

As the national elections are approaching at our country and we still have memories of pre-electoral messages from candidates in the municipal elections and the European elections, we expect to see if the candidates will take into account the personal data of the citizens as a worth-protecting element.

In any case, if you feel that your personal data are being violated by candidates in the upcoming elections, you can file a direct and free complaint with the Greek Data Protection Authority. In fact, the Greek Authority has recently published its decision on a similar case in which it imposed a fine of 2,000 euros to a candidate for a Member of the European Parliament.