The Ministry of Digital Governance and Artificial Intelligence Consults the Greek Authority on the Bill Concerning the Single Public Payments Portal
The Hellenic Data Protection Authority issued an opinion on a bill from the Ministry of Digital Governance and Artificial Intelligence (ΥΨΔΤΝ) aiming to create a single digital payment portal (ΕΨΠΠ).
This portal is designed as a central digital infrastructure to manage benefits paid by public bodies to natural persons and to recover debts. It will unify procedures, provide an overview to the citizen, and support automated or semi-automated selection of beneficiaries, with the possibility of human intervention. The ministry acts as the processor for public bodies, which remain controllers of the processing, but also as controller for authentication and financial data passing through the portal. The processing is based on the performance of a task carried out in the public interest, pursuant to Article 6, paragraph 1, point e) of the GDPR, and data collected by interoperability with other public registers must be limited to what is strictly necessary.
The authority's opinion highlights several compliance points. It recommends adding an obligation for bodies to inform individuals about their rights under Articles 15 to 22 of the GDPR when issuing acts via the portal. The bill foresees the creation of an "electronic deposit of financial transactions" (HAHS) centralizing all data on debts, payments, and aids, whose purpose the authority suggests to reconsider. Finally, it advocates conducting a data protection impact assessment, pursuant to Article 35 of the GDPR, from the legislative design phase. Joint ministerial decisions (ΚΥΑ) will need to specify technical details, exchanged data, and the obligations of the parties under Article 28 of the GDPR.
This portal is designed as a central digital infrastructure to manage benefits paid by public bodies to natural persons and to recover debts. It will unify procedures, provide an overview to the citizen, and support automated or semi-automated selection of beneficiaries, with the possibility of human intervention. The ministry acts as the processor for public bodies, which remain controllers of the processing, but also as controller for authentication and financial data passing through the portal. The processing is based on the performance of a task carried out in the public interest, pursuant to Article 6, paragraph 1, point e) of the GDPR, and data collected by interoperability with other public registers must be limited to what is strictly necessary.
The authority's opinion highlights several compliance points. It recommends adding an obligation for bodies to inform individuals about their rights under Articles 15 to 22 of the GDPR when issuing acts via the portal. The bill foresees the creation of an "electronic deposit of financial transactions" (HAHS) centralizing all data on debts, payments, and aids, whose purpose the authority suggests to reconsider. Finally, it advocates conducting a data protection impact assessment, pursuant to Article 35 of the GDPR, from the legislative design phase. Joint ministerial decisions (ΚΥΑ) will need to specify technical details, exchanged data, and the obligations of the parties under Article 28 of the GDPR.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire