"Personal Data": Any information relating to an identified or identifiable natural person ("data subject"); an identifiable natural person is one who can be identified, directly or indirectly, particularly by reference to an identifier such as a name, an identification number, location data, an online identifier, or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
"Special Categories of Personal Data": Personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, as well as the processing of genetic data, biometric data for the purpose of uniquely identifying a person, data concerning health, or data concerning a natural person's sex life or sexual orientation.
"Processing": Any operation or set of operations performed on personal data or on sets of personal data, whether by automated means or not, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination, or otherwise making available, alignment or combination, restriction, erasure, or destruction.
"Anonymization": The processing of personal data in such a way that the data can no longer be attributed to a specific data subject.
"Pseudonymization": The processing of personal data in such a way that the data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the data cannot be attributed to an identified or identifiable natural person.
"Data Controller": The natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the data controller or the specific criteria for its nomination may be provided for by Union or Member State law.
"Processor": A natural or legal person, public authority, agency, or other body that processes personal data on behalf of the data controller.
"Consent" of the data subject: Any freely given, specific, informed, and unambiguous indication of the data subject's wishes by which they, by a statement or by a clear affirmative action, signify agreement to the processing of personal data relating to them.
"Personal Data Breach": A breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed.
"Existing Legislation": The provisions of the currently applicable Greek, Union, or other legislation to which Euroxx is subject and which regulate matters of personal data protection, such as:
- Law 2472/1997 on the protection of individuals from the processing of personal data, as amended,
- Law 3471/2006 on the protection of personal data and privacy in the field of electronic communications and amendment of Law 2472/1997, as amended,
- Directive 2002/58/EC of the European Parliament and of the Council, dated July 12, 2002, concerning the processing of personal data and the protection of privacy in the electronic communications sector (e-Privacy Directive), as amended,
- Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, repealing Directive 95/46/EC (General Data Protection Regulation, GDPR) and its implementing laws, if any.