1. Purpose
This Privacy Policy provides information on the processing of personal data in connection with the use of the IIS NEPPS (ESIDIS) and applies exclusively to matters relating to the protection of personal data.
2. Scope
This Policy applies to every natural person whose personal data are processed through the IIS NEPPS, including users of Contracting Authorities, Contracting Entities, Audit Authorities, Economic Operators, system administrators and visitors to the Portal. It applies to the entire IIS NEPPS, excluding NEPPS (ESIDIS) Public Works.
This Policy applies exclusively to the IIS NEPPS and does not extend to third-party websites or electronic services, even where access to such services is provided through hyperlinks available on the NEPPS Portal. Such services are governed by the respective privacy policies of the organizations providing them.
3. Legal Framework
The processing of personal data through the IIS NEPPS is carried out in accordance with Regulation (EU) 2016/679 (GDPR), Law 4624/2019, Law 4727/2020, Law 4412/2016, as well as any other applicable national or European Union legislation governing the operation of the IIS NEPPS and the award and performance of public procurement procedures.
The processing is based, where applicable, on the legal bases provided for in Article 6 of the GDPR, in particular:
- the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller (Article 6(1)(e));
- and, where required by the applicable legal framework, any other lawful basis provided for by the GDPR.
4. Controllers
The processing of personal data through the IIS NEPPS is carried out within the scope of the responsibilities established by the applicable legislation governing the conduct and support of public procurement procedures.
Depending on the nature of the specific processing activity and the role of each entity involved, the following act as Controllers, within the meaning of Article 4(7) of the General Data Protection Regulation (GDPR):
- the Ministry of Digital Governance and Artificial Intelligence, acting as the Operating Authority of the IIS NEPPS;
- the Ministry of Development, with respect to processing activities falling within its statutory responsibilities under the applicable legal framework;
- the Contracting Authorities and Contracting Entities, with respect to the personal data they process in the context of public procurement procedures conducted through the IIS NEPPS.
5. Fundamental Principles
Personal data processed through the IIS NEPPS are processed in accordance with the principles of lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, as well as accountability, in accordance with Article 5 of the GDPR.
6. Categories of Personal Data
Depending on the nature of the relevant processing activity, the operation of the IIS NEPPS may involve the processing of the following categories of personal data:
- identification data;
- contact details;
- employment-related information and organizational affiliation;
- information contained in support requests submitted through the electronic communication channels of the NEPPS Help Centre;
- information contained in documents and supporting evidence submitted through the IIS NEPPS, in accordance with the applicable legal framework;
- technical data necessary for the secure and proper operation of the system.
7. Purposes of Processing
Personal data are processed for the following purposes:
- user authentication;
- operation of the IIS NEPPS;
- management of public procurement procedures;
- provision of user support services;
- information security;
- compliance with applicable legal and regulatory obligations.
8. Recipients
Personal data are accessible exclusively to the competent organisational units and authorised users of the IIS NEPPS, as well as to Contracting Authorities, Contracting Entities, Economic Operators, competent audit authorities and processors, solely to the extent necessary for the performance of their respective responsibilities and in accordance with the applicable legal framework.
9. Transfers of Personal Data
Personal data are processed, as a rule, within the European Economic Area (EEA).
Where the provision of specific services requires the transfer of personal data outside the EEA, such transfers shall take place only in accordance with the safeguards and conditions provided for by the GDPR.
10. Support Centre Ticketing System
Personal data submitted through the electronic communication channels of the NEPPS Help Centre ticketing system are processed exclusively for the purpose of managing, handling and resolving support requests submitted by users.
11. Technical Cookies
The IIS NEPPS uses exclusively technical cookies and session management mechanisms that are strictly necessary for the secure and proper operation of the system.
No tracking, analytics or advertising cookies are used.
The use of such technical cookies does not require the user's consent, in accordance with the applicable legislation.
12. Logging
Log records are maintained for the purposes of security, auditing, accountability and incident investigation.
Such log records are used exclusively for:
- maintaining the security of the IIS NEPPS;
- auditing system operation;
- ensuring the proper operation of the system; and
- investigating security incidents.
13. Data Retention
Personal data are retained only for the period necessary to fulfil the purposes of processing and to comply with the obligations arising from the applicable legal framework.
Upon expiry of the applicable retention period, personal data are deleted or anonymised, where permitted by the applicable legislation.
14. Rights of Data Subjects
Data subjects may exercise the rights provided for under the GDPR, to the extent that such rights are applicable to the specific processing activity and subject to any restrictions arising from the legislation governing the operation of the IIS NEPPS.
The exercise of such rights shall not give rise to any obligation to erase or modify information contained in administrative acts or records maintained pursuant to applicable legislation.
The exercise of data subject rights shall be free of charge, unless a request is manifestly unfounded or excessive, in accordance with Article 12 of the GDPR.
15. Contact for Personal Data Protection Matters
For matters relating to the processing of personal data through the IIS NEPPS, interested parties may contact the Operating Authority via the following email address:
secr-esidis@gsis.gr
The Operating Authority shall ensure that the request is forwarded to the competent Controller, where appropriate.
For matters relating to personal data protection or the exercise of rights under the GDPR, interested parties may also contact the Data Protection Officer (DPO) of the Ministry of Digital Governance and Artificial Intelligence through the contact details published on the Ministry's official website.
Requests concerning the exercise of rights under the GDPR shall be examined without undue delay and, in any event, within one (1) month of receipt, in accordance with Article 12 of the GDPR.
Where necessary, taking into account the complexity or number of requests, this period may be extended by two (2) additional months, in accordance with the conditions laid down in the GDPR, provided that the applicant is duly informed.
Where a data subject considers that his or her rights under the GDPR have been infringed, he or she has the right to lodge a complaint with the Hellenic Data Protection Authority (HDPA) in accordance with the applicable legislation.
16. Amendments
This Privacy Policy may be amended or updated at any time, particularly where required as a result of changes to the applicable legal or regulatory framework or to the operation of the IIS NEPPS.
The most recent version shall be published on the NEPPS Portal and shall enter into force upon its publication.
17. Entry into Force
This Privacy Policy shall enter into force upon its publication on the NEPPS Portal.