Greek Law 4961/2022 on artificial intelligence
What Law 4961/2022 asks of private sector entities and public bodies using AI in Greece — employee notification, registers of AI systems, data ethics policies and algorithmic impact assessments.
In this ever-changing world of technology, the need for a regulatory framework on artificial intelligence (“AI”) is imperative and the Artificial Intelligence Act (“AIA”), the EU’s first attempt to horizontally regulate AI and promote trustworthy products with an AI component, is much anticipated. The AIA, which is expected to be adopted in 2023, proposes a risk-based approach. It establishes, inter alia, a list of prohibited AI practices (“unacceptable risk”) and sets certain mandatory requirements and conformity assessment procedures for high-risk AI systems. Further, specific transparency requirements apply to certain AI systems deemed of limited risk.
In this spirit and in anticipation of the adoption of the AIA by the EU, the Greek legislator enacted Law 4961/2022 (the “Law”) on emerging information and communication technologies with the aim of introducing appropriate safeguards for the protection of the rights of natural and legal persons and strengthening accountability and transparency. The Law is without prejudice to rights and obligations arising from data protection rules and regulations. The Law regulates, inter alia, the use of AI and introduces obligations for private entities and public bodies using AI tools and systems.
Private sector entities
Private sector entities using AI systems, which impact decision-making processes relating to employees or prospective employees and their working conditions, selection, recruitment, or evaluation, are required to notify all employees or prospective employees in a clear and adequate manner, prior to the use of such AI system. Private sector entities must, at the very least, provide to all employees or prospective employees information on the parameters of the decision-making process.
The above notification requirement also applies to digital platforms with regard to natural persons linked to them by virtue of an employment contract or a contract for the provision of independent services or a works contract.
Private sector entities are also required to:
- ensure compliance with the principles of equal treatment and non-discrimination in the workplace for reasons of gender, race, religion, etc.
- comply with article 22 of the General Data Protection Regulation (“GDPR”) regarding automated individual decision-making, including profiling.
Non-compliance with the above incurs administrative and penal fines.
Medium or large private sector entities falling within the meaning of para. 5 and 6 of article 2 of Greek law 4308/2014 must maintain an electronic register of any AI systems used in the context of consumer profiling, employee evaluation or evaluation of any other natural persons with whom such entities cooperate. The electronic register should, at least, contain the following information:
- a description of the operating parameters, capabilities and technical characteristics of the AI system;
- the number and status of the natural persons concerned or likely to be concerned;
- technical information concerning the supplier or external partners involved in the development or operation of the AI system;
- the operation period of the AI system; and
- the measures taken to ensure the safe operation of the AI system.
Medium or large private sector entities are also required to adopt a policy for the ethical use of data. Such policy should include information on the measures, actions and procedures applied to data ethics issues.
Listed sociétés anonymes are required to include information about their data ethics policy in their corporate governance statements prepared in accordance with article 152 of Greek law 4548/2018.
Public bodies
Use of AI stipulated by law: public bodies can use AI systems in decision-making processes, if such use is specifically stipulated by law. The laws permitting such use must have the appropriate safeguards in place to protect the rights of the persons affected by these decisions. The above does not apply to the Ministry of National Defence, the Ministry of Citizen Protection and the National Intelligence Service.
Algorithmic impact assessment: prior to the entry into operation of an AI system, public bodies are required to carry out an algorithmic impact assessment. Such algorithmic impact assessment must, inter alia, map potential risks to the rights, freedoms and legitimate interests of persons concerned or affected by a decision taken using AI, evaluate the risks and potential societal benefits of such AI use, set out the type of decisions taken using AI etc. The above assessment is additional and separate to the DPIA imposed by the GDPR.
Transparency: public bodies are required to publicly disclose information pertaining, inter alia, to the date of entry into operation of the AI system, the operating parameters of the AI system, the capabilities and technical characteristics of the AI system and type of decisions taken or supported by the AI system. Public bodies must also ensure that natural or legal persons affected or concerned by a decision have been made aware of the decision-making parameters.
Register of AI Systems: public bodies are required to maintain a register of the AI systems used.
This article does not cover every aspect of Law 4961/2022 and is for general guidance only.
This article is for general information only and does not constitute legal advice. For advice on a specific matter, please contact us.