SEMAC Group (Greece) — Semac Construction S.A. (ΣΕΜΑΚ ΚΑΤΑΣΚΕΥΑΣΤΙΚΗ Α.Ε.) & Semac Automation S.A. (ΣΕΜΑΚ ΑΥΤΟΜΑΤΙΣΜΟΙ Α.Ε.)
Version 2.1 — Effective date: 14 September 2026
Version 2.1 adds the website automation.semac.gr to the systems that are searched (§11) and to the request form; no other procedure, deadline or rule changes.
At a glance
What this document is. It has two parts. Part I is addressed to you, the person whose data we process: it explains what rights you have and how you exercise them. Part II is the internal procedure that SEMAC staff are required to follow when answering your request. We publish it in full so that you can check what we have promised.
Where to send your request. privacy@semac.gr. No particular form is required: a request may be written, electronic or oral.
What it costs. Nothing. Exercising your rights is free of charge.
How long you will wait. One month. In complex cases we may take an extension of two further months, but we must tell you — with reasons — within the first month.
What we will ask you for. Only what is proportionate to satisfy ourselves that you are who you say you are. We do not ask for a copy of an ID document as a matter of course.
If you are not satisfied. Come to us first, then to the HDPA (or the supervisory authority of your own habitual residence), and in any event to the courts.
Table of contents
PART I — FOR DATA SUBJECTS
- Purpose, scope and controllers
- Your rights — what each one covers and what it does not
- How to submit a request
- What we will ask you for to identify you
- Timelines
- Cost
- Requests made through a representative
- If you are not satisfied
PART II — SEMAC INTERNAL PROCEDURE
- Roles and responsibilities
- Step-by-step workflow and day-by-day timeline
- Where we search — systems checklist
- Redaction rules and third-party data
- Exemptions and refusal grounds
- Records we keep
- Breach interface
- KPIs and periodic review
- ANNEX A — Data Subject Request Form
- ANNEX B — DSAR register template
- ANNEX C — Response letter templates
- Version, effective date and change log
PART I — FOR DATA SUBJECTS
1. Purpose, scope and controllers
1.1 Purpose
This Policy sets out how the SEMAC Group receives, logs, examines and answers requests to exercise rights under Articles 15 to 22 and Article 7(3) of the General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), read together with Law 4624/2019.
The purpose is twofold: so that you know what you can ask for and what you will receive, and so that our staff know exactly what they must do, within what deadlines and with what documentation. A right that does not correspond to a defined internal procedure remains theoretical — which is why we publish both parts together.
1.2 Controllers
| Entity | Legal name | Registered address | Request address |
|---|---|---|---|
| E1 | Semac Construction S.A. (ΣΕΜΑΚ ΚΑΤΑΣΚΕΥΑΣΤΙΚΗ Α.Ε.) | Industrial Area of Sindos, Block 39B, 570 22 Thessaloniki, Greece · tel. (+30) 231 056 9823 | privacy@semac.gr |
| E2 | Semac Automation S.A. (ΣΕΜΑΚ ΑΥΤΟΜΑΤΙΣΜΟΙ Α.Ε.) | Industrial Area of Sindos, Block 39B, 570 22 Thessaloniki, Greece · Branch: Ethnikis Antistaseos 125, 186 48 Drapetsona, Piraeus · tel. (+30) 231 056 9031, (+30) 210 462 2625 | privacy@semac.gr |
Registration details: Semac Construction S.A. GEMI no. 38335405000 · VAT no. EL094490672 — Semac Automation S.A. GEMI no. 58436104000 · VAT no. EL099790960
E1 and E2 act as separate (independent) controllers, not as joint controllers, except where expressly stated otherwise. Each is responsible for its own processing. If your request concerns both entities, we route it internally and tell you which entity is answering which part. Where your data were referred to our affiliated company Semac International Ltd (Cyprus, Reg. No. HE 397733) — which acts as a separate controller under its own privacy policy published at semacint.com — we tell you so and give you its contact details, so that you can also exercise your rights against it.
1.3 Data protection contact point
SEMAC has not appointed a Data Protection Officer (DPO) under Article 37 GDPR, because on the nature, scope and purposes of its activities no such obligation arises. It has, however, designated a Data Protection Contact Point, who coordinates the application of this procedure: Stamatios Evmorfiadis.
1.4 Scope
This procedure covers all personal data processed by SEMAC, whatever its origin or medium: www.semac.gr, services.semac.gr, automation.semac.gr, corporate mailboxes, the CRM, accounting systems, personnel files, paper records and backups.
It covers every data subject: customers and customer contacts, suppliers and partners, job applicants, employees and former employees, website visitors, newsletter recipients and visitors to our premises.
2. Your rights — what each one covers and what it does not
2.0 Summary table
| Right | Article | When it applies | Main limit |
|---|---|---|---|
| Access and copy | 15 | Always | Rights of others (para. 4) |
| Rectification | 16 | Always | Concerns facts, not opinions |
| Erasure | 17 | In six specific cases | Five exceptions in para. 3 |
| Restriction | 18 | In four cases | A temporary measure |
| Portability | 20 | Consent or contract and automated means only | Only data you provided |
| Objection | 21(1) | Legitimate interests / public task only | Balancing of compelling grounds |
| Objection to direct marketing | 21(2) | Always | None — it is absolute |
| Automated decisions | 22 | Only for solely automated decisions | SEMAC does not take any |
| Withdrawal of consent | 7(3) | Where consent is the basis | Not retroactive |
Exercising any right will never be used against you in your dealings with SEMAC — commercial, employment or otherwise.
2.1 Right of access (Article 15 GDPR)
What it covers. You have the right to know whether we process data relating to you and, if so, to receive a copy of it (Article 15(3)), together with information on: the purposes, the categories of data, the recipients or categories of recipients, the retention period or the criteria used to determine it, your other rights, the right to complain to a supervisory authority, the source of the data where we did not collect it from you, and the existence of automated decision-making.
What it does not cover. It is not a right of access to documents: you may receive an extract or a summary where a document also contains other content. The copy must not adversely affect the rights and freedoms of others (Article 15(4)): this is why we redact third-party data unless the third party consents or disclosure is reasonable in the circumstances. It also does not cover trade secrets or third-party intellectual property rights, to the extent that protecting them does not result in refusing all information (Recital 63).
2.2 Right to rectification (Article 16)
You may ask us to correct inaccurate data and to complete incomplete data, including by means of a supplementary statement. The right concerns matters of fact, not evaluative judgements (for example a performance appraisal or a technical opinion): in those cases we record your opposing view on the file.
2.3 Right to erasure — the "right to be forgotten" (Article 17)
The six grounds for erasure (Article 17(1)):
- the data are no longer necessary for the purposes for which they were collected or processed;
- you withdraw your consent and there is no other legal basis;
- you object under Article 21(1) and there are no overriding legitimate grounds, or you object under Article 21(2) (direct marketing);
- the data have been unlawfully processed;
- erasure is required for compliance with a legal obligation;
- the data were collected in relation to information society services offered to a child (Article 8(1)).
The exceptions (Article 17(3)) — we do not erase to the extent that processing is necessary:
- for freedom of expression and information;
- for compliance with a legal obligation or for the performance of a task carried out in the public interest (for example tax and accounting records: 6 years from the end of the fiscal year, under Greek tax legislation);
- for reasons of public interest in the area of public health;
- for archiving purposes in the public interest, scientific or historical research or statistical purposes;
- for the establishment, exercise or defence of legal claims.
Backups. We do not refuse erasure "because there are backups". Where erasure is granted, we delete from live systems immediately and from backups on the natural backup rotation cycle. In the meantime the data are placed under restriction of processing: they are not restored and are not used for any purpose other than disaster recovery, in which case the deletion is repeated. We tell you the estimated time for the cycle to complete.
2.4 Right to restriction of processing (Article 18)
You may ask us to "freeze" processing where: (a) you contest the accuracy of the data, for the period we need to verify it; (b) processing is unlawful but you oppose erasure; (c) we no longer need the data but you need it for legal claims; (d) you have objected under Article 21(1) and the balancing exercise is pending. Under restriction the data are stored but not otherwise processed, except with your consent or for legal claims, the protection of another person's rights or important public interest. We tell you before the restriction is lifted.
2.5 Right to data portability (Article 20)
What it covers. You receive the data you have provided to us, in a structured, commonly used and machine-readable format, and you may transmit it to another controller — or ask us to transmit it directly where this is technically feasible.
What it does not cover. It applies only where processing is based on consent (Article 6(1)(a) or 9(2)(a)) or on a contract (Article 6(1)(b)) and is carried out by automated means. It does not cover data we process on the basis of a legal obligation or legitimate interests, nor paper records, nor inferences or assessments generated by SEMAC. It must not adversely affect the rights of others.
2.6 Right to object (Article 21)
General right (para. 1). Where we process data on the basis of legitimate interests (Article 6(1)(f)) or for a public interest task, you may object on grounds relating to your particular situation. We stop the processing unless we demonstrate compelling legitimate grounds which override your interests and rights, or unless the processing is needed for legal claims.
Direct marketing (para. 2). The right to object to direct marketing, including profiling related to it, is absolute. It is not balanced and does not need to be justified. On receipt of your objection we stop immediately and add your details to a suppression list so that it does not happen again.
2.7 Automated decision-making (Article 22)
SEMAC does not carry out automated decision-making producing legal effects or similarly significantly affecting individuals, including profiling. If this changes, we will tell you in advance and give you the rights under Article 22(3) (human intervention, expression of your point of view, contesting the decision).
2.8 Withdrawal of consent (Article 7(3))
Where processing is based on consent (for example the newsletter, non-essential cookies, retention of a CV in a talent pool), you may withdraw it at any time, as easily as you gave it. Withdrawal does not affect the lawfulness of processing carried out before it.
2.9 Notification to recipients (Article 19)
Where we rectify, erase or restrict data, we communicate the change to each recipient to whom we disclosed it, unless this proves impossible or involves disproportionate effort. If you ask, we tell you who those recipients are.
3. How to submit a request
3.1 Channels
| Channel | Semac Construction S.A. and Semac Automation S.A. (E1/E2) |
|---|---|
| privacy@semac.gr | |
| Post | Attn: Data Protection Contact Point, Industrial Area of Sindos, Block 39B, 570 22 Thessaloniki |
| Telephone / orally | (+30) 231 056 9823 · (+30) 231 056 9031 · (+30) 210 462 2625 |
3.2 No particular form is required
You are not obliged to use a particular form, a particular address or a particular wording. A request may be made in writing, electronically or orally — and to any SEMAC employee. You do not have to cite the GDPR or name the right you are exercising. If a request reaches the wrong address (for example a commercial mailbox), we route it internally; the deadline runs from the day the request reached SEMAC, not from the day it reached the right department.
3.3 Optional form
For convenience an optional form is provided in ANNEX A to this Policy. Its use is optional, and not using it is never a ground for refusing or delaying a request.
3.4 What helps (without being required)
Handling is quicker if you tell us: the right or the outcome you are seeking; your relationship with SEMAC (customer, supplier, applicant, employee, website visitor); any period or specific system; and the contact details you used with us (for example the email address you wrote from or subscribed with).
4. What we will ask you for to identify you
4.1 The proportionality principle
We ask only for the additional information that is necessary to confirm your identity, and only where we have reasonable doubts (Article 12(6) GDPR). In most cases it is enough that the request comes from the email address we already hold for you, or that you confirm two or three details we already hold (for example a quotation number, a project number, a date of contact).
4.2 Express commitment on identity documents
SEMAC does NOT ask for a copy of an identity card or passport as a matter of course. Such a document is requested exceptionally, only where the request concerns particularly sensitive data or where disclosure to the wrong person would carry a serious risk, and always with reasons given for the necessity.
If you voluntarily provide a copy of an identity document, we apply the following: (a) we redact every element that is not necessary for identification — for example the photograph, the ID or passport number beyond the last digits, place of birth, parents' names, height, signature; (b) we use it solely for identification; (c) we delete it immediately once identification is complete, and keep on file only a note that identification was carried out, by what means and by whom.
4.3 Effect on the deadline
Where we request further information under Article 12(6), your request is treated as complete — and the one-month deadline starts — on receipt of the information that enables identification. The identification request is made without delay and at the latest within five (5) working days of receipt of the request, so that it cannot be used as a way of buying time.
5. Timelines
5.1 Basic rule
We reply without undue delay and in any event within one (1) month of receipt of the request (Article 12(3)).
5.2 Extension
The period may be extended by two (2) further months, taking into account the complexity and number of requests. In that case we inform you within the first month, stating the reasons for the delay. The extension is not automatic: it is approved by name and recorded in the DSAR register (see section 10.7).
5.3 Where we need more information
- Identification (Article 12(6)): the period runs from receipt of the necessary information.
- Clarification of scope (Recital 63): where we process a large quantity of data about you, we may ask you to specify which data or which processing operations the request relates to. A request for clarification does not stop the clock and cannot be made a precondition of an answer: if no clarification is received, we answer on a reasonable reading of the request.
5.4 If we take no action
If we do not act on your request, we tell you within one month of the reasons, and of your right to lodge a complaint with a supervisory authority and to seek a judicial remedy (Article 12(4)).
6. Cost
6.1 Rule
Exercising your rights is free of charge.
6.2 Exception (Article 12(5))
Where a request is manifestly unfounded or excessive, in particular because of its repetitive character, we may either charge a reasonable fee covering administrative costs or refuse to act. Before any such decision we consider whether a less onerous measure would do (for example a targeted answer, or a reference to data already provided).
6.3 Burden of proof
The burden of demonstrating the manifestly unfounded or excessive character of a request lies with SEMAC. Any refusal or charge is always given in writing with reasons, documented in the DSAR register, and accompanied by information on the rights to complain and to a judicial remedy. A large volume of data does not on its own make a request excessive.
6.4 Further copies
For further copies of the same data a reasonable fee based on administrative costs may be charged (Article 15(3)). The first copy is always free.
7. Requests made through a representative
7.1 Authorised representative or lawyer
You may exercise your rights through a third party. In that case we ask for a written authorisation or power of attorney identifying you, the representative and the scope of the mandate. The reply is sent to the representative, unless there are reasons requiring it to be sent directly to you (for example sensitive data or doubt about the mandate), in which case we tell you.
7.2 Minors
For a minor, the request is made by the holder of parental responsibility, with evidence of that capacity. We take into account the minor's degree of maturity and best interests, particularly where the parents are separated or disagree.
7.3 Persons under judicial assistance
The request is made by the judicial assistant, on production of the relevant court decision.
7.4 Deceased persons
The GDPR does not apply to the data of deceased persons (Recital 27). Article 34 of Law 4624/2019 provides specific treatment in certain cases. We consider such requests case by case, on the basis of the applicable national law and the legitimate interests of the heirs.
8. If you are not satisfied
8.1 Internal escalation
Contact the Data Protection Contact Point first (privacy@semac.gr), quoting your request reference. The review is carried out by a person different from the one who took the original decision and is answered within thirty (30) days. Internal escalation is optional and is not a precondition for going to a supervisory authority or to court.
8.2 Supervisory authorities
Greece — Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα, ΑΠΔΠΧ / HDPA) Kifissias Avenue 1-3, 115 23 Athens tel. +30 210 6475600 · contact@dpa.gr · www.dpa.gr
Under Article 77 GDPR you may lodge a complaint with the authority of the Member State of your habitual residence, your place of work or the place of the alleged infringement.
8.3 Judicial remedy
You retain the right to an effective judicial remedy against a supervisory authority decision (Article 78) and against SEMAC (Article 79). Proceedings are brought before the courts of the Member State where SEMAC has an establishment or, at your option, of your habitual residence.
8.4 No detriment
Making a request, a complaint or a report does not affect your relationship with SEMAC. It is not a ground for ending a business relationship, changing commercial terms, excluding you from a recruitment process or treating you unfavourably in an employment relationship.
8.5 Compensation
Under Article 82 GDPR, any person who has suffered material or non-material damage as a result of an infringement of the Regulation is entitled to compensation from the controller or the processor.
PART II — SEMAC INTERNAL PROCEDURE
Part II is addressed to SEMAC staff and contractors. It is published together with Part I because transparency about how we answer is part of the accountability obligation (Article 5(2) GDPR). Failure to follow it is a breach of internal policy, whether or not a complaint results.
9. Roles and responsibilities
9.1 Roles table
The principle is simple: recognition is everyone's job, answering is one person's job. The most common failure found by supervisory authorities is not a poor answer but a late one — because the request sat unanswered in a commercial mailbox.
| Role | Who | Responsibility |
|---|---|---|
| First recipient | Any employee or contractor | Recognises the request as a DSAR (even if it is not called one) and forwards it the same day to privacy@semac.gr. Answering it independently is prohibited. |
| DSAR Coordinator | Assigned internally | Assigns a reference, logs it in the register, sends the acknowledgement, organises the search, keeps to the timetable. |
| System owners | IT, HR, Finance, Sales/CRM | Run the search in their system and sign a completeness confirmation. |
| Data Protection Contact Point | Stamatios Evmorfiadis |
Decides on exemptions, refusals, extensions and the application of Article 15(4); approves the final response. |
| Legal counsel | Internal or external legal counsel | Advises on requests with a litigation dimension, an employment dispute or a third-party claim. |
| Approver | Board member | Approves refusals, charges and extensions beyond one month. |
9.2 Escalation
Escalation to the Data Protection Contact Point is mandatory for any request that: concerns special categories of data (Article 9); comes from a current or former employee; is connected with pending or anticipated litigation; seeks erasure of data subject to a mandatory retention period; concerns more than one Group entity; or reveals a possible personal data breach (see section 15).
9.3 Training
All staff receive short DSAR-recognition training on joining and annually thereafter. The duty to recognise falls on every employee; the duty to answer falls on the DSAR Coordinator alone.
10. Step-by-step workflow and day-by-day timeline
10.1 Timeline
| Days | Stage | Actions | Owner | Deliverable |
|---|---|---|---|---|
| Day 0 | Receipt and acknowledgement | Request received through any channel; forwarded the same day; acknowledgement sent with reference number and expected reply date | First recipient → DSAR Coordinator | Letter A (Annex C) |
| Day 0–3 | Logging and identification | Entry opened in the DSAR register; rights characterised; adequacy of identification assessed; further information requested if needed (Article 12(6)); check for conflict with pending disputes | DSAR Coordinator | Register entry; identification note |
| Day 3–10 | Scoping and search | Scope set (period, entity, systems); search instructions issued to system owners using the checklist in section 11; legal hold applied to the relevant data | DSAR Coordinator + system owners | Scoping sheet; search confirmations |
| Day 10–20 | Collection, review and redaction | Results gathered into a secure folder; de-duplication; item-by-item review; redaction of third-party data and privileged material; every redaction documented | DSAR Coordinator + system owners | Response pack v1; redaction log |
| Day 20–25 | Legal and internal review | Exemptions, Article 15(4), trade secrets and employment issues reviewed; any partial refusal approved with reasons | Contact Point + legal counsel | Response pack v2 (approved) |
| Day 25–30 | Response and dispatch | Covering letter drafted; secure dispatch (encrypted file or secure link with a separately transmitted password); delivery confirmed; entry closed | DSAR Coordinator | Letter C or D (Annex C); file closed |
| by Day 30 | Extension path | Where an extension is needed: reasoned approval by the Approver and extension notice sent before the end of the first month | Contact Point | Letter B (Annex C) |
| Days 31–90 | Extended path | The scoping/search, collection-review-redaction and response/dispatch stages above are repeated against a new target date; progress update on day 60 | DSAR Coordinator | Final reply within 3 months of receipt |
10.2 Legal hold
From logging until the file is closed, data within the scope of the request are not deleted under the routine retention schedule. The hold is expressly lifted on closure.
10.3 No alteration
Altering, deleting or "tidying up" data after a request has been received is strictly prohibited. Doing so is a disciplinary offence and may also constitute a criminal offence under applicable law.
10.4 Secure dispatch
The response pack is sent encrypted, with the password transmitted through a different channel (for example SMS). Data are never sent to an address that has not been verified.
10.5 Determining the responsible entity
The Coordinator determines which entity (E1, E2) is the controller for each element. Where both are involved, a single reply is prepared which expressly separates the elements by entity. Where an element was referred to the affiliated company Semac International Ltd, the reply says so and identifies that company as a separate controller with its own privacy policy.
10.6 Processors
Where data are held by a processor (for example a hosting provider, an accounting bureau, an ATS), the Coordinator invokes the assistance clause under Article 28(3)(e) with a seven (7) day response deadline for the processor.
10.7 Approval of an extension
An extension is approved by name, recording the specific reason (volume, complexity, number of systems, third-party involvement). A generic justification such as "workload" is not accepted.
10.8 Pre-dispatch checklist
Before every dispatch the Coordinator confirms and signs off the following:
☐ All rights exercised have been answered, not just the most obvious one.
☐ All the Article 15(1) information has been given, not just the copy.
☐ Every system in section 11 is marked "searched" or "not applicable", with a date.
☐ Redactions have been checked by a second person and are irreversible.
☐ File metadata have been checked.
☐ The pack relates exclusively to the requesting person — no other person's record has leaked into the file.
☐ The language of the reply is clear and plain (Article 12(1)).
☐ Every refusal carries a legal basis and a specific reason.
☐ The full details of the supervisory authorities and the reference to the judicial remedy are included.
☐ The delivery address has been verified; the password goes by a different channel.
☐ The register entry is complete and the file deletion date has been set.
11. Where we search — systems checklist
The following checklist is completed for every request. Each line is marked Searched / Not applicable, with the date, the search terms and the name of the person who ran it.
| # | System / source | What it holds | Notes |
|---|---|---|---|
| 1 | Corporate email and cloud document storage (e.g. Microsoft 365) | Correspondence, attachments, shared documents | Use tenant-level eDiscovery / Content Search; search by name, email, telephone, tax number, project number |
| 2 | CRM | Contacts, communication history, quotations, opportunities | Check archived and inactive records too |
| 3 | Website form submissions (Wix) — www.semac.gr | Contact form, newsletter signup, Resource Center downloads, careers applications | Check the Wix Inbox/Contacts, not only the notification emails |
| 4 | services.semac.gr and automation.semac.gr | Verification/calibration service form (services), contact and product enquiry form (automation), consent record | Google Firebase Hosting; one shared enquiry collection for both websites — the search must cover both, and the source field shows which one each enquiry came from |
| 5 | ATS / recruitment | CVs, applications, interview notes, assessments | Interview notes are personal data and are disclosed, with third-party assessors' identities redacted where required |
| 6 | Accounting / ERP system | Invoices, payments, customer/supplier records | Subject to mandatory 6-year retention — not deleted before it expires |
| 7 | Personnel and HR files | Contract, payroll, leave, training, certifications, disciplinary | Escalation mandatory |
| 8 | Paper records | Project files, delivery notes, visitor books, site safety forms | Article 15 also covers non-automated records that form part of a filing system |
| 9 | Backups | System snapshots | See 11.1 |
| 10 | Referrals to the affiliated company Semac International Ltd | Enquiries forwarded because they concern the Cyprus or Middle East market | Separate controller; we identify it to the data subject and pass on its contact details rather than answering on its behalf |
11.1 Correct treatment of backups
Backups are not searched as a rule for the purposes of Article 15: they are recovery snapshots, not a working record, and searching them is normally disproportionate. This is stated expressly in the reply.
For Articles 17 and 18 the position is different: the existence of backups is not a ground for refusing erasure. The following sequence applies: (a) deletion from live systems within the deadline; (b) entry of the data subject on a pending backup deletions list; (c) restriction of processing on the backups in the interim — no restoration, no use; (d) definitive removal on the natural rotation cycle; (e) where a restore is forced by a disaster, the deletion is repeated immediately after the restore; (f) the data subject is told the estimated completion time. SEMAC's backup cycle follows our backup and disaster-recovery policy, with a limited retention period.
11.2 Search methodology
Search terms are recorded before execution and cover at least: the name in both Greek and Latin script (and any variants or abbreviations); every known email address; telephone numbers with and without country code; tax or registration numbers; the name of the company the data subject represents; and project, quotation and invoice numbers. The systems in which a search was not run, and why, are also recorded. The completeness confirmation is signed by each system owner and kept on file as evidence of diligence.
11.3 Intra-group searching
Where a request may concern both entities (for example a contact logged in the shared CRM, or an enquiry referred from E1 to E2), the search extends to both. Each answers as a separate controller for its own processing, but the reply is coordinated so that the data subject receives one consolidated letter. Where an enquiry was referred to the affiliated company Semac International Ltd, that company is not searched on our behalf: it is a separate controller, and we simply tell the data subject that the referral took place and how to contact it.
12. Redaction rules and third-party data
12.1 Principle
Article 15(4) does not permit a blanket refusal because a document also contains third-party data. It permits selective redaction. The rule is: give as much as possible, redact as little as necessary.
12.2 What is redacted
- Names, contact details and identifiers of third-party individuals, where disclosure would not be reasonable.
- Special categories of third-party data — always.
- Information that would reveal the identity of a complainant or witness.
- Trade secrets and third-party pricing information, to the extent it does not concern the data subject.
- Legal professional privilege and litigation preparation material.
12.3 What is NOT redacted
- Names and roles of SEMAC employees acting in their professional capacity (for example the person who signed a quotation), unless there is a documented risk to that individual.
- Negative or unfavourable information about the data subject themselves. Unwelcome information is not a ground for redaction.
- Details of legal persons, which are not personal data.
12.4 Balancing for third-party data
A written balancing exercise is recorded covering: (a) has the third party consented? (b) is the information professional or private? (c) does the data subject already know the third party's identity? (d) has the third party expressly objected? (e) is it reasonable to disclose without consent? The assessment is kept on file.
12.5 Technical execution
Redaction is applied in flattened form — irreversible blacking-out in PDF, with a check that the underlying text cannot be recovered by copying or searching. Metadata are also checked (author, comments, revision history). A second person verifies before dispatch.
12.6 Redaction log
Every redaction is recorded: item, page, what was removed (in general terms), legal basis, date, approver.
13. Exemptions and refusal grounds
13.1 Available grounds
| Ground | Basis | Extent |
|---|---|---|
| Rights and freedoms of others | Art. 15(4); Recital 63 | Partial — redaction, not outright refusal |
| Manifestly unfounded or excessive request | Art. 12(5) | Refusal or fee; burden of proof on SEMAC |
| Mandatory retention (tax, social security, employment) | Art. 17(3)(b) | Refusal only as to erasure; other rights remain |
| Legal claims | Art. 17(3)(e); 6(1)(f) | Partial, with the claim documented |
| Data outside the scope of portability | Art. 20(1) | Portability refused; access remains |
| National law restrictions | Law 4624/2019 | Case by case, on legal advice |
| No data found | — | Stated expressly, with a description of the search |
13.2 What is NOT a ground for refusal
The volume of data; the existence of backups; the presumed motive of the requester (for example preparing an employment claim — motive is irrelevant); not using the Annex A form; not citing the GDPR; the existence of an ongoing commercial dispute.
13.3 Duty to give reasons
Every full or partial refusal must include: (a) a clear statement of what is not being provided; (b) the legal basis and the specific reason — not a bare reference to an article; (c) whatever can be provided, provided; (d) information on the right to complain to the HDPA / the Commissioner, with full details; (e) information on the right to a judicial remedy (Article 79) and to compensation (Article 82); (f) information on the availability of internal review (section 8.1).
14. Records we keep
14.1 DSAR register fields
The full template is at ANNEX B. The register is held with restricted access (DSAR Coordinator, Contact Point, approvers) and does not contain the substantive data themselves, only the administrative details of the request.
14.2 Retention
The DSAR file is retained for five (5) years from closure, to evidence compliance under Article 5(2) GDPR (accountability). It is then deleted under a documented process.
14.3 Minimisation within the file
The response pack that was provided is not retained for five years as a copy. After dispatch we keep: the request, the correspondence, the scoping sheet, the redaction log, the decisions with their reasons, and an index (not a copy) of the material provided.
The reason is both practical and legal: gathering all of a person's data into one file creates new, aggregated processing with its own risk. The DSAR file must evidence what we did, not reproduce the data.
15. Breach interface
15.1 When it is triggered
Handling a DSAR may reveal a personal data breach — for example: data were sent to the wrong recipient; a file was accessible without authorisation; data were kept far beyond the retention period and exposed; a leaver's account remained active; or the request itself reports a leak.
15.2 Immediate action
The DSAR Coordinator does not assess severity personally. They notify the Data Protection Contact Point the same day and trigger the Incident Management Procedure.
15.3 The 72-hour deadline
Where the breach is likely to result in a risk to the rights and freedoms of natural persons, it is notified to the competent supervisory authority without undue delay and, where feasible, not later than 72 hours after SEMAC becomes aware of it (Article 33 GDPR). Awareness runs from the moment the employee handling the DSAR identified the fact — not from internal confirmation. Where notification is late, it is accompanied by reasons for the delay.
15.4 Informing data subjects
Where the breach is likely to result in a high risk, the affected data subjects are also informed without undue delay (Article 34).
15.5 Separate handling
The breach is handled in parallel and independently: it does not suspend the DSAR, and the DSAR does not suspend notification. Both are logged with a cross-reference to each other.
16. KPIs and periodic review
16.1 Indicators
| Indicator | Target |
|---|---|
| Requests answered within one month | ≥ 95% |
| Requests acknowledged within 3 working days | 100% |
| Requests taking an extension | ≤ 15%, always with timely notice |
| Requests fully refused | All logged with reasons; a sample audited annually |
| Complaints to a supervisory authority arising from a DSAR | 0 |
| Completion of annual staff training | 100% |
| Requests that revealed a breach | Logged and reported to management |
16.2 Review
This procedure is reviewed annually and additionally whenever: the legal framework changes or new EDPB/HDPA guidance is issued; a system is added to or removed from the checklist in section 11; a complaint or incident occurs; or the Group's corporate structure changes. Owner: the Data Protection Contact Point.
16.3 Reporting to management
An annual summary to management: number and type of requests by entity, response times, refusals, complaints, weaknesses identified and corrective actions taken.
17. ANNEX A — Data Subject Request Form
Use of this form is optional. You may make a request in any way, including orally.
A1. Requester details
- Full name:
_________________________________ - Email address:
_________________________________ - Telephone (optional):
_________________________________ - Postal address (if you want a paper reply):
_________________________________
A2. Your relationship with SEMAC (tick all that apply)
☐ Customer ☐ Supplier/partner ☐ Job applicant ☐ Employee / former employee
☐ Website visitor ☐ Newsletter recipient ☐ Other: ____________
A3. Entity you are addressing (leave blank if you do not know)
☐ Semac Construction S.A. ☐ Semac Automation S.A. ☐ Semac International Ltd ☐ I do not know
A4. Right you are exercising (tick one or more)
☐ Access / copy (Article 15)
☐ Rectification (Article 16) — state what is wrong and what is correct
☐ Erasure (Article 17)
☐ Restriction of processing (Article 18)
☐ Portability (Article 20) — preferred format: ____________
☐ Objection (Article 21(1))
☐ Stop direct marketing (Article 21(2))
☐ Withdrawal of consent (Article 7(3))
☐ Information on automated decisions (Article 22)
A5. Description of your request
```
```
A6. Details that help us search (optional)
- Period: from
__________to__________ - Email addresses / telephone numbers you used:
_________________________________ - Project, quotation or invoice number:
_________________________________ - Specific systems or websites:
☐www.semac.gr☐services.semac.gr☐automation.semac.gr
A7. Submission through a representative
☐ I am making this request as a representative. I attach an authorisation / power of attorney.
Representative's full name: _________________________________
A8. How you want the reply
☐ Secure email (encrypted attachment) ☐ Post ☐ Collection from our offices
A9. Declaration
I declare that the above details are accurate and that this request concerns data relating to me (or to a person I lawfully represent).
Date: __________ Signature: _________________________________
Information: the details on this form are used solely to handle your request — legal basis: Article 6(1)(c) GDPR (compliance with a legal obligation). The file is kept for 5 years from closure.
18. ANNEX B — DSAR register template
| Field | Description |
|---|---|
| Reference number | Unique code, format DSAR-YYYY-NNN |
| Date received | Date the request reached SEMAC (not the responsible department) |
| Channel | Email / post / oral / form |
| First recipient | Employee name |
| Controller | E1 / E2 / both |
| Data subject category | Customer / supplier / applicant / employee / visitor / other |
| Rights exercised | Articles 15/16/17/18/20/21/22/7(3) |
| Identification status | Not required / requested / completed (means, date) |
| Deadline start date | Date the request became complete |
| Response deadline | Target date (1 month) |
| Extension | Yes/No · reason · date of notice · new deadline |
| Systems searched | Cross-reference to the section 11 checklist, with dates |
| Search terms | Keywords and identifiers used |
| Processors involved | Who, date instructed, date replied |
| Decision | Fully granted / partial / refused |
| Exemptions applied | Legal basis and reasons |
| Redactions | Cross-reference to the redaction log |
| Date of reply | Date sent |
| Method of dispatch | Encrypted email / secure link / post / collection |
| Fee charged | Yes/No · amount · reasons |
| Internal review | Requested? outcome |
| Complaint to an authority | Yes/No · authority · case number |
| Breach indicator | Yes/No · cross-reference to the Incident Register |
| Date closed | — |
| File deletion date | Closure + 5 years |
| Handler / approver | Names |
19. ANNEX C — Response letter templates
19.1 Letter A — Acknowledgement of receipt
Subject: Acknowledgement of your request —
[DSAR-YYYY-NNN]Dear
[Name],We confirm that on
[date]we received your request to exercise rights under the General Data Protection Regulation. The request has been logged under reference[DSAR-YYYY-NNN]; please quote it in any further correspondence.We understand you are exercising the right to:
[description]. If that does not reflect your request accurately, please tell us.We will reply to you by
[date = receipt + 1 month]. If the request turns out to be particularly complex, we may need an extension of up to two further months; in that case we will tell you, with reasons, before that date.Handling your request is free of charge.
[Optional identification paragraph: to make sure we do not disclose data to the wrong person, we would be grateful if you could confirm[specific, proportionate detail]. You do not need to send us a copy of an identity document.]Yours sincerely,
[Name]— Data Protection Contact Point,[Entity]privacy@semac.gr
19.2 Letter B — Extension notice (sent before the end of the first month)
Subject: Extension of the reply period —
[DSAR-YYYY-NNN]Dear
[Name],We are writing to tell you that, under Article 12(3) GDPR, we are extending the period for replying to your request by
[one / two]month(s). New reply date:[date].The specific reasons for the extension are:
[for example, the request covers a period of[X]years and requires searches across[N]systems, as well as a review of[volume]items for third-party data].We are already working on your request and will come back to you sooner if we finish earlier. You retain the right to lodge a complaint with a supervisory authority and to seek a judicial remedy (details in section 8 of our Policy).
Yours sincerely,
[Name]
19.3 Letter C — Full response
Subject: Reply to your request —
[DSAR-YYYY-NNN]Dear
[Name],Further to your request of
[date], we write as follows.1. What we did. We searched for data relating to you in the following systems:
[list], for the period[period], using the search terms[terms].2. Confirmation of processing.
[The entity] processes data relating to you./No data relating to you were found.3. Article 15(1) information. Purposes:
[…]. Categories of data:[…]. Recipients or categories of recipients:[…]. Retention period or criteria:[…]. Source of the data (where not collected from you):[…]. Transfers outside the EEA and the safeguards applied:[…]. No automated decision-making producing legal effects or similarly significantly affecting you, including profiling, is carried out.4. Copy. Enclosed is
[description of file]. The password is sent separately by[SMS].5. Redactions. In some items we have redacted details relating to other people, applying Article 15(4) GDPR. We have not redacted any information relating to you.
6. Your rights. You retain the rights to rectification, erasure, restriction, portability and objection, as well as the right to withdraw consent and to lodge a complaint with the HDPA (Kifissias Ave. 1-3, 115 23 Athens, +30 210 6475600, contact@dpa.gr) or with the supervisory authority of your habitual residence, and to a judicial remedy.
Yours sincerely,
[Name]
19.4 Letter D — Partial refusal with reasons
Subject: Reply to your request — partially granted —
[DSAR-YYYY-NNN]Dear
[Name],We have granted your request in large part. Enclosed are
[…].What has not been provided, and why.
Not provided Legal basis Specific reason [e.g. the names of third parties in the correspondence of 12 May]Article 15(4) GDPR [these are private details of third parties who have not consented and whose disclosure would not be reasonable; the content relating to you has been provided in full][e.g. erasure of the 2022–2026 invoices]Article 17(3)(b) GDPR · Greek tax legislation [a legal obligation requires retention for 6 years from the end of the fiscal year; the data will be deleted on[date]. Until then they are not used for any other purpose.]Your right to challenge this. If you disagree, you may: (a) request an internal review by a different person at
[privacy@semac.gr], answered within 30 days; (b) lodge a complaint with the HDPA (Kifissias Ave. 1-3, 115 23 Athens, +30 210 6475600, contact@dpa.gr, www.dpa.gr), or with the authority of your habitual residence or place of work (Article 77); (c) seek a judicial remedy (Article 79) and claim compensation for material or non-material damage (Article 82).Yours sincerely,
[Name]
20. Version, effective date and change log
- Version: 2.0
- Effective date: 15 August 2026
- Previous version: none — there was no equivalent document. This Policy replaces the fragmentary references to rights in the Privacy Policy and Terms & Conditions dated 21 September 2021.
- Next scheduled review: 15 August 2027
| Version | Date | Description of changes | Approved by |
|---|---|---|---|
| — | 21.09.2021 | No DSAR procedure existed. The Privacy Policy did not mention the rights to restriction, portability, objection or withdrawal of consent, nor the right to complain to the HDPA. Erasure was refused wholesale on the ground of backups. | — |
| 2.0 | 15.08.2026 | First edition of a standalone DSAR Policy and Procedure. Full statement of the Articles 15–22 and 7(3) rights; Article 12 timelines; express commitment not to demand identity documents; internal workflow with a day-by-day timeline; systems checklist; correct treatment of backups; redaction rules; DSAR register; Article 33 interface; response letter templates. | Data Protection Contact Point |
