Privacy Protection Policy
PRIVACY POLICY
Institute of Education of SOEL (IESOEL)
28 Kapodistriou Street, Athens
The Institute of Certified Public Accountants of Greece (SOEL) and the former Institute of Certified Public Accountants (SOL) established in 1997 the Institute of Education of SOEL (IESOEL), with the purpose of providing professional postgraduate training and continuing education.
IESOEL has now entered its 23rd year of successful operation, offering Postgraduate Professional Training and Continuing Education to graduates of Higher Educational Institutions (Universities) and Technological Educational Institutions (TEI), who aim to pursue a career in the auditing and accounting profession, as well as to professionals working in companies and organizations. The educational focus is on Applied Auditing and Accounting.
The two-year postgraduate program of IESOEL includes instruction in all subject areas of the professional examinations as defined in Article 9 of Law 4449/2017, in application of Directive 2014/56/EU, necessary for obtaining the professional license of Certified Public Accountant (CPA).
Graduates of the program, holders of the Postgraduate Professional Audit and Accounting Qualification (METKEL), upon completion of the required audit practice, obtain the license to practice as Certified Public Accountants.
The postgraduate program operates in accordance with the Regulation on the Operation of the Postgraduate Program in Professional Education, as approved by the Board of Directors of IESOEL. Examinations are conducted in accordance with the Regulation on the Conduct of Professional Examinations for SOEL members.
IESOEL is also tasked with organizing specialized seminars for Continuing Professional Development (CPD), Specialization, and Ongoing Professional Education for professionals working in the auditing and accounting fields.
The National and Kapodistrian University of Athens (NKUA-EKPA), a public law legal entity, in collaboration with the Institute of Certified Public Accountants of Greece (SOEL), has successfully operated for the fifteenth consecutive year the Postgraduate Program in Applied Auditing and Accounting. Students of this program have the opportunity to sit for SOEL’s professional examinations and obtain, in addition to the postgraduate degree, the license to practice as Certified Public Accountants, provided they have also completed the required audit practice. NKUA recognizes the METKEL title awarded by IESOEL and, following examinations in certain subjects, grants IESOEL graduates the postgraduate degree in Applied Auditing and Accounting.
SOEL also collaborates with NKUA in a Postgraduate Program in Public Sector Auditing.
Within the framework of its collaboration with the Association of Chartered Certified Accountants (ACCA), SOEL offers IESOEL graduates the opportunity to obtain the ACCA professional title by sitting only four (4) exams at the Professional Level. Interested individuals may also participate in the Joint Examination Scheme (JES), where they may be examined in Greek in the tax and legal modules and in English in the remaining ACCA modules, thus having the opportunity to acquire the professional title of both bodies.
SOEL, under its cooperation agreement with the Institute of Chartered Accountants in England and Wales (ICAEW), enables its graduates to obtain the ICAEW professional title by sitting only four (4) exams at the Advanced Level. IESOEL also operates the Accredited Membership Programme (AMP), which allows students to obtain membership in both SOEL and ICAEW. Participants in this program may be examined in Greek in the tax and legal modules and in English in the remaining ICAEW modules, and thus obtain the professional title of both bodies.
Since the academic year 2015–2016, SOEL has been collaborating with the International Hellenic University (IHU), a public law legal entity which absorbed the former TEI of Eastern Macedonia and Thrace, in postgraduate programs in Accounting and Auditing, aiming to grant postgraduate degrees in these fields.
All educational programs of SOEL are conducted in compliance with the requirements of Law 4449/2017 and Directive 2014/56/EU, and are approved by the Greek regulatory authority, ELTE.
IESOEL, as the official educational institution in Greece, has been assigned—by decision of the SOEL Supervisory Council—the responsibility for the Continuous Professional Education of Certified Public Accountants, as stipulated in Article 12 of Law 4449/2017. This training is delivered through specialized seminars on topics relevant to the auditing profession.
IESOEL is also engaged in scientific, economic, and accounting publications, as well as the organization of training and educational seminars for executives of public organizations, banks, large enterprises, and other entities.
In order to properly assess the lawful grounds for personal data processing and to evaluate the legal framework that governs the public interest arising from IESOEL’s operations, the above are taken into account when assessing the complex of rights and obligations under the legislation governing the processing of personal data.
- GENERAL PERSONAL DATA PROTECTION POLICY (Privacy Policy)
The Institute conducts its business activities in accordance with privacy principles, implementing ethical and responsible practices.
The applicable legislation defines our standards for managing and protecting personal data in order to ensure the highest possible level of security. These principles, which safeguard personal data, apply to all types of activities involving the collection and processing of personal information related to individuals, including, but not limited to, research, data management, and data transfer.
This Policy applies, indicatively, to the following:
- Management of student, trainee, and participant accounts: registration and requests submitted to the Institute / processing of data for purposes defined by the legislation governing the Certified Public Accountant profession, the operation of the Institute, as regulated by legislative or regulatory acts, and the functioning of the Hellenic Accounting and Auditing Standards Oversight Board (ELTE) / provision of personal data at visitor entry points / management of issues relating to ethics and privacy / management and safeguarding of our assets and infrastructure / procurement and payment for goods and services / compliance with our safety obligations / communication with media representatives.
- Management of legal relationships with employees and individuals who provide services within facilities utilized by the Institute’s bodies.
- Online presence of IESOEL: use of the website “iesoel.gr” / “iesoel.com” (the “Website”), as outlined in the relevant section of this policy, including privacy mechanisms and features.
If you are a prospective or current student, trainee, or participant, the personal data you provide to initiate or maintain your relationship with IESOEL may include any information for which a lawful basis for processing is provided by applicable law. This may include:
- Name, addresses (residential/work), contact details (phone numbers, email address), identification data (ID card, passport, etc.), social security number (AMKA), date and place of birth, marital status, profession, and other personal data necessary for fulfilling legal or contractual obligations, such as financial information (e.g., tax identification number, tax residence).
During registration on our website, at our facilities, or in our programs, we use your personal data for the following purposes:
- Full name:
a) for registration in the Institute’s programs,
b) for execution of the education services agreement (if not already governed by a legal relationship with a public sector body),
c) for invoicing of services,
d) for sending you information about our educational programs,
e) for maintaining our alumni records. - Father’s name: for identity verification and to distinguish you from individuals with the same name.
- Postal address: collected for billing purposes, postal delivery of related documents, and any other postal communication with you.
- Email address:
a) to communicate with you regarding questions or feedback and your academic progress,
b) to send newsletters from the Institute, provided you do not object and always in compliance with Law 3471/2006. - Phone number(s): for telephone communication with you to ensure optimal service delivery, inform you about your academic progress, handle any complaints, and for sending informational SMS messages (provided you do not object and in compliance with Law 3471/2006).
- Billing information: such as Tax Identification Number (TIN), Tax Office, and profession—used for invoicing purposes.
- Age: collected only when you apply for a program in order to verify eligibility according to the program’s age requirements.
- Identification documents (ID or passport): used to confirm your identity when signing an educational services contract with the Institute.
This Policy applies to all individuals whose data is processed by the Institute.
Likewise, every employee and third party acting as a data processor for the Institute is contractually obligated—prior to any processing—to understand and comply with their responsibilities under this Policy. They are bound by specific data processing agreements, unless there is a legal obligation under public law governing the data subject. In such cases, both the data processors and the data controller are subject to the legal constraints, always in accordance with the legislative framework for the protection of personal data.
PRINCIPLES FOLLOWED
The privacy principles outlined below summarize the standards and fundamental requirements for the collection and processing of personal data by the Institute of Education of SOEL (IESOEL).
Personal data:
- a) is processed lawfully, fairly, and in a transparent manner in relation to the data subject (“lawfulness, fairness and transparency”),
- b) is collected for specified, explicit, and legitimate purposes and is not further processed in a manner that is incompatible with those purposes (“purpose limitation”),
- c) is adequate, relevant, and limited to what is necessary in relation to the purposes for which it is processed (“data minimization”),
- d) is accurate and, where necessary, kept up to date (“accuracy”),
- e) is kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data is processed (“storage limitation”),
- f) is processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, using appropriate technical or organizational measures (“integrity and confidentiality”).
Lawfulness, Fairness and Transparency
We do not process Personal Data in ways that are unfair to the individuals to whom the data relates.
We assess whether the proposed collection, use, or other form of processing of Personal Data poses a risk of actual or potential harm to individuals, with the aim of preventing such harm. Where the nature of the data, the data subjects involved, or the activity itself presents an inherent risk of actual or undefined harm, we ensure that such risk does not outweigh the corresponding benefits for the individuals.
The necessary processing of special categories of Personal Data (“sensitive data”) is carried out in full compliance with the General Data Protection Regulation (GDPR), as implemented by Greek Law 4624/2019 and to the extent it is consistent with European legislation.
We document risk assessments and design any required mechanisms for obtaining and recording evidence of consent, where required, through supporting technologies.
We do not process Personal Data in ways or for purposes that are not transparent.
All individuals whose Personal Data is processed under this Policy shall have the right to access a copy of this Policy, which is published on our website.
The Data Protection Officer shall provide digital and/or physical copies of this Policy upon request to the contact addresses listed below.
When Personal Data is collected directly from individuals, we inform them through a clear and easily accessible privacy notice or similar mechanism, providing the following information:
- the identity and contact details of the data controller;
- the purposes of the processing;
- where processing is based on the legitimate interests of the data controller, what those interests are;
- the recipients of the personal data;
- any data transfers that may occur;
- the period for which the data will be stored;
- the existence of the right to request access to and rectification or erasure of personal data or restriction of processing;
- where processing is based on the data subject’s consent, the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal;
- the right to lodge a complaint with the Hellenic Data Protection Authority;
- the legal nature of the data provision and the possibility of automated decision-making.
If new legitimate purposes are identified for previously collected Personal Data, we ensure that either the new purpose (including a substantially similar purpose) is compatible with the purpose described in the original privacy notice or other transparency mechanism provided to the individual, or we obtain the individual’s consent for the new use of their Personal Data.
We are responsible for maintaining the privacy and security of Personal Data when it is transferred to or from other organizations or entities.
We only transfer Personal Data or allow it to be processed by third parties if the following conditions are met, and we are responsible for ensuring their fulfillment.
Where a third party processes Personal Data on our behalf or in support of the vital interests of IESOEL, before the third party receives any Personal Data, we:
(a) conduct legal due diligence to evaluate the third party’s privacy practices and associated risks;
(b) seek to obtain written contractual assurances that the third party will process the Personal Data in accordance with our instructions and in compliance with this Policy;
(c) ensure that they promptly notify us of any Security Incident and agree to cooperate when required;
(d) where the third party is to receive data for processing beyond our direct oversight, we ensure that the data will be used strictly for the operational purposes specified in the agreement and in compliance with applicable law.
- Data Necessity – Data Minimization – Storage Limitation
Before collecting, using, or disclosing Personal Data, we identify and document the specific, lawful purpose being served.
We determine and record the period for which the Personal Data will be used in relation to the defined purposes. This duration is established on a case-by-case basis, depending on the nature and type of the activity involved.
We do not collect, use, or share more Personal Data than is necessary, nor do we retain Personal Data in identifiable form for longer than is required to fulfil the specified operational purposes.
We anonymise data when operational or legal requirements necessitate it, and particularly when information relating to an activity or process must be retained for a period longer than strictly necessary.
We ensure that such requirements are embedded within any supporting technologies, and that third parties involved in supporting the activity or processing have been adequately informed.
- Data Accuracy, Integrity, and Confidentiality
We maintain Personal Data in a manner that is accurate, complete, and up to date, consistent with its intended use.
We ensure that periodic data verification mechanisms are embedded within supporting technologies to validate data accuracy.
We ensure that Sensitive Data is verified for accuracy and currency before being used, evaluated, analyzed, reported, or otherwise processed in ways that may risk unfair outcomes for individuals if inaccurate or outdated data is used.
In cases of changes to Personal Data, the data subject is responsible for notifying us so that the necessary updates can be made.
We implement safeguards to protect both Personal Data and Special Categories of Personal Data.
We have established a comprehensive information security program and security controls based on the sensitivity of the information and the level of risk associated with the activity, employing modern best practices in technology.
Our safeguards against loss, misuse, unauthorized access, disclosure, or destruction include—but are not limited to—business continuity and disaster recovery standards, identity and access management, information classification, incident response management, network access control, physical security, and risk management.
5. Special Safeguards for the Protection of Special Categories of Personal Data (Sensitive Data)
When processing special categories of personal data, we implement all appropriate and specific safeguards to protect the rights and interests of the data subject, in accordance with Article 22(3) of Law 4624/2019.
Taking into account the state of the technology, the cost of implementation, and the nature, scope, context, and purposes of processing, as well as the risks to the rights and freedoms of natural persons of varying severity, the safeguards include, in particular:
a) Technical and organizational measures ensuring that processing is carried out in compliance with the GDPR;
b) Measures to ensure that it is possible to retrospectively verify and determine whether, when, and by whom personal data have been entered, modified, or deleted;
c) Measures to increase awareness among staff involved in data processing;
d) Access restrictions for controllers and processors;
e) Pseudonymization of personal data;
f) Encryption of personal data;
g) Measures ensuring the capability, confidentiality, integrity, availability, and resilience of processing systems and services related to personal data processing, including the ability to restore data availability and access in a timely manner in the event of a physical or technical incident;
h) Procedures for regularly testing, assessing, and evaluating the effectiveness of technical and organizational measures to ensure the security of processing;
i) Specific rules to ensure compliance with the aforementioned law and the GDPR in the event of data transfers or processing for other purposes
j) Appointment of a Data Protection Officer (DPO).
Data Subject Rights (Access, Rectification, Erasure, Portability, Restriction of Processing, and Objection to Processing)
– You have the right to access your personal data.
This means that you have the right to be informed whether we process your Data. If we do process your Data, you may request information regarding the purpose of the processing, the type of Data we retain, the recipients of the Data, the storage duration, whether automated decision-making is involved, and your other rights, such as rectification, erasure, restriction of processing, and the right to lodge a complaint with the Hellenic Data Protection Authority (HDPA).
The above applies subject to Article 33 of Law 4624/2019, where applicable in accordance with European and superior legal standards. In any case, refusal to provide access must be fully justified. Such justification shall be communicated to the data subject unless such disclosure would endanger the purpose served by the refusal, in accordance with Article 33(2) of Law 4624/2019.
– You have the right to rectification of inaccurate personal data.
If you identify any inaccuracies in your Data, you may submit a request for correction (e.g., name correction or updated address).
– You have the right to erasure / right to be forgotten.
You may request the erasure of your Data if it is no longer necessary for the purposes for which it was collected. This is subject to Article 34 of Law 4624/2019, particularly paragraph 1, which states that “If erasure in the case of non-automated processing is impossible or requires a disproportionately high effort due to the specific nature of the storage method and the data subject’s interest in erasure is not considered significant, the right to erasure and the controller’s obligation to erase the data under Article 17(1) GDPR does not apply. In such cases, erasure shall be replaced by restriction of processing pursuant to Article 18 GDPR.”
– You have the right to data portability.
You may request to receive your Data in a structured, commonly used, and machine-readable format, or to have it transmitted directly to another controller.
– You have the right to restriction of processing.
You may request that we restrict the processing of your Data while your objections to the processing are being reviewed.
– You have the right to object to the processing of your Data.
You may object to the processing of your Data or withdraw your consent, and we will cease processing unless there are compelling legitimate grounds which override your interests, subject to Article 35 of Law 4624/2019, which states that “The right to object under Article 21(1) GDPR does not apply to public bodies if processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority, or if a legal provision requires such processing.”
The Institute may act as a public body to the extent that its services are essential for acquiring capacities regulated by specific legislative frameworks.
To exercise any of your rights, you may send us a request specifying the right you wish to exercise either:
- by post to our mailing address: 28 Kapodistriou St., Athens, 10682, marked “Exercise of right of access / rectification / erasure / restriction / objection”;
- by email at: dpo@soel.gr;
- or via the online contact form on our website (https://www.iesoel.com/gr) under the section “Exercise of right of access / rectification / erasure / restriction / objection”, describing your request.
We will respond to your request free of charge and without undue delay, and in any case within one (1) month of receiving it. If your request is particularly complex or numerous, we will inform you within the month if we need to extend the response time by an additional two (2) months.
If your requests are manifestly unfounded or excessive, particularly due to their repetitive nature, we may charge a reasonable administrative fee or refuse to act on the request.
You have the right to lodge a complaint with the Hellenic Data Protection Authority (postal address: 1-3 Kifisias Ave., Athens / website: www.dpa.gr) if you believe your personal data is being processed in violation of applicable national and regulatory data protection law.
ΙI. Privacy Policy on Specific Regulatory Matters
Website Usage
Below, we provide information on how and for what purposes we process your personal data when you use the aforementioned website of our organization.
The controller responsible for managing personal data is the Institute of Education of SOEL (I.E.S.O.E.L.), headquartered at 28 Kapodistriou Street, 10682 Athens.
This website uses the SSL (Secure Sockets Layer) protocol, which applies encryption methods to secure data exchanged between two devices (typically computers), establishing a secure connection over the Internet. This ensures the protection of your personal and other sensitive data (e.g., commands or inquiries submitted to the data controller). You can verify that you are connected securely by checking for the characters https:// and the padlock icon in your browser’s address bar.
- A) Data Collection
When visiting the website for informational purposes only—meaning you do not actively submit any personal data (e.g., via contact forms)—the only data we collect are those transmitted by your browser to our server (so-called server log files), specifically:
- Date and time of access to the website
- Amount of data transmitted (in bytes)
- Browser used during access
- Operating system used during access
- Your IP address (Internet Protocol address) at the time of access
When emails are sent from the I.E.S.O.E.L. platform, the third-party service provider Elastic Email is used.
Data processing is carried out in accordance with Article 6(1)(f) of the General Data Protection Regulation (GDPR), based on our legitimate interest in enhancing the stability and functionality of our website. The data will not be transferred or used in any other way. However, we reserve the right to review server log files if specific indications of illegal use are detected.
- B) Cookies
Cookies are small text files that are sent to your device when you visit a website. They are then returned to the originating website on each subsequent visit, or to another website that recognizes the same cookie. Cookies function as a memory for the website, enabling it to recognize your device on future visits. They can also remember your preferences, enhance your user experience, and tailor advertisements based on your interests.
For more information about cookies, including how to view, manage, and delete cookies stored on your device, please visit www.aboutcookies.org.
Types of Cookies
– Session and Persistent Cookies
We may use session cookies, which are active only while your browser is open and are automatically deleted once you close it. We may also use persistent cookies, which remain stored on your device for a longer, predefined period.
– Third-Party Cookies
Our website may allow the placement of third-party cookies, which appear on our website but are set and controlled by third parties. These cookies are not under our control. For more information about their use, please refer to the respective third party’s privacy or cookie policy. Details of potential third-party cookies are provided in the table below.
Cookies Used on This Website
Below is a summary of the cookies used on our website.
(Note: The actual table listing each cookie, its purpose, provider, duration, and type should follow here. Let me know if you’d like help drafting it.)
Cookie Name | _ga | _gat | _gid | PHPSESSID | _utma | _utmb | _utmc | _utmt | _utmv | _utmz |
Purpose | Google Analytics | Google Analytics | Google Analytics | PHP SESSION | Google Analytics | Google Analytics | Google Analytics | Google Analytics | Google Analytics | Google Analytics |
Expiration | 2 years | 1 min | 24 hours | Upon closing the browser | 2 years | 30 min | Upon closing the browser | 10 min | 2 years | 6 months |
You can set your browser in such a way that you are informed about the setting of cookies and you can either decide individually to accept them or in total, or block the acceptance of cookies in certain cases.. Each browser handles cookie settings differently. You can find information on how to change your cookie settings in the help menu of your specific browser. Please refer to the links below depending on the browser you are using:
Internet Explorer: https://support.microsoft.com/en-us/help/17442/windows internet-explorer-delete-manage-cookies
Firefox: https://www.mozilla.org/en-US/privacy/websites/#cookies
Chrome: https://support.google.com/accounts/answer/61416?co=GENIE.Pl atform%3DDesktop&hl=en
Safari: https://support.apple.com/en-gb/guide/safari/manage-cookies-and website-data-sfri11471/mac
Opera: http://help.opera.com/Windows/10.20/en/cookies.html
Please note: The functionality of our website may be limited if cookies are not accepted.
C) Contact Form
As part of our communication with you (e.g. via the contact form or email), personal data is collected. The data collected in such cases is exactly what you voluntarily provide through the specific form. This data is stored and used exclusively for the purpose of responding to your inquiry, or for technical and administrative communication on our part.
Legal basis for processing:
The processing of your personal data is based on our legitimate interest in responding to your inquiry, pursuant to Article 6(1)(f) of the General Data Protection Regulation (GDPR).
If the communication aims to conclude a contract between us, then an additional legal basis applies under Article 6(1)(b) of the GDPR.
Your data will be deleted once our communication is definitively concluded, provided it can be reasonably inferred that your inquiry has been resolved and there are no legal obligations requiring further retention of such data.
D) Web Analysis Services
Google Analytics
Our website uses Google Analytics, a web analytics service provided by Google LLC, 1600 Amphitheater Parkway, Mountain View, CA 94043, USA (“Google”). Google Analytics uses so-called cookies, which are text files stored on your computer, to help our website analyze how users interact with the site. The information generated by the cookies about your use of this website (including your IP address) is generally transmitted to and stored on a Google server in the USA.
On our behalf, Google will use this information to evaluate your use of the website, compile reports on website activity, and provide us with other services related to website usage and internet usage. The IP address transmitted by your browser within the scope of Google Analytics will not be merged with other Google data.
You can refuse the use of cookies by selecting the appropriate settings on your browser, as mentioned above. However, please note that if you do so, you may not be able to fully use all features of this website. You can also prevent Google from collecting and processing data generated by cookies related to your use of the website (including your IP address) by downloading and installing the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout?hl=en-GB
For more information about how this service works, you can visit: https://support.google.com/analytics/answer/6004245?hl=en
Terms You Should Know:
- Legislation: All laws, regulations, rules, and advisory orders that have the force of law.
- Personal Data: All data about an identified or identifiable individual, including data that identifies a person or can be used to identify, track, or contact them. Personal data includes both directly identifying information such as name, identification number, or job title, and indirectly identifying information such as date of birth, phone number, or encoded data.
- Sensitive Data or Special Category Data: Any type of data related to individuals that carries inherent risks of harm, including data defined by law as sensitive. This includes, but is not limited to, data related to health, genetics, race, ethnic origin, religion, political or philosophical beliefs, criminal record, precise geolocation, bank or other financial account numbers, government-issued identifiers, minors, sexual life, trade union membership, security, social security, and other employment or state benefits.
- Processing: Any operation or set of operations performed on data related to individuals, whether or not by automated means, including but not limited to collecting, recording, organizing, storing, accessing, adapting, altering, retrieving, using, evaluating, analyzing, reporting, disseminating, disclosing, transmitting, aligning, restricting, deleting, or destroying.
- Anonymization: The alteration, deletion, erasure, or other restriction or transformation of personal data so that it can no longer be used to identify, locate, or contact an individual.
- Privacy Incident: A breach or violation of this policy or of a privacy or data protection law.
- Security Incident: Access by or disclosure to an unauthorized person of personal data, or our company’s reasonable belief that such access or disclosure has occurred. Access to personal data by or on behalf of our company without the intent to violate this policy does not constitute a security incident, provided that the data was later used and disclosed only as permitted by this policy.
- Third Party: Any legal entity, organization, or individual not part of our company, not controlled by our company, and not working for our Institute. Unless explicitly stated otherwise in this policy, no part of our Instituteis required to meet the obligations of a third party under this policy, as all departments are required to process human-related data in accordance with this policy.
- Changes to This Policy. This policy may be revised from time to time, in accordance with applicable legal requirements. As we continue to develop, update, and improve our website, we will also update this policy accordingly. We recommend reviewing this document regularly to stay informed about any changes to the content of this privacy policy. This policy may be amended from time to time without prior notice to users.
For IESOEL, 5th August 2020
ADDRESSES
STREET ADDRESS
Kapodistriou 28, 106 82
Phone
+30 210 38 91 400
Email
secretary@soel.gr
