🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
CY v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 3 failing15 sources retrieved model claude-sonnet-5 · 2026-08-03

Cyprus

CY schema gdpri-v2 trajectory: not yet assessedregulated (omnibus)overlaps: FIM, WPM, AIC

Last updated update date not yet available · 10 categories · 27 claims · 13 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
27Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No red categories; 10 sub-modules are flagged red.

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Comprehensive omnibus statute in force with an operational, EDPB-recognised supervisory authority.

Primary frameworkGDPR (Regulation (EU) 2016/679) as implemented by Law 125(I) of 2018
Traffic-light rationale — GreenComprehensive omnibus statute in force with an operational, EDPB-recognised supervisory authority.

Sub-modules (5)

Regulator And AuthorityGreen

The Commissioner for Personal Data Protection is the sole national supervisory authority and EDPB member for Cyprus, based in Nicosia.

Claims (1):

  • The Office of the Commissioner for Personal Data Protection is the national supervisory authority for Cyprus, monitoring application of the GDPR and Law 125(I)/2018.

Act And InstrumentsGreen

Primary instruments are the GDPR and the national implementing Law 125(I)/2018.

Claims (1):

  • Cyprus implemented the GDPR by means of Law 125(I) of 2018 Providing for the Protection of Natural Persons with regard to the Processing of Personal Data and for the Free Movement of Such Data, which entered into force on 31 July 2018.

Material ScopeGreen

Material scope follows GDPR Art 2/4 definitions of personal data and processing, as transposed by Law 125(I)/2018; the Law adds sector variations for genetic/biometric data used for life-insurance purposes.

Claims (1):

  • Law 125(I)/2018 presents variations from the GDPR relating to the processing of genetic and biometric data for life-insurance purposes and to the international transfer of special categories of personal data.

Territorial ScopeGreen

Territorial scope mirrors GDPR Art 3 (establishment + targeting tests); no CY-specific narrowing identified in the sources reviewed.

Absence provenance: unavailable. Searched: C, y, p, r, u, s, , L, a, w, , 1, 2, 5, (, I, ), /, 2, 0, 1, 8, , t, e, r, r, i, t, o, r, i, a, l, , s, c, o, p, e, , d, e, r, o, g, a, t, i, o, n.

Regulator Registration And FilingAmber

No general controller registration/filing requirement was identified beyond GDPR-standard record-keeping and DPO notification practice; the Commissioner's 2024 compliance guide addresses self-assessment rather than filing.

Claims (1):

  • The Commissioner published a question-based GDPR compliance guide on 19 February 2024 to help controllers and processors self-assess processing operations, including DPO, legal-basis and transfer sections.
Category narrative73 words

Cyprus operates a GDPR-omnibus regime. The GDPR applies directly as an EU Regulation and is supplemented by Law 125(I) of 2018, the national implementing act, which entered into force on 31 July 2018 and establishes the Office of the Commissioner for Personal Data Protection as the national supervisory authority. The national Law also introduces limited derogations (e.g. age of consent at 14, genetic/biometric data for life-insurance purposes, and international transfer of special-category data).

Sources and claims (4)
  1. ConfirmedEuropean Data Protection Board — The Office of the Commissioner for Personal Data Protection is the national supervisory authority for Cyprus, monitoring application of the GDPR and Law 125(I)/2018.observed
  2. ConfirmedDataGuidance (summarising official Cyprus Gazette text) — Cyprus implemented the GDPR by means of Law 125(I) of 2018 Providing for the Protection of Natural Persons with regard to the Processing of Personal Data and for the Free Movement of Such Data, which entered into force on 31 July 2018.observed
  3. ConfirmedDataGuidance — Law 125(I)/2018 presents variations from the GDPR relating to the processing of genetic and biometric data for life-insurance purposes and to the international transfer of special categories of personal data.observed
  4. ConfirmedDataGuidance — The Commissioner published a question-based GDPR compliance guide on 19 February 2024 to help controllers and processors self-assess processing operations, including DPO, legal-basis and transfer sections.observed

#

GDPR Art 6/9 bases apply directly; national derogations are narrow and well-documented.

Primary frameworkGDPR Arts 6, 7, 9 as implemented by Law 125(I) of 2018
Traffic-light rationale — GreenGDPR Art 6/9 bases apply directly; national derogations are narrow and well-documented.

Sub-modules (4)

Lawful BasesGreen

The six GDPR Art 6 lawful bases apply directly in Cyprus with no local substitution identified.

Claims (1):

  • GDPR Article 6 lawful bases apply directly in Cyprus as an EU Member State without local substitution of the enumerated grounds.

Special CategoriesAmber

Special categories follow GDPR Art 9, with a national derogation permitting genetic and biometric data processing for life-insurance purposes.

Claims (1):

  • Law 125(I)/2018 presents variations from the GDPR in relation to the processing of genetic and biometric data for life insurance purposes.

Pseudonymisation And AnonymisationAmber

No Cyprus-specific statutory definition beyond GDPR Art 4(5) pseudonymisation was located in the sources reviewed.

Absence provenance: unavailable. Searched: C, y, p, r, u, s, , L, a, w, , 1, 2, 5, (, I, ), /, 2, 0, 1, 8, , p, s, e, u, d, o, n, y, m, i, s, a, t, i, o, n, , a, n, o, n, y, m, i, s, a, t, i, o, n, , s, a, f, e, , h, a, r, b, o, u, r.

Category narrative50 words

Lawful bases and special-category rules follow GDPR Arts 6 and 9 as transposed by Law 125(I)/2018. The Law's principal derogation is the age of digital consent, fixed at 14 (below the GDPR default of 16), and a sector carve-out permitting processing of genetic and biometric data for life-insurance underwriting purposes.

Sources and claims (3)
  1. ConfirmedEUR-Lex — GDPR Article 6 lawful bases apply directly in Cyprus as an EU Member State without local substitution of the enumerated grounds.observed
  2. ConfirmedDataGuidance — Law 125(I)/2018 sets the age of consent for information-society services at 14 years old, a derogation from the GDPR default age.observed
  3. ConfirmedDataGuidance — Law 125(I)/2018 presents variations from the GDPR in relation to the processing of genetic and biometric data for life insurance purposes.observed

#

Full GDPR rights suite in force with documented enforcement practice via Article 60 cooperation decisions.

Primary frameworkGDPR Arts 12-23 as implemented by Law 125(I) of 2018
Traffic-light rationale — GreenFull GDPR rights suite in force with documented enforcement practice via Article 60 cooperation decisions.

Sub-modules (5)

Access RightGreen

The Commissioner has directly handled subject-access and erasure complaints, including a documented Article 60 cross-border cooperation case.

Claims (1):

  • The Commissioner has exercised her GDPR and Law 125(I)/2018 powers in handling data-subject complaints concerning the right of access and right to erasure, including cross-border Article 60 cooperation.

Rectification And ErasureGreen

Erasure ('right to be forgotten') is enforced alongside access rights per the same Article 60 case practice.

Claims (1):

  • The Commissioner has exercised her GDPR and Law 125(I)/2018 powers in handling data-subject complaints concerning the right of access and right to erasure, including cross-border Article 60 cooperation.

Restriction And ObjectionGreen

GDPR Arts 18 and 21 apply directly; no CY-specific narrowing identified.

Absence provenance: unavailable. Searched: C, y, p, r, u, s, , r, e, s, t, r, i, c, t, i, o, n, , o, f, , p, r, o, c, e, s, s, i, n, g, , o, b, j, e, c, t, i, o, n, , r, i, g, h, t, , d, e, r, o, g, a, t, i, o, n.

Data PortabilityGreen

GDPR Art 20 portability right applies directly; no CY-specific derogation identified.

Absence provenance: unavailable. Searched: C, y, p, r, u, s, , d, a, t, a, , p, o, r, t, a, b, i, l, i, t, y, , d, e, r, o, g, a, t, i, o, n, , L, a, w, , 1, 2, 5, (, I, ), /, 2, 0, 1, 8.

Deadlines And Response WindowsGreen

Standard GDPR one-month (extendable to three-month) response window applies; no CY-specific shortening/extension was identified.

Absence provenance: unavailable. Searched: C, y, p, r, u, s, , s, t, a, t, u, t, o, r, y, , r, e, s, p, o, n, s, e, , d, e, a, d, l, i, n, e, , v, a, r, i, a, t, i, o, n.

Category narrative38 words

Data subject rights (access, rectification, erasure, restriction, objection, portability) follow GDPR Arts 15-22 directly, enforced by the Commissioner. A published Article 60 decision demonstrates the Commissioner's practical handling of access/erasure complaints, including cross-border cooperation with other EU SAs.

Sources and claims (1)
  1. ConfirmedEuropean Data Protection Board / Cyprus Commissioner — The Commissioner has exercised her GDPR and Law 125(I)/2018 powers in handling data-subject complaints concerning the right of access and right to erasure, including cross-border Article 60 cooperation.observed

#

Full GDPR controller/processor duty regime in force with multiple documented enforcement actions on security and accountability failures.

Primary frameworkGDPR Arts 24-39 as implemented by Law 125(I) of 2018
Traffic-light rationale — GreenFull GDPR controller/processor duty regime in force with multiple documented enforcement actions on security and accountability failures.

Sub-modules (7)

Accountability And DpiaGreen

Cyprus's DPIA exemption list under GDPR Art 35(5) was submitted to and processed through the EDPB's Article 64 consistency mechanism.

Claims (1):

  • Cyprus submitted a national DPIA exemption/inclusion list under GDPR Article 35(5), which was reviewed through the EDPB's Article 64 consistency opinion process (DPIA List Cyprus).

Dpo RequirementsGreen

The Commissioner has issued DPO-appointment guidelines and, in a 2022 Bank of Cyprus decision, recommended prior DPO consultation before actions risking GDPR violations.

Claims (1):

  • Following a 2022 data-breach decision, the Commissioner recommended that the Bank of Cyprus consult its data protection officer before taking actions that may violate GDPR.

Ropa RequirementsAmber

GDPR Art 30 record-keeping applies directly; the Commissioner's September 2024 public-sector audit found 60% of audited bodies lacked posted data-protection policies/DPO contact details, indicating documentation gaps subsequently remediated.

Claims (1):

  • A September 2024 Commissioner audit of 28 public-sector websites found 60% lacked a posted data-protection policy and DPO contact details, with 40% having policies containing gaps and inaccuracies, before full compliance was achieved by August 2024.

Joint Controller ArrangementsGreen

GDPR Art 26/28 joint-controller and processor rules apply directly; no CY-specific supplementary provision was identified.

Absence provenance: unavailable. Searched: C, y, p, r, u, s, , j, o, i, n, t, , c, o, n, t, r, o, l, l, e, r, , p, r, o, c, e, s, s, o, r, , a, g, r, e, e, m, e, n, t, , s, u, p, p, l, e, m, e, n, t, a, r, y, , r, u, l, e.

Security MeasuresAmber

The Commissioner fined the Bank of Cyprus €17,000 in November 2022 for violations of Articles 5(1)(f), 24(1) and 32 GDPR following data-security failures involving misdirected shipments.

Claims (1):

  • The Office of the Commissioner for Personal Data Protection fined the Bank of Cyprus Public Company Ltd €17,000 for violations of Articles 5(1)(f), 24(1) and 32 GDPR following a data breach involving misdirected letters and electronic files affecting thousands of data subjects.

Breach NotificationAmber

The Commissioner fined the State Health Services Organization €46,500 for GDPR breaches involving lost patient data, evidencing active breach-notification/security enforcement in the health sector.

Claims (1):

  • Cyprus fined the State Health Services Organization €46,500 for GDPR breaches involving lost patient data.

Retention And DisposalAmber

The Commissioner has separately guided that hotels may not retain identity-card or passport copies, and that pharmacies must minimise and discreetly handle beneficiary identification data, reflecting retention-minimisation enforcement.

Claims (1):

  • Cyprus prohibits hotels from retaining identity card or passport copies due to GDPR violations, and pharmacies must collect beneficiary identification data discreetly to avoid system abuse.
Category narrative60 words

Accountability, DPIA, DPO, ROPA, security and breach-notification duties follow GDPR Arts 24-39. Cyprus's national DPIA exemption list (Art 35(5)) has been submitted to and reviewed by the EDPB. Enforcement decisions against the Bank of Cyprus (Arts 5(1)(f), 24(1), 32) evidence active supervision of security-of-processing and accountability duties; a State Health Services Organization fine evidences breach-notification/security enforcement in the health sector.

Sources and claims (6)
  1. ProbableEuropean Data Protection Board — Cyprus submitted a national DPIA exemption/inclusion list under GDPR Article 35(5), which was reviewed through the EDPB's Article 64 consistency opinion process (DPIA List Cyprus).observed
  2. ConfirmedDataGuidance — Following a 2022 data-breach decision, the Commissioner recommended that the Bank of Cyprus consult its data protection officer before taking actions that may violate GDPR.observed
  3. ConfirmedDataGuidance — A September 2024 Commissioner audit of 28 public-sector websites found 60% lacked a posted data-protection policy and DPO contact details, with 40% having policies containing gaps and inaccuracies, before full compliance was achieved by August 2024.observed
  4. ConfirmedDataGuidance — The Office of the Commissioner for Personal Data Protection fined the Bank of Cyprus Public Company Ltd €17,000 for violations of Articles 5(1)(f), 24(1) and 32 GDPR following a data breach involving misdirected letters and electronic files affecting thousands of data subjects.observed
  5. ConfirmedDataGuidance — Cyprus fined the State Health Services Organization €46,500 for GDPR breaches involving lost patient data.observed
  6. ProbableDataGuidance — Cyprus prohibits hotels from retaining identity card or passport copies due to GDPR violations, and pharmacies must collect beneficiary identification data discreetly to avoid system abuse.observed

#

Standard GDPR Chapter V mechanisms apply with no CY-specific localisation mandate identified.

Primary frameworkGDPR Arts 44-49
Traffic-light rationale — GreenStandard GDPR Chapter V mechanisms apply with no CY-specific localisation mandate identified.

Sub-modules (6)

Transfer MechanismsGreen

GDPR Art 44-49 transfer mechanisms (adequacy, SCCs, BCRs, derogations) apply directly to Cyprus-established controllers/processors.

Claims (1):

  • As an EU Member State, Cyprus applies GDPR Chapter V (Arts 44-49) transfer mechanisms directly, including adequacy decisions, SCCs, BCRs and Article 49 derogations, without a separate national transfer regime.

Adequacy ReceivedGreen

Adequacy determinations are an EU Commission competence, not a Cyprus national one; Cyprus is bound by whichever adequacy decisions the Commission adopts EU-wide.

Claims (1):

  • As an EU Member State, Cyprus applies GDPR Chapter V (Arts 44-49) transfer mechanisms directly, including adequacy decisions, SCCs, BCRs and Article 49 derogations, without a separate national transfer regime.

Adequacy GrantedGreen

Cyprus does not independently grant adequacy; adequacy is granted at EU level under GDPR Art 45, with the EDPB reviewing Commission adequacy-decision reports.

Claims (1):

  • The EDPB reviews the European Commission's periodic reports on the functioning of existing adequacy decisions, including methodological observations on government-access assessments, as part of the EU-wide (not Cyprus-specific) adequacy review process.

Sccs And BcrsGreen

Standard Contractual Clauses and Binding Corporate Rules apply under GDPR Arts 46-47; no CY-specific supplementary form was identified.

Absence provenance: unavailable. Searched: C, y, p, r, u, s, , n, a, t, i, o, n, a, l, , S, C, C, /, B, C, R, , s, u, p, p, l, e, m, e, n, t, a, r, y, , f, o, r, m, , o, r, , g, u, i, d, a, n, c, e.

Transfer Impact AssessmentAmber

TIA obligations follow the EDPB's general post-Schrems II recommendations; no CY-specific TIA template was identified.

Absence provenance: unavailable. Searched: C, y, p, r, u, s, , C, o, m, m, i, s, s, i, o, n, e, r, , t, r, a, n, s, f, e, r, , i, m, p, a, c, t, , a, s, s, e, s, s, m, e, n, t, , g, u, i, d, a, n, c, e.

Data LocalisationGreen

No general data-localisation mandate was identified in Cyprus law beyond GDPR-compliant transfer mechanisms.

Absence provenance: unavailable. Searched: C, y, p, r, u, s, , d, a, t, a, , l, o, c, a, l, i, s, a, t, i, o, n, , m, a, n, d, a, t, e.

Category narrative56 words

As an EU Member State, Cyprus applies the GDPR Chapter V transfer regime directly: transfers to third countries rely on European Commission adequacy decisions, SCCs, BCRs or Art 49 derogations. Cyprus does not independently grant or receive adequacy decisions (this is an EU Commission competence); the Commissioner participates in EDPB review of the Commission's adequacy-decision reports.

Sources and claims (2)
  1. ConfirmedEUR-Lex — As an EU Member State, Cyprus applies GDPR Chapter V (Arts 44-49) transfer mechanisms directly, including adequacy decisions, SCCs, BCRs and Article 49 derogations, without a separate national transfer regime.observed
  2. ConfirmedEuropean Data Protection Board — The EDPB reviews the European Commission's periodic reports on the functioning of existing adequacy decisions, including methodological observations on government-access assessments, as part of the EU-wide (not Cyprus-specific) adequacy review process.observed

#

Financial and telecoms overlays are well evidenced; credit-scoring, education and insurance sub-modules lack dedicated sectoral instruments beyond the general Law and are marked amber/gap.

Primary frameworkGDPR + Law 125(I)/2018, overlaid by Law 112(I)/2004 (electronic communications) and Law 92(I)/96 (private communications)
Traffic-light rationale — AmberFinancial and telecoms overlays are well evidenced; credit-scoring, education and insurance sub-modules lack dedicated sectoral instruments beyond the general Law and are marked amber/gap.

Sub-modules (7)

Financial Sector OverlayAmber

The Commissioner has issued multiple enforcement decisions against the Bank of Cyprus for GDPR security and accountability violations, evidencing active financial-sector DP supervision alongside CBC/prudential oversight.

Claims (1):

  • The Bank of Cyprus has been subject to multiple GDPR enforcement decisions by the Commissioner, including a €17,000 fine in 2022 for security-of-processing violations and a further €8,000 fine, evidencing sustained financial-sector DP supervision.

Health Sector OverlayAmber

The Commissioner fined the State Health Services Organization €46,500 for GDPR breaches involving lost patient data, evidencing health-sector DP enforcement.

Claims (1):

  • Cyprus fined the State Health Services Organization €46,500 for GDPR breaches involving lost patient data.

Telecoms And EprivacyGreen

Electronic-communications data protection is governed by Law 112(I)/2004 (transposing the EU electronic communications framework) and the Private Communications (Surveillance of Conversations) Law 92(I)/96, alongside GDPR.

Claims (1):

  • Law 112(I)/2004 on the Regulation of Electronic Communications and Postal Services is the relevant national telecoms instrument interfacing with data protection in Cyprus.

Employment DataAmber

Employee monitoring is governed by GDPR, Law 125(I)/2018, the Private Communications Law 92(I)/96, and Articles 15/17 of the Cyprus Constitution.

Claims (1):

  • Employee monitoring in Cyprus is governed by the GDPR, Law 125(I)/2018, the Protection of the Secrecy of Private Communications (Surveillance of Conversations) Law No. 92(I)/96, and Articles 15 and 17 of the Constitution of the Republic of Cyprus.

Credit And ScoringRed

No CY-specific credit-scoring statute distinct from GDPR/Law 125(I)/2018 was identified.

Absence provenance: unavailable. Searched: C, y, p, r, u, s, , c, r, e, d, i, t, , s, c, o, r, i, n, g, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , s, e, c, t, o, r, a, l, , l, a, w.

EducationAmber

No dedicated education-sector DP statute distinct from GDPR/Law 125(I)/2018 was identified, though the Open University of Cyprus has been subject to GDPR enforcement following a cyber-attack.

Claims (1):

  • The Open University of Cyprus was fined €45,000 for GDPR violations following a cyber-attack, evidencing education-sector DP enforcement under the general GDPR/Law 125(I)/2018 regime.

InsuranceAmber

Law 125(I)/2018 carries a specific derogation permitting processing of genetic and biometric data for life-insurance purposes.

Claims (1):

  • Law 125(I)/2018 presents variations from the GDPR in relation to the processing of genetic and biometric data for life insurance purposes.
Category narrative77 words

Sectoral overlays supplementing GDPR/Law 125(I)/2018 include: telecoms/ePrivacy rules under Law 112(I)/2004 (electronic communications and postal services) and the Private Communications Law 92(I)/96 (secrecy of conversations); financial-sector processing supervised jointly by the Commissioner and prudential regulators, evidenced by repeated Bank of Cyprus enforcement actions; and health-sector processing evidenced by the State Health Services Organization fine. No CY-specific credit-scoring, education-sector or insurance-sector statute distinct from GDPR/Law 125(I)/2018 was identified beyond the genetic/biometric life-insurance derogation already noted in module 2.

Sources and claims (4)
  1. ConfirmedDataGuidance — The Bank of Cyprus has been subject to multiple GDPR enforcement decisions by the Commissioner, including a €17,000 fine in 2022 for security-of-processing violations and a further €8,000 fine, evidencing sustained financial-sector DP supervision.observed
  2. ConfirmedDataGuidance (summarising official Cyprus Gazette text) — Law 112(I)/2004 on the Regulation of Electronic Communications and Postal Services is the relevant national telecoms instrument interfacing with data protection in Cyprus.observed
  3. ConfirmedDataGuidance (summarising official Cyprus Gazette text) — Employee monitoring in Cyprus is governed by the GDPR, Law 125(I)/2018, the Protection of the Secrecy of Private Communications (Surveillance of Conversations) Law No. 92(I)/96, and Articles 15 and 17 of the Constitution of the Republic of Cyprus.observed
  4. ProbableDataGuidance — The Open University of Cyprus was fined €45,000 for GDPR violations following a cyber-attack, evidencing education-sector DP enforcement under the general GDPR/Law 125(I)/2018 regime.observed

#

Cookie/tracker and direct-marketing enforcement is well evidenced; dark-patterns, opt-out-signal (GPC-style) and clean-room/cross-context-advertising specific rules were not located.

Primary frameworkePrivacy Directive 2002/58/EC (as amended) transposed via Law 112(I)/2004, and GDPR
Traffic-light rationale — AmberCookie/tracker and direct-marketing enforcement is well evidenced; dark-patterns, opt-out-signal (GPC-style) and clean-room/cross-context-advertising specific rules were not located.

Sub-modules (6)

Cookies And TrackersAmber

The Commissioner fined Aylo Freesites Ltd €58,400 for GDPR violations and illegal cookie use, and separately published cookie-audit findings highlighting consent and categorisation issues.

Claims (1):

  • The Cyprus Commissioner for Personal Data Protection fined Aylo Freesites Ltd €58,400 for GDPR violations and illegal cookie use, and separately reported cookie-audit findings highlighting consent and categorisation issues.

Dark PatternsRed

No CY-specific dark-pattern prohibition distinct from GDPR consent-validity principles was identified.

Absence provenance: unavailable. Searched: C, y, p, r, u, s, , d, a, r, k, , p, a, t, t, e, r, n, s, , p, r, o, h, i, b, i, t, i, o, n, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n.

Opt Out SignalsRed

No Cyprus-specific recognition of browser-level opt-out signals (e.g. GPC) was identified.

Absence provenance: unavailable. Searched: C, y, p, r, u, s, , G, l, o, b, a, l, , P, r, i, v, a, c, y, , C, o, n, t, r, o, l, , o, p, t, -, o, u, t, , s, i, g, n, a, l, , r, e, c, o, g, n, i, t, i, o, n.

Clean Rooms And DcrRed

No Cyprus-specific data clean-room or data-collaboration-room regulation was identified.

Absence provenance: unavailable. Searched: C, y, p, r, u, s, , d, a, t, a, , c, l, e, a, n, , r, o, o, m, , r, e, g, u, l, a, t, i, o, n.

Cross Context AdvertisingAmber

No Cyprus-specific 'sale'/'share' cross-context advertising framework analogous to US state law was identified; general GDPR consent/legitimate-interest rules apply to ad-tech data sharing.

Absence provenance: unavailable. Searched: C, y, p, r, u, s, , c, r, o, s, s, -, c, o, n, t, e, x, t, , a, d, v, e, r, t, i, s, i, n, g, , d, a, t, a, , s, h, a, r, i, n, g, , r, u, l, e.

Direct MarketingGreen

The Commissioner has issued dedicated guidelines on direct marketing under the GDPR/Law 125(I)/2018 framework.

Claims (1):

  • The Commissioner has issued guidelines covering direct marketing among other key GDPR compliance topics.
Category narrative51 words

Cookie and tracker consent follows the ePrivacy Directive as transposed via Law 112(I)/2004, enforced by the Commissioner alongside GDPR. The Commissioner conducted a cookie compliance audit and fined Aylo Freesites Ltd €58,400 for GDPR violations and illegal cookie use, evidencing active adtech/cookie enforcement. Direct marketing is covered by dedicated Commissioner guidelines.

Sources and claims (2)
  1. ConfirmedDataGuidance — The Cyprus Commissioner for Personal Data Protection fined Aylo Freesites Ltd €58,400 for GDPR violations and illegal cookie use, and separately reported cookie-audit findings highlighting consent and categorisation issues.observed
  2. ConfirmedDataGuidance — The Commissioner has issued guidelines covering direct marketing among other key GDPR compliance topics.observed

#

Core Art 22 ADM protections are in force; biometric-specific, AI-risk-assessment and surveillance-carveout sub-modules rely on the general GDPR framework with no CY-specific instrument located.

Primary frameworkGDPR Art 22 as implemented by Law 125(I) of 2018
Traffic-light rationale — AmberCore Art 22 ADM protections are in force; biometric-specific, AI-risk-assessment and surveillance-carveout sub-modules rely on the general GDPR framework with no CY-specific instrument located.

Sub-modules (6)

Profiling RestrictionsGreen

GDPR Art 22 profiling restrictions apply directly; no CY-specific narrowing or broadening identified.

Absence provenance: unavailable. Searched: C, y, p, r, u, s, , p, r, o, f, i, l, i, n, g, , r, e, s, t, r, i, c, t, i, o, n, , s, u, p, p, l, e, m, e, n, t, a, r, y, , r, u, l, e.

Automated Decision Making TransparencyGreen

GDPR Art 22 ADM transparency and explanation rights apply directly in Cyprus with no local supplement identified.

Claims (1):

  • GDPR Article 22 automated-decision-making transparency and explanation rights apply directly to Cyprus-established controllers under the GDPR/Law 125(I)/2018 framework.

Ai Risk AssessmentsRed

No Cyprus-specific AI risk-assessment statute distinct from the EU AI Act's forthcoming application was identified.

Absence provenance: unavailable. Searched: C, y, p, r, u, s, , A, I, , r, i, s, k, , a, s, s, e, s, s, m, e, n, t, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , l, a, w, , 2, 0, 2, 6.

Biometric RegimeAmber

Beyond the life-insurance genetic/biometric derogation in Law 125(I)/2018, no dedicated facial-recognition or biometric-specific statute was identified.

Claims (1):

  • Law 125(I)/2018 presents variations from the GDPR in relation to the processing of genetic and biometric data for life insurance purposes.

Genetic DataAmber

Genetic data processing for life-insurance purposes is subject to the Law 125(I)/2018 derogation noted above.

Claims (1):

  • Law 125(I)/2018 presents variations from the GDPR in relation to the processing of genetic and biometric data for life insurance purposes.

State Surveillance CarveoutsRed

No CY-specific national-security surveillance carve-out distinct from GDPR Art 23/Law 125(I)/2018 general exemptions was identified.

Absence provenance: unavailable. Searched: C, y, p, r, u, s, , n, a, t, i, o, n, a, l, , s, e, c, u, r, i, t, y, , s, u, r, v, e, i, l, l, a, n, c, e, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , e, x, e, m, p, t, i, o, n.

Category narrative60 words

Profiling and automated-decision-making transparency follow GDPR Art 22 directly. The national genetic/biometric derogation for life insurance interacts with the biometric and genetic data sub-modules. No Cyprus-specific AI-risk-assessment regime distinct from the incoming EU AI Act, nor a dedicated facial-recognition/biometric statute, nor a state-surveillance carve-out statute distinct from national-security exemptions in GDPR Art 23/Law 125(I)/2018, was identified in the sources reviewed.

Sources and claims (1)
  1. ConfirmedEUR-Lex — GDPR Article 22 automated-decision-making transparency and explanation rights apply directly to Cyprus-established controllers under the GDPR/Law 125(I)/2018 framework.observed

#

Age-of-consent and parental-consent sub-modules are well evidenced; minor-profiling-ban, education-settings and dependent-adults sub-modules rely on the general regime with no dedicated instrument located.

Primary frameworkLaw 125(I) of 2018 (age of consent derogation) and GDPR Art 8
Traffic-light rationale — AmberAge-of-consent and parental-consent sub-modules are well evidenced; minor-profiling-ban, education-settings and dependent-adults sub-modules rely on the general regime with no dedicated instrument located.

Sub-modules (5)

Age VerificationAmber

The age of consent for information-society services in Cyprus is set at 14, a derogation from the GDPR default of 16.

Claims (1):

  • Law 125(I)/2018 sets the age of consent for information-society services at 14 years old, a derogation from the GDPR default age.

Minor Profiling BansRed

No CY-specific statutory ban on profiling of minors distinct from general GDPR Art 22/Recital 71 protections was identified.

Absence provenance: unavailable. Searched: C, y, p, r, u, s, , m, i, n, o, r, , p, r, o, f, i, l, i, n, g, , b, a, n, , s, t, a, t, u, t, e.

Education SettingsAmber

No dedicated education-settings DP statute distinct from GDPR/Law 125(I)/2018 was identified, notwithstanding enforcement action involving the Open University of Cyprus.

Claims (1):

  • The Open University of Cyprus was fined €45,000 for GDPR violations following a cyber-attack, evidencing education-sector DP enforcement under the general GDPR/Law 125(I)/2018 regime.

Dependent AdultsRed

No CY-specific dependent-adults (elderly/incapacitated) data-protection regime distinct from the general Law was identified.

Absence provenance: unavailable. Searched: C, y, p, r, u, s, , d, e, p, e, n, d, e, n, t, , a, d, u, l, t, s, , v, u, l, n, e, r, a, b, l, e, , p, e, r, s, o, n, s, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , r, e, g, i, m, e.

Category narrative58 words

Cyprus sets the digital age of consent at 14 (below the GDPR default of 16), requiring parental/guardian consent for data activities involving users aged 14 and under. The Commissioner has publicly emphasised children's data protection, urging parental, guardian and educator vigilance. No dedicated minor-profiling-ban statute, education-settings-specific DP rule, or dependent-adults-specific regime distinct from the general Law was identified.

Sources and claims (1)
  1. ConfirmedInternational Association of Privacy Professionals — The Cyprus Commissioner for the Protection of Personal Data has stressed the need for companies to ensure parental or legal-guardian consent for data activities related to users aged 14 and under.observed

#

Regulator possesses full GDPR enforcement powers and demonstrates sustained enforcement activity across sectors within the last 24 months.

Primary frameworkGDPR Arts 58, 77-84, as implemented by Law 125(I) of 2018
Traffic-light rationale — GreenRegulator possesses full GDPR enforcement powers and demonstrates sustained enforcement activity across sectors within the last 24 months.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

Law 125(I)/2018 provides for criminal offences, punishable with imprisonment, for certain violations of the Law and the GDPR, in addition to standard GDPR administrative fines.

Claims (1):

  • Legislation in Cyprus provides for criminal offences, punishable with imprisonment, for certain violations of Law 125(I)/2018 and the GDPR, in addition to the standard GDPR administrative fining regime.

Enforcement Activity IndexGreen

Multiple fines were issued in 2024-2025 spanning adtech (Aylo €58,400), health (State Health Services Organization €46,500), education (Open University €45,000), banking (Bank of Cyprus €17,000/€8,000), media (Politis €7,000, Arktinos €5,000).

Claims (1):

  • Recent Commissioner enforcement activity includes fines against Aylo Freesites Ltd (€58,400), the State Health Services Organization (€46,500), the Open University of Cyprus (€45,000), the Bank of Cyprus (€17,000 and €8,000), Politis (€7,000), and Arktinos Publishing Ltd (€5,000).

Regulator Funding And CapacityRed

No specific budget/headcount disclosure for the Commissioner's office was located in the sources reviewed.

Absence provenance: unavailable. Searched: C, y, p, r, u, s, , C, o, m, m, i, s, s, i, o, n, e, r, , P, e, r, s, o, n, a, l, , D, a, t, a, , P, r, o, t, e, c, t, i, o, n, , b, u, d, g, e, t, , h, e, a, d, c, o, u, n, t, , a, n, n, u, a, l, , r, e, p, o, r, t.

Collective Redress And Class ActionsRed

No Cyprus-specific collective-redress/class-action mechanism for data-protection claims distinct from GDPR Art 80 representative-action provisions was identified.

Absence provenance: unavailable. Searched: C, y, p, r, u, s, , c, o, l, l, e, c, t, i, v, e, , r, e, d, r, e, s, s, , c, l, a, s, s, , a, c, t, i, o, n, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , G, D, P, R, , A, r, t, i, c, l, e, , 8, 0, , i, m, p, l, e, m, e, n, t, a, t, i, o, n.

Private Right Of ActionGreen

GDPR Arts 79/82 judicial-remedy and compensation rights apply directly; no CY-specific supplementary private right of action was identified.

Absence provenance: unavailable. Searched: C, y, p, r, u, s, , p, r, i, v, a, t, e, , r, i, g, h, t, , o, f, , a, c, t, i, o, n, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , s, u, p, p, l, e, m, e, n, t, a, r, y.

Recent Developments 180DAmber

Within the last 180 days, Cyprus adopted a Law of 2025 implementing the Digital Services Act (designating competent authorities and fines) and approved amendments to the Network and Information Systems Security Law of 2025, both of which interface with the data-protection enforcement landscape.

Claims (1):

  • Cyprus published a Law of 2025 implementing the Digital Services Act, designating competent authorities and outlining fines for non-compliance, and approved the Network and Information Systems Security (Amendment) Law of 2025 enhancing cybersecurity measures and responsibilities.
Category narrative87 words

The Commissioner holds standard GDPR Art 58 investigative and corrective powers and Art 83 administrative-fining powers, plus Law 125(I)/2018 criminal offences (punishable by imprisonment) for certain violations. Enforcement activity in the last 12-24 months includes fines against Aylo Freesites (€58,400), the State Health Services Organization (€46,500), the Open University of Cyprus (€45,000), the Bank of Cyprus (€17,000 and €8,000), Politis (€7,000), and Arktinos Publishing (€5,000), plus a September 2024 public-sector compliance audit. No dedicated CY collective-redress/class-action mechanism or private-right-of-action statute distinct from GDPR Arts 79-82 was identified.

Sources and claims (3)
  1. ConfirmedDataGuidance — Legislation in Cyprus provides for criminal offences, punishable with imprisonment, for certain violations of Law 125(I)/2018 and the GDPR, in addition to the standard GDPR administrative fining regime.observed
  2. ConfirmedDataGuidance — Recent Commissioner enforcement activity includes fines against Aylo Freesites Ltd (€58,400), the State Health Services Organization (€46,500), the Open University of Cyprus (€45,000), the Bank of Cyprus (€17,000 and €8,000), Politis (€7,000), and Arktinos Publishing Ltd (€5,000).observed
  3. ProbableDataGuidance — Cyprus published a Law of 2025 implementing the Digital Services Act, designating competent authorities and outlining fines for non-compliance, and approved the Network and Information Systems Security (Amendment) Law of 2025 enhancing cybersecurity measures and responsibilities.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

Blocking. 3 failing check(s).

schema_validpass
min_architecture_patterns0
min_red_flags0
min_controls0
worked_examples_count0
decision_tree_nodes0
counterparty_diligence_questions0
min_t1_per_instrument_metn/a — no subject in this jurisdiction
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
board_briefing_presentFAIL
every_practical_object_has_source_idFAIL
source_tier_integrity_okpass
jurisdiction_source_floor_metFAIL
tier_a_b_national_primary_pct0.0
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Cyprus
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 27 claim(s) (27 category placement(s)), 13 source(s) in the cumulative register.

Audit trail

Machine checkChallenged on 29 Sep 2026: nothing tested (no claim on this page was eligible for an automated test). An automated, adversarial test run by a second model; no person has assessed the result.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsdeadlines and response windows
Art. 14Data Subject Rightsdeadlines and response windows
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsdeadlines and response windows
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy granted
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressregulator powers and penalties
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 81Enforcement & Redressenforcement activity index
Art. 82Enforcement & Redressprivate right of action
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

All 10 modules populated. T1 (primary legal instrument / regulator / EDPB official record) coverage was achieved for regulator_and_framework, lawful_processing_and_special_data core provisions, controller_processor_duties (DPIA list, security/breach enforcement decisions), cross_border_and_adequacy general mechanism, and enforcement_and_redress powers. T3 (secondary reporting via DataGuidance/IAPP) coverage was relied upon for enforcement-activity narratives (fines against Aylo, Bank of Cyprus, State Health Services Organization, Open University, Politis, Arktinos), the public-sector compliance audit, and the 2024 GDPR compliance guide, since primary Commissioner decision PDFs were not directly retrieved for all cases. Several sub-modules (credit_and_scoring, dark_patterns, opt_out_signals, clean_rooms_and_dcr, ai_risk_assessments, state_surveillance_carveouts, minor_profiling_bans, dependent_adults, regulator_funding_and_capacity, collective_redress_and_class_actions) carry explicit absent_field_provenance as no CY-specific instrument was located distinct from the general GDPR/Law 125(I)/2018 baseline.

Unresolved questions (4):

  • Does the Commissioner maintain a published annual budget/headcount report suitable for regulator_funding_and_capacity scoring?
  • Has Cyprus adopted any GDPR Article 80(2) collective-redress implementing provision beyond the bare GDPR text?
  • Is there a Cyprus-specific transfer impact assessment (TIA) template or guidance distinct from general EDPB recommendations?
  • Does the current Commissioner (per most recent EDPB member listing) supersede earlier-named officeholders referenced in older secondary sources?

Escalate to primary-source review: yes