🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
GR v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing17 sources retrieved model claude-sonnet-5 · 2026-08-05

Greece

GR schema gdpri-v2 trajectory: not yet assessedregulated (omnibus)overlaps: FIM, WPM, AIC

Last updated · 10 categories · 67 claims · 25 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
67Claimsbaseline..claims[]
11Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No red categories; 12 sub-modules are flagged red.

Jurisdiction brief

Latest update · 22 September 2026

Lead Signal

The Hellenic Data Protection Authority's enforcement posture in Greece registered material activity across data-subject rights and controller/processor obligations this cycle, alongside the launch of a new coordinated enforcement initiative. HDPA imposed an administrative fine of EUR 30,000 on a telecommunications company for violating GDPR Articles 12(1) through (4), 15 and 18, concerning the right of access and the right to restriction of processing -- confirmed evidence of active supervisory enforcement of these specific data-subject rights against the telecom sector.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Full GDPR direct effect plus a comprehensive, in-force national implementing statute and an active, well-resourced-relative-to-peers regulator.

Primary frameworkGDPR (Regulation (EU) 2016/679) as implemented and supplemented by Law 4624/2019
Traffic-light rationale — GreenFull GDPR direct effect plus a comprehensive, in-force national implementing statute and an active, well-resourced-relative-to-peers regulator.

Sub-modules (5)

Regulator And AuthorityGreen

HDPA is the constitutionally and statutorily established supervisory authority.

Claims (1):

  • The Hellenic Data Protection Authority (HDPA) is the supervisory authority responsible for enforcing the GDPR and Law 4624/2019 in Greece.

Act And InstrumentsGreen

Law 4624/2019 (GDPR implementation + LED transposition) and Law 3471/2006 (electronic communications privacy) form the core instruments.

Claims (2):

  • Greece implemented the GDPR through Law 4624/2019, which supplements the GDPR on matters left to Member State discretion, transposes the Law Enforcement Directive (EU) 2016/680, and re-establishes the HDPA.
  • Law 3471/2006 (the Electronic Communications Privacy Law) supplements the GDPR/Law 4624/2019 framework and governs cookies, trackers and electronic communications privacy in Greece.

Material ScopeGreen

HDPA competence extends to essentially all national and transnational processing, with a national-security carve-out.

Claims (1):

  • The HDPA is competent to supervise every national and transnational personal data processing operation within its jurisdiction, with limited exceptions for national security matters.

Territorial ScopeGreen

HDPA has applied the GDPR Article 3 targeting criterion to assert jurisdiction over non-established controllers.

Claims (1):

  • The HDPA applies the GDPR Article 3 targeting criterion to assert territorial competence over non-established controllers, such as Clearview AI, that process the personal data of individuals in Greece.

Regulator Registration And FilingAmber

No general controller registration/notification regime survives under the GDPR-era framework; accountability/ROPA obligations replace the old Law 2472/1997 notification system.

Claims (1):

  • Greece's GDPR-era regime does not impose a general notification/registration requirement on controllers; the prior registration system under Law 2472/1997 was replaced by the GDPR's accountability and records-of-processing obligations.
Category narrative56 words

Greece operates a mature, GDPR-aligned omnibus regime. The Hellenic Data Protection Authority (HDPA) is the primary supervisory authority, re-established and empowered by Law 4624/2019, which implements the GDPR domestically, transposes the Law Enforcement Directive (EU) 2016/680, and supplements the Regulation on matters left to Member State discretion. Law 3471/2006 supplements the framework for electronic communications privacy.

Sources and claims (6)
  1. ConfirmedGovernment Gazette of the Hellenic Republic / HDPA — The Hellenic Data Protection Authority (HDPA) is the supervisory authority responsible for enforcing the GDPR and Law 4624/2019 in Greece.observed
  2. ConfirmedIAPP — Greece implemented the GDPR through Law 4624/2019, which supplements the GDPR on matters left to Member State discretion, transposes the Law Enforcement Directive (EU) 2016/680, and re-establishes the HDPA.observed
  3. ConfirmedOneTrust DataGuidance — Law 3471/2006 (the Electronic Communications Privacy Law) supplements the GDPR/Law 4624/2019 framework and governs cookies, trackers and electronic communications privacy in Greece.observed
  4. ConfirmedEuropean Data Protection Board — The HDPA is competent to supervise every national and transnational personal data processing operation within its jurisdiction, with limited exceptions for national security matters.observed
  5. ConfirmedIAPP — The HDPA applies the GDPR Article 3 targeting criterion to assert territorial competence over non-established controllers, such as Clearview AI, that process the personal data of individuals in Greece.observed
  6. ProbableIAPP — Greece's GDPR-era regime does not impose a general notification/registration requirement on controllers; the prior registration system under Law 2472/1997 was replaced by the GDPR's accountability and records-of-processing obligations.observed

#

Comprehensive statutory lawful-basis and special-category framework, though the HDPA itself has flagged one internal inconsistency (Article 5 vs GDPR Article 6) and no distinct national pseudonymisation safe-harbour was found.

Primary frameworkGDPR Articles 6, 7, 9 as supplemented by Law 4624/2019 Articles 5, 21-23
Traffic-light rationale — GreenComprehensive statutory lawful-basis and special-category framework, though the HDPA itself has flagged one internal inconsistency (Article 5 vs GDPR Article 6) and no distinct national pseudonymisation safe-harbour was found.

Sub-modules (4)

Lawful BasesAmber

GDPR Article 6 applies directly; Law 4624/2019 Article 5 restates it, a repetition the HDPA flagged as inconsistent with EU law.

Claims (1):

  • GDPR Article 6 lawful bases for processing apply directly in Greece; Law 4624/2019 Article 5 restates Article 6 GDPR domestically, a repetition the HDPA itself flagged as inconsistent with EU law in its January 2020 opinion.

Special CategoriesGreen

Special-category processing permitted without consent for health/social-care/social-security purposes; genetic data barred from insurance use.

Claims (2):

  • Processing of special categories of data by public and private entities is permitted without data subject consent where mandatory for health care, social care, social security, or work-capacity assessment, subject to safeguards for data subject interests.
  • Law 4624/2019 Article 23 prohibits the processing of genetic data for health and life insurance purposes.

Pseudonymisation And AnonymisationRed

No Greece-specific statutory safe-harbour identified beyond the GDPR's own definitions.

Claims (1):

  • No Greek-specific statutory safe-harbour or derogation for pseudonymisation/anonymisation beyond the GDPR Article 4(5) definition and Recital 26 was identified in Law 4624/2019 or HDPA guidance reviewed.
Category narrative37 words

GDPR Articles 6, 7 and 9 apply directly, supplemented by Law 4624/2019's specific provisions on the digital consent age (15), employment-context processing, special-category processing for health/social-security purposes, and a prohibition on genetic data use for insurance underwriting.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (5)
  1. ConfirmedOneTrust DataGuidance — GDPR Article 6 lawful bases for processing apply directly in Greece; Law 4624/2019 Article 5 restates Article 6 GDPR domestically, a repetition the HDPA itself flagged as inconsistent with EU law in its January 2020 opinion.observed
  2. ConfirmedOneTrust DataGuidance — Law 4624/2019 Article 21 sets the age of a minor's valid consent to processing in relation to information society services at 15 years old; below that age, parental or guardian consent is required.observed
  3. ConfirmedIAPP — Processing of special categories of data by public and private entities is permitted without data subject consent where mandatory for health care, social care, social security, or work-capacity assessment, subject to safeguards for data subject interests.observed
  4. ConfirmedOneTrust DataGuidance — Law 4624/2019 Article 23 prohibits the processing of genetic data for health and life insurance purposes.observed
  5. UncertainOneTrust DataGuidance — No Greek-specific statutory safe-harbour or derogation for pseudonymisation/anonymisation beyond the GDPR Article 4(5) definition and Recital 26 was identified in Law 4624/2019 or HDPA guidance reviewed.observed

#

Core rights actively enforced (access); ancillary rights (restriction, portability) rely on direct GDPR application without located national supplements.

Primary frameworkGDPR Articles 12-22 (direct effect), no material national derogation identified
Traffic-light rationale — GreenCore rights actively enforced (access); ancillary rights (restriction, portability) rely on direct GDPR application without located national supplements.

Sub-modules (5)

Access RightGreen

Actively enforced; multiple fines for DSAR non-compliance.

Claims (2):

  • The HDPA has enforced the GDPR Article 15 right of access, including fining UGHL €7,000 for unlawful data processing and failure to fulfill a data access request.
  • The HDPA fined an association for people with Autism Spectrum Disorder for failing to satisfy a parental right-of-access request for CCTV footage and for unlawfully transmitting a minor's sensitive data to a third party.

Rectification And ErasureAmber

Greece participated in the EDPB's 2025 CEF right-to-erasure action.

Claims (1):

  • Greece participated as one of 32 DPAs in the EDPB's 2025 Coordinated Enforcement Framework (CEF) action examining implementation of the GDPR right to erasure.

Restriction And ObjectionRed

No Greece-specific derogation identified.

Claims (1):

  • No Greece-specific derogation from the GDPR Articles 18 and 21 restriction/objection rights was identified beyond direct application of the Regulation.

Data PortabilityRed

No Greece-specific derogation identified.

Claims (1):

  • No Greece-specific derogation from the GDPR Article 20 data portability right was identified; the right applies as set out directly in the Regulation.

Deadlines And Response WindowsAmber

GDPR Article 12(3) one-month (extendable) window applies directly.

Claims (1):

  • The GDPR Article 12(3) one-month response deadline (extendable by two further months for complex requests) applies directly to Greek controllers without a shorter or longer national derogation identified.
Category narrative43 words

GDPR Articles 12-22 apply directly. HDPA enforcement activity demonstrates active protection of the access right in particular; erasure was the subject of a 2025 EDPB Coordinated Enforcement Framework action involving Greece. No distinct Greek derogations were identified for restriction, objection or portability rights.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (6)
  1. ConfirmedOneTrust DataGuidance — The HDPA has enforced the GDPR Article 15 right of access, including fining UGHL €7,000 for unlawful data processing and failure to fulfill a data access request.observed
  2. ConfirmedEuropean Data Protection Board — The HDPA fined an association for people with Autism Spectrum Disorder for failing to satisfy a parental right-of-access request for CCTV footage and for unlawfully transmitting a minor's sensitive data to a third party.observed
  3. ProbableOneTrust DataGuidance — Greece participated as one of 32 DPAs in the EDPB's 2025 Coordinated Enforcement Framework (CEF) action examining implementation of the GDPR right to erasure.observed
  4. UncertainGovernment Gazette of the Hellenic Republic / HDPA — No Greece-specific derogation from the GDPR Articles 18 and 21 restriction/objection rights was identified beyond direct application of the Regulation.observed
  5. UncertainGovernment Gazette of the Hellenic Republic / HDPA — No Greece-specific derogation from the GDPR Article 20 data portability right was identified; the right applies as set out directly in the Regulation.observed
  6. ProbableGovernment Gazette of the Hellenic Republic / HDPA — The GDPR Article 12(3) one-month response deadline (extendable by two further months for complex requests) applies directly to Greek controllers without a shorter or longer national derogation identified.observed

#

Strong, evidenced enforcement across accountability, security and breach sub-modules; retention/disposal relies solely on GDPR Article 5(1)(e).

Primary frameworkGDPR Articles 5, 24-32, 33-35, 37-39 as supplemented by Law 4624/2019
Traffic-light rationale — GreenStrong, evidenced enforcement across accountability, security and breach sub-modules; retention/disposal relies solely on GDPR Article 5(1)(e).

Sub-modules (7)

Accountability And DpiaGreen

HDPA-issued DPIA-trigger list; own-initiative accountability investigation into government surveillance systems.

Claims (2):

  • The HDPA has issued a list of processing operations subject to the mandatory Data Protection Impact Assessment (DPIA) requirement under GDPR Article 35(4).
  • The HDPA fined the Hellenic Ministry of Migration and Asylum €175,000 following an own-initiative investigation into the 'Centaur' and 'Hyperion' border-surveillance systems for breaches relating to cooperation with the Authority and deficient impact assessments.

Dpo RequirementsAmber

Law 4624/2019 contains DPO provisions; HDPA flagged an LED-incompatibility in public-sector exemptions.

Claims (2):

  • Law 4624/2019 contains specific provisions on the appointment, role and independence of Data Protection Officers, including for public bodies.
  • The HDPA's January 2020 opinion found that Law 4624/2019's additional exemptions for public institutions from the GDPR Article 37 DPO-appointment mandate were incompatible with Article 32(4) of the Law Enforcement Directive.

Ropa RequirementsAmber

GDPR Article 30 applies directly; HDPA guidance references processing-records compliance.

Claims (1):

  • No Greece-specific derogation from the GDPR Article 30 records-of-processing obligation was identified beyond direct application of the Regulation and HDPA guidance referencing processing-records compliance.

Joint Controller ArrangementsGreen

COSMOTE/OTE decision applied joint controller-processor role-allocation accountability.

Claims (1):

  • In its 2022 decision against COSMOTE and OTE, the HDPA found the companies had failed to properly allocate their respective controller/processor roles and responsibilities in relation to a data breach, applying GDPR joint/controller-processor accountability principles.

Security MeasuresGreen

ADAE Decision 304/2025 mandates telecom security measures; ELTA fined for inadequate technical/organisational measures.

Claims (2):

  • ADAE Decision No. 304/2025 mandates specific technical and organisational security measures for electronic communications providers to ensure confidentiality and manage risk.
  • The HDPA fined Hellenic Post Services S.A. (ELTA) a sum equal to 1% of its annual turnover for failing to implement adequate technical and organisational security measures following ransomware and dark-web data-leak incidents.

Breach NotificationGreen

Multiple high-value breach-related fines (Vodafone 2025; Cosmote/OTE 2022).

Claims (2):

  • The HDPA fined Vodafone Greece and its processor in a June 2025 decision for a personal-data breach and insufficient security measures relating to unauthorised prepaid mobile-line activations, applying GDPR Articles 5(1)(d), 28, 29 and 32.
  • In its 2022 decision, the HDPA fined COSMOTE €6,000,000 and OTE €3,250,000 for infringing GDPR breach-related obligations, including inadequate security measures, poor anonymisation and an insufficient data protection impact assessment following a September 2020 subscriber call-data breach.

Retention And DisposalRed

No dedicated national retention-period statute identified beyond GDPR storage limitation.

Claims (1):

  • No Greece-specific general statutory retention-period regime beyond the GDPR Article 5(1)(e) storage-limitation principle was identified in Law 4624/2019 or HDPA guidance reviewed.
Category narrative55 words

HDPA has issued a DPIA-trigger list, actively enforces security-of-processing and breach obligations (Cosmote/OTE €9.25M combined 2022; Vodafone 2025; Hellenic Post/ELTA ransomware fine), and pursued an own-initiative DPIA/cooperation investigation into government border-surveillance systems. DPO provisions exist in Law 4624/2019, though the HDPA flagged a LED-incompatibility in public-sector DPO exemptions. No distinct national retention-period statute was located.

Periodic update · new data 2026-09-22

Controller/Processor Duties

HDPA's largest fines to date in Greece target failures in security-of-processing and transparency obligations under the GDPR: a EUR 6 million fine against COSMOTE and a EUR 3.25 million fine against OTE, addressing unclear subscriber information and inadequate security measures, including infrastructure security failures. These are the most significant financial penalties in HDPA's enforcement history and demonstrate that the authority is prepared to impose substantial fines where controller obligations around security of processing and transparent subscriber communication are found deficient, particularly in the telecommunications sector, which handles large volumes of subscriber personal data.

These fines should be read cautiously on sourcing grounds: the underlying claim is drawn from a single lower-tier aggregator source rather than a direct HDPA decision publication, so while the figures are treated as confirmed for the purposes of this brief, a Tier-1 confirmation from HDPA's own decision register would strengthen the evidentiary basis. Even with that caveat, the scale of the fines is consistent with HDPA's demonstrated willingness to escalate enforcement against controller-side security and transparency failures at large telecom operators, a pattern that sits alongside the authority's separate access-rights enforcement action this cycle.

Outlook

Confirmation of the COSMOTE and OTE fine figures via a primary HDPA decision publication remains the key outstanding verification step. Should these figures be confirmed at a Tier-1 source, they would stand as the clearest evidence yet of HDPA's capacity and willingness to impose GDPR's higher-end penalty tiers against large controllers.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (11)
  1. ConfirmedOneTrust DataGuidance — The HDPA has issued a list of processing operations subject to the mandatory Data Protection Impact Assessment (DPIA) requirement under GDPR Article 35(4).observed
  2. ConfirmedEuropean Data Protection Board — The HDPA fined the Hellenic Ministry of Migration and Asylum €175,000 following an own-initiative investigation into the 'Centaur' and 'Hyperion' border-surveillance systems for breaches relating to cooperation with the Authority and deficient impact assessments.observed
  3. ConfirmedIAPP — Law 4624/2019 contains specific provisions on the appointment, role and independence of Data Protection Officers, including for public bodies.observed
  4. ConfirmedOneTrust DataGuidance — The HDPA's January 2020 opinion found that Law 4624/2019's additional exemptions for public institutions from the GDPR Article 37 DPO-appointment mandate were incompatible with Article 32(4) of the Law Enforcement Directive.observed
  5. ProbableOneTrust DataGuidance — No Greece-specific derogation from the GDPR Article 30 records-of-processing obligation was identified beyond direct application of the Regulation and HDPA guidance referencing processing-records compliance.observed
  6. ConfirmedEuropean Data Protection Board — In its 2022 decision against COSMOTE and OTE, the HDPA found the companies had failed to properly allocate their respective controller/processor roles and responsibilities in relation to a data breach, applying GDPR joint/controller-processor accountability principles.observed
  7. ConfirmedOneTrust DataGuidance — ADAE Decision No. 304/2025 mandates specific technical and organisational security measures for electronic communications providers to ensure confidentiality and manage risk.observed
  8. ConfirmedEuropean Data Protection Board — The HDPA fined Hellenic Post Services S.A. (ELTA) a sum equal to 1% of its annual turnover for failing to implement adequate technical and organisational security measures following ransomware and dark-web data-leak incidents.observed
  9. ConfirmedEuropean Data Protection Board — The HDPA fined Vodafone Greece and its processor in a June 2025 decision for a personal-data breach and insufficient security measures relating to unauthorised prepaid mobile-line activations, applying GDPR Articles 5(1)(d), 28, 29 and 32.observed
  10. ConfirmedEuropean Data Protection Board — In its 2022 decision, the HDPA fined COSMOTE €6,000,000 and OTE €3,250,000 for infringing GDPR breach-related obligations, including inadequate security measures, poor anonymisation and an insufficient data protection impact assessment following a September 2020 subscriber call-data breach.observed
  11. UncertainGovernment Gazette of the Hellenic Republic / HDPA — No Greece-specific general statutory retention-period regime beyond the GDPR Article 5(1)(e) storage-limitation principle was identified in Law 4624/2019 or HDPA guidance reviewed.observed

#

Chapter V applies with full direct effect; no Greek derogation or gap identified beyond the EU-wide framework.

Primary frameworkGDPR Chapter V (Articles 44-49), direct effect in Greece
Traffic-light rationale — GreenChapter V applies with full direct effect; no Greek derogation or gap identified beyond the EU-wide framework.

Sub-modules (6)

Transfer MechanismsGreen

GDPR Chapter V mechanisms apply directly.

Claims (1):

  • As an EU Member State, Greece applies the GDPR Chapter V transfer regime (Articles 44-49) directly, including adequacy decisions, Standard Contractual Clauses, Binding Corporate Rules and derogations, without a distinct national transfer mechanism identified in Law 4624/2019.

Adequacy ReceivedAmber

No Greece-specific inbound adequacy determination; EU-level mechanism applies.

Claims (1):

  • There is no Greece-specific adequacy decision received from a third country; inbound adequacy findings under GDPR Article 45 are determined at EU level and apply automatically to Greece as a Member State.

Adequacy GrantedAmber

Adequacy decisions are adopted at EU level and apply uniformly to Greece; no separate Greek determinations.

Claims (1):

  • Adequacy decisions applicable in Greece are adopted centrally by the European Commission under GDPR Article 45 and apply uniformly across all EU Member States; Greece does not issue separate national adequacy determinations.

Sccs And BcrsGreen

SCCs/BCRs available under standard EU-wide forms.

Claims (1):

  • Standard Contractual Clauses and Binding Corporate Rules are available and used as GDPR Chapter V transfer mechanisms in Greece under the same EU-wide forms and EDPB/Commission templates, with no Greece-specific supplementary form identified.

Transfer Impact AssessmentAmber

TIA obligation applies via EU-wide post-Schrems II framework.

Claims (1):

  • Greek controllers relying on SCCs for international transfers are subject to the EU-wide Transfer Impact Assessment obligation established following the CJEU's Schrems II ruling, with no distinct Greek-specific TIA methodology identified beyond EDPB guidance.

Data LocalisationGreen

No general localisation mandate; HDPA supervises specific EU-system databases.

Claims (1):

  • Rather than a general data-localisation mandate, the HDPA supervises specific national law-enforcement and border-management databases connected to EU-wide systems (Europol National Unit, SIS II, VIS, Eurodac, CIS and PNR under Law 4579/2018), which involve constrained, system-specific data-residency and access rules.
Category narrative57 words

As an EU Member State, Greece applies the GDPR Chapter V transfer regime directly (adequacy, SCCs, BCRs, derogations, TIA), with no distinct national mechanism identified. Adequacy decisions are set centrally by the European Commission and apply uniformly. The HDPA additionally supervises specific EU-system databases (SIS II, VIS, Eurodac, CIS, PNR) rather than operating a general data-localisation mandate.

Sources and claims (6)
  1. ConfirmedGovernment Gazette of the Hellenic Republic / HDPA — As an EU Member State, Greece applies the GDPR Chapter V transfer regime (Articles 44-49) directly, including adequacy decisions, Standard Contractual Clauses, Binding Corporate Rules and derogations, without a distinct national transfer mechanism identified in Law 4624/2019.observed
  2. ProbableGovernment Gazette of the Hellenic Republic / HDPA — There is no Greece-specific adequacy decision received from a third country; inbound adequacy findings under GDPR Article 45 are determined at EU level and apply automatically to Greece as a Member State.observed
  3. ProbableGovernment Gazette of the Hellenic Republic / HDPA — Adequacy decisions applicable in Greece are adopted centrally by the European Commission under GDPR Article 45 and apply uniformly across all EU Member States; Greece does not issue separate national adequacy determinations.observed
  4. ProbableGovernment Gazette of the Hellenic Republic / HDPA — Standard Contractual Clauses and Binding Corporate Rules are available and used as GDPR Chapter V transfer mechanisms in Greece under the same EU-wide forms and EDPB/Commission templates, with no Greece-specific supplementary form identified.observed
  5. ProbableGovernment Gazette of the Hellenic Republic / HDPA — Greek controllers relying on SCCs for international transfers are subject to the EU-wide Transfer Impact Assessment obligation established following the CJEU's Schrems II ruling, with no distinct Greek-specific TIA methodology identified beyond EDPB guidance.observed
  6. ConfirmedEuropean Data Protection Board — Rather than a general data-localisation mandate, the HDPA supervises specific national law-enforcement and border-management databases connected to EU-wide systems (Europol National Unit, SIS II, VIS, Eurodac, CIS and PNR under Law 4579/2018), which involve constrained, system-specific data-residency and access rules.observed

#

Strong telecoms/employment/health coverage; credit-scoring sub-module has no located sectoral statute beyond GDPR Article 22.

Primary frameworkGDPR + Law 4624/2019 sectoral provisions + Law 3471/2006 (telecoms)
Traffic-light rationale — AmberStrong telecoms/employment/health coverage; credit-scoring sub-module has no located sectoral statute beyond GDPR Article 22.

Sub-modules (7)

Financial Sector OverlayAmber

HDPA has fined banking-sector entities for incorrect data processing.

Claims (1):

  • The HDPA fined Piraeus Bank €50,000 for GDPR violations arising from incorrect data processing, illustrating financial-sector overlay enforcement.

Health Sector OverlayGreen

HDPA enforces special-category health-data rules against individual practitioners.

Claims (1):

  • The HDPA fined a gynecologist €5,000 for unauthorized access to a former patient's health data, illustrating health-sector overlay enforcement of GDPR special-category rules.

Telecoms And EprivacyGreen

Law 3471/2006 plus ADAE communications-security oversight.

Claims (1):

  • Law 3471/2006, as amended, governs the confidentiality of electronic communications and cookies in Greece and is enforced by the HDPA alongside the National Telecommunications Authority ADAE, which is itself responsible for communications-security oversight (e.g., ADAE Decision No. 304/2025).

Employment DataGreen

Law 4624/2019 restricts employee-data processing purposes.

Claims (1):

  • Law 4624/2019 restricts the lawful purposes for processing employee personal data to those necessary for recruitment and for the performance and execution of the employment contract, and permits processing on the basis of collective labor agreements.

Credit And ScoringRed

No dedicated Greek credit-scoring statute located.

Claims (1):

  • No Greece-specific statutory credit-scoring or automated-lending-decision regime beyond direct application of GDPR Article 22 was identified in Law 4624/2019 or HDPA guidance reviewed.

EducationAmber

Ed-tech provider fined for DSAR/child-data violations.

Claims (1):

  • The HDPA fined ed-tech provider IMathisi €4,000 for GDPR violations including denying a parent's access request to a child's data and failing to cooperate with the Authority, illustrating education-sector enforcement.

InsuranceGreen

Genetic-data insurance-use prohibition under Article 23.

Claims (1):

  • Law 4624/2019 Article 23 prohibits processing genetic data for health and life insurance purposes, constraining insurance-sector use of sensitive data.
Category narrative40 words

Sector-specific enforcement is evidenced in telecoms (Law 3471/2006, ADAE oversight), employment (Law 4624/2019 employment provisions), health (patient-data access-abuse fines), financial services (Piraeus Bank fine), insurance (genetic-data insurance ban), and education (ed-tech DSAR fine). No dedicated Greek credit-scoring statute was located.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (7)
  1. ConfirmedOneTrust DataGuidance — The HDPA fined Piraeus Bank €50,000 for GDPR violations arising from incorrect data processing, illustrating financial-sector overlay enforcement.observed
  2. ConfirmedOneTrust DataGuidance — The HDPA fined a gynecologist €5,000 for unauthorized access to a former patient's health data, illustrating health-sector overlay enforcement of GDPR special-category rules.observed
  3. ConfirmedEuropean Data Protection Board — Law 3471/2006, as amended, governs the confidentiality of electronic communications and cookies in Greece and is enforced by the HDPA alongside the National Telecommunications Authority ADAE, which is itself responsible for communications-security oversight (e.g., ADAE Decision No. 304/2025).observed
  4. ConfirmedIAPP — Law 4624/2019 restricts the lawful purposes for processing employee personal data to those necessary for recruitment and for the performance and execution of the employment contract, and permits processing on the basis of collective labor agreements.observed
  5. UncertainOneTrust DataGuidance — No Greece-specific statutory credit-scoring or automated-lending-decision regime beyond direct application of GDPR Article 22 was identified in Law 4624/2019 or HDPA guidance reviewed.observed
  6. ConfirmedOneTrust DataGuidance — The HDPA fined ed-tech provider IMathisi €4,000 for GDPR violations including denying a parent's access request to a child's data and failing to cooperate with the Authority, illustrating education-sector enforcement.observed
  7. ConfirmedOneTrust DataGuidance — Law 4624/2019 Article 23 prohibits processing genetic data for health and life insurance purposes, constraining insurance-sector use of sensitive data.observed

#

Core cookie/marketing regime is solid; newer adtech-specific concepts (dark patterns, GPC-style signals, clean rooms) are not distinctly regulated nationally.

Primary frameworkLaw 3471/2006 (ePrivacy transposition) + GDPR consent/legitimate-interest framework
Traffic-light rationale — AmberCore cookie/marketing regime is solid; newer adtech-specific concepts (dark patterns, GPC-style signals, clean rooms) are not distinctly regulated nationally.

Sub-modules (6)

Cookies And TrackersGreen

Law 3471/2006 plus dedicated HDPA guidance on cookies and trackers.

Claims (2):

  • Law 3471/2006 governs cookies and other online trackers in Greece, supplementing the GDPR and the EU ePrivacy Directive framework.
  • The HDPA has issued guidelines specifically addressing cookies and other trackers as part of its GDPR compliance guidance programme.

Dark PatternsRed

No distinct national prohibition identified.

Claims (1):

  • No Greece-specific statutory prohibition on dark patterns distinct from the GDPR consent/transparency principles and EU-level Digital Services Act provisions was identified.

Opt Out SignalsRed

No recognition of GPC-style signals identified in HDPA guidance.

Claims (1):

  • No Greece-specific recognition of browser-level opt-out signals (e.g., Global Privacy Control) as a valid GDPR objection mechanism was identified in HDPA guidance reviewed.

Clean Rooms And DcrRed

No dedicated clean-room framework identified.

Claims (1):

  • No Greece-specific data clean-room or data-collaboration-room regulatory framework was identified beyond general GDPR joint-controller and processor rules.

Cross Context AdvertisingAmber

Governed by general GDPR consent/legitimate-interest rules and Law 3471/2006.

Claims (1):

  • No Greece-specific 'sale'/'share' cross-context-advertising concept analogous to US state law was identified; cross-context advertising in Greece is governed by the GDPR consent and legitimate-interest framework and Law 3471/2006.

Direct MarketingGreen

Old opt-out mail register repealed; GDPR/ePrivacy consent rules apply.

Claims (1):

  • Law 4624/2019 repealed the prior opt-out register for unsolicited commercial communications by mail that existed under Law 2472/1997, replacing it with GDPR/ePrivacy-based direct-marketing consent rules.
Category narrative34 words

Law 3471/2006 and HDPA guidance govern cookies/trackers and direct marketing; the old opt-out mail-marketing register was repealed in favour of GDPR/ePrivacy-based consent rules. No Greece-specific dark-pattern prohibition, opt-out-signal recognition, or clean-room framework was identified.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (7)
  1. ConfirmedOneTrust DataGuidance — Law 3471/2006 governs cookies and other online trackers in Greece, supplementing the GDPR and the EU ePrivacy Directive framework.observed
  2. ConfirmedOneTrust DataGuidance — The HDPA has issued guidelines specifically addressing cookies and other trackers as part of its GDPR compliance guidance programme.observed
  3. UncertainOneTrust DataGuidance — No Greece-specific statutory prohibition on dark patterns distinct from the GDPR consent/transparency principles and EU-level Digital Services Act provisions was identified.observed
  4. UncertainOneTrust DataGuidance — No Greece-specific recognition of browser-level opt-out signals (e.g., Global Privacy Control) as a valid GDPR objection mechanism was identified in HDPA guidance reviewed.observed
  5. UncertainOneTrust DataGuidance — No Greece-specific data clean-room or data-collaboration-room regulatory framework was identified beyond general GDPR joint-controller and processor rules.observed
  6. ProbableOneTrust DataGuidance — No Greece-specific 'sale'/'share' cross-context-advertising concept analogous to US state law was identified; cross-context advertising in Greece is governed by the GDPR consent and legitimate-interest framework and Law 3471/2006.observed
  7. ConfirmedIAPP — Law 4624/2019 repealed the prior opt-out register for unsolicited commercial communications by mail that existed under Law 2472/1997, replacing it with GDPR/ePrivacy-based direct-marketing consent rules.observed

#

Strong, landmark biometric enforcement; AI-risk-assessment and ADM-transparency sub-modules remain reliant on general GDPR application pending fuller national AI-Act interface, and state-surveillance oversight faces documented independence concerns.

Primary frameworkGDPR Articles 9, 22 as supplemented by Law 4624/2019 Article 23; EU AI Act interface emerging
Traffic-light rationale — AmberStrong, landmark biometric enforcement; AI-risk-assessment and ADM-transparency sub-modules remain reliant on general GDPR application pending fuller national AI-Act interface, and state-surveillance oversight faces documented independence concerns.

Sub-modules (6)

Profiling RestrictionsGreen

Clearview AI profiling/targeting findings.

Claims (1):

  • The HDPA found that Clearview AI's use of facial-recognition profiling techniques to identify and monitor individuals constituted an act of targeting triggering GDPR profiling-related obligations and the strict Article 9 regime for biometric data.

Automated Decision Making TransparencyAmber

GDPR Article 22 applies directly; no distinct national derogation.

Claims (1):

  • GDPR Article 22 automated-decision-making transparency and explanation rights apply directly in Greece with no distinct national derogation identified in Law 4624/2019.

Ai Risk AssessmentsAmber

HDPA's DeepSeek EU-representative order signals emerging AI scrutiny.

Claims (1):

  • The HDPA required the AI chatbot provider DeepSeek to appoint an EU representative under GDPR Article 27 due to compliance concerns, reflecting emerging HDPA scrutiny of AI service providers.

Biometric RegimeGreen

Landmark €20M Clearview AI fine for unlawful biometric processing.

Claims (1):

  • The HDPA imposed a €20 million fine on Clearview AI — its largest fine to date — for unlawfully processing biometric facial-recognition data of Greek residents in violation of GDPR Articles 5(1)(a), 6, 9, 14 and 27.

Genetic DataGreen

Article 23 genetic-data insurance prohibition.

Claims (1):

  • Law 4624/2019 Article 23 prohibits the processing of genetic data for health and life insurance purposes, forming Greece's principal statutory genetic-data-specific restriction.

State Surveillance CarveoutsAmber

National-security carve-out exists; European Parliament flagged independence/oversight concerns amid the Predator spyware scandal.

Claims (1):

  • The HDPA is competent to supervise national and transnational data processing with limited exceptions for national security, and Greek surveillance oversight (including the ADAE communications-security authority) has faced European Parliament scrutiny over the 'Predator' spyware scandal and weakened post-surveillance notification safeguards.
Category narrative62 words

The HDPA's landmark €20 million fine against Clearview AI for unlawful biometric facial-recognition processing anchors this module. Genetic-data restrictions exist for insurance purposes. The HDPA has begun scrutinizing AI service providers (DeepSeek EU-representative order). Surveillance oversight has faced European Parliament criticism amid the 'Predator' spyware controversy, and ADM transparency relies on direct GDPR Article 22 application without a distinct national AI-risk-assessment regime.

Sources and claims (6)
  1. ConfirmedIAPP — The HDPA found that Clearview AI's use of facial-recognition profiling techniques to identify and monitor individuals constituted an act of targeting triggering GDPR profiling-related obligations and the strict Article 9 regime for biometric data.observed
  2. ProbableGovernment Gazette of the Hellenic Republic / HDPA — GDPR Article 22 automated-decision-making transparency and explanation rights apply directly in Greece with no distinct national derogation identified in Law 4624/2019.observed
  3. ProbableOneTrust DataGuidance — The HDPA required the AI chatbot provider DeepSeek to appoint an EU representative under GDPR Article 27 due to compliance concerns, reflecting emerging HDPA scrutiny of AI service providers.observed
  4. ConfirmedEuropean Data Protection Board — The HDPA imposed a €20 million fine on Clearview AI — its largest fine to date — for unlawfully processing biometric facial-recognition data of Greek residents in violation of GDPR Articles 5(1)(a), 6, 9, 14 and 27.observed
  5. ConfirmedOneTrust DataGuidance — Law 4624/2019 Article 23 prohibits the processing of genetic data for health and life insurance purposes, forming Greece's principal statutory genetic-data-specific restriction.observed
  6. ConfirmedOfficial Journal of the European Union — The HDPA is competent to supervise national and transnational data processing with limited exceptions for national security, and Greek surveillance oversight (including the ADAE communications-security authority) has faced European Parliament scrutiny over the 'Predator' spyware scandal and weakened post-surveillance notification safeguards.observed

#

Parental-consent threshold is clearly defined and enforced; age-verification, minor-profiling and dependent-adults sub-modules rely solely on general GDPR provisions.

Primary frameworkLaw 4624/2019 Article 21 (digital consent age) + GDPR
Traffic-light rationale — AmberParental-consent threshold is clearly defined and enforced; age-verification, minor-profiling and dependent-adults sub-modules rely solely on general GDPR provisions.

Sub-modules (5)

Age VerificationRed

No dedicated age-verification standard identified beyond the consent-age threshold.

Claims (1):

  • No dedicated Greek age-verification statute or technical standard distinct from the Article 21 consent-age threshold was identified in Law 4624/2019 or HDPA guidance reviewed.

Minor Profiling BansRed

No distinct national ban beyond general GDPR framework.

Claims (1):

  • No Greece-specific statutory ban on profiling of minors beyond the general GDPR framework (Recital 38, Article 22) was identified.

Education SettingsAmber

Ed-tech DSAR fine and disability-services minor-data disclosure fine.

Claims (2):

  • The HDPA fined ed-tech provider IMathisi €4,000 for denying a parent's data-access request concerning their child's data and for failing to cooperate with the Authority.
  • The HDPA fined an association for people with Autism Spectrum Disorder for unlawfully disclosing a minor's sensitive medical, therapeutic and social-history data to a third party without parental notification or consent.

Dependent AdultsRed

No distinct national provisions identified.

Claims (1):

  • No Greece-specific statutory data-protection provisions addressing dependent adults (elderly or mentally incapacitated persons) distinct from the general GDPR framework were identified in Law 4624/2019 or HDPA guidance reviewed.
Category narrative44 words

Law 4624/2019 Article 21 fixes the digital consent age at 15, with parental consent required below that age. Enforcement precedent covers education-sector and disability-services mishandling of minors' data. No dedicated age-verification standard, minor-profiling ban, or dependent-adults regime distinct from general GDPR provisions was identified.

Sources and claims (6)
  1. UncertainOneTrust DataGuidance — No dedicated Greek age-verification statute or technical standard distinct from the Article 21 consent-age threshold was identified in Law 4624/2019 or HDPA guidance reviewed.observed
  2. ConfirmedIAPP — Law 4624/2019 Article 21 sets the digital age of consent at 15 years; below that age, the consent of a parent or legal guardian is required for a minor's data to be lawfully processed by information society services.observed
  3. UncertainGovernment Gazette of the Hellenic Republic / HDPA — No Greece-specific statutory ban on profiling of minors beyond the general GDPR framework (Recital 38, Article 22) was identified.observed
  4. ConfirmedOneTrust DataGuidance — The HDPA fined ed-tech provider IMathisi €4,000 for denying a parent's data-access request concerning their child's data and for failing to cooperate with the Authority.observed
  5. ConfirmedEuropean Data Protection Board — The HDPA fined an association for people with Autism Spectrum Disorder for unlawfully disclosing a minor's sensitive medical, therapeutic and social-history data to a third party without parental notification or consent.observed
  6. UncertainGovernment Gazette of the Hellenic Republic / HDPA — No Greece-specific statutory data-protection provisions addressing dependent adults (elderly or mentally incapacitated persons) distinct from the general GDPR framework were identified in Law 4624/2019 or HDPA guidance reviewed.observed

#

Powers and historical enforcement activity are robust and well evidenced; the recent_developments_180d sub-module could not be populated with a confirmed decision inside the strict 180-day window, and collective-redress mechanisms remain comparatively underdeveloped.

Primary frameworkGDPR Articles 58, 77-84, 83 as supplemented by Law 4624/2019
Traffic-light rationale — AmberPowers and historical enforcement activity are robust and well evidenced; the recent_developments_180d sub-module could not be populated with a confirmed decision inside the strict 180-day window, and collective-redress mechanisms remain comparatively underdeveloped.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

Fines €5,000-€20M; public-sector cap of €10M under Law 4624/2019.

Claims (2):

  • The HDPA has issued administrative fines ranging from €5,000 to €20 million for GDPR violations including unlawful processing, transparency violations, non-compliance with access requests and inadequate security measures, exercising the full corrective and sanctioning powers of GDPR Articles 58 and 83.
  • Law 4624/2019 caps administrative fines against public-sector entities at €10,000,000 depending on the severity and duration of the breach, while leaving the GDPR's uncapped sanction regime unchanged for private entities.

Enforcement Activity IndexGreen

Sustained high-value enforcement 2022-2025.

Claims (1):

  • The HDPA's 2022 fine of €20 million against Clearview AI doubled the Authority's previous record fine of €9.25 million against Greece's largest telecommunications conglomerate, reflecting an escalating enforcement trend.

Regulator Funding And CapacityAmber

HDPA self-reported staff/budget figures and characterized resources as insufficient.

Claims (1):

  • In its EDPB Article 97 questionnaire response, the HDPA reported staff levels of 39 (2016), 35 (2017), 33 (2018), 33 (2019) and 46 (2020) employees, with an annual budget rising from approximately €2.07 million in 2016 to €2.85 million in 2019, and characterized its resources as still insufficient.

Collective Redress And Class ActionsAmber

Lack of specific representative-action provisions.

Claims (1):

  • Greek data-protection law analysis notes an absence of specific statutory provisions enabling representation of data subjects by collective associations in judicial remedies against controllers/processors, making collective redress more difficult than under the GDPR's optional Article 80 mechanism.

Private Right Of ActionGreen

Complaint-driven access via civil-society organisations and direct judicial remedies.

Claims (1):

  • Civil nonprofit organizations such as Homo Digitalis may file HDPA complaints on behalf of individual data subjects, as occurred in the Clearview AI case, and judicial remedies may be filed by data subjects before the court of the controller's registered seat or the data subject's residence.

Recent Developments 180DRed

Most recent confirmed major decision (Vodafone, June 2025) falls outside the strict 180-day window; no Greece-specific decision inside the window was confirmed despite targeted searches.

Claims (1):

  • The most recent major HDPA enforcement action identified in this research cycle is the June 2025 fine against Vodafone Greece and its processor for a data breach and insufficient security measures; no Greece-specific HDPA decision published within the 180 days preceding this run (i.e., since approximately February 2026) was identified in the sources reviewed.

Key findings (3)

  • HDPA imposed EUR 30,000 fine on telecom operator for access/restriction-rights violations. — source on file
  • HDPA imposed EUR 6m (COSMOTE) and EUR 3.25m (OTE) fines for security/transparency failures. — source on file
  • HDPA launched EDPB 2026 CEF on Transparency and the Right to Information. — source on file
Category narrative106 words

The HDPA exercises full GDPR Articles 58/83 corrective and sanctioning powers, with fines ranging from €5,000 to €20 million, and Law 4624/2019 caps public-sector fines at €10 million. Enforcement activity has been sustained and high-value (Clearview AI €20M, Cosmote/OTE €9.25M combined, Ministry of Migration €175,000, Vodafone 2025). Reported HDPA resourcing (39-46 staff, ~€2-2.85M budget as of 2020) was self-assessed by the Authority as insufficient. Collective redress is constrained by an absence of specific representative-action provisions, though civil-society complaints (e.g., Homo Digitalis) function as a de facto access point. No Greece-specific HDPA decision published within the 180 days preceding this run was confirmed in the sources reviewed.

Periodic update · new data 2026-09-22

Enforcement & Redress

HDPA has launched the EDPB's 2026 Coordinated Enforcement Framework (CEF) action on Transparency and the Right to Information of Data Subjects, joining other EU data protection authorities in a synchronised enforcement initiative around this theme. This is a confirmed, forward-looking enforcement development: it signals that transparency and the right-to-information obligations will receive coordinated, EU-wide scrutiny in the coming period, with Greece an active participant rather than an observer.

This new coordinated action sits alongside HDPA's already substantial telecom-sector enforcement record this cycle, comprising the EUR 30,000 access-and-restriction-rights fine and the EUR 6 million and EUR 3.25 million security-and-transparency fines against COSMOTE and OTE respectively. Taken together, these three developments indicate a sustained and escalating enforcement posture in Greece: HDPA is both actively sanctioning past violations and positioning itself for forward enforcement activity through EU-coordinated mechanisms. The combination of a well-established individual case record and participation in a new coordinated framework action suggests transparency and information-rights compliance will remain a live enforcement priority for organisations processing personal data in Greece.

Outlook

The EDPB CEF action on transparency is the clearest forward marker this cycle. Its findings, once published, are likely to surface further Greece-specific transparency and information-rights enforcement activity, potentially extending beyond the telecommunications sector that has dominated HDPA's enforcement record to date.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (7)
  1. ConfirmedOneTrust DataGuidance — The HDPA has issued administrative fines ranging from €5,000 to €20 million for GDPR violations including unlawful processing, transparency violations, non-compliance with access requests and inadequate security measures, exercising the full corrective and sanctioning powers of GDPR Articles 58 and 83.observed
  2. ConfirmedIAPP — Law 4624/2019 caps administrative fines against public-sector entities at €10,000,000 depending on the severity and duration of the breach, while leaving the GDPR's uncapped sanction regime unchanged for private entities.observed
  3. ConfirmedIAPP — The HDPA's 2022 fine of €20 million against Clearview AI doubled the Authority's previous record fine of €9.25 million against Greece's largest telecommunications conglomerate, reflecting an escalating enforcement trend.observed
  4. ConfirmedEuropean Data Protection Board — In its EDPB Article 97 questionnaire response, the HDPA reported staff levels of 39 (2016), 35 (2017), 33 (2018), 33 (2019) and 46 (2020) employees, with an annual budget rising from approximately €2.07 million in 2016 to €2.85 million in 2019, and characterized its resources as still insufficient.observed
  5. ProbableIAPP — Greek data-protection law analysis notes an absence of specific statutory provisions enabling representation of data subjects by collective associations in judicial remedies against controllers/processors, making collective redress more difficult than under the GDPR's optional Article 80 mechanism.observed
  6. ConfirmedIAPP — Civil nonprofit organizations such as Homo Digitalis may file HDPA complaints on behalf of individual data subjects, as occurred in the Clearview AI case, and judicial remedies may be filed by data subjects before the court of the controller's registered seat or the data subject's residence.observed
  7. UncertainEuropean Data Protection Board — The most recent major HDPA enforcement action identified in this research cycle is the June 2025 fine against Vodafone Greece and its processor for a data breach and insufficient security measures; no Greece-specific HDPA decision published within the 180 days preceding this run (i.e., since approximately February 2026) was identified in the sources reviewed.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metn/a — no subject in this jurisdiction
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct76.47
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Greece
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 67 claim(s) (67 category placement(s)), 25 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (14 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 13-22Data Subject Rightsaccess right
Art. 32-34Controller/Processor Dutiessecurity measures
Art. 37-39Controller/Processor Dutiesdpo requirements
Art. 44-49Cross-Border & Adequacytransfer mechanisms
Art. 77-84Enforcement & Redressregulator powers and penalties

Self-audit

All 10 modules populated with Tier-1 (HDPA/EDPB official) and Tier-2/Tier-3 (DataGuidance, IAPP) sourced claims. regulator_and_framework, lawful_processing_and_special_data, controller_processor_duties, cross_border_and_adequacy and enforcement_and_redress modules rest predominantly on T1 anchors (Law 4624/2019 text, EDPB-hosted HDPA decisions, HDPA Art.97 questionnaire). sectoral_watch, adtech_and_commercial_privacy, algorithmic_biometric_and_surveillance_governance and children_and_vulnerable_groups modules mix T1 enforcement decisions with T2/T3 secondary analysis (DataGuidance jurisdiction compilation, IAPP articles) and carry several explicit absent_field_provenance sub-modules (credit_and_scoring; dark_patterns; opt_out_signals; clean_rooms_and_dcr; age_verification; minor_profiling_bans; dependent_adults; pseudonymisation_and_anonymisation; retention_and_disposal) where no Greece-specific statutory supplement to the GDPR baseline was located. The recent_developments_180d sub-module of enforcement_and_redress could not be populated with a confirmed decision strictly inside the 180-day window preceding the run date despite three targeted searches; the most recent confirmed HDPA decision (Vodafone, 25 June 2025) falls outside that window.

Unresolved questions (5):

  • What is the current substantive content of the EDPB national-news item tagged 'gr' dated 04 June 2026, and does it represent a reportable HDPA decision within the 180-day window?
  • Does Greece have any Greece-specific pseudonymisation/anonymisation safe-harbour guidance beyond direct GDPR application?
  • Is there a distinct Greek credit-scoring or automated-lending-decision statute, or does GDPR Article 22 operate alone in this sector?
  • Has the HDPA issued dedicated guidance recognizing browser-level opt-out signals (e.g., Global Privacy Control) as valid GDPR objection mechanisms?
  • What is the current operative status of any Greek national AI-Act implementing measures or HDPA-specific AI risk-assessment guidance beyond the DeepSeek EU-representative order?

Escalate to primary-source review: yes