#
Full GDPR direct effect plus a comprehensive, in-force national implementing statute and an active, well-resourced-relative-to-peers regulator.
Sub-modules (5)
Regulator And AuthorityGreen
HDPA is the constitutionally and statutorily established supervisory authority.
Claims (1):
- The Hellenic Data Protection Authority (HDPA) is the supervisory authority responsible for enforcing the GDPR and Law 4624/2019 in Greece.
Act And InstrumentsGreen
Law 4624/2019 (GDPR implementation + LED transposition) and Law 3471/2006 (electronic communications privacy) form the core instruments.
Claims (2):
- Greece implemented the GDPR through Law 4624/2019, which supplements the GDPR on matters left to Member State discretion, transposes the Law Enforcement Directive (EU) 2016/680, and re-establishes the HDPA.
- Law 3471/2006 (the Electronic Communications Privacy Law) supplements the GDPR/Law 4624/2019 framework and governs cookies, trackers and electronic communications privacy in Greece.
Material ScopeGreen
HDPA competence extends to essentially all national and transnational processing, with a national-security carve-out.
Claims (1):
- The HDPA is competent to supervise every national and transnational personal data processing operation within its jurisdiction, with limited exceptions for national security matters.
Territorial ScopeGreen
HDPA has applied the GDPR Article 3 targeting criterion to assert jurisdiction over non-established controllers.
Claims (1):
- The HDPA applies the GDPR Article 3 targeting criterion to assert territorial competence over non-established controllers, such as Clearview AI, that process the personal data of individuals in Greece.
Regulator Registration And FilingAmber
No general controller registration/notification regime survives under the GDPR-era framework; accountability/ROPA obligations replace the old Law 2472/1997 notification system.
Claims (1):
- Greece's GDPR-era regime does not impose a general notification/registration requirement on controllers; the prior registration system under Law 2472/1997 was replaced by the GDPR's accountability and records-of-processing obligations.
Sources and claims (6)
- ConfirmedGovernment Gazette of the Hellenic Republic / HDPA — The Hellenic Data Protection Authority (HDPA) is the supervisory authority responsible for enforcing the GDPR and Law 4624/2019 in Greece.observed
- ConfirmedIAPP — Greece implemented the GDPR through Law 4624/2019, which supplements the GDPR on matters left to Member State discretion, transposes the Law Enforcement Directive (EU) 2016/680, and re-establishes the HDPA.observed
- ConfirmedOneTrust DataGuidance — Law 3471/2006 (the Electronic Communications Privacy Law) supplements the GDPR/Law 4624/2019 framework and governs cookies, trackers and electronic communications privacy in Greece.observed
- ConfirmedEuropean Data Protection Board — The HDPA is competent to supervise every national and transnational personal data processing operation within its jurisdiction, with limited exceptions for national security matters.observed
- ConfirmedIAPP — The HDPA applies the GDPR Article 3 targeting criterion to assert territorial competence over non-established controllers, such as Clearview AI, that process the personal data of individuals in Greece.observed
- ProbableIAPP — Greece's GDPR-era regime does not impose a general notification/registration requirement on controllers; the prior registration system under Law 2472/1997 was replaced by the GDPR's accountability and records-of-processing obligations.observed