{
 "jurisdiction_id": "CY",
 "jurisdiction": "Cyprus",
 "url": "https://dataprotection.gi/jurisdictions/cyprus/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-05",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 27,
  "sub_modules": 57,
  "source_register": 15
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "green",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/cyprus/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "Comprehensive omnibus statute in force with an operational, EDPB-recognised supervisory authority.",
   "claims": [
    {
     "statement": "The Office of the Commissioner for Personal Data Protection is the national supervisory authority for Cyprus, monitoring application of the GDPR and Law 125(I)/2018.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "European Data Protection Board",
     "source_url": "https://www.edpb.europa.eu/about-edpb/about-edpb/members_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Cyprus implemented the GDPR by means of Law 125(I) of 2018 Providing for the Protection of Natural Persons with regard to the Processing of Personal Data and for the Free Movement of Such Data, which entered into force on 31 July 2018.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance (summarising official Cyprus Gazette text)",
     "source_url": "https://www.dataguidance.com/jurisdictions/cyprus",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Law 125(I)/2018 presents variations from the GDPR relating to the processing of genetic and biometric data for life-insurance purposes and to the international transfer of special categories of personal data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/cyprus",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Commissioner published a question-based GDPR compliance guide on 19 February 2024 to help controllers and processors self-assess processing operations, including DPO, legal-basis and transfer sections.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/cyprus-commissioner-publishes-guidance-compliance-gdpr",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "green",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/cyprus/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "GDPR Art 6/9 bases apply directly; national derogations are narrow and well-documented.",
   "claims": [
    {
     "statement": "GDPR Article 6 lawful bases apply directly in Cyprus as an EU Member State without local substitution of the enumerated grounds.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Law 125(I)/2018 sets the age of consent for information-society services at 14 years old, a derogation from the GDPR default age.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/cyprus",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Law 125(I)/2018 presents variations from the GDPR in relation to the processing of genetic and biometric data for life insurance purposes.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/cyprus",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "green",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/cyprus/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Full GDPR rights suite in force with documented enforcement practice via Article 60 cooperation decisions.",
   "claims": [
    {
     "statement": "The Commissioner has exercised her GDPR and Law 125(I)/2018 powers in handling data-subject complaints concerning the right of access and right to erasure, including cross-border Article 60 cooperation.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "European Data Protection Board / Cyprus Commissioner",
     "source_url": "https://www.edpb.europa.eu/sites/default/files/article-60-final-decisions/publishable_cy_2019-11_right_of_access_and_right_to_erasure_decisionpublic.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "green",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/cyprus/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Full GDPR controller/processor duty regime in force with multiple documented enforcement actions on security and accountability failures.",
   "claims": [
    {
     "statement": "Cyprus submitted a national DPIA exemption/inclusion list under GDPR Article 35(5), which was reviewed through the EDPB's Article 64 consistency opinion process (DPIA List Cyprus).",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "European Data Protection Board",
     "source_url": "https://www.edpb.europa.eu/news/news/2019/twelfth-plenary-session-adopted-documents_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Following a 2022 data-breach decision, the Commissioner recommended that the Bank of Cyprus consult its data protection officer before taking actions that may violate GDPR.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/cyprus-commissioner-fines-bank-cyprus-17000-data",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "A September 2024 Commissioner audit of 28 public-sector websites found 60% lacked a posted data-protection policy and DPO contact details, with 40% having policies containing gaps and inaccuracies, before full compliance was achieved by August 2024.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/cyprus-commissioner-releases-results-data-protection",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Office of the Commissioner for Personal Data Protection fined the Bank of Cyprus Public Company Ltd €17,000 for violations of Articles 5(1)(f), 24(1) and 32 GDPR following a data breach involving misdirected letters and electronic files affecting thousands of data subjects.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/cyprus-commissioner-fines-bank-cyprus-17000-data",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Cyprus fined the State Health Services Organization €46,500 for GDPR breaches involving lost patient data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/cyprus",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Cyprus prohibits hotels from retaining identity card or passport copies due to GDPR violations, and pharmacies must collect beneficiary identification data discreetly to avoid system abuse.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/cyprus",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "green",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/cyprus/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "Standard GDPR Chapter V mechanisms apply with no CY-specific localisation mandate identified.",
   "claims": [
    {
     "statement": "As an EU Member State, Cyprus applies GDPR Chapter V (Arts 44-49) transfer mechanisms directly, including adequacy decisions, SCCs, BCRs and Article 49 derogations, without a separate national transfer regime.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The EDPB reviews the European Commission's periodic reports on the functioning of existing adequacy decisions, including methodological observations on government-access assessments, as part of the EU-wide (not Cyprus-specific) adequacy review process.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "European Data Protection Board",
     "source_url": "https://www.edpb.europa.eu/system/files/documents/2024-12/edpb_letter_20241205_european-commission-review-of-11-existing-adequacy-decisions_en.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/cyprus/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Financial and telecoms overlays are well evidenced; credit-scoring, education and insurance sub-modules lack dedicated sectoral instruments beyond the general Law and are marked amber/gap.",
   "claims": [
    {
     "statement": "The Bank of Cyprus has been subject to multiple GDPR enforcement decisions by the Commissioner, including a €17,000 fine in 2022 for security-of-processing violations and a further €8,000 fine, evidencing sustained financial-sector DP supervision.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/cyprus-commissioner-fines-bank-cyprus-17000-data",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Law 112(I)/2004 on the Regulation of Electronic Communications and Postal Services is the relevant national telecoms instrument interfacing with data protection in Cyprus.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance (summarising official Cyprus Gazette text)",
     "source_url": "https://www.dataguidance.com/legal-research/law-112i2004-regulation-electronic-communications-and-postal-services",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Employee monitoring in Cyprus is governed by the GDPR, Law 125(I)/2018, the Protection of the Secrecy of Private Communications (Surveillance of Conversations) Law No. 92(I)/96, and Articles 15 and 17 of the Constitution of the Republic of Cyprus.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance (summarising official Cyprus Gazette text)",
     "source_url": "https://www.dataguidance.com/notes/cyprus-employee-monitoring",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Open University of Cyprus was fined €45,000 for GDPR violations following a cyber-attack, evidencing education-sector DP enforcement under the general GDPR/Law 125(I)/2018 regime.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/cyprus",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "amber",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/cyprus/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "Cookie/tracker and direct-marketing enforcement is well evidenced; dark-patterns, opt-out-signal (GPC-style) and clean-room/cross-context-advertising specific rules were not located.",
   "claims": [
    {
     "statement": "The Cyprus Commissioner for Personal Data Protection fined Aylo Freesites Ltd €58,400 for GDPR violations and illegal cookie use, and separately reported cookie-audit findings highlighting consent and categorisation issues.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/cyprus-commissioner-fines-aylo-freesites-eu58400-data",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Commissioner has issued guidelines covering direct marketing among other key GDPR compliance topics.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/cyprus",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "amber",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/cyprus/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "Core Art 22 ADM protections are in force; biometric-specific, AI-risk-assessment and surveillance-carveout sub-modules rely on the general GDPR framework with no CY-specific instrument located.",
   "claims": [
    {
     "statement": "GDPR Article 22 automated-decision-making transparency and explanation rights apply directly to Cyprus-established controllers under the GDPR/Law 125(I)/2018 framework.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "amber",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/cyprus/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "Age-of-consent and parental-consent sub-modules are well evidenced; minor-profiling-ban, education-settings and dependent-adults sub-modules rely on the general regime with no dedicated instrument located.",
   "claims": [
    {
     "statement": "The Cyprus Commissioner for the Protection of Personal Data has stressed the need for companies to ensure parental or legal-guardian consent for data activities related to users aged 14 and under.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/cyprus-dpa-emphasizes-childrens-privacy/",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "green",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/cyprus/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Regulator possesses full GDPR enforcement powers and demonstrates sustained enforcement activity across sectors within the last 24 months.",
   "claims": [
    {
     "statement": "Legislation in Cyprus provides for criminal offences, punishable with imprisonment, for certain violations of Law 125(I)/2018 and the GDPR, in addition to the standard GDPR administrative fining regime.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/cyprus",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Recent Commissioner enforcement activity includes fines against Aylo Freesites Ltd (€58,400), the State Health Services Organization (€46,500), the Open University of Cyprus (€45,000), the Bank of Cyprus (€17,000 and €8,000), Politis (€7,000), and Arktinos Publishing Ltd (€5,000).",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/cyprus",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Cyprus published a Law of 2025 implementing the Digital Services Act, designating competent authorities and outlining fines for non-compliance, and approved the Network and Information Systems Security (Amendment) Law of 2025 enhancing cybersecurity measures and responsibilities.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/cyprus",
     "source_tier": null,
     "observed_at": null
    }
   ]
  }
 ]
}