{
 "jurisdiction_id": "GR",
 "jurisdiction": "Greece",
 "url": "https://dataprotection.gi/jurisdictions/greece/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-05",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 67,
  "sub_modules": 57,
  "source_register": 17
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "green",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/greece/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "Full GDPR direct effect plus a comprehensive, in-force national implementing statute and an active, well-resourced-relative-to-peers regulator.",
   "claims": [
    {
     "statement": "The Hellenic Data Protection Authority (HDPA) is the supervisory authority responsible for enforcing the GDPR and Law 4624/2019 in Greece.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Government Gazette of the Hellenic Republic / HDPA",
     "source_url": "https://www.dataguidance.com/sites/default/files/law_4624_2019_en_translated_by_the_hdpa_0.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Greece implemented the GDPR through Law 4624/2019, which supplements the GDPR on matters left to Member State discretion, transposes the Law Enforcement Directive (EU) 2016/680, and re-establishes the HDPA.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/greece-incorporated-gdpr-data-protection-regulation-into-law",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Law 3471/2006 (the Electronic Communications Privacy Law) supplements the GDPR/Law 4624/2019 framework and governs cookies, trackers and electronic communications privacy in Greece.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/greece",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The HDPA is competent to supervise every national and transnational personal data processing operation within its jurisdiction, with limited exceptions for national security matters.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "European Data Protection Board",
     "source_url": "https://www.edpb.europa.eu/sites/default/files/gr_sa_gdpr_art_97questionnaire.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The HDPA applies the GDPR Article 3 targeting criterion to assert territorial competence over non-established controllers, such as Clearview AI, that process the personal data of individuals in Greece.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/greek-dpa-imposes-20m-euro-fine-on-clearview-ai-for-unlawful-processing-of-personal-data",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Greece's GDPR-era regime does not impose a general notification/registration requirement on controllers; the prior registration system under Law 2472/1997 was replaced by the GDPR's accountability and records-of-processing obligations.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/greece-incorporated-gdpr-data-protection-regulation-into-law",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "green",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/greece/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Comprehensive statutory lawful-basis and special-category framework, though the HDPA itself has flagged one internal inconsistency (Article 5 vs GDPR Article 6) and no distinct national pseudonymisation safe-harbour was found.",
   "claims": [
    {
     "statement": "GDPR Article 6 lawful bases for processing apply directly in Greece; Law 4624/2019 Article 5 restates Article 6 GDPR domestically, a repetition the HDPA itself flagged as inconsistent with EU law in its January 2020 opinion.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/greece-hdpa-issues-opinion-gdpr-and-law-enforcement-directive-implementation-law",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Law 4624/2019 Article 21 sets the age of a minor's valid consent to processing in relation to information society services at 15 years old; below that age, parental or guardian consent is required.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://corporate.dataguidance.com/greece-new-government-acted-in-a-very-quick-way-to-pass-the-bill/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Processing of special categories of data by public and private entities is permitted without data subject consent where mandatory for health care, social care, social security, or work-capacity assessment, subject to safeguards for data subject interests.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/greece-incorporated-gdpr-data-protection-regulation-into-law",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Law 4624/2019 Article 23 prohibits the processing of genetic data for health and life insurance purposes.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://corporate.dataguidance.com/greece-new-government-acted-in-a-very-quick-way-to-pass-the-bill/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "No Greek-specific statutory safe-harbour or derogation for pseudonymisation/anonymisation beyond the GDPR Article 4(5) definition and Recital 26 was identified in Law 4624/2019 or HDPA guidance reviewed.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/greece",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "green",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/greece/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Core rights actively enforced (access); ancillary rights (restriction, portability) rely on direct GDPR application without located national supplements.",
   "claims": [
    {
     "statement": "The HDPA has enforced the GDPR Article 15 right of access, including fining UGHL €7,000 for unlawful data processing and failure to fulfill a data access request.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/greece",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The HDPA fined an association for people with Autism Spectrum Disorder for failing to satisfy a parental right-of-access request for CCTV footage and for unlawfully transmitting a minor's sensitive data to a third party.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "European Data Protection Board",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2025/greek-sa-imposition-fine-association-transmission-sensitive-data-failure_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Greece participated as one of 32 DPAs in the EDPB's 2025 Coordinated Enforcement Framework (CEF) action examining implementation of the GDPR right to erasure.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/greece",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "No Greece-specific derogation from the GDPR Articles 18 and 21 restriction/objection rights was identified beyond direct application of the Regulation.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "Government Gazette of the Hellenic Republic / HDPA",
     "source_url": "https://www.dataguidance.com/sites/default/files/law_4624_2019_en_translated_by_the_hdpa_0.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "No Greece-specific derogation from the GDPR Article 20 data portability right was identified; the right applies as set out directly in the Regulation.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "Government Gazette of the Hellenic Republic / HDPA",
     "source_url": "https://www.dataguidance.com/sites/default/files/law_4624_2019_en_translated_by_the_hdpa_0.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The GDPR Article 12(3) one-month response deadline (extendable by two further months for complex requests) applies directly to Greek controllers without a shorter or longer national derogation identified.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "Government Gazette of the Hellenic Republic / HDPA",
     "source_url": "https://www.dataguidance.com/sites/default/files/law_4624_2019_en_translated_by_the_hdpa_0.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "green",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/greece/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Strong, evidenced enforcement across accountability, security and breach sub-modules; retention/disposal relies solely on GDPR Article 5(1)(e).",
   "claims": [
    {
     "statement": "The HDPA has issued a list of processing operations subject to the mandatory Data Protection Impact Assessment (DPIA) requirement under GDPR Article 35(4).",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/greece",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The HDPA fined the Hellenic Ministry of Migration and Asylum €175,000 following an own-initiative investigation into the 'Centaur' and 'Hyperion' border-surveillance systems for breaches relating to cooperation with the Authority and deficient impact assessments.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "European Data Protection Board",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2024/ministry-migration-and-asylum-receives-administrative-fine-and-gdpr_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Law 4624/2019 contains specific provisions on the appointment, role and independence of Data Protection Officers, including for public bodies.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/greece-incorporated-gdpr-data-protection-regulation-into-law",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The HDPA's January 2020 opinion found that Law 4624/2019's additional exemptions for public institutions from the GDPR Article 37 DPO-appointment mandate were incompatible with Article 32(4) of the Law Enforcement Directive.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/greece-hdpa-issues-opinion-gdpr-and-law-enforcement-directive-implementation-law",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "No Greece-specific derogation from the GDPR Article 30 records-of-processing obligation was identified beyond direct application of the Regulation and HDPA guidance referencing processing-records compliance.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/greece",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "In its 2022 decision against COSMOTE and OTE, the HDPA found the companies had failed to properly allocate their respective controller/processor roles and responsibilities in relation to a data breach, applying GDPR joint/controller-processor accountability principles.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "European Data Protection Board",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2022/hellenic-dpa-fines-imposed-telecommunications-companies-due-personal-data_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "ADAE Decision No. 304/2025 mandates specific technical and organisational security measures for electronic communications providers to ensure confidentiality and manage risk.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/greece",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The HDPA fined Hellenic Post Services S.A. (ELTA) a sum equal to 1% of its annual turnover for failing to implement adequate technical and organisational security measures following ransomware and dark-web data-leak incidents.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "European Data Protection Board",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2024/hellenic-sa-fine-company-failure-implement-technical-and-organisational_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The HDPA fined Vodafone Greece and its processor in a June 2025 decision for a personal-data breach and insufficient security measures relating to unauthorised prepaid mobile-line activations, applying GDPR Articles 5(1)(d), 28, 29 and 32.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "European Data Protection Board",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2025/greek-sa-imposition-fines-telecommunications-company-and-data-processor_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "In its 2022 decision, the HDPA fined COSMOTE €6,000,000 and OTE €3,250,000 for infringing GDPR breach-related obligations, including inadequate security measures, poor anonymisation and an insufficient data protection impact assessment following a September 2020 subscriber call-data breach.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "European Data Protection Board",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2022/hellenic-dpa-fines-imposed-telecommunications-companies-due-personal-data_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "No Greece-specific general statutory retention-period regime beyond the GDPR Article 5(1)(e) storage-limitation principle was identified in Law 4624/2019 or HDPA guidance reviewed.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "Government Gazette of the Hellenic Republic / HDPA",
     "source_url": "https://www.dataguidance.com/sites/default/files/law_4624_2019_en_translated_by_the_hdpa_0.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "green",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/greece/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "Chapter V applies with full direct effect; no Greek derogation or gap identified beyond the EU-wide framework.",
   "claims": [
    {
     "statement": "As an EU Member State, Greece applies the GDPR Chapter V transfer regime (Articles 44-49) directly, including adequacy decisions, Standard Contractual Clauses, Binding Corporate Rules and derogations, without a distinct national transfer mechanism identified in Law 4624/2019.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Government Gazette of the Hellenic Republic / HDPA",
     "source_url": "https://www.dataguidance.com/sites/default/files/law_4624_2019_en_translated_by_the_hdpa_0.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "There is no Greece-specific adequacy decision received from a third country; inbound adequacy findings under GDPR Article 45 are determined at EU level and apply automatically to Greece as a Member State.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "Government Gazette of the Hellenic Republic / HDPA",
     "source_url": "https://www.dataguidance.com/sites/default/files/law_4624_2019_en_translated_by_the_hdpa_0.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Adequacy decisions applicable in Greece are adopted centrally by the European Commission under GDPR Article 45 and apply uniformly across all EU Member States; Greece does not issue separate national adequacy determinations.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "Government Gazette of the Hellenic Republic / HDPA",
     "source_url": "https://www.dataguidance.com/sites/default/files/law_4624_2019_en_translated_by_the_hdpa_0.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Standard Contractual Clauses and Binding Corporate Rules are available and used as GDPR Chapter V transfer mechanisms in Greece under the same EU-wide forms and EDPB/Commission templates, with no Greece-specific supplementary form identified.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "Government Gazette of the Hellenic Republic / HDPA",
     "source_url": "https://www.dataguidance.com/sites/default/files/law_4624_2019_en_translated_by_the_hdpa_0.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Greek controllers relying on SCCs for international transfers are subject to the EU-wide Transfer Impact Assessment obligation established following the CJEU's Schrems II ruling, with no distinct Greek-specific TIA methodology identified beyond EDPB guidance.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "Government Gazette of the Hellenic Republic / HDPA",
     "source_url": "https://www.dataguidance.com/sites/default/files/law_4624_2019_en_translated_by_the_hdpa_0.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Rather than a general data-localisation mandate, the HDPA supervises specific national law-enforcement and border-management databases connected to EU-wide systems (Europol National Unit, SIS II, VIS, Eurodac, CIS and PNR under Law 4579/2018), which involve constrained, system-specific data-residency and access rules.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "European Data Protection Board",
     "source_url": "https://www.edpb.europa.eu/sites/default/files/gr_sa_gdpr_art_97questionnaire.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/greece/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Strong telecoms/employment/health coverage; credit-scoring sub-module has no located sectoral statute beyond GDPR Article 22.",
   "claims": [
    {
     "statement": "The HDPA fined Piraeus Bank €50,000 for GDPR violations arising from incorrect data processing, illustrating financial-sector overlay enforcement.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/greece",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The HDPA fined a gynecologist €5,000 for unauthorized access to a former patient's health data, illustrating health-sector overlay enforcement of GDPR special-category rules.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/greece",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Law 3471/2006, as amended, governs the confidentiality of electronic communications and cookies in Greece and is enforced by the HDPA alongside the National Telecommunications Authority ADAE, which is itself responsible for communications-security oversight (e.g., ADAE Decision No. 304/2025).",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "European Data Protection Board",
     "source_url": "https://www.edpb.europa.eu/sites/default/files/gr_sa_gdpr_art_97questionnaire.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Law 4624/2019 restricts the lawful purposes for processing employee personal data to those necessary for recruitment and for the performance and execution of the employment contract, and permits processing on the basis of collective labor agreements.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/greece-incorporated-gdpr-data-protection-regulation-into-law",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "No Greece-specific statutory credit-scoring or automated-lending-decision regime beyond direct application of GDPR Article 22 was identified in Law 4624/2019 or HDPA guidance reviewed.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/greece",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The HDPA fined ed-tech provider IMathisi €4,000 for GDPR violations including denying a parent's access request to a child's data and failing to cooperate with the Authority, illustrating education-sector enforcement.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/greece",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Law 4624/2019 Article 23 prohibits processing genetic data for health and life insurance purposes, constraining insurance-sector use of sensitive data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://corporate.dataguidance.com/greece-new-government-acted-in-a-very-quick-way-to-pass-the-bill/",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "amber",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/greece/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "Core cookie/marketing regime is solid; newer adtech-specific concepts (dark patterns, GPC-style signals, clean rooms) are not distinctly regulated nationally.",
   "claims": [
    {
     "statement": "Law 3471/2006 governs cookies and other online trackers in Greece, supplementing the GDPR and the EU ePrivacy Directive framework.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/greece",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The HDPA has issued guidelines specifically addressing cookies and other trackers as part of its GDPR compliance guidance programme.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/greece",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "No Greece-specific statutory prohibition on dark patterns distinct from the GDPR consent/transparency principles and EU-level Digital Services Act provisions was identified.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/greece",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "No Greece-specific recognition of browser-level opt-out signals (e.g., Global Privacy Control) as a valid GDPR objection mechanism was identified in HDPA guidance reviewed.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/greece",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "No Greece-specific data clean-room or data-collaboration-room regulatory framework was identified beyond general GDPR joint-controller and processor rules.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/greece",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "No Greece-specific 'sale'/'share' cross-context-advertising concept analogous to US state law was identified; cross-context advertising in Greece is governed by the GDPR consent and legitimate-interest framework and Law 3471/2006.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/greece",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Law 4624/2019 repealed the prior opt-out register for unsolicited commercial communications by mail that existed under Law 2472/1997, replacing it with GDPR/ePrivacy-based direct-marketing consent rules.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/greece-incorporated-gdpr-data-protection-regulation-into-law",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "amber",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/greece/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "Strong, landmark biometric enforcement; AI-risk-assessment and ADM-transparency sub-modules remain reliant on general GDPR application pending fuller national AI-Act interface, and state-surveillance oversight faces documented independence concerns.",
   "claims": [
    {
     "statement": "The HDPA found that Clearview AI's use of facial-recognition profiling techniques to identify and monitor individuals constituted an act of targeting triggering GDPR profiling-related obligations and the strict Article 9 regime for biometric data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/greek-dpa-imposes-20m-euro-fine-on-clearview-ai-for-unlawful-processing-of-personal-data",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "GDPR Article 22 automated-decision-making transparency and explanation rights apply directly in Greece with no distinct national derogation identified in Law 4624/2019.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "Government Gazette of the Hellenic Republic / HDPA",
     "source_url": "https://www.dataguidance.com/sites/default/files/law_4624_2019_en_translated_by_the_hdpa_0.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The HDPA required the AI chatbot provider DeepSeek to appoint an EU representative under GDPR Article 27 due to compliance concerns, reflecting emerging HDPA scrutiny of AI service providers.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/greece",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The HDPA imposed a €20 million fine on Clearview AI — its largest fine to date — for unlawfully processing biometric facial-recognition data of Greek residents in violation of GDPR Articles 5(1)(a), 6, 9, 14 and 27.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "European Data Protection Board",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2022/hellenic-dpa-fines-clearview-ai-20-million-euros_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Law 4624/2019 Article 23 prohibits the processing of genetic data for health and life insurance purposes, forming Greece's principal statutory genetic-data-specific restriction.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://corporate.dataguidance.com/greece-new-government-acted-in-a-very-quick-way-to-pass-the-bill/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The HDPA is competent to supervise national and transnational data processing with limited exceptions for national security, and Greek surveillance oversight (including the ADAE communications-security authority) has faced European Parliament scrutiny over the 'Predator' spyware scandal and weakened post-surveillance notification safeguards.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Official Journal of the European Union",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=OJ%3AC_202400494",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "amber",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/greece/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "Parental-consent threshold is clearly defined and enforced; age-verification, minor-profiling and dependent-adults sub-modules rely solely on general GDPR provisions.",
   "claims": [
    {
     "statement": "No dedicated Greek age-verification statute or technical standard distinct from the Article 21 consent-age threshold was identified in Law 4624/2019 or HDPA guidance reviewed.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://corporate.dataguidance.com/greece-new-government-acted-in-a-very-quick-way-to-pass-the-bill/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Law 4624/2019 Article 21 sets the digital age of consent at 15 years; below that age, the consent of a parent or legal guardian is required for a minor's data to be lawfully processed by information society services.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/greece-incorporated-gdpr-data-protection-regulation-into-law",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "No Greece-specific statutory ban on profiling of minors beyond the general GDPR framework (Recital 38, Article 22) was identified.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "Government Gazette of the Hellenic Republic / HDPA",
     "source_url": "https://www.dataguidance.com/sites/default/files/law_4624_2019_en_translated_by_the_hdpa_0.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The HDPA fined ed-tech provider IMathisi €4,000 for denying a parent's data-access request concerning their child's data and for failing to cooperate with the Authority.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/greece",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The HDPA fined an association for people with Autism Spectrum Disorder for unlawfully disclosing a minor's sensitive medical, therapeutic and social-history data to a third party without parental notification or consent.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "European Data Protection Board",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2025/greek-sa-imposition-fine-association-transmission-sensitive-data-failure_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "No Greece-specific statutory data-protection provisions addressing dependent adults (elderly or mentally incapacitated persons) distinct from the general GDPR framework were identified in Law 4624/2019 or HDPA guidance reviewed.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "Government Gazette of the Hellenic Republic / HDPA",
     "source_url": "https://www.dataguidance.com/sites/default/files/law_4624_2019_en_translated_by_the_hdpa_0.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "amber",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/greece/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Powers and historical enforcement activity are robust and well evidenced; the recent_developments_180d sub-module could not be populated with a confirmed decision inside the strict 180-day window, and collective-redress mechanisms remain comparatively underdeveloped.",
   "claims": [
    {
     "statement": "The HDPA has issued administrative fines ranging from €5,000 to €20 million for GDPR violations including unlawful processing, transparency violations, non-compliance with access requests and inadequate security measures, exercising the full corrective and sanctioning powers of GDPR Articles 58 and 83.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/greece",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Law 4624/2019 caps administrative fines against public-sector entities at €10,000,000 depending on the severity and duration of the breach, while leaving the GDPR's uncapped sanction regime unchanged for private entities.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/greece-incorporated-gdpr-data-protection-regulation-into-law",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The HDPA's 2022 fine of €20 million against Clearview AI doubled the Authority's previous record fine of €9.25 million against Greece's largest telecommunications conglomerate, reflecting an escalating enforcement trend.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/greek-dpa-imposes-20m-euro-fine-on-clearview-ai-for-unlawful-processing-of-personal-data",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "In its EDPB Article 97 questionnaire response, the HDPA reported staff levels of 39 (2016), 35 (2017), 33 (2018), 33 (2019) and 46 (2020) employees, with an annual budget rising from approximately €2.07 million in 2016 to €2.85 million in 2019, and characterized its resources as still insufficient.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "European Data Protection Board",
     "source_url": "https://www.edpb.europa.eu/sites/default/files/gr_sa_gdpr_art_97questionnaire.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Greek data-protection law analysis notes an absence of specific statutory provisions enabling representation of data subjects by collective associations in judicial remedies against controllers/processors, making collective redress more difficult than under the GDPR's optional Article 80 mechanism.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/greece-incorporated-gdpr-data-protection-regulation-into-law",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Civil nonprofit organizations such as Homo Digitalis may file HDPA complaints on behalf of individual data subjects, as occurred in the Clearview AI case, and judicial remedies may be filed by data subjects before the court of the controller's registered seat or the data subject's residence.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/greek-dpa-imposes-20m-euro-fine-on-clearview-ai-for-unlawful-processing-of-personal-data",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The most recent major HDPA enforcement action identified in this research cycle is the June 2025 fine against Vodafone Greece and its processor for a data breach and insufficient security measures; no Greece-specific HDPA decision published within the 180 days preceding this run (i.e., since approximately February 2026) was identified in the sources reviewed.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "European Data Protection Board",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2025/greek-sa-imposition-fines-telecommunications-company-and-data-processor_en",
     "source_tier": null,
     "observed_at": null
    }
   ]
  }
 ]
}