🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
CY · run data-protection-2026-08-03 v13-gdpri-1.0.0
content: ai_generated 15 sources retrieved model claude-sonnet-5 ·

Cyprus

CY schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 27 claims · 15 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
27Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No categories are currently flagged red.

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Comprehensive omnibus statute in force with an operational, EDPB-recognised supervisory authority.

Primary frameworkGDPR (Regulation (EU) 2016/679) as implemented by Law 125(I) of 2018
Traffic-light rationale — GreenComprehensive omnibus statute in force with an operational, EDPB-recognised supervisory authority.

Sub-modules (5)

Regulator And AuthorityGreen

The Commissioner for Personal Data Protection is the sole national supervisory authority and EDPB member for Cyprus, based in Nicosia.

Claims: CLM-CY-a1b2c3d4

Act And InstrumentsGreen

Primary instruments are the GDPR and the national implementing Law 125(I)/2018.

Claims: CLM-CY-b2c3d4e5

Material ScopeGreen

Material scope follows GDPR Art 2/4 definitions of personal data and processing, as transposed by Law 125(I)/2018; the Law adds sector variations for genetic/biometric data used for life-insurance purposes.

Claims: CLM-CY-c3d4e5f6

Territorial ScopeGreen

Territorial scope mirrors GDPR Art 3 (establishment + targeting tests); no CY-specific narrowing identified in the sources reviewed.

Absence provenance: not recorded. Searched: C, y, p, r, u, s, , L, a, w, , 1, 2, 5, (, I, ), /, 2, 0, 1, 8, , t, e, r, r, i, t, o, r, i, a, l, , s, c, o, p, e, , d, e, r, o, g, a, t, i, o, n.

Regulator Registration And FilingAmber

No general controller registration/filing requirement was identified beyond GDPR-standard record-keeping and DPO notification practice; the Commissioner's 2024 compliance guide addresses self-assessment rather than filing.

Claims: CLM-CY-d4e5f6a7

Category narrative73 words

Cyprus operates a GDPR-omnibus regime. The GDPR applies directly as an EU Regulation and is supplemented by Law 125(I) of 2018, the national implementing act, which entered into force on 31 July 2018 and establishes the Office of the Commissioner for Personal Data Protection as the national supervisory authority. The national Law also introduces limited derogations (e.g. age of consent at 14, genetic/biometric data for life-insurance purposes, and international transfer of special-category data).

Sources and claims (4)
  1. ConfirmedEuropean Data Protection BoardThe Office of the Commissioner for Personal Data Protection is the national supervisory authority for Cyprus, monitoring application of the GDPR and Law 125(I)/2018.
  2. ConfirmedDataGuidance (summarising official Cyprus Gazette text)Cyprus implemented the GDPR by means of Law 125(I) of 2018 Providing for the Protection of Natural Persons with regard to the Processing of Personal Data and for the Free Movement of Such Data, which entered into force on 31 July 2018.
  3. ConfirmedDataGuidanceLaw 125(I)/2018 presents variations from the GDPR relating to the processing of genetic and biometric data for life-insurance purposes and to the international transfer of special categories of personal data.
  4. ConfirmedDataGuidanceThe Commissioner published a question-based GDPR compliance guide on 19 February 2024 to help controllers and processors self-assess processing operations, including DPO, legal-basis and transfer sections.

#

GDPR Art 6/9 bases apply directly; national derogations are narrow and well-documented.

Primary frameworkGDPR Arts 6, 7, 9 as implemented by Law 125(I) of 2018
Traffic-light rationale — GreenGDPR Art 6/9 bases apply directly; national derogations are narrow and well-documented.

Sub-modules (4)

Lawful BasesGreen

The six GDPR Art 6 lawful bases apply directly in Cyprus with no local substitution identified.

Claims: CLM-CY-e5f6a7b8

Special CategoriesAmber

Special categories follow GDPR Art 9, with a national derogation permitting genetic and biometric data processing for life-insurance purposes.

Claims: CLM-CY-a7b8c9d0

Pseudonymisation And AnonymisationAmber

No Cyprus-specific statutory definition beyond GDPR Art 4(5) pseudonymisation was located in the sources reviewed.

Absence provenance: not recorded. Searched: C, y, p, r, u, s, , L, a, w, , 1, 2, 5, (, I, ), /, 2, 0, 1, 8, , p, s, e, u, d, o, n, y, m, i, s, a, t, i, o, n, , a, n, o, n, y, m, i, s, a, t, i, o, n, , s, a, f, e, , h, a, r, b, o, u, r.

Category narrative50 words

Lawful bases and special-category rules follow GDPR Arts 6 and 9 as transposed by Law 125(I)/2018. The Law's principal derogation is the age of digital consent, fixed at 14 (below the GDPR default of 16), and a sector carve-out permitting processing of genetic and biometric data for life-insurance underwriting purposes.

Sources and claims (3)
  1. ConfirmedEUR-LexGDPR Article 6 lawful bases apply directly in Cyprus as an EU Member State without local substitution of the enumerated grounds.
  2. ConfirmedDataGuidanceLaw 125(I)/2018 sets the age of consent for information-society services at 14 years old, a derogation from the GDPR default age.
  3. ConfirmedDataGuidanceLaw 125(I)/2018 presents variations from the GDPR in relation to the processing of genetic and biometric data for life insurance purposes.

#

Full GDPR rights suite in force with documented enforcement practice via Article 60 cooperation decisions.

Primary frameworkGDPR Arts 12-23 as implemented by Law 125(I) of 2018
Traffic-light rationale — GreenFull GDPR rights suite in force with documented enforcement practice via Article 60 cooperation decisions.

Sub-modules (5)

Access RightGreen

The Commissioner has directly handled subject-access and erasure complaints, including a documented Article 60 cross-border cooperation case.

Claims: CLM-CY-b8c9d0e1

Rectification And ErasureGreen

Erasure ('right to be forgotten') is enforced alongside access rights per the same Article 60 case practice.

Claims: CLM-CY-b8c9d0e1

Restriction And ObjectionGreen

GDPR Arts 18 and 21 apply directly; no CY-specific narrowing identified.

Absence provenance: not recorded. Searched: C, y, p, r, u, s, , r, e, s, t, r, i, c, t, i, o, n, , o, f, , p, r, o, c, e, s, s, i, n, g, , o, b, j, e, c, t, i, o, n, , r, i, g, h, t, , d, e, r, o, g, a, t, i, o, n.

Data PortabilityGreen

GDPR Art 20 portability right applies directly; no CY-specific derogation identified.

Absence provenance: not recorded. Searched: C, y, p, r, u, s, , d, a, t, a, , p, o, r, t, a, b, i, l, i, t, y, , d, e, r, o, g, a, t, i, o, n, , L, a, w, , 1, 2, 5, (, I, ), /, 2, 0, 1, 8.

Deadlines And Response WindowsGreen

Standard GDPR one-month (extendable to three-month) response window applies; no CY-specific shortening/extension was identified.

Absence provenance: not recorded. Searched: C, y, p, r, u, s, , s, t, a, t, u, t, o, r, y, , r, e, s, p, o, n, s, e, , d, e, a, d, l, i, n, e, , v, a, r, i, a, t, i, o, n.

Category narrative38 words

Data subject rights (access, rectification, erasure, restriction, objection, portability) follow GDPR Arts 15-22 directly, enforced by the Commissioner. A published Article 60 decision demonstrates the Commissioner's practical handling of access/erasure complaints, including cross-border cooperation with other EU SAs.

Sources and claims (1)
  1. ConfirmedEuropean Data Protection Board / Cyprus CommissionerThe Commissioner has exercised her GDPR and Law 125(I)/2018 powers in handling data-subject complaints concerning the right of access and right to erasure, including cross-border Article 60 cooperation.

#

Full GDPR controller/processor duty regime in force with multiple documented enforcement actions on security and accountability failures.

Primary frameworkGDPR Arts 24-39 as implemented by Law 125(I) of 2018
Traffic-light rationale — GreenFull GDPR controller/processor duty regime in force with multiple documented enforcement actions on security and accountability failures.

Sub-modules (7)

Accountability And DpiaGreen

Cyprus's DPIA exemption list under GDPR Art 35(5) was submitted to and processed through the EDPB's Article 64 consistency mechanism.

Claims: CLM-CY-c9d0e1f2

Dpo RequirementsGreen

The Commissioner has issued DPO-appointment guidelines and, in a 2022 Bank of Cyprus decision, recommended prior DPO consultation before actions risking GDPR violations.

Claims: CLM-CY-d0e1f2a3

Ropa RequirementsAmber

GDPR Art 30 record-keeping applies directly; the Commissioner's September 2024 public-sector audit found 60% of audited bodies lacked posted data-protection policies/DPO contact details, indicating documentation gaps subsequently remediated.

Claims: CLM-CY-e1f2a3b4

Joint Controller ArrangementsGreen

GDPR Art 26/28 joint-controller and processor rules apply directly; no CY-specific supplementary provision was identified.

Absence provenance: not recorded. Searched: C, y, p, r, u, s, , j, o, i, n, t, , c, o, n, t, r, o, l, l, e, r, , p, r, o, c, e, s, s, o, r, , a, g, r, e, e, m, e, n, t, , s, u, p, p, l, e, m, e, n, t, a, r, y, , r, u, l, e.

Security MeasuresAmber

The Commissioner fined the Bank of Cyprus €17,000 in November 2022 for violations of Articles 5(1)(f), 24(1) and 32 GDPR following data-security failures involving misdirected shipments.

Claims: CLM-CY-f2a3b4c5

Breach NotificationAmber

The Commissioner fined the State Health Services Organization €46,500 for GDPR breaches involving lost patient data, evidencing active breach-notification/security enforcement in the health sector.

Claims: CLM-CY-a3b4c5d6

Retention And DisposalAmber

The Commissioner has separately guided that hotels may not retain identity-card or passport copies, and that pharmacies must minimise and discreetly handle beneficiary identification data, reflecting retention-minimisation enforcement.

Claims: CLM-CY-b4c5d6e7

Category narrative60 words

Accountability, DPIA, DPO, ROPA, security and breach-notification duties follow GDPR Arts 24-39. Cyprus's national DPIA exemption list (Art 35(5)) has been submitted to and reviewed by the EDPB. Enforcement decisions against the Bank of Cyprus (Arts 5(1)(f), 24(1), 32) evidence active supervision of security-of-processing and accountability duties; a State Health Services Organization fine evidences breach-notification/security enforcement in the health sector.

Sources and claims (6)
  1. ProbableEuropean Data Protection BoardCyprus submitted a national DPIA exemption/inclusion list under GDPR Article 35(5), which was reviewed through the EDPB's Article 64 consistency opinion process (DPIA List Cyprus).
  2. ConfirmedDataGuidanceFollowing a 2022 data-breach decision, the Commissioner recommended that the Bank of Cyprus consult its data protection officer before taking actions that may violate GDPR.
  3. ConfirmedDataGuidanceA September 2024 Commissioner audit of 28 public-sector websites found 60% lacked a posted data-protection policy and DPO contact details, with 40% having policies containing gaps and inaccuracies, before full compliance was achieved by August 2024.
  4. ConfirmedDataGuidanceThe Office of the Commissioner for Personal Data Protection fined the Bank of Cyprus Public Company Ltd €17,000 for violations of Articles 5(1)(f), 24(1) and 32 GDPR following a data breach involving misdirected letters and electronic files affecting thousands of data subjects.
  5. ConfirmedDataGuidanceCyprus fined the State Health Services Organization €46,500 for GDPR breaches involving lost patient data.
  6. ProbableDataGuidanceCyprus prohibits hotels from retaining identity card or passport copies due to GDPR violations, and pharmacies must collect beneficiary identification data discreetly to avoid system abuse.

#

Standard GDPR Chapter V mechanisms apply with no CY-specific localisation mandate identified.

Primary frameworkGDPR Arts 44-49
Traffic-light rationale — GreenStandard GDPR Chapter V mechanisms apply with no CY-specific localisation mandate identified.

Sub-modules (6)

Transfer MechanismsGreen

GDPR Art 44-49 transfer mechanisms (adequacy, SCCs, BCRs, derogations) apply directly to Cyprus-established controllers/processors.

Claims: CLM-CY-c5d6e7f8

Adequacy ReceivedGreen

Adequacy determinations are an EU Commission competence, not a Cyprus national one; Cyprus is bound by whichever adequacy decisions the Commission adopts EU-wide.

Claims: CLM-CY-c5d6e7f8

Adequacy GrantedGreen

Cyprus does not independently grant adequacy; adequacy is granted at EU level under GDPR Art 45, with the EDPB reviewing Commission adequacy-decision reports.

Claims: CLM-CY-d6e7f8a9

Sccs And BcrsGreen

Standard Contractual Clauses and Binding Corporate Rules apply under GDPR Arts 46-47; no CY-specific supplementary form was identified.

Absence provenance: not recorded. Searched: C, y, p, r, u, s, , n, a, t, i, o, n, a, l, , S, C, C, /, B, C, R, , s, u, p, p, l, e, m, e, n, t, a, r, y, , f, o, r, m, , o, r, , g, u, i, d, a, n, c, e.

Transfer Impact AssessmentAmber

TIA obligations follow the EDPB's general post-Schrems II recommendations; no CY-specific TIA template was identified.

Absence provenance: not recorded. Searched: C, y, p, r, u, s, , C, o, m, m, i, s, s, i, o, n, e, r, , t, r, a, n, s, f, e, r, , i, m, p, a, c, t, , a, s, s, e, s, s, m, e, n, t, , g, u, i, d, a, n, c, e.

Data LocalisationGreen

No general data-localisation mandate was identified in Cyprus law beyond GDPR-compliant transfer mechanisms.

Absence provenance: not recorded. Searched: C, y, p, r, u, s, , d, a, t, a, , l, o, c, a, l, i, s, a, t, i, o, n, , m, a, n, d, a, t, e.

Category narrative56 words

As an EU Member State, Cyprus applies the GDPR Chapter V transfer regime directly: transfers to third countries rely on European Commission adequacy decisions, SCCs, BCRs or Art 49 derogations. Cyprus does not independently grant or receive adequacy decisions (this is an EU Commission competence); the Commissioner participates in EDPB review of the Commission's adequacy-decision reports.

Sources and claims (2)
  1. ConfirmedEUR-LexAs an EU Member State, Cyprus applies GDPR Chapter V (Arts 44-49) transfer mechanisms directly, including adequacy decisions, SCCs, BCRs and Article 49 derogations, without a separate national transfer regime.
  2. ConfirmedEuropean Data Protection BoardThe EDPB reviews the European Commission's periodic reports on the functioning of existing adequacy decisions, including methodological observations on government-access assessments, as part of the EU-wide (not Cyprus-specific) adequacy review process.

#

Financial and telecoms overlays are well evidenced; credit-scoring, education and insurance sub-modules lack dedicated sectoral instruments beyond the general Law and are marked amber/gap.

Primary frameworkGDPR + Law 125(I)/2018, overlaid by Law 112(I)/2004 (electronic communications) and Law 92(I)/96 (private communications)
Traffic-light rationale — AmberFinancial and telecoms overlays are well evidenced; credit-scoring, education and insurance sub-modules lack dedicated sectoral instruments beyond the general Law and are marked amber/gap.

Sub-modules (7)

Financial Sector OverlayAmber

The Commissioner has issued multiple enforcement decisions against the Bank of Cyprus for GDPR security and accountability violations, evidencing active financial-sector DP supervision alongside CBC/prudential oversight.

Claims: CLM-CY-e7f8a9b0

Health Sector OverlayAmber

The Commissioner fined the State Health Services Organization €46,500 for GDPR breaches involving lost patient data, evidencing health-sector DP enforcement.

Claims: CLM-CY-a3b4c5d6

Telecoms And EprivacyGreen

Electronic-communications data protection is governed by Law 112(I)/2004 (transposing the EU electronic communications framework) and the Private Communications (Surveillance of Conversations) Law 92(I)/96, alongside GDPR.

Claims: CLM-CY-f8a9b0c1

Employment DataAmber

Employee monitoring is governed by GDPR, Law 125(I)/2018, the Private Communications Law 92(I)/96, and Articles 15/17 of the Cyprus Constitution.

Claims: CLM-CY-a9b0c1d2

Credit And ScoringRed

No CY-specific credit-scoring statute distinct from GDPR/Law 125(I)/2018 was identified.

Absence provenance: not recorded. Searched: C, y, p, r, u, s, , c, r, e, d, i, t, , s, c, o, r, i, n, g, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , s, e, c, t, o, r, a, l, , l, a, w.

EducationAmber

No dedicated education-sector DP statute distinct from GDPR/Law 125(I)/2018 was identified, though the Open University of Cyprus has been subject to GDPR enforcement following a cyber-attack.

Claims: CLM-CY-b0c1d2e3

InsuranceAmber

Law 125(I)/2018 carries a specific derogation permitting processing of genetic and biometric data for life-insurance purposes.

Claims: CLM-CY-a7b8c9d0

Category narrative77 words

Sectoral overlays supplementing GDPR/Law 125(I)/2018 include: telecoms/ePrivacy rules under Law 112(I)/2004 (electronic communications and postal services) and the Private Communications Law 92(I)/96 (secrecy of conversations); financial-sector processing supervised jointly by the Commissioner and prudential regulators, evidenced by repeated Bank of Cyprus enforcement actions; and health-sector processing evidenced by the State Health Services Organization fine. No CY-specific credit-scoring, education-sector or insurance-sector statute distinct from GDPR/Law 125(I)/2018 was identified beyond the genetic/biometric life-insurance derogation already noted in module 2.

Sources and claims (4)
  1. ConfirmedDataGuidanceThe Bank of Cyprus has been subject to multiple GDPR enforcement decisions by the Commissioner, including a €17,000 fine in 2022 for security-of-processing violations and a further €8,000 fine, evidencing sustained financial-sector DP supervision.
  2. ConfirmedDataGuidance (summarising official Cyprus Gazette text)Law 112(I)/2004 on the Regulation of Electronic Communications and Postal Services is the relevant national telecoms instrument interfacing with data protection in Cyprus.
  3. ConfirmedDataGuidance (summarising official Cyprus Gazette text)Employee monitoring in Cyprus is governed by the GDPR, Law 125(I)/2018, the Protection of the Secrecy of Private Communications (Surveillance of Conversations) Law No. 92(I)/96, and Articles 15 and 17 of the Constitution of the Republic of Cyprus.
  4. ProbableDataGuidanceThe Open University of Cyprus was fined €45,000 for GDPR violations following a cyber-attack, evidencing education-sector DP enforcement under the general GDPR/Law 125(I)/2018 regime.

#

Cookie/tracker and direct-marketing enforcement is well evidenced; dark-patterns, opt-out-signal (GPC-style) and clean-room/cross-context-advertising specific rules were not located.

Primary frameworkePrivacy Directive 2002/58/EC (as amended) transposed via Law 112(I)/2004, and GDPR
Traffic-light rationale — AmberCookie/tracker and direct-marketing enforcement is well evidenced; dark-patterns, opt-out-signal (GPC-style) and clean-room/cross-context-advertising specific rules were not located.

Sub-modules (6)

Cookies And TrackersAmber

The Commissioner fined Aylo Freesites Ltd €58,400 for GDPR violations and illegal cookie use, and separately published cookie-audit findings highlighting consent and categorisation issues.

Claims: CLM-CY-c1d2e3f4

Dark PatternsRed

No CY-specific dark-pattern prohibition distinct from GDPR consent-validity principles was identified.

Absence provenance: not recorded. Searched: C, y, p, r, u, s, , d, a, r, k, , p, a, t, t, e, r, n, s, , p, r, o, h, i, b, i, t, i, o, n, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n.

Opt Out SignalsRed

No Cyprus-specific recognition of browser-level opt-out signals (e.g. GPC) was identified.

Absence provenance: not recorded. Searched: C, y, p, r, u, s, , G, l, o, b, a, l, , P, r, i, v, a, c, y, , C, o, n, t, r, o, l, , o, p, t, -, o, u, t, , s, i, g, n, a, l, , r, e, c, o, g, n, i, t, i, o, n.

Clean Rooms And DcrRed

No Cyprus-specific data clean-room or data-collaboration-room regulation was identified.

Absence provenance: not recorded. Searched: C, y, p, r, u, s, , d, a, t, a, , c, l, e, a, n, , r, o, o, m, , r, e, g, u, l, a, t, i, o, n.

Cross Context AdvertisingAmber

No Cyprus-specific 'sale'/'share' cross-context advertising framework analogous to US state law was identified; general GDPR consent/legitimate-interest rules apply to ad-tech data sharing.

Absence provenance: not recorded. Searched: C, y, p, r, u, s, , c, r, o, s, s, -, c, o, n, t, e, x, t, , a, d, v, e, r, t, i, s, i, n, g, , d, a, t, a, , s, h, a, r, i, n, g, , r, u, l, e.

Direct MarketingGreen

The Commissioner has issued dedicated guidelines on direct marketing under the GDPR/Law 125(I)/2018 framework.

Claims: CLM-CY-d2e3f4a5

Category narrative51 words

Cookie and tracker consent follows the ePrivacy Directive as transposed via Law 112(I)/2004, enforced by the Commissioner alongside GDPR. The Commissioner conducted a cookie compliance audit and fined Aylo Freesites Ltd €58,400 for GDPR violations and illegal cookie use, evidencing active adtech/cookie enforcement. Direct marketing is covered by dedicated Commissioner guidelines.

Sources and claims (2)
  1. ConfirmedDataGuidanceThe Cyprus Commissioner for Personal Data Protection fined Aylo Freesites Ltd €58,400 for GDPR violations and illegal cookie use, and separately reported cookie-audit findings highlighting consent and categorisation issues.
  2. ConfirmedDataGuidanceThe Commissioner has issued guidelines covering direct marketing among other key GDPR compliance topics.

#

Core Art 22 ADM protections are in force; biometric-specific, AI-risk-assessment and surveillance-carveout sub-modules rely on the general GDPR framework with no CY-specific instrument located.

Primary frameworkGDPR Art 22 as implemented by Law 125(I) of 2018
Traffic-light rationale — AmberCore Art 22 ADM protections are in force; biometric-specific, AI-risk-assessment and surveillance-carveout sub-modules rely on the general GDPR framework with no CY-specific instrument located.

Sub-modules (6)

Profiling RestrictionsGreen

GDPR Art 22 profiling restrictions apply directly; no CY-specific narrowing or broadening identified.

Absence provenance: not recorded. Searched: C, y, p, r, u, s, , p, r, o, f, i, l, i, n, g, , r, e, s, t, r, i, c, t, i, o, n, , s, u, p, p, l, e, m, e, n, t, a, r, y, , r, u, l, e.

Automated Decision Making TransparencyGreen

GDPR Art 22 ADM transparency and explanation rights apply directly in Cyprus with no local supplement identified.

Claims: CLM-CY-e3f4a5b6

Ai Risk AssessmentsRed

No Cyprus-specific AI risk-assessment statute distinct from the EU AI Act's forthcoming application was identified.

Absence provenance: not recorded. Searched: C, y, p, r, u, s, , A, I, , r, i, s, k, , a, s, s, e, s, s, m, e, n, t, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , l, a, w, , 2, 0, 2, 6.

Biometric RegimeAmber

Beyond the life-insurance genetic/biometric derogation in Law 125(I)/2018, no dedicated facial-recognition or biometric-specific statute was identified.

Claims: CLM-CY-a7b8c9d0

Genetic DataAmber

Genetic data processing for life-insurance purposes is subject to the Law 125(I)/2018 derogation noted above.

Claims: CLM-CY-a7b8c9d0

State Surveillance CarveoutsRed

No CY-specific national-security surveillance carve-out distinct from GDPR Art 23/Law 125(I)/2018 general exemptions was identified.

Absence provenance: not recorded. Searched: C, y, p, r, u, s, , n, a, t, i, o, n, a, l, , s, e, c, u, r, i, t, y, , s, u, r, v, e, i, l, l, a, n, c, e, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , e, x, e, m, p, t, i, o, n.

Category narrative60 words

Profiling and automated-decision-making transparency follow GDPR Art 22 directly. The national genetic/biometric derogation for life insurance interacts with the biometric and genetic data sub-modules. No Cyprus-specific AI-risk-assessment regime distinct from the incoming EU AI Act, nor a dedicated facial-recognition/biometric statute, nor a state-surveillance carve-out statute distinct from national-security exemptions in GDPR Art 23/Law 125(I)/2018, was identified in the sources reviewed.

Sources and claims (1)
  1. ConfirmedEUR-LexGDPR Article 22 automated-decision-making transparency and explanation rights apply directly to Cyprus-established controllers under the GDPR/Law 125(I)/2018 framework.

#

Age-of-consent and parental-consent sub-modules are well evidenced; minor-profiling-ban, education-settings and dependent-adults sub-modules rely on the general regime with no dedicated instrument located.

Primary frameworkLaw 125(I) of 2018 (age of consent derogation) and GDPR Art 8
Traffic-light rationale — AmberAge-of-consent and parental-consent sub-modules are well evidenced; minor-profiling-ban, education-settings and dependent-adults sub-modules rely on the general regime with no dedicated instrument located.

Sub-modules (5)

Age VerificationAmber

The age of consent for information-society services in Cyprus is set at 14, a derogation from the GDPR default of 16.

Claims: CLM-CY-f6a7b8c9

Minor Profiling BansRed

No CY-specific statutory ban on profiling of minors distinct from general GDPR Art 22/Recital 71 protections was identified.

Absence provenance: not recorded. Searched: C, y, p, r, u, s, , m, i, n, o, r, , p, r, o, f, i, l, i, n, g, , b, a, n, , s, t, a, t, u, t, e.

Education SettingsAmber

No dedicated education-settings DP statute distinct from GDPR/Law 125(I)/2018 was identified, notwithstanding enforcement action involving the Open University of Cyprus.

Claims: CLM-CY-b0c1d2e3

Dependent AdultsRed

No CY-specific dependent-adults (elderly/incapacitated) data-protection regime distinct from the general Law was identified.

Absence provenance: not recorded. Searched: C, y, p, r, u, s, , d, e, p, e, n, d, e, n, t, , a, d, u, l, t, s, , v, u, l, n, e, r, a, b, l, e, , p, e, r, s, o, n, s, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , r, e, g, i, m, e.

Category narrative58 words

Cyprus sets the digital age of consent at 14 (below the GDPR default of 16), requiring parental/guardian consent for data activities involving users aged 14 and under. The Commissioner has publicly emphasised children's data protection, urging parental, guardian and educator vigilance. No dedicated minor-profiling-ban statute, education-settings-specific DP rule, or dependent-adults-specific regime distinct from the general Law was identified.

Sources and claims (1)
  1. ConfirmedInternational Association of Privacy ProfessionalsThe Cyprus Commissioner for the Protection of Personal Data has stressed the need for companies to ensure parental or legal-guardian consent for data activities related to users aged 14 and under.

#

Regulator possesses full GDPR enforcement powers and demonstrates sustained enforcement activity across sectors within the last 24 months.

Primary frameworkGDPR Arts 58, 77-84, as implemented by Law 125(I) of 2018
Traffic-light rationale — GreenRegulator possesses full GDPR enforcement powers and demonstrates sustained enforcement activity across sectors within the last 24 months.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

Law 125(I)/2018 provides for criminal offences, punishable with imprisonment, for certain violations of the Law and the GDPR, in addition to standard GDPR administrative fines.

Claims: CLM-CY-a5b6c7d8

Enforcement Activity IndexGreen

Multiple fines were issued in 2024-2025 spanning adtech (Aylo €58,400), health (State Health Services Organization €46,500), education (Open University €45,000), banking (Bank of Cyprus €17,000/€8,000), media (Politis €7,000, Arktinos €5,000).

Claims: CLM-CY-b6c7d8e9

Regulator Funding And CapacityRed

No specific budget/headcount disclosure for the Commissioner's office was located in the sources reviewed.

Absence provenance: not recorded. Searched: C, y, p, r, u, s, , C, o, m, m, i, s, s, i, o, n, e, r, , P, e, r, s, o, n, a, l, , D, a, t, a, , P, r, o, t, e, c, t, i, o, n, , b, u, d, g, e, t, , h, e, a, d, c, o, u, n, t, , a, n, n, u, a, l, , r, e, p, o, r, t.

Collective Redress And Class ActionsRed

No Cyprus-specific collective-redress/class-action mechanism for data-protection claims distinct from GDPR Art 80 representative-action provisions was identified.

Absence provenance: not recorded. Searched: C, y, p, r, u, s, , c, o, l, l, e, c, t, i, v, e, , r, e, d, r, e, s, s, , c, l, a, s, s, , a, c, t, i, o, n, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , G, D, P, R, , A, r, t, i, c, l, e, , 8, 0, , i, m, p, l, e, m, e, n, t, a, t, i, o, n.

Private Right Of ActionGreen

GDPR Arts 79/82 judicial-remedy and compensation rights apply directly; no CY-specific supplementary private right of action was identified.

Absence provenance: not recorded. Searched: C, y, p, r, u, s, , p, r, i, v, a, t, e, , r, i, g, h, t, , o, f, , a, c, t, i, o, n, , d, a, t, a, , p, r, o, t, e, c, t, i, o, n, , s, u, p, p, l, e, m, e, n, t, a, r, y.

Recent Developments 180DAmber

Within the last 180 days, Cyprus adopted a Law of 2025 implementing the Digital Services Act (designating competent authorities and fines) and approved amendments to the Network and Information Systems Security Law of 2025, both of which interface with the data-protection enforcement landscape.

Claims: CLM-CY-c7d8e9f0

Category narrative87 words

The Commissioner holds standard GDPR Art 58 investigative and corrective powers and Art 83 administrative-fining powers, plus Law 125(I)/2018 criminal offences (punishable by imprisonment) for certain violations. Enforcement activity in the last 12-24 months includes fines against Aylo Freesites (€58,400), the State Health Services Organization (€46,500), the Open University of Cyprus (€45,000), the Bank of Cyprus (€17,000 and €8,000), Politis (€7,000), and Arktinos Publishing (€5,000), plus a September 2024 public-sector compliance audit. No dedicated CY collective-redress/class-action mechanism or private-right-of-action statute distinct from GDPR Arts 79-82 was identified.

Sources and claims (3)
  1. ConfirmedDataGuidanceLegislation in Cyprus provides for criminal offences, punishable with imprisonment, for certain violations of Law 125(I)/2018 and the GDPR, in addition to the standard GDPR administrative fining regime.
  2. ConfirmedDataGuidanceRecent Commissioner enforcement activity includes fines against Aylo Freesites Ltd (€58,400), the State Health Services Organization (€46,500), the Open University of Cyprus (€45,000), the Bank of Cyprus (€17,000 and €8,000), Politis (€7,000), and Arktinos Publishing Ltd (€5,000).
  3. ProbableDataGuidanceCyprus published a Law of 2025 implementing the Digital Services Act, designating competent authorities and outlining fines for non-compliance, and approved the Network and Information Systems Security (Amendment) Law of 2025 enhancing cybersecurity measures and responsibilities.
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Cyprus
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 27 claim(s), 15 source(s) in the cumulative register.