Traffic-light rationale — GreenFull GDPR direct effect plus a comprehensive, in-force national implementing statute and an active, well-resourced-relative-to-peers regulator.
Sub-modules (5)
Regulator And AuthorityGreen
HDPA is the constitutionally and statutorily established supervisory authority.
Claims: CLM-GR-1a2b3c4d
Act And InstrumentsGreen
Law 4624/2019 (GDPR implementation + LED transposition) and Law 3471/2006 (electronic communications privacy) form the core instruments.
Claims: CLM-GR-2b3c4d5e, CLM-GR-3c4d5e6f
Material ScopeGreen
HDPA competence extends to essentially all national and transnational processing, with a national-security carve-out.
Claims: CLM-GR-4d5e6f70
Territorial ScopeGreen
HDPA has applied the GDPR Article 3 targeting criterion to assert jurisdiction over non-established controllers.
Claims: CLM-GR-5e6f7081
Regulator Registration And FilingAmber
No general controller registration/notification regime survives under the GDPR-era framework; accountability/ROPA obligations replace the old Law 2472/1997 notification system.
Claims: CLM-GR-6f708192
Category narrative56 words
Greece operates a mature, GDPR-aligned omnibus regime. The Hellenic Data Protection Authority (HDPA) is the primary supervisory authority, re-established and empowered by Law 4624/2019, which implements the GDPR domestically, transposes the Law Enforcement Directive (EU) 2016/680, and supplements the Regulation on matters left to Member State discretion. Law 3471/2006 supplements the framework for electronic communications privacy.
Sources and claims (6)
ConfirmedGovernment Gazette of the Hellenic Republic / HDPA — The Hellenic Data Protection Authority (HDPA) is the supervisory authority responsible for enforcing the GDPR and Law 4624/2019 in Greece.
ConfirmedIAPP — Greece implemented the GDPR through Law 4624/2019, which supplements the GDPR on matters left to Member State discretion, transposes the Law Enforcement Directive (EU) 2016/680, and re-establishes the HDPA.
ConfirmedOneTrust DataGuidance — Law 3471/2006 (the Electronic Communications Privacy Law) supplements the GDPR/Law 4624/2019 framework and governs cookies, trackers and electronic communications privacy in Greece.
ConfirmedEuropean Data Protection Board — The HDPA is competent to supervise every national and transnational personal data processing operation within its jurisdiction, with limited exceptions for national security matters.
ConfirmedIAPP — The HDPA applies the GDPR Article 3 targeting criterion to assert territorial competence over non-established controllers, such as Clearview AI, that process the personal data of individuals in Greece.
ProbableIAPP — Greece's GDPR-era regime does not impose a general notification/registration requirement on controllers; the prior registration system under Law 2472/1997 was replaced by the GDPR's accountability and records-of-processing obligations.
Comprehensive statutory lawful-basis and special-category framework, though the HDPA itself has flagged one internal inconsistency (Article 5 vs GDPR Article 6) and no distinct national pseudonymisation safe-harbour was found.
Primary frameworkGDPR Articles 6, 7, 9 as supplemented by Law 4624/2019 Articles 5, 21-23
Traffic-light rationale — GreenComprehensive statutory lawful-basis and special-category framework, though the HDPA itself has flagged one internal inconsistency (Article 5 vs GDPR Article 6) and no distinct national pseudonymisation safe-harbour was found.
Sub-modules (4)
Lawful BasesAmber
GDPR Article 6 applies directly; Law 4624/2019 Article 5 restates it, a repetition the HDPA flagged as inconsistent with EU law.
Claims: CLM-GR-708192a3
Consent ThresholdsGreen
Digital age of consent set at 15 by Article 21 of Law 4624/2019.
Claims: CLM-GR-8192a3b4
Special CategoriesGreen
Special-category processing permitted without consent for health/social-care/social-security purposes; genetic data barred from insurance use.
Claims: CLM-GR-92a3b4c5, CLM-GR-a3b4c5d6
Pseudonymisation And AnonymisationRed
No Greece-specific statutory safe-harbour identified beyond the GDPR's own definitions.
Claims: CLM-GR-b4c5d6e7
Category narrative37 words
GDPR Articles 6, 7 and 9 apply directly, supplemented by Law 4624/2019's specific provisions on the digital consent age (15), employment-context processing, special-category processing for health/social-security purposes, and a prohibition on genetic data use for insurance underwriting.
Sources and claims (5)
ConfirmedOneTrust DataGuidance — GDPR Article 6 lawful bases for processing apply directly in Greece; Law 4624/2019 Article 5 restates Article 6 GDPR domestically, a repetition the HDPA itself flagged as inconsistent with EU law in its January 2020 opinion.
ConfirmedOneTrust DataGuidance — Law 4624/2019 Article 21 sets the age of a minor's valid consent to processing in relation to information society services at 15 years old; below that age, parental or guardian consent is required.
ConfirmedIAPP — Processing of special categories of data by public and private entities is permitted without data subject consent where mandatory for health care, social care, social security, or work-capacity assessment, subject to safeguards for data subject interests.
ConfirmedOneTrust DataGuidance — Law 4624/2019 Article 23 prohibits the processing of genetic data for health and life insurance purposes.
UncertainOneTrust DataGuidance — No Greek-specific statutory safe-harbour or derogation for pseudonymisation/anonymisation beyond the GDPR Article 4(5) definition and Recital 26 was identified in Law 4624/2019 or HDPA guidance reviewed.
Core rights actively enforced (access); ancillary rights (restriction, portability) rely on direct GDPR application without located national supplements.
Primary frameworkGDPR Articles 12-22 (direct effect), no material national derogation identified
Traffic-light rationale — GreenCore rights actively enforced (access); ancillary rights (restriction, portability) rely on direct GDPR application without located national supplements.
Sub-modules (5)
Access RightGreen
Actively enforced; multiple fines for DSAR non-compliance.
Claims: CLM-GR-c5d6e7f8, CLM-GR-d6e7f809
Rectification And ErasureAmber
Greece participated in the EDPB's 2025 CEF right-to-erasure action.
GDPR Articles 12-22 apply directly. HDPA enforcement activity demonstrates active protection of the access right in particular; erasure was the subject of a 2025 EDPB Coordinated Enforcement Framework action involving Greece. No distinct Greek derogations were identified for restriction, objection or portability rights.
Sources and claims (6)
ConfirmedOneTrust DataGuidance — The HDPA has enforced the GDPR Article 15 right of access, including fining UGHL €7,000 for unlawful data processing and failure to fulfill a data access request.
ConfirmedEuropean Data Protection Board — The HDPA fined an association for people with Autism Spectrum Disorder for failing to satisfy a parental right-of-access request for CCTV footage and for unlawfully transmitting a minor's sensitive data to a third party.
ProbableOneTrust DataGuidance — Greece participated as one of 32 DPAs in the EDPB's 2025 Coordinated Enforcement Framework (CEF) action examining implementation of the GDPR right to erasure.
UncertainGovernment Gazette of the Hellenic Republic / HDPA — No Greece-specific derogation from the GDPR Articles 18 and 21 restriction/objection rights was identified beyond direct application of the Regulation.
UncertainGovernment Gazette of the Hellenic Republic / HDPA — No Greece-specific derogation from the GDPR Article 20 data portability right was identified; the right applies as set out directly in the Regulation.
ProbableGovernment Gazette of the Hellenic Republic / HDPA — The GDPR Article 12(3) one-month response deadline (extendable by two further months for complex requests) applies directly to Greek controllers without a shorter or longer national derogation identified.
Multiple high-value breach-related fines (Vodafone 2025; Cosmote/OTE 2022).
Claims: CLM-GR-a3b4c5e7, CLM-GR-b4c5d6f8
Retention And DisposalRed
No dedicated national retention-period statute identified beyond GDPR storage limitation.
Claims: CLM-GR-c5d6e709
Category narrative55 words
HDPA has issued a DPIA-trigger list, actively enforces security-of-processing and breach obligations (Cosmote/OTE €9.25M combined 2022; Vodafone 2025; Hellenic Post/ELTA ransomware fine), and pursued an own-initiative DPIA/cooperation investigation into government border-surveillance systems. DPO provisions exist in Law 4624/2019, though the HDPA flagged a LED-incompatibility in public-sector DPO exemptions. No distinct national retention-period statute was located.
Sources and claims (11)
ConfirmedOneTrust DataGuidance — The HDPA has issued a list of processing operations subject to the mandatory Data Protection Impact Assessment (DPIA) requirement under GDPR Article 35(4).
ConfirmedEuropean Data Protection Board — The HDPA fined the Hellenic Ministry of Migration and Asylum €175,000 following an own-initiative investigation into the 'Centaur' and 'Hyperion' border-surveillance systems for breaches relating to cooperation with the Authority and deficient impact assessments.
ConfirmedIAPP — Law 4624/2019 contains specific provisions on the appointment, role and independence of Data Protection Officers, including for public bodies.
ConfirmedOneTrust DataGuidance — The HDPA's January 2020 opinion found that Law 4624/2019's additional exemptions for public institutions from the GDPR Article 37 DPO-appointment mandate were incompatible with Article 32(4) of the Law Enforcement Directive.
ProbableOneTrust DataGuidance — No Greece-specific derogation from the GDPR Article 30 records-of-processing obligation was identified beyond direct application of the Regulation and HDPA guidance referencing processing-records compliance.
ConfirmedEuropean Data Protection Board — In its 2022 decision against COSMOTE and OTE, the HDPA found the companies had failed to properly allocate their respective controller/processor roles and responsibilities in relation to a data breach, applying GDPR joint/controller-processor accountability principles.
ConfirmedOneTrust DataGuidance — ADAE Decision No. 304/2025 mandates specific technical and organisational security measures for electronic communications providers to ensure confidentiality and manage risk.
ConfirmedEuropean Data Protection Board — The HDPA fined Hellenic Post Services S.A. (ELTA) a sum equal to 1% of its annual turnover for failing to implement adequate technical and organisational security measures following ransomware and dark-web data-leak incidents.
ConfirmedEuropean Data Protection Board — The HDPA fined Vodafone Greece and its processor in a June 2025 decision for a personal-data breach and insufficient security measures relating to unauthorised prepaid mobile-line activations, applying GDPR Articles 5(1)(d), 28, 29 and 32.
ConfirmedEuropean Data Protection Board — In its 2022 decision, the HDPA fined COSMOTE €6,000,000 and OTE €3,250,000 for infringing GDPR breach-related obligations, including inadequate security measures, poor anonymisation and an insufficient data protection impact assessment following a September 2020 subscriber call-data breach.
UncertainGovernment Gazette of the Hellenic Republic / HDPA — No Greece-specific general statutory retention-period regime beyond the GDPR Article 5(1)(e) storage-limitation principle was identified in Law 4624/2019 or HDPA guidance reviewed.
Traffic-light rationale — GreenChapter V applies with full direct effect; no Greek derogation or gap identified beyond the EU-wide framework.
Sub-modules (6)
Transfer MechanismsGreen
GDPR Chapter V mechanisms apply directly.
Claims: CLM-GR-d6e7f81a
Adequacy ReceivedAmber
No Greece-specific inbound adequacy determination; EU-level mechanism applies.
Claims: CLM-GR-e7f8092b
Adequacy GrantedAmber
Adequacy decisions are adopted at EU level and apply uniformly to Greece; no separate Greek determinations.
Claims: CLM-GR-f8091a3c
Sccs And BcrsGreen
SCCs/BCRs available under standard EU-wide forms.
Claims: CLM-GR-091a2b4d
Transfer Impact AssessmentAmber
TIA obligation applies via EU-wide post-Schrems II framework.
Claims: CLM-GR-1a2b3c5f
Data LocalisationGreen
No general localisation mandate; HDPA supervises specific EU-system databases.
Claims: CLM-GR-2b3c4d70
Category narrative57 words
As an EU Member State, Greece applies the GDPR Chapter V transfer regime directly (adequacy, SCCs, BCRs, derogations, TIA), with no distinct national mechanism identified. Adequacy decisions are set centrally by the European Commission and apply uniformly. The HDPA additionally supervises specific EU-system databases (SIS II, VIS, Eurodac, CIS, PNR) rather than operating a general data-localisation mandate.
Sources and claims (6)
ConfirmedGovernment Gazette of the Hellenic Republic / HDPA — As an EU Member State, Greece applies the GDPR Chapter V transfer regime (Articles 44-49) directly, including adequacy decisions, Standard Contractual Clauses, Binding Corporate Rules and derogations, without a distinct national transfer mechanism identified in Law 4624/2019.
ProbableGovernment Gazette of the Hellenic Republic / HDPA — There is no Greece-specific adequacy decision received from a third country; inbound adequacy findings under GDPR Article 45 are determined at EU level and apply automatically to Greece as a Member State.
ProbableGovernment Gazette of the Hellenic Republic / HDPA — Adequacy decisions applicable in Greece are adopted centrally by the European Commission under GDPR Article 45 and apply uniformly across all EU Member States; Greece does not issue separate national adequacy determinations.
ProbableGovernment Gazette of the Hellenic Republic / HDPA — Standard Contractual Clauses and Binding Corporate Rules are available and used as GDPR Chapter V transfer mechanisms in Greece under the same EU-wide forms and EDPB/Commission templates, with no Greece-specific supplementary form identified.
ProbableGovernment Gazette of the Hellenic Republic / HDPA — Greek controllers relying on SCCs for international transfers are subject to the EU-wide Transfer Impact Assessment obligation established following the CJEU's Schrems II ruling, with no distinct Greek-specific TIA methodology identified beyond EDPB guidance.
ConfirmedEuropean Data Protection Board — Rather than a general data-localisation mandate, the HDPA supervises specific national law-enforcement and border-management databases connected to EU-wide systems (Europol National Unit, SIS II, VIS, Eurodac, CIS and PNR under Law 4579/2018), which involve constrained, system-specific data-residency and access rules.
Traffic-light rationale — AmberStrong telecoms/employment/health coverage; credit-scoring sub-module has no located sectoral statute beyond GDPR Article 22.
Sub-modules (7)
Financial Sector OverlayAmber
HDPA has fined banking-sector entities for incorrect data processing.
Claims: CLM-GR-3c4d5e81
Health Sector OverlayGreen
HDPA enforces special-category health-data rules against individual practitioners.
Claims: CLM-GR-4d5e6f92
Telecoms And EprivacyGreen
Law 3471/2006 plus ADAE communications-security oversight.
Claims: CLM-GR-5e6f70a3
Employment DataGreen
Law 4624/2019 restricts employee-data processing purposes.
Claims: CLM-GR-6f7081b4
Credit And ScoringRed
No dedicated Greek credit-scoring statute located.
Claims: CLM-GR-708192c5
EducationAmber
Ed-tech provider fined for DSAR/child-data violations.
Claims: CLM-GR-8192a3d6
InsuranceGreen
Genetic-data insurance-use prohibition under Article 23.
Claims: CLM-GR-92a3b4e7
Category narrative40 words
Sector-specific enforcement is evidenced in telecoms (Law 3471/2006, ADAE oversight), employment (Law 4624/2019 employment provisions), health (patient-data access-abuse fines), financial services (Piraeus Bank fine), insurance (genetic-data insurance ban), and education (ed-tech DSAR fine). No dedicated Greek credit-scoring statute was located.
Sources and claims (7)
ConfirmedOneTrust DataGuidance — The HDPA fined Piraeus Bank €50,000 for GDPR violations arising from incorrect data processing, illustrating financial-sector overlay enforcement.
ConfirmedOneTrust DataGuidance — The HDPA fined a gynecologist €5,000 for unauthorized access to a former patient's health data, illustrating health-sector overlay enforcement of GDPR special-category rules.
ConfirmedEuropean Data Protection Board — Law 3471/2006, as amended, governs the confidentiality of electronic communications and cookies in Greece and is enforced by the HDPA alongside the National Telecommunications Authority ADAE, which is itself responsible for communications-security oversight (e.g., ADAE Decision No. 304/2025).
ConfirmedIAPP — Law 4624/2019 restricts the lawful purposes for processing employee personal data to those necessary for recruitment and for the performance and execution of the employment contract, and permits processing on the basis of collective labor agreements.
UncertainOneTrust DataGuidance — No Greece-specific statutory credit-scoring or automated-lending-decision regime beyond direct application of GDPR Article 22 was identified in Law 4624/2019 or HDPA guidance reviewed.
ConfirmedOneTrust DataGuidance — The HDPA fined ed-tech provider IMathisi €4,000 for GDPR violations including denying a parent's access request to a child's data and failing to cooperate with the Authority, illustrating education-sector enforcement.
ConfirmedOneTrust DataGuidance — Law 4624/2019 Article 23 prohibits processing genetic data for health and life insurance purposes, constraining insurance-sector use of sensitive data.
Traffic-light rationale — AmberCore cookie/marketing regime is solid; newer adtech-specific concepts (dark patterns, GPC-style signals, clean rooms) are not distinctly regulated nationally.
Sub-modules (6)
Cookies And TrackersGreen
Law 3471/2006 plus dedicated HDPA guidance on cookies and trackers.
Claims: CLM-GR-a3b4c5f8, CLM-GR-b4c5d709
Dark PatternsRed
No distinct national prohibition identified.
Claims: CLM-GR-c5d6e81a
Opt Out SignalsRed
No recognition of GPC-style signals identified in HDPA guidance.
Claims: CLM-GR-d6e7f92b
Clean Rooms And DcrRed
No dedicated clean-room framework identified.
Claims: CLM-GR-e7f8093c
Cross Context AdvertisingAmber
Governed by general GDPR consent/legitimate-interest rules and Law 3471/2006.
Claims: CLM-GR-f8091a4d
Direct MarketingGreen
Old opt-out mail register repealed; GDPR/ePrivacy consent rules apply.
Claims: CLM-GR-091a2b5e
Category narrative34 words
Law 3471/2006 and HDPA guidance govern cookies/trackers and direct marketing; the old opt-out mail-marketing register was repealed in favour of GDPR/ePrivacy-based consent rules. No Greece-specific dark-pattern prohibition, opt-out-signal recognition, or clean-room framework was identified.
Sources and claims (7)
ConfirmedOneTrust DataGuidance — Law 3471/2006 governs cookies and other online trackers in Greece, supplementing the GDPR and the EU ePrivacy Directive framework.
ConfirmedOneTrust DataGuidance — The HDPA has issued guidelines specifically addressing cookies and other trackers as part of its GDPR compliance guidance programme.
UncertainOneTrust DataGuidance — No Greece-specific statutory prohibition on dark patterns distinct from the GDPR consent/transparency principles and EU-level Digital Services Act provisions was identified.
UncertainOneTrust DataGuidance — No Greece-specific recognition of browser-level opt-out signals (e.g., Global Privacy Control) as a valid GDPR objection mechanism was identified in HDPA guidance reviewed.
UncertainOneTrust DataGuidance — No Greece-specific data clean-room or data-collaboration-room regulatory framework was identified beyond general GDPR joint-controller and processor rules.
ProbableOneTrust DataGuidance — No Greece-specific 'sale'/'share' cross-context-advertising concept analogous to US state law was identified; cross-context advertising in Greece is governed by the GDPR consent and legitimate-interest framework and Law 3471/2006.
ConfirmedIAPP — Law 4624/2019 repealed the prior opt-out register for unsolicited commercial communications by mail that existed under Law 2472/1997, replacing it with GDPR/ePrivacy-based direct-marketing consent rules.
Traffic-light rationale — AmberStrong, landmark biometric enforcement; AI-risk-assessment and ADM-transparency sub-modules remain reliant on general GDPR application pending fuller national AI-Act interface, and state-surveillance oversight faces documented independence concerns.
Sub-modules (6)
Profiling RestrictionsGreen
Clearview AI profiling/targeting findings.
Claims: CLM-GR-1a2b3c60
Automated Decision Making TransparencyAmber
GDPR Article 22 applies directly; no distinct national derogation.
Claims: CLM-GR-2b3c4d81
Ai Risk AssessmentsAmber
HDPA's DeepSeek EU-representative order signals emerging AI scrutiny.
Claims: CLM-GR-3c4d5e92
Biometric RegimeGreen
Landmark €20M Clearview AI fine for unlawful biometric processing.
Claims: CLM-GR-4d5e6fa3
Genetic DataGreen
Article 23 genetic-data insurance prohibition.
Claims: CLM-GR-5e6f70b4
State Surveillance CarveoutsAmber
National-security carve-out exists; European Parliament flagged independence/oversight concerns amid the Predator spyware scandal.
Claims: CLM-GR-6f7081c5
Category narrative62 words
The HDPA's landmark €20 million fine against Clearview AI for unlawful biometric facial-recognition processing anchors this module. Genetic-data restrictions exist for insurance purposes. The HDPA has begun scrutinizing AI service providers (DeepSeek EU-representative order). Surveillance oversight has faced European Parliament criticism amid the 'Predator' spyware controversy, and ADM transparency relies on direct GDPR Article 22 application without a distinct national AI-risk-assessment regime.
Sources and claims (6)
ConfirmedIAPP — The HDPA found that Clearview AI's use of facial-recognition profiling techniques to identify and monitor individuals constituted an act of targeting triggering GDPR profiling-related obligations and the strict Article 9 regime for biometric data.
ProbableGovernment Gazette of the Hellenic Republic / HDPA — GDPR Article 22 automated-decision-making transparency and explanation rights apply directly in Greece with no distinct national derogation identified in Law 4624/2019.
ProbableOneTrust DataGuidance — The HDPA required the AI chatbot provider DeepSeek to appoint an EU representative under GDPR Article 27 due to compliance concerns, reflecting emerging HDPA scrutiny of AI service providers.
ConfirmedEuropean Data Protection Board — The HDPA imposed a €20 million fine on Clearview AI — its largest fine to date — for unlawfully processing biometric facial-recognition data of Greek residents in violation of GDPR Articles 5(1)(a), 6, 9, 14 and 27.
ConfirmedOneTrust DataGuidance — Law 4624/2019 Article 23 prohibits the processing of genetic data for health and life insurance purposes, forming Greece's principal statutory genetic-data-specific restriction.
ConfirmedOfficial Journal of the European Union — The HDPA is competent to supervise national and transnational data processing with limited exceptions for national security, and Greek surveillance oversight (including the ADAE communications-security authority) has faced European Parliament scrutiny over the 'Predator' spyware scandal and weakened post-surveillance notification safeguards.
Parental-consent threshold is clearly defined and enforced; age-verification, minor-profiling and dependent-adults sub-modules rely solely on general GDPR provisions.
Traffic-light rationale — AmberParental-consent threshold is clearly defined and enforced; age-verification, minor-profiling and dependent-adults sub-modules rely solely on general GDPR provisions.
Sub-modules (5)
Age VerificationRed
No dedicated age-verification standard identified beyond the consent-age threshold.
Claims: CLM-GR-708192d6
Parental ConsentGreen
Article 21 sets the digital consent age at 15.
Claims: CLM-GR-8192a3e7
Minor Profiling BansRed
No distinct national ban beyond general GDPR framework.
Claims: CLM-GR-92a3b4f8
Education SettingsAmber
Ed-tech DSAR fine and disability-services minor-data disclosure fine.
Claims: CLM-GR-a3b4c609, CLM-GR-b4c5d71a
Dependent AdultsRed
No distinct national provisions identified.
Claims: CLM-GR-c5d6e82b
Category narrative44 words
Law 4624/2019 Article 21 fixes the digital consent age at 15, with parental consent required below that age. Enforcement precedent covers education-sector and disability-services mishandling of minors' data. No dedicated age-verification standard, minor-profiling ban, or dependent-adults regime distinct from general GDPR provisions was identified.
Sources and claims (6)
UncertainOneTrust DataGuidance — No dedicated Greek age-verification statute or technical standard distinct from the Article 21 consent-age threshold was identified in Law 4624/2019 or HDPA guidance reviewed.
ConfirmedIAPP — Law 4624/2019 Article 21 sets the digital age of consent at 15 years; below that age, the consent of a parent or legal guardian is required for a minor's data to be lawfully processed by information society services.
ConfirmedOneTrust DataGuidance — The HDPA fined ed-tech provider IMathisi €4,000 for denying a parent's data-access request concerning their child's data and for failing to cooperate with the Authority.
ConfirmedEuropean Data Protection Board — The HDPA fined an association for people with Autism Spectrum Disorder for unlawfully disclosing a minor's sensitive medical, therapeutic and social-history data to a third party without parental notification or consent.
UncertainGovernment Gazette of the Hellenic Republic / HDPA — No Greece-specific statutory data-protection provisions addressing dependent adults (elderly or mentally incapacitated persons) distinct from the general GDPR framework were identified in Law 4624/2019 or HDPA guidance reviewed.
Powers and historical enforcement activity are robust and well evidenced; the recent_developments_180d sub-module could not be populated with a confirmed decision inside the strict 180-day window, and collective-redress mechanisms remain comparatively underdeveloped.
Primary frameworkGDPR Articles 58, 77-84, 83 as supplemented by Law 4624/2019
Traffic-light rationale — AmberPowers and historical enforcement activity are robust and well evidenced; the recent_developments_180d sub-module could not be populated with a confirmed decision inside the strict 180-day window, and collective-redress mechanisms remain comparatively underdeveloped.
Sub-modules (6)
Regulator Powers And PenaltiesGreen
Fines €5,000-€20M; public-sector cap of €10M under Law 4624/2019.
Claims: CLM-GR-d6e7f93c, CLM-GR-e7f8094d
Enforcement Activity IndexGreen
Sustained high-value enforcement 2022-2025.
Claims: CLM-GR-f809a5e
Regulator Funding And CapacityAmber
HDPA self-reported staff/budget figures and characterized resources as insufficient.
Claims: CLM-GR-091b2c6f
Collective Redress And Class ActionsAmber
Lack of specific representative-action provisions.
Claims: CLM-GR-1a2c3d70
Private Right Of ActionGreen
Complaint-driven access via civil-society organisations and direct judicial remedies.
Claims: CLM-GR-2b3d4e81
Recent Developments 180DRed
Most recent confirmed major decision (Vodafone, June 2025) falls outside the strict 180-day window; no Greece-specific decision inside the window was confirmed despite targeted searches.
Claims: CLM-GR-3c4e5f92
Category narrative106 words
The HDPA exercises full GDPR Articles 58/83 corrective and sanctioning powers, with fines ranging from €5,000 to €20 million, and Law 4624/2019 caps public-sector fines at €10 million. Enforcement activity has been sustained and high-value (Clearview AI €20M, Cosmote/OTE €9.25M combined, Ministry of Migration €175,000, Vodafone 2025). Reported HDPA resourcing (39-46 staff, ~€2-2.85M budget as of 2020) was self-assessed by the Authority as insufficient. Collective redress is constrained by an absence of specific representative-action provisions, though civil-society complaints (e.g., Homo Digitalis) function as a de facto access point. No Greece-specific HDPA decision published within the 180 days preceding this run was confirmed in the sources reviewed.
Sources and claims (7)
ConfirmedOneTrust DataGuidance — The HDPA has issued administrative fines ranging from €5,000 to €20 million for GDPR violations including unlawful processing, transparency violations, non-compliance with access requests and inadequate security measures, exercising the full corrective and sanctioning powers of GDPR Articles 58 and 83.
ConfirmedIAPP — Law 4624/2019 caps administrative fines against public-sector entities at €10,000,000 depending on the severity and duration of the breach, while leaving the GDPR's uncapped sanction regime unchanged for private entities.
ConfirmedIAPP — The HDPA's 2022 fine of €20 million against Clearview AI doubled the Authority's previous record fine of €9.25 million against Greece's largest telecommunications conglomerate, reflecting an escalating enforcement trend.
ConfirmedEuropean Data Protection Board — In its EDPB Article 97 questionnaire response, the HDPA reported staff levels of 39 (2016), 35 (2017), 33 (2018), 33 (2019) and 46 (2020) employees, with an annual budget rising from approximately €2.07 million in 2016 to €2.85 million in 2019, and characterized its resources as still insufficient.
ProbableIAPP — Greek data-protection law analysis notes an absence of specific statutory provisions enabling representation of data subjects by collective associations in judicial remedies against controllers/processors, making collective redress more difficult than under the GDPR's optional Article 80 mechanism.
ConfirmedIAPP — Civil nonprofit organizations such as Homo Digitalis may file HDPA complaints on behalf of individual data subjects, as occurred in the Clearview AI case, and judicial remedies may be filed by data subjects before the court of the controller's registered seat or the data subject's residence.
UncertainEuropean Data Protection Board — The most recent major HDPA enforcement action identified in this research cycle is the June 2025 fine against Vodafone Greece and its processor for a data breach and insufficient security measures; no Greece-specific HDPA decision published within the 180 days preceding this run (i.e., since approximately February 2026) was identified in the sources reviewed.
No categories match.
Filters combine as OR inside a group and AND across
groups.
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for Greece
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
not recorded
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 67 claim(s), 17 source(s) in the cumulative register.