🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
GR · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 17 sources retrieved model claude-sonnet-5 ·

Greece

GR schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 67 claims · 17 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
67Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No categories are currently flagged red.

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Full GDPR direct effect plus a comprehensive, in-force national implementing statute and an active, well-resourced-relative-to-peers regulator.

Primary frameworkGDPR (Regulation (EU) 2016/679) as implemented and supplemented by Law 4624/2019
Traffic-light rationale — GreenFull GDPR direct effect plus a comprehensive, in-force national implementing statute and an active, well-resourced-relative-to-peers regulator.

Sub-modules (5)

Regulator And AuthorityGreen

HDPA is the constitutionally and statutorily established supervisory authority.

Claims: CLM-GR-1a2b3c4d

Act And InstrumentsGreen

Law 4624/2019 (GDPR implementation + LED transposition) and Law 3471/2006 (electronic communications privacy) form the core instruments.

Claims: CLM-GR-2b3c4d5e, CLM-GR-3c4d5e6f

Material ScopeGreen

HDPA competence extends to essentially all national and transnational processing, with a national-security carve-out.

Claims: CLM-GR-4d5e6f70

Territorial ScopeGreen

HDPA has applied the GDPR Article 3 targeting criterion to assert jurisdiction over non-established controllers.

Claims: CLM-GR-5e6f7081

Regulator Registration And FilingAmber

No general controller registration/notification regime survives under the GDPR-era framework; accountability/ROPA obligations replace the old Law 2472/1997 notification system.

Claims: CLM-GR-6f708192

Category narrative56 words

Greece operates a mature, GDPR-aligned omnibus regime. The Hellenic Data Protection Authority (HDPA) is the primary supervisory authority, re-established and empowered by Law 4624/2019, which implements the GDPR domestically, transposes the Law Enforcement Directive (EU) 2016/680, and supplements the Regulation on matters left to Member State discretion. Law 3471/2006 supplements the framework for electronic communications privacy.

Sources and claims (6)
  1. ConfirmedGovernment Gazette of the Hellenic Republic / HDPAThe Hellenic Data Protection Authority (HDPA) is the supervisory authority responsible for enforcing the GDPR and Law 4624/2019 in Greece.
  2. ConfirmedIAPPGreece implemented the GDPR through Law 4624/2019, which supplements the GDPR on matters left to Member State discretion, transposes the Law Enforcement Directive (EU) 2016/680, and re-establishes the HDPA.
  3. ConfirmedOneTrust DataGuidanceLaw 3471/2006 (the Electronic Communications Privacy Law) supplements the GDPR/Law 4624/2019 framework and governs cookies, trackers and electronic communications privacy in Greece.
  4. ConfirmedEuropean Data Protection BoardThe HDPA is competent to supervise every national and transnational personal data processing operation within its jurisdiction, with limited exceptions for national security matters.
  5. ConfirmedIAPPThe HDPA applies the GDPR Article 3 targeting criterion to assert territorial competence over non-established controllers, such as Clearview AI, that process the personal data of individuals in Greece.
  6. ProbableIAPPGreece's GDPR-era regime does not impose a general notification/registration requirement on controllers; the prior registration system under Law 2472/1997 was replaced by the GDPR's accountability and records-of-processing obligations.

#

Comprehensive statutory lawful-basis and special-category framework, though the HDPA itself has flagged one internal inconsistency (Article 5 vs GDPR Article 6) and no distinct national pseudonymisation safe-harbour was found.

Primary frameworkGDPR Articles 6, 7, 9 as supplemented by Law 4624/2019 Articles 5, 21-23
Traffic-light rationale — GreenComprehensive statutory lawful-basis and special-category framework, though the HDPA itself has flagged one internal inconsistency (Article 5 vs GDPR Article 6) and no distinct national pseudonymisation safe-harbour was found.

Sub-modules (4)

Lawful BasesAmber

GDPR Article 6 applies directly; Law 4624/2019 Article 5 restates it, a repetition the HDPA flagged as inconsistent with EU law.

Claims: CLM-GR-708192a3

Special CategoriesGreen

Special-category processing permitted without consent for health/social-care/social-security purposes; genetic data barred from insurance use.

Claims: CLM-GR-92a3b4c5, CLM-GR-a3b4c5d6

Pseudonymisation And AnonymisationRed

No Greece-specific statutory safe-harbour identified beyond the GDPR's own definitions.

Claims: CLM-GR-b4c5d6e7

Category narrative37 words

GDPR Articles 6, 7 and 9 apply directly, supplemented by Law 4624/2019's specific provisions on the digital consent age (15), employment-context processing, special-category processing for health/social-security purposes, and a prohibition on genetic data use for insurance underwriting.

Sources and claims (5)
  1. ConfirmedOneTrust DataGuidanceGDPR Article 6 lawful bases for processing apply directly in Greece; Law 4624/2019 Article 5 restates Article 6 GDPR domestically, a repetition the HDPA itself flagged as inconsistent with EU law in its January 2020 opinion.
  2. ConfirmedOneTrust DataGuidanceLaw 4624/2019 Article 21 sets the age of a minor's valid consent to processing in relation to information society services at 15 years old; below that age, parental or guardian consent is required.
  3. ConfirmedIAPPProcessing of special categories of data by public and private entities is permitted without data subject consent where mandatory for health care, social care, social security, or work-capacity assessment, subject to safeguards for data subject interests.
  4. ConfirmedOneTrust DataGuidanceLaw 4624/2019 Article 23 prohibits the processing of genetic data for health and life insurance purposes.
  5. UncertainOneTrust DataGuidanceNo Greek-specific statutory safe-harbour or derogation for pseudonymisation/anonymisation beyond the GDPR Article 4(5) definition and Recital 26 was identified in Law 4624/2019 or HDPA guidance reviewed.

#

Core rights actively enforced (access); ancillary rights (restriction, portability) rely on direct GDPR application without located national supplements.

Primary frameworkGDPR Articles 12-22 (direct effect), no material national derogation identified
Traffic-light rationale — GreenCore rights actively enforced (access); ancillary rights (restriction, portability) rely on direct GDPR application without located national supplements.

Sub-modules (5)

Access RightGreen

Actively enforced; multiple fines for DSAR non-compliance.

Claims: CLM-GR-c5d6e7f8, CLM-GR-d6e7f809

Rectification And ErasureAmber

Greece participated in the EDPB's 2025 CEF right-to-erasure action.

Claims: CLM-GR-e7f8091a

Restriction And ObjectionRed

No Greece-specific derogation identified.

Claims: CLM-GR-f8091a2b

Data PortabilityRed

No Greece-specific derogation identified.

Claims: CLM-GR-091a2b3c

Deadlines And Response WindowsAmber

GDPR Article 12(3) one-month (extendable) window applies directly.

Claims: CLM-GR-1a2b3c4e

Category narrative43 words

GDPR Articles 12-22 apply directly. HDPA enforcement activity demonstrates active protection of the access right in particular; erasure was the subject of a 2025 EDPB Coordinated Enforcement Framework action involving Greece. No distinct Greek derogations were identified for restriction, objection or portability rights.

Sources and claims (6)
  1. ConfirmedOneTrust DataGuidanceThe HDPA has enforced the GDPR Article 15 right of access, including fining UGHL €7,000 for unlawful data processing and failure to fulfill a data access request.
  2. ConfirmedEuropean Data Protection BoardThe HDPA fined an association for people with Autism Spectrum Disorder for failing to satisfy a parental right-of-access request for CCTV footage and for unlawfully transmitting a minor's sensitive data to a third party.
  3. ProbableOneTrust DataGuidanceGreece participated as one of 32 DPAs in the EDPB's 2025 Coordinated Enforcement Framework (CEF) action examining implementation of the GDPR right to erasure.
  4. UncertainGovernment Gazette of the Hellenic Republic / HDPANo Greece-specific derogation from the GDPR Articles 18 and 21 restriction/objection rights was identified beyond direct application of the Regulation.
  5. UncertainGovernment Gazette of the Hellenic Republic / HDPANo Greece-specific derogation from the GDPR Article 20 data portability right was identified; the right applies as set out directly in the Regulation.
  6. ProbableGovernment Gazette of the Hellenic Republic / HDPAThe GDPR Article 12(3) one-month response deadline (extendable by two further months for complex requests) applies directly to Greek controllers without a shorter or longer national derogation identified.

#

Strong, evidenced enforcement across accountability, security and breach sub-modules; retention/disposal relies solely on GDPR Article 5(1)(e).

Primary frameworkGDPR Articles 5, 24-32, 33-35, 37-39 as supplemented by Law 4624/2019
Traffic-light rationale — GreenStrong, evidenced enforcement across accountability, security and breach sub-modules; retention/disposal relies solely on GDPR Article 5(1)(e).

Sub-modules (7)

Accountability And DpiaGreen

HDPA-issued DPIA-trigger list; own-initiative accountability investigation into government surveillance systems.

Claims: CLM-GR-2b3c4d5f, CLM-GR-3c4d5e70

Dpo RequirementsAmber

Law 4624/2019 contains DPO provisions; HDPA flagged an LED-incompatibility in public-sector exemptions.

Claims: CLM-GR-4d5e6f81, CLM-GR-5e6f7092

Ropa RequirementsAmber

GDPR Article 30 applies directly; HDPA guidance references processing-records compliance.

Claims: CLM-GR-6f7081a3

Joint Controller ArrangementsGreen

COSMOTE/OTE decision applied joint controller-processor role-allocation accountability.

Claims: CLM-GR-708192b4

Security MeasuresGreen

ADAE Decision 304/2025 mandates telecom security measures; ELTA fined for inadequate technical/organisational measures.

Claims: CLM-GR-8192a3c5, CLM-GR-92a3b4d6

Breach NotificationGreen

Multiple high-value breach-related fines (Vodafone 2025; Cosmote/OTE 2022).

Claims: CLM-GR-a3b4c5e7, CLM-GR-b4c5d6f8

Retention And DisposalRed

No dedicated national retention-period statute identified beyond GDPR storage limitation.

Claims: CLM-GR-c5d6e709

Category narrative55 words

HDPA has issued a DPIA-trigger list, actively enforces security-of-processing and breach obligations (Cosmote/OTE €9.25M combined 2022; Vodafone 2025; Hellenic Post/ELTA ransomware fine), and pursued an own-initiative DPIA/cooperation investigation into government border-surveillance systems. DPO provisions exist in Law 4624/2019, though the HDPA flagged a LED-incompatibility in public-sector DPO exemptions. No distinct national retention-period statute was located.

Sources and claims (11)
  1. ConfirmedOneTrust DataGuidanceThe HDPA has issued a list of processing operations subject to the mandatory Data Protection Impact Assessment (DPIA) requirement under GDPR Article 35(4).
  2. ConfirmedEuropean Data Protection BoardThe HDPA fined the Hellenic Ministry of Migration and Asylum €175,000 following an own-initiative investigation into the 'Centaur' and 'Hyperion' border-surveillance systems for breaches relating to cooperation with the Authority and deficient impact assessments.
  3. ConfirmedIAPPLaw 4624/2019 contains specific provisions on the appointment, role and independence of Data Protection Officers, including for public bodies.
  4. ConfirmedOneTrust DataGuidanceThe HDPA's January 2020 opinion found that Law 4624/2019's additional exemptions for public institutions from the GDPR Article 37 DPO-appointment mandate were incompatible with Article 32(4) of the Law Enforcement Directive.
  5. ProbableOneTrust DataGuidanceNo Greece-specific derogation from the GDPR Article 30 records-of-processing obligation was identified beyond direct application of the Regulation and HDPA guidance referencing processing-records compliance.
  6. ConfirmedEuropean Data Protection BoardIn its 2022 decision against COSMOTE and OTE, the HDPA found the companies had failed to properly allocate their respective controller/processor roles and responsibilities in relation to a data breach, applying GDPR joint/controller-processor accountability principles.
  7. ConfirmedOneTrust DataGuidanceADAE Decision No. 304/2025 mandates specific technical and organisational security measures for electronic communications providers to ensure confidentiality and manage risk.
  8. ConfirmedEuropean Data Protection BoardThe HDPA fined Hellenic Post Services S.A. (ELTA) a sum equal to 1% of its annual turnover for failing to implement adequate technical and organisational security measures following ransomware and dark-web data-leak incidents.
  9. ConfirmedEuropean Data Protection BoardThe HDPA fined Vodafone Greece and its processor in a June 2025 decision for a personal-data breach and insufficient security measures relating to unauthorised prepaid mobile-line activations, applying GDPR Articles 5(1)(d), 28, 29 and 32.
  10. ConfirmedEuropean Data Protection BoardIn its 2022 decision, the HDPA fined COSMOTE €6,000,000 and OTE €3,250,000 for infringing GDPR breach-related obligations, including inadequate security measures, poor anonymisation and an insufficient data protection impact assessment following a September 2020 subscriber call-data breach.
  11. UncertainGovernment Gazette of the Hellenic Republic / HDPANo Greece-specific general statutory retention-period regime beyond the GDPR Article 5(1)(e) storage-limitation principle was identified in Law 4624/2019 or HDPA guidance reviewed.

#

Chapter V applies with full direct effect; no Greek derogation or gap identified beyond the EU-wide framework.

Primary frameworkGDPR Chapter V (Articles 44-49), direct effect in Greece
Traffic-light rationale — GreenChapter V applies with full direct effect; no Greek derogation or gap identified beyond the EU-wide framework.

Sub-modules (6)

Transfer MechanismsGreen

GDPR Chapter V mechanisms apply directly.

Claims: CLM-GR-d6e7f81a

Adequacy ReceivedAmber

No Greece-specific inbound adequacy determination; EU-level mechanism applies.

Claims: CLM-GR-e7f8092b

Adequacy GrantedAmber

Adequacy decisions are adopted at EU level and apply uniformly to Greece; no separate Greek determinations.

Claims: CLM-GR-f8091a3c

Sccs And BcrsGreen

SCCs/BCRs available under standard EU-wide forms.

Claims: CLM-GR-091a2b4d

Transfer Impact AssessmentAmber

TIA obligation applies via EU-wide post-Schrems II framework.

Claims: CLM-GR-1a2b3c5f

Data LocalisationGreen

No general localisation mandate; HDPA supervises specific EU-system databases.

Claims: CLM-GR-2b3c4d70

Category narrative57 words

As an EU Member State, Greece applies the GDPR Chapter V transfer regime directly (adequacy, SCCs, BCRs, derogations, TIA), with no distinct national mechanism identified. Adequacy decisions are set centrally by the European Commission and apply uniformly. The HDPA additionally supervises specific EU-system databases (SIS II, VIS, Eurodac, CIS, PNR) rather than operating a general data-localisation mandate.

Sources and claims (6)
  1. ConfirmedGovernment Gazette of the Hellenic Republic / HDPAAs an EU Member State, Greece applies the GDPR Chapter V transfer regime (Articles 44-49) directly, including adequacy decisions, Standard Contractual Clauses, Binding Corporate Rules and derogations, without a distinct national transfer mechanism identified in Law 4624/2019.
  2. ProbableGovernment Gazette of the Hellenic Republic / HDPAThere is no Greece-specific adequacy decision received from a third country; inbound adequacy findings under GDPR Article 45 are determined at EU level and apply automatically to Greece as a Member State.
  3. ProbableGovernment Gazette of the Hellenic Republic / HDPAAdequacy decisions applicable in Greece are adopted centrally by the European Commission under GDPR Article 45 and apply uniformly across all EU Member States; Greece does not issue separate national adequacy determinations.
  4. ProbableGovernment Gazette of the Hellenic Republic / HDPAStandard Contractual Clauses and Binding Corporate Rules are available and used as GDPR Chapter V transfer mechanisms in Greece under the same EU-wide forms and EDPB/Commission templates, with no Greece-specific supplementary form identified.
  5. ProbableGovernment Gazette of the Hellenic Republic / HDPAGreek controllers relying on SCCs for international transfers are subject to the EU-wide Transfer Impact Assessment obligation established following the CJEU's Schrems II ruling, with no distinct Greek-specific TIA methodology identified beyond EDPB guidance.
  6. ConfirmedEuropean Data Protection BoardRather than a general data-localisation mandate, the HDPA supervises specific national law-enforcement and border-management databases connected to EU-wide systems (Europol National Unit, SIS II, VIS, Eurodac, CIS and PNR under Law 4579/2018), which involve constrained, system-specific data-residency and access rules.

#

Strong telecoms/employment/health coverage; credit-scoring sub-module has no located sectoral statute beyond GDPR Article 22.

Primary frameworkGDPR + Law 4624/2019 sectoral provisions + Law 3471/2006 (telecoms)
Traffic-light rationale — AmberStrong telecoms/employment/health coverage; credit-scoring sub-module has no located sectoral statute beyond GDPR Article 22.

Sub-modules (7)

Financial Sector OverlayAmber

HDPA has fined banking-sector entities for incorrect data processing.

Claims: CLM-GR-3c4d5e81

Health Sector OverlayGreen

HDPA enforces special-category health-data rules against individual practitioners.

Claims: CLM-GR-4d5e6f92

Telecoms And EprivacyGreen

Law 3471/2006 plus ADAE communications-security oversight.

Claims: CLM-GR-5e6f70a3

Employment DataGreen

Law 4624/2019 restricts employee-data processing purposes.

Claims: CLM-GR-6f7081b4

Credit And ScoringRed

No dedicated Greek credit-scoring statute located.

Claims: CLM-GR-708192c5

EducationAmber

Ed-tech provider fined for DSAR/child-data violations.

Claims: CLM-GR-8192a3d6

InsuranceGreen

Genetic-data insurance-use prohibition under Article 23.

Claims: CLM-GR-92a3b4e7

Category narrative40 words

Sector-specific enforcement is evidenced in telecoms (Law 3471/2006, ADAE oversight), employment (Law 4624/2019 employment provisions), health (patient-data access-abuse fines), financial services (Piraeus Bank fine), insurance (genetic-data insurance ban), and education (ed-tech DSAR fine). No dedicated Greek credit-scoring statute was located.

Sources and claims (7)
  1. ConfirmedOneTrust DataGuidanceThe HDPA fined Piraeus Bank €50,000 for GDPR violations arising from incorrect data processing, illustrating financial-sector overlay enforcement.
  2. ConfirmedOneTrust DataGuidanceThe HDPA fined a gynecologist €5,000 for unauthorized access to a former patient's health data, illustrating health-sector overlay enforcement of GDPR special-category rules.
  3. ConfirmedEuropean Data Protection BoardLaw 3471/2006, as amended, governs the confidentiality of electronic communications and cookies in Greece and is enforced by the HDPA alongside the National Telecommunications Authority ADAE, which is itself responsible for communications-security oversight (e.g., ADAE Decision No. 304/2025).
  4. ConfirmedIAPPLaw 4624/2019 restricts the lawful purposes for processing employee personal data to those necessary for recruitment and for the performance and execution of the employment contract, and permits processing on the basis of collective labor agreements.
  5. UncertainOneTrust DataGuidanceNo Greece-specific statutory credit-scoring or automated-lending-decision regime beyond direct application of GDPR Article 22 was identified in Law 4624/2019 or HDPA guidance reviewed.
  6. ConfirmedOneTrust DataGuidanceThe HDPA fined ed-tech provider IMathisi €4,000 for GDPR violations including denying a parent's access request to a child's data and failing to cooperate with the Authority, illustrating education-sector enforcement.
  7. ConfirmedOneTrust DataGuidanceLaw 4624/2019 Article 23 prohibits processing genetic data for health and life insurance purposes, constraining insurance-sector use of sensitive data.

#

Core cookie/marketing regime is solid; newer adtech-specific concepts (dark patterns, GPC-style signals, clean rooms) are not distinctly regulated nationally.

Primary frameworkLaw 3471/2006 (ePrivacy transposition) + GDPR consent/legitimate-interest framework
Traffic-light rationale — AmberCore cookie/marketing regime is solid; newer adtech-specific concepts (dark patterns, GPC-style signals, clean rooms) are not distinctly regulated nationally.

Sub-modules (6)

Cookies And TrackersGreen

Law 3471/2006 plus dedicated HDPA guidance on cookies and trackers.

Claims: CLM-GR-a3b4c5f8, CLM-GR-b4c5d709

Dark PatternsRed

No distinct national prohibition identified.

Claims: CLM-GR-c5d6e81a

Opt Out SignalsRed

No recognition of GPC-style signals identified in HDPA guidance.

Claims: CLM-GR-d6e7f92b

Clean Rooms And DcrRed

No dedicated clean-room framework identified.

Claims: CLM-GR-e7f8093c

Cross Context AdvertisingAmber

Governed by general GDPR consent/legitimate-interest rules and Law 3471/2006.

Claims: CLM-GR-f8091a4d

Direct MarketingGreen

Old opt-out mail register repealed; GDPR/ePrivacy consent rules apply.

Claims: CLM-GR-091a2b5e

Category narrative34 words

Law 3471/2006 and HDPA guidance govern cookies/trackers and direct marketing; the old opt-out mail-marketing register was repealed in favour of GDPR/ePrivacy-based consent rules. No Greece-specific dark-pattern prohibition, opt-out-signal recognition, or clean-room framework was identified.

Sources and claims (7)
  1. ConfirmedOneTrust DataGuidanceLaw 3471/2006 governs cookies and other online trackers in Greece, supplementing the GDPR and the EU ePrivacy Directive framework.
  2. ConfirmedOneTrust DataGuidanceThe HDPA has issued guidelines specifically addressing cookies and other trackers as part of its GDPR compliance guidance programme.
  3. UncertainOneTrust DataGuidanceNo Greece-specific statutory prohibition on dark patterns distinct from the GDPR consent/transparency principles and EU-level Digital Services Act provisions was identified.
  4. UncertainOneTrust DataGuidanceNo Greece-specific recognition of browser-level opt-out signals (e.g., Global Privacy Control) as a valid GDPR objection mechanism was identified in HDPA guidance reviewed.
  5. UncertainOneTrust DataGuidanceNo Greece-specific data clean-room or data-collaboration-room regulatory framework was identified beyond general GDPR joint-controller and processor rules.
  6. ProbableOneTrust DataGuidanceNo Greece-specific 'sale'/'share' cross-context-advertising concept analogous to US state law was identified; cross-context advertising in Greece is governed by the GDPR consent and legitimate-interest framework and Law 3471/2006.
  7. ConfirmedIAPPLaw 4624/2019 repealed the prior opt-out register for unsolicited commercial communications by mail that existed under Law 2472/1997, replacing it with GDPR/ePrivacy-based direct-marketing consent rules.

#

Strong, landmark biometric enforcement; AI-risk-assessment and ADM-transparency sub-modules remain reliant on general GDPR application pending fuller national AI-Act interface, and state-surveillance oversight faces documented independence concerns.

Primary frameworkGDPR Articles 9, 22 as supplemented by Law 4624/2019 Article 23; EU AI Act interface emerging
Traffic-light rationale — AmberStrong, landmark biometric enforcement; AI-risk-assessment and ADM-transparency sub-modules remain reliant on general GDPR application pending fuller national AI-Act interface, and state-surveillance oversight faces documented independence concerns.

Sub-modules (6)

Profiling RestrictionsGreen

Clearview AI profiling/targeting findings.

Claims: CLM-GR-1a2b3c60

Automated Decision Making TransparencyAmber

GDPR Article 22 applies directly; no distinct national derogation.

Claims: CLM-GR-2b3c4d81

Ai Risk AssessmentsAmber

HDPA's DeepSeek EU-representative order signals emerging AI scrutiny.

Claims: CLM-GR-3c4d5e92

Biometric RegimeGreen

Landmark €20M Clearview AI fine for unlawful biometric processing.

Claims: CLM-GR-4d5e6fa3

Genetic DataGreen

Article 23 genetic-data insurance prohibition.

Claims: CLM-GR-5e6f70b4

State Surveillance CarveoutsAmber

National-security carve-out exists; European Parliament flagged independence/oversight concerns amid the Predator spyware scandal.

Claims: CLM-GR-6f7081c5

Category narrative62 words

The HDPA's landmark €20 million fine against Clearview AI for unlawful biometric facial-recognition processing anchors this module. Genetic-data restrictions exist for insurance purposes. The HDPA has begun scrutinizing AI service providers (DeepSeek EU-representative order). Surveillance oversight has faced European Parliament criticism amid the 'Predator' spyware controversy, and ADM transparency relies on direct GDPR Article 22 application without a distinct national AI-risk-assessment regime.

Sources and claims (6)
  1. ConfirmedIAPPThe HDPA found that Clearview AI's use of facial-recognition profiling techniques to identify and monitor individuals constituted an act of targeting triggering GDPR profiling-related obligations and the strict Article 9 regime for biometric data.
  2. ProbableGovernment Gazette of the Hellenic Republic / HDPAGDPR Article 22 automated-decision-making transparency and explanation rights apply directly in Greece with no distinct national derogation identified in Law 4624/2019.
  3. ProbableOneTrust DataGuidanceThe HDPA required the AI chatbot provider DeepSeek to appoint an EU representative under GDPR Article 27 due to compliance concerns, reflecting emerging HDPA scrutiny of AI service providers.
  4. ConfirmedEuropean Data Protection BoardThe HDPA imposed a €20 million fine on Clearview AI — its largest fine to date — for unlawfully processing biometric facial-recognition data of Greek residents in violation of GDPR Articles 5(1)(a), 6, 9, 14 and 27.
  5. ConfirmedOneTrust DataGuidanceLaw 4624/2019 Article 23 prohibits the processing of genetic data for health and life insurance purposes, forming Greece's principal statutory genetic-data-specific restriction.
  6. ConfirmedOfficial Journal of the European UnionThe HDPA is competent to supervise national and transnational data processing with limited exceptions for national security, and Greek surveillance oversight (including the ADAE communications-security authority) has faced European Parliament scrutiny over the 'Predator' spyware scandal and weakened post-surveillance notification safeguards.

#

Parental-consent threshold is clearly defined and enforced; age-verification, minor-profiling and dependent-adults sub-modules rely solely on general GDPR provisions.

Primary frameworkLaw 4624/2019 Article 21 (digital consent age) + GDPR
Traffic-light rationale — AmberParental-consent threshold is clearly defined and enforced; age-verification, minor-profiling and dependent-adults sub-modules rely solely on general GDPR provisions.

Sub-modules (5)

Age VerificationRed

No dedicated age-verification standard identified beyond the consent-age threshold.

Claims: CLM-GR-708192d6

Minor Profiling BansRed

No distinct national ban beyond general GDPR framework.

Claims: CLM-GR-92a3b4f8

Education SettingsAmber

Ed-tech DSAR fine and disability-services minor-data disclosure fine.

Claims: CLM-GR-a3b4c609, CLM-GR-b4c5d71a

Dependent AdultsRed

No distinct national provisions identified.

Claims: CLM-GR-c5d6e82b

Category narrative44 words

Law 4624/2019 Article 21 fixes the digital consent age at 15, with parental consent required below that age. Enforcement precedent covers education-sector and disability-services mishandling of minors' data. No dedicated age-verification standard, minor-profiling ban, or dependent-adults regime distinct from general GDPR provisions was identified.

Sources and claims (6)
  1. UncertainOneTrust DataGuidanceNo dedicated Greek age-verification statute or technical standard distinct from the Article 21 consent-age threshold was identified in Law 4624/2019 or HDPA guidance reviewed.
  2. ConfirmedIAPPLaw 4624/2019 Article 21 sets the digital age of consent at 15 years; below that age, the consent of a parent or legal guardian is required for a minor's data to be lawfully processed by information society services.
  3. UncertainGovernment Gazette of the Hellenic Republic / HDPANo Greece-specific statutory ban on profiling of minors beyond the general GDPR framework (Recital 38, Article 22) was identified.
  4. ConfirmedOneTrust DataGuidanceThe HDPA fined ed-tech provider IMathisi €4,000 for denying a parent's data-access request concerning their child's data and for failing to cooperate with the Authority.
  5. ConfirmedEuropean Data Protection BoardThe HDPA fined an association for people with Autism Spectrum Disorder for unlawfully disclosing a minor's sensitive medical, therapeutic and social-history data to a third party without parental notification or consent.
  6. UncertainGovernment Gazette of the Hellenic Republic / HDPANo Greece-specific statutory data-protection provisions addressing dependent adults (elderly or mentally incapacitated persons) distinct from the general GDPR framework were identified in Law 4624/2019 or HDPA guidance reviewed.

#

Powers and historical enforcement activity are robust and well evidenced; the recent_developments_180d sub-module could not be populated with a confirmed decision inside the strict 180-day window, and collective-redress mechanisms remain comparatively underdeveloped.

Primary frameworkGDPR Articles 58, 77-84, 83 as supplemented by Law 4624/2019
Traffic-light rationale — AmberPowers and historical enforcement activity are robust and well evidenced; the recent_developments_180d sub-module could not be populated with a confirmed decision inside the strict 180-day window, and collective-redress mechanisms remain comparatively underdeveloped.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

Fines €5,000-€20M; public-sector cap of €10M under Law 4624/2019.

Claims: CLM-GR-d6e7f93c, CLM-GR-e7f8094d

Enforcement Activity IndexGreen

Sustained high-value enforcement 2022-2025.

Claims: CLM-GR-f809a5e

Regulator Funding And CapacityAmber

HDPA self-reported staff/budget figures and characterized resources as insufficient.

Claims: CLM-GR-091b2c6f

Collective Redress And Class ActionsAmber

Lack of specific representative-action provisions.

Claims: CLM-GR-1a2c3d70

Private Right Of ActionGreen

Complaint-driven access via civil-society organisations and direct judicial remedies.

Claims: CLM-GR-2b3d4e81

Recent Developments 180DRed

Most recent confirmed major decision (Vodafone, June 2025) falls outside the strict 180-day window; no Greece-specific decision inside the window was confirmed despite targeted searches.

Claims: CLM-GR-3c4e5f92

Category narrative106 words

The HDPA exercises full GDPR Articles 58/83 corrective and sanctioning powers, with fines ranging from €5,000 to €20 million, and Law 4624/2019 caps public-sector fines at €10 million. Enforcement activity has been sustained and high-value (Clearview AI €20M, Cosmote/OTE €9.25M combined, Ministry of Migration €175,000, Vodafone 2025). Reported HDPA resourcing (39-46 staff, ~€2-2.85M budget as of 2020) was self-assessed by the Authority as insufficient. Collective redress is constrained by an absence of specific representative-action provisions, though civil-society complaints (e.g., Homo Digitalis) function as a de facto access point. No Greece-specific HDPA decision published within the 180 days preceding this run was confirmed in the sources reviewed.

Sources and claims (7)
  1. ConfirmedOneTrust DataGuidanceThe HDPA has issued administrative fines ranging from €5,000 to €20 million for GDPR violations including unlawful processing, transparency violations, non-compliance with access requests and inadequate security measures, exercising the full corrective and sanctioning powers of GDPR Articles 58 and 83.
  2. ConfirmedIAPPLaw 4624/2019 caps administrative fines against public-sector entities at €10,000,000 depending on the severity and duration of the breach, while leaving the GDPR's uncapped sanction regime unchanged for private entities.
  3. ConfirmedIAPPThe HDPA's 2022 fine of €20 million against Clearview AI doubled the Authority's previous record fine of €9.25 million against Greece's largest telecommunications conglomerate, reflecting an escalating enforcement trend.
  4. ConfirmedEuropean Data Protection BoardIn its EDPB Article 97 questionnaire response, the HDPA reported staff levels of 39 (2016), 35 (2017), 33 (2018), 33 (2019) and 46 (2020) employees, with an annual budget rising from approximately €2.07 million in 2016 to €2.85 million in 2019, and characterized its resources as still insufficient.
  5. ProbableIAPPGreek data-protection law analysis notes an absence of specific statutory provisions enabling representation of data subjects by collective associations in judicial remedies against controllers/processors, making collective redress more difficult than under the GDPR's optional Article 80 mechanism.
  6. ConfirmedIAPPCivil nonprofit organizations such as Homo Digitalis may file HDPA complaints on behalf of individual data subjects, as occurred in the Clearview AI case, and judicial remedies may be filed by data subjects before the court of the controller's registered seat or the data subject's residence.
  7. UncertainEuropean Data Protection BoardThe most recent major HDPA enforcement action identified in this research cycle is the June 2025 fine against Vodafone Greece and its processor for a data breach and insufficient security measures; no Greece-specific HDPA decision published within the 180 days preceding this run (i.e., since approximately February 2026) was identified in the sources reviewed.
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Greece
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 67 claim(s), 17 source(s) in the cumulative register.