>
HomeServicesData ProtectionGreece

Data Protection in Greece

A multinational company establishes a Greek subsidiary and begins processing customer data across its EU network. Within months, a routine vendor audit reveals that the local data processing agreements were drafted without accounting for Greek supervisory authority guidance. exposing the group to enforcement action and reputational risk before the business has even reached full operating capacity.

Data Protection in Greece is governed by the General Data Protection Regulation as directly applied across the EU, supplemented by Greek national legislation that adapts and specifies GDPR provisions for local contexts. The Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Hellenic Data Protection Authority, HDPA) serves as the competent supervisory body and exercises enforcement powers including administrative fines, corrective orders, and temporary processing bans. Compliance obligations apply from the moment personal data is collected or processed on Greek territory, with no grace period for newly established entities.

This page covers the principal legal instruments for data protection compliance in Greece, practical pitfalls that affect international businesses. Cross-border strategy across the EU and Portugal. Additionally, a self-assessment checklist to help you identify where immediate action is required.

The regulatory setting for data protection in Greece

Greece operates within the EU's unified data protection system. The GDPR applies directly as binding law. Greek national legislation – enacted to exercise the member-state discretions permitted under the Regulation – fills important gaps in areas such as the processing of sensitive data, employment-related data, and the powers of the HDPA. Understanding both layers is essential for any international business operating in the Greek market.

The HDPA has demonstrated a consistent willingness to investigate complaints and initiate ex officio proceedings. The Authority publishes guidance on consent mechanisms, data retention, and cross-border transfers. Its decisions bind controllers and processors operating in Greece regardless of where they are established. For a group with its main EU establishment elsewhere, Greece may still be the competent lead authority for processing activities centred in Athens or directed primarily at Greek residents.

Several features of the Greek regulatory environment deserve attention. Greek data protection legislation extends GDPR provisions to cover specific public-sector processing activities, journalistic and academic exemptions, and conditions for processing criminal conviction data. Employment data receives particular attention: Greek labour law and data protection legislation together restrict the scope of lawful employer monitoring, and controllers that import generic group-wide HR policies without local adaptation routinely face compliance gaps.

The consequences of non-compliance are significant. The HDPA can issue fines under the GDPR's two-tier penalty structure. Corrective orders may require a controller to cease or restrict processing within a defined period. Beyond monetary sanctions, reputational damage from a published HDPA decision – which the Authority routinely publicises – can affect client relationships and tender eligibility in regulated sectors. For businesses with an eye on the Greek public procurement market, a data protection violation on record introduces a direct commercial risk.

Key legal instruments and compliance procedures

Effective data protection compliance in Greece rests on a set of core legal instruments. Each instrument has specific content requirements, timelines, and consequences if absent or defective.

Lawful basis assessment and records of processing activities. Every data controller must identify and document a lawful basis for each processing activity. In Greece, as across the EU, the six available bases include consent, contract performance, legal obligation, vital interests, public task, and legitimate interests. The legitimate interests basis requires a documented balancing test. Greek courts and the HDPA apply this test strictly: a generic assertion of commercial interest is not sufficient. Records of processing activities must be maintained in writing – including electronic form – and made available to the HDPA on request. For organisations with fewer than 250 employees, an exemption from this obligation applies in principle, but the conditions are narrow and rarely satisfy groups engaged in any systematic or sensitive processing.

Consent mechanisms. Where a controller relies on consent as the lawful basis, the consent mechanism must meet stringent conditions under Greek-applied GDPR rules. Consent must be freely given, specific, informed, and unambiguous. Pre-ticked boxes and bundled consent – linking data processing consent to service terms – are not valid. The HDPA has specifically criticised cookie consent banners that make rejection harder than acceptance. Controllers must maintain records demonstrating that valid consent was obtained and must implement a withdrawal mechanism that is as easy to use as the original consent request. Many international businesses import consent forms developed for other markets without adapting them to HDPA guidance, creating a documented compliance failure from day one.

Data processing agreements. When a controller engages a data processor, Greek-applied data protection legislation requires a binding written contract specifying the processor's obligations. This requirement applies to cloud service providers, payroll processors, marketing platforms, and any other external party that handles personal data on the controller's behalf. The contract must include specific mandatory provisions: subject matter and duration of processing, nature and purpose, type of data, categories of data subjects, and the controller's rights and obligations. A contract that omits any mandatory element exposes both the controller and the processor to HDPA enforcement, even if actual harm to data subjects is minimal.

Data Protection Officer appointment. Certain controllers and processors must appoint a Υπεύθυνος Προστασίας Δεδομένων (Data Protection Officer, DPO). The obligation arises in three situations: public authorities, controllers whose core activities require large-scale systematic monitoring of individuals, and controllers whose core activities involve large-scale processing of special-category or criminal offence data. For international businesses, the DPO obligation often arises at group level but must be operationalised locally. The DPO must have sufficient expert knowledge, resources, and organisational independence. Appointing a DPO who lacks genuine autonomy. for example. One who reports to the same manager responsible for the processing decisions. is a pattern the HDPA has treated as a substantive non-compliance rather than a technical defect.

Data Protection Impact Assessments. Processing likely to result in a high risk to individuals requires a prior Data Protection Impact Assessment (DPIA). The HDPA has published a list of processing types that presumptively require a DPIA in Greece. This list includes systematic profiling, large-scale processing of sensitive data, and processing using new technologies where the risk profile is not yet established. A DPIA must identify the risks, assess necessity and proportionality, and set out mitigating measures. Where residual risk remains high after mitigation, prior consultation with the HDPA is mandatory before processing commences. Commencing high-risk processing without a completed DPIA – or without consulting the HDPA where required – constitutes a standalone infringement.

For a tailored strategy on data protection compliance procedures in Greece, reach out to info@ferrazwhitmore.com.

Practical pitfalls for international businesses in Greece

International businesses entering Greece bring compliance programmes developed in other legal systems. Several recurring gaps surface in practice.

Failure to adapt group-wide policies to Greek requirements. A common mistake is treating GDPR compliance as a uniform EU exercise. Greek national legislation introduces derogations and additions that are not replicated in every member state. Employment data processing in Greece is subject to conditions that differ materially from, for example, German or Dutch national rules. A group that deploys a single-template compliance programme without local law review frequently violates Greek-specific obligations while maintaining technically sound GDPR documentation.

Underestimating the HDPA's investigation process. When the HDPA opens an investigation. whether on complaint or ex officio – it typically requests extensive written submissions within a short response window of around 15 to 30 days. Controllers that lack well-organised records of processing activities, consent records, and contractual documentation face the dual problem of defending a potential infringement while simultaneously trying to reconstruct compliance evidence under time pressure. The HDPA has treated poor record-keeping as an aggravating factor in penalty assessments.

Data breach notification delays. Greek-applied data protection rules require notification of a personal data breach to the HDPA within 72 hours of the controller becoming aware. There. The breach is likely to result in a risk to individuals. Many international businesses apply internal escalation procedures designed for their home jurisdiction – often longer than 72 hours – before triggering a Greek notification. The 72-hour clock runs from awareness at any level of the organisation with responsibility for data governance, not from formal escalation to group headquarters. A delayed notification is itself a reportable infringement, separate from the underlying breach.

Cross-border data transfer mechanisms. Controllers that transfer personal data outside the European Economic Area must implement an adequate transfer mechanism. Standard Contractual Clauses remain the most widely used instrument after the invalidation of previous frameworks. In Greece, as across the EU, controllers must conduct a Transfer Impact Assessment to verify that the destination country's legal system does not undermine the protections in the standard clauses. Many controllers skip this assessment or perform it at group level without verifying that the local Greek processing is covered. The HDPA has the authority to suspend or prohibit a transfer where the assessment is absent or inadequate.

Businesses operating in the technology sector in Greece should also review their obligations under AI and algorithmic processing rules. Our analysis of AI law in Greece addresses the interaction between data protection obligations and AI regulatory requirements in detail.

Cross-border strategy: Greece, Portugal, and EU dimensions

For international groups with a presence in multiple EU member states, the one-stop-shop mechanism under the GDPR creates both opportunities and complications. A controller with its main EU establishment in one member state – for example, Portugal – may designate the Portuguese supervisory authority as its lead authority for cross-border processing. This means that complaints originating in Greece may, in principle, be handled through the Portuguese supervisory body. The Comissão Nacional de Proteção de Dados (National Data Protection Commission, CNPD), under a cooperation procedure with the HDPA.

In practice, this mechanism does not eliminate direct Greek regulatory exposure. The HDPA retains jurisdiction over locally focused processing activities and over urgent enforcement measures. A business that processes Greek residents' data through a purely Greek-facing operation. a retail website, a local HR system. A customer service platform. cannot rely on the one-stop-shop mechanism to route all regulatory contact away from Athens. The distinction between cross-border processing and locally focused processing requires careful analysis and is frequently misunderstood.

For groups using Portugal as an EU gateway, aligning data protection programmes across both jurisdictions is commercially efficient. Portuguese and Greek national data protection legislation differ in several respects – particularly in employment data processing and public-sector exemptions – but the core documentation requirements are consistent. A group that invests in a robust cross-EU compliance programme, verified for both Portuguese and Greek national law derogations, can achieve cohesive regulatory standing across both markets. Our data protection practice in Portugal addresses the Portuguese dimension in full.

Transfer strategies also benefit from cross-border planning. Groups that route data between Greece and non-EEA entities through Portuguese holding structures must ensure that the transfer mechanism covers each step of the data flow. A Transfer Impact Assessment completed for a Portugal-to-third-country transfer does not automatically cover a Greece-to-Portugal leg where the Greek entity acts as a separate data controller.

The EU's developing regulatory environment adds further complexity. The ePrivacy Regulation, once finalised, will impose specific rules on electronic communications data that will interact with and in some areas supersede GDPR provisions for online channels. Greek businesses operating in telecommunications, digital marketing, and connected services should monitor this development and begin assessing the implementation gap between current cookie consent practices and the expected ePrivacy standard.

To discuss how data protection obligations apply to your cross-border operations in Greece and the EU, contact us at info@ferrazwhitmore.com.

Self-assessment checklist for data protection compliance in Greece

Data protection compliance in Greece is applicable and immediately relevant to your business if any of the following conditions are met:

  • Your organisation processes personal data of individuals located in Greece, regardless of where you are established.
  • You operate a Greek-registered entity – including a branch or representative office – that collects or handles personal data.
  • You process sensitive categories of data, including health, biometric, or criminal record data, in connection with Greek customers or employees.
  • You engage Greek-established processors, cloud providers, or marketing platforms under data processing agreements.
  • You transfer personal data collected in Greece to non-EEA countries or to group entities outside the European Economic Area.

Before initiating or reviewing your data protection programme in Greece, verify the following critical items:

  • Lawful basis documentation: every active processing activity has a documented, accurate lawful basis recorded in your processing register.
  • Consent mechanisms: all consent-based processing uses compliant, separately obtained, freely revocable consent with functioning withdrawal tools.
  • Data processing agreements: every third-party processor engaged in Greece is covered by a written agreement meeting all mandatory content requirements under Greek-applied data protection legislation.
  • DPO assessment: you have determined whether a DPO appointment is legally required and, if so, have appointed a sufficiently qualified and operationally independent officer.
  • DPIA register: you have identified all processing activities that require a DPIA and completed those assessments before or as processing commences.
  • Breach response procedures: your incident response protocol includes a 72-hour HDPA notification path with a clearly designated notification owner.
  • Transfer impact assessments: all transfers of Greek personal data outside the EEA are covered by a current, documented Transfer Impact Assessment and an adequate transfer mechanism.

A detailed guide to incorporating a legal entity in Greece – a prerequisite step for many data controllers establishing local presence – is available in our guide to company formation in Greece.

Frequently asked questions

How long does it take to bring a Greek operation into full GDPR and national data protection compliance?
For a business starting from a documented baseline, a structured compliance programme covering records of processing, lawful basis mapping, consent mechanisms, and data processing agreements typically takes between six and twelve weeks. Where a DPIA is required and HDPA prior consultation becomes necessary. The timeline extends: the HDPA has up to eight weeks to respond to a prior consultation request, with a possible extension of a further six weeks. Early engagement with a lawyer in Greece specialising in data protection significantly reduces the time spent on iterative document revision.
Is it true that a small company with fewer than 250 employees does not need to maintain records of processing activities in Greece?
This is a common misconception. The exemption for organisations with fewer than 250 employees is extremely narrow. It does not apply where the processing is likely to result in a risk to individuals' rights and freedoms, where the processing is not occasional, or where it involves special-category data or criminal conviction data. In practice, the overwhelming majority of businesses – including small ones – carry out at least some processing that falls outside the exemption. Relying on the exemption without a formal assessment is a documented compliance risk.
What are the cost implications of HDPA enforcement proceedings in Greece?
Engaging a law firm in Greece for HDPA enforcement defence involves legal fees that vary with the complexity and volume of the matter. The HDPA's investigative process can span several months. Administrative fines under the GDPR's two-tier system can reach significant amounts depending on the nature of the infringement, the controller's turnover, and mitigating or aggravating factors including cooperation and remediation steps taken. Beyond fines, corrective orders – such as a temporary ban on processing – can interrupt business operations directly. Early investment in compliance is measurably less costly than reactive enforcement defence.

About Ferraz & Whitmore

Ferraz & Whitmore is an international law firm based in Lisbon, advising business clients across 46 jurisdictions on data protection, technology law, and cross-border regulatory matters. Our data protection practice covers the full lifecycle of compliance – from initial gap analysis and records of processing through to HDPA representation, breach response, and cross-border transfer structuring. As an international law firm with deep experience in both Portuguese civil law and English common law traditions. We assist controllers and processors operating across Greece, Portugal. Additionally, the wider EU in building consistent, enforceable data protection programmes. Our team includes practitioners with experience before supervisory authorities in multiple EU member states, and we participate in cross-border practice groups focused on data protection and technology regulation. The firm's 15 practice areas and Lisbon base provide direct access to EU and EEA regulatory systems, while our common law expertise supports enforcement and dispute resolution strategies in English-speaking jurisdictions. Engaging a lawyer in Greece with genuine cross-border experience is essential when data flows span multiple legal systems – and that is precisely the service we provide. To receive an expert assessment of your data protection situation in Greece, contact us at info@ferrazwhitmore.com.

Isabel Carvalho Legal Analyst, Real Estate & Mobility

Isabel Carvalho leads our Southern European and Latin American desks. She advises foreign individuals and family offices on Portuguese real estate acquisitions, the Golden Visa programme and family relocation. Isabel qualified at the Lisbon Bar and the Madrid Bar, and worked for four years at a leading Madrid-based real estate firm before joining Ferraz & Whitmore. She is the lead author of our Iberian and Latin American real estate, immigration and employment guides.

Disclaimer: This publication is provided for informational purposes only and does not constitute legal advice. The information herein should not be relied upon as a substitute for professional legal counsel tailored to your specific circumstances. Ferraz & Whitmore assumes no liability for actions taken or not taken based on the contents of this material. For advice regarding your particular situation, please contact info@ferrazwhitmore.com.