Doing Business In..._2026

GREECE Law and Practice Contributed by: Anastasia Dritsa, Elisabeth Eleftheriades, Vicky Kriketou, Irene Kyriakides, Ioanna Kyriazi, Victoria Mertikopoulou, Claire Pavlou and Panagiotis Pothos, Kyriakides Georgopoulos Law Firm

8. Data Protection 8.1 Applicable Regulations

which play a key role in interpreting and enforcing the framework. 8.2 Geographical Scope Cross-Border Application of Data Protection Law • Territorial Scope Under the GDPR: The applicability of Greek and EU data protection rules in an inter - national context is primarily governed by the GDPR territorial scope (Article 3). The GDPR applies not only to controllers and processors established in Greece or elsewhere in the EU, but also to non-EU entities where their processing activities relate to the offering of goods or services to individuals in Greece, or the monitoring of behaviour of individu - als within Greece (eg, through tracking technolo - gies or profiling). Accordingly, a foreign company targeting customers in Greece (eg, via a Greek- language website) will be subject to the GDPR. • Supervisory Authority and One-Stop-Shop Mecha - nism: Enforcement is carried out by the HDPA where Greece is the relevant jurisdiction (eg, where data subjects are located or where a local estab - lishment exists), subject to the GDPR’s one-stop- shop mechanism for cross-border processing. 8.3 Role and Authority of the Data Protection Agency Data Protection Authority and Regulatory Enforcement Framework The Hellenic Data Protection Authority Data protection in Greece is enforced primarily by the HDPA, established under Law 2472/1997 and operat - ing within the framework of the GDPR, Law 4624/2019 and Law 3471/2006. The Authority exercises a broad range of powers, including monitoring compliance and issuing guidelines and recommendations. Enforcement activity is largely complaint-driven, although the HDPA also initiates ex-officio investiga - tions in cases of broader public interest. Proceedings before the HDPA follow administrative procedures and typically involve the preparation of a case file, a hear - ing, and the issuance of a reasoned, binding decision after the parties have been heard. Where a breach of data protection law is established, the HDPA exercises its corrective powers, including the imposition of administrative fines. Decisions of the

Sources of Data Protection Law in Greece • System Overview: The Greek data protection framework is based on a combination of constitu - tional provisions, EU law, national legislation, and regulatory guidance. Overall, the system is charac - terised by the primacy of the GDPR, supplemented by national laws and extensive regulatory guid - ance, including sector-specific lex specialis rules. • Constitution: At the constitutional level, the Greek Constitution establishes core safeguards: Article 9A guarantees the protection of personal data and mandates an independent authority, while Article 19 protects the confidentiality of communications. • GDPR and National Implementing Legislation: The primary legal instrument is the General Data Pro - tection Regulation (GDPR), which is directly appli - cable in Greece and establishes the general rules on lawful processing. It is supplemented by Law 4624/2019, which implements the GDPR, trans - poses Directive (EU) 2016/680 and regulates the operation of the Hellenic Data Protection Authority (HDPA). The framework is further complemented by the residual provisions of Law 2472/1997, which had originally transposed Directive 95/46/ EC into the Greek legal order. Notably, the Hellenic Data Protection Authority has clarified, in Opinion 1/2020, that national provisions which conflict with the GDPR, or which lack a valid legal basis under its opening clauses, should not be applied. • Relevant and Sector-Specific Regulation: The framework is complemented by relevant and sector-specific laws, notably: (a) Law 3471/2006 on electronic communications (cookies, direct marketing, soft opt-in and opt- out rules); (b) Law 5002/2022 (confidentiality of communica - tions); (c) Law 5086/2024 and Law 5160/2024 (cyberse - curity); and (d) Law 5169/2025, and Law 4961/2022 (emerging technologies). • Role of Supervisory Authorities: Competent super - visory authorities, such as the HDPA, issue bind - ing decisions, guidelines, and recommendations,

425 CHAMBERS.COM

Powered by