GREECE Law and Practice Contributed by: Orfeas Mavredakis and Evangelos Katsaras, ALG Manousakis Law Firm
Data location: Specification of the countries or regions where ser - vices are delivered and data are stored, along with an obligation to provide prior notice – and, where required, obtain consent – for any changes. Security and confidentiality: Clauses describing ICT security and confidentiality measures, including resilience and business continu - ity plans, as well as the provider’s obligation to sup - port the financial institution in meeting its regulatory requirements. Incident notification: An obligation for the provider to immediately inform the financial institution of any circumstances that may have an impact on it, and to fully co-operate with both the institution and relevant supervisory authorities. Control: Clear service‑level targets and monitoring procedures, allowing the institution to maintain active oversight and undertake timely corrective actions. Audit: Rights for on‑site inspections by both the financial institution and competent supervisory authorities (and, for critical ICT third‑party providers, by the des - ignated lead supervisor). Exit strategy: Clauses ensuring that, in cases of termination, can - cellation, insolvency, or cessation of activity, data remains accessible and is returned in a usable format, accompanied by transition support and secure dele - tion once the process is complete. Termination options: Defined conditions and notice periods, including the option to terminate the arrangement when requested
by a supervisory authority or when the provider’s risk profile becomes unacceptable. Concentration risks: Requirements for institutions to assess concentration risks and third‑country or jurisdictional risks, particu - larly where local regulations may hinder access or control. Through Law 5193/2025, these obligations become enforceable by the Bank of Greece or the Hellenic Capital Market Commission. Institutions are expected to review existing significant contracts, and authorities may impose corrective measures where necessary. 3.3 Key Operational Resilience Obligations DORA sets out obligations for governance, risk man - agement, incident management, and incident report - ing. Governance (Tone From the Top and Accountability) Financial entities must ensure clear management body accountability for ICT risk. This includes the responsibility to approve and oversee the ICT risk management framework, allocate appropriate roles, resources, and expertise, and ensure directors receive adequate training. Policies and controls must cover all phases of the ICT risk life cycle: identification, protection, detection, response, recovery, and backup/restore, along with periodic review and board-level reporting. ICT Risk Management (End-to-End) Organisations must maintain comprehensive asset and dependency mapping, including business ser - vices, ICT assets, and third‑party dependencies. They must establish and maintain controls for protec - tion, prevention, and detection of ICT risks. Business continuity and disaster recovery (BCP/DRP) plans must be in place, regularly tested, and reviewed for lessons learned.
173 CHAMBERS.COM
Powered by FlippingBook