GREECE Law and Practice Contributed by: Orfeas Mavredakis and Evangelos Katsaras, ALG Manousakis Law Firm
the same time, national supervisors (such as the Bank of Greece) continue to supervise financial entities that rely on those ICT services. Once an ICT provider is designated as critical, the ESAs may exercise the following powers. Information and Access Powers • Request any information relevant to operational resilience. • Access, inspect, and audit ICT systems, premises, and security processes. • Interview staff and request incident reports, test results, or any other relevant documentation. On‑Site Inspections • Conduct planned or unannounced on‑site inspec - tions. • Examine configuration settings, logging practices, security controls, resilience measures, and subcon - tracting arrangements. Oversight Recommendations and Binding Instructions • Require improvements to risk management, inci - dent handling, or resilience testing frameworks. Testing and Validation Requirements • Require participation in threat‑led penetration test - ing (TLPT). • Request evidence of resilience controls, backup capabilities, and incident detection mechanisms. Sanctioning Powers • Supervisory (non‑financial) measures: (c) Suspensions or restrictions of activities (d) Penalties for natural persons or officials • Financial penalties: (a) Recurring penalty payments until compliance is achieved • Issue remediation recommendations. • Impose mandatory corrective actions. (a) Compliance orders (b) Public statements • Fines for violations of oversight requirements (up to 10% of annual turnover or EUR5 million for serious infringements)
Although DORA introduces a central EU‑level super - visory regime for critical third‑party providers (CTPPs) through the ESAs acting as Lead Overseers, national authorities continue to enforce requirements on pro - viders indirectly. This is achieved through mandatory obligations imposed on financial entities – such as contractual clauses, oversight mechanisms, auditing and testing obligations, and exit strategies. National supervisors may also require institutions to modify or terminate outsourcing arrangements if the associated risk is deemed unacceptable. The Bank of Greece conducts supervision via both off‑site monitoring (submitted data reports, incident reporting, information on critical assignments, and testing results) and on‑site audits focused on ICT risk and resilience. Audits typically examine: • governance structures; • policies and procedures; • technical evidence (logs, monitoring data, security controls, test results); and • third‑party risk management practices (assignment registers, risk assessments, SLAs, audit/inspection rights, provider participation in testing, data exit and portability plans). Greek authorities may require a financial entity to miti - gate third‑party risks or, if risks remain unacceptably high, to suspend or terminate a critical outsourcing arrangement. 3.5 International Data Transfers The operational resilience rules for the financial sector in Greece operate alongside European data transfer law and the supervisory requirements that apply to outsourcing in third countries. Although these rules do not impose a general obligation to localise data, in practice financial entities must select providers that do not impede supervision, allow effective control and access, and ensure that international data transfers remain lawful. At the DORA level, the key issue is not a “prohibi - tion” on data transfer but the need for transparency and control. Contracts with ICT providers must clearly specify the locations (regions/countries) where ser - vices are delivered and where data is processed or
175 CHAMBERS.COM
Powered by FlippingBook