GREECE Law and Practice Contributed by: Orfeas Mavredakis and Evangelos Katsaras, ALG Manousakis Law Firm
organisational measures” that are proportionate to the level of risk. In practical terms, this requires a risk- based approach: the more sensitive or critical the data, the stronger the expected safeguards. Although the GDPR does not prescribe specific security con - trols, demonstrating due diligence is often supported through recognised standards – such as ISO 27001 – though these are not legally mandatory. Alongside this, the GDPR embeds the principle of privacy by design and by default. This means that systems and processes handling personal data must be designed from the outset to incorporate secure defaults. In prac - tice, any application or platform operating in Greece must collect only what is necessary, avoid exposing data through default settings, enforce role-based iso - lation, and integrate risk-reducing techniques wher - ever feasible. In cases of personal data breaches, clear notification rules apply. Notification to the Hellenic Data Protec - tion Authority (HDPA) must be made “without undue delay and, where feasible, within 72 hours” whenever the breach is likely to pose a risk to the rights and free - doms of individuals. The notification should include, in a practical and well-documented manner: • the nature of the breach; • the categories and approximate number of indi - viduals and records affected; • the potential consequences for the individuals; • the measures taken or planned to address and mitigate the breach; and • the contact details of the controller, where required. Notification to affected individuals is required only when the breach is likely to result in a high risk to their rights and freedoms, unless standard excep - tions apply – for example, when individual notification would involve a disproportionate effort. This commu - nication must be written in clear, accessible language and should focus on practical steps individuals can take to protect themselves, without unnecessary tech - nical detail. 6.2 Cybersecurity and AI In the Greek legal system, there is no standalone national “AI law” that horizontally regulates the securi - ty of AI systems. The primary framework is Regulation
(EU) 2024/1689 (the EU AI Act), published on 12 July 2024 and being implemented gradually. The main date of application is 2 August 2026, although some provi - sions take effect earlier (eg, from 2 February 2025). At the core of the AI Act, cybersecurity obligations apply to high-risk AI systems, alongside requirements relating to governance, monitoring, transparency, and the reporting of serious incidents. For high-risk AI systems, the AI Act requires provid - ers or manufacturers to design and develop systems with an appropriate level of accuracy, robustness, and cybersecurity. In particular, they must ensure: • protection against adversarial inputs; • prevention of data poisoning; • model and parameter integrity checks; and • secure update and change-management mecha - nisms to prevent unauthorised “hidden” modifica - tions. A second layer concerns the security of the AI supply chain. Many AI systems incorporate pre-trained mod - els, third-party libraries, and other external compo - nents. Regulatory expectations therefore emphasise documentation, traceability, and controls that mitigate the risks of backdoors, vulnerabilities, dependencies, and supply-chain attacks. This resembles a secure development life cycle, but adapted to the specific characteristics of machine learning (ML). Furthermore, the AI Act requires notification of serious incidents to competent authorities. For high-risk sys - tems, such reports must generally be submitted within 15 days of the provider or user (depending on the scenario) becoming aware of the incident. This may overlap with other regulatory reporting frameworks, meaning organisations need an operationally unified incident-management process capable of address - ing multiple reporting obligations within the correct timeframes. In practice, compliance in Greece will be multi-lay - ered, because the AI Act does not replace general cybersecurity or data-protection frameworks – it com - plements them.
180 CHAMBERS.COM
Powered by FlippingBook