Data Protection and Privacy 2025

GREECE Law and Practice Contributed by: Natasha Mezini, Lambros Katsiamagkos and Jenny Georgountzou, Psarras, Georgountzou, Gavrilis - GKP Law Firm

of appropriate organisational and technical means, as automated processing could lead to illegal transfer of personal data and fail - ure to reply appropriately to a data subject request. • The HDPA (decision 35/2023) imposed a fine of EUR50,000 upon a Greek bank for failure to notify a data breach. • The HDPA has occasionally imposed smaller fines amounting to approximately EUR10,000 per incident upon Greek banks for failing to satisfy data subject rights. 1.5 AI Regulation Regulation (EU) 2024/1689, known as the AI Act, establishes harmonised rules on artificial intel - ligence and represents the first comprehensive legal framework for AI worldwide. It covers AI systems’ development, marketing, deployment, and use. In Greece, there have been no recent legislative updates concerning the regulation of artificial intelligence that would affect data pro - tection. Existing data protection laws continue to apply directly to the safeguarding of personal data, even in the context of using AI systems. For example, the HDPA (decision 57/2022) examined the remote procedure for conclud - ing new contracts through a digital onboarding service, in the context of which the data sub - ject/subscriber is electronically identified by processing their biometric data (real-time selfie) on the legal basis of consent. The information provided to subscribers by the data controller contained ambiguities and shortcomings regard - ing the outsourcing of the onboarding service to a third-party data processor and recipient of the biometric data. The Authority reprimanded the telecommunications provider for established violations of Article 5 of the GDPR and instructed it to appropriately amend and supplement the text of the information provided to the data sub -

jects to fully comply with the principle of trans - parency of processing. 1.6 Interplay Between AI and Data Protection Regulations As expressly stated in the preamble of the AI Act, the AI Act does not seek: • to affect the application of existing EU law governing the processing of personal data, including the tasks and powers of the inde - pendent supervisory authorities competent to monitor compliance with those instruments; • to affect the obligations of providers and deployers of AI systems in their role as data controllers or processors stemming from EU or national law on the protection of personal data in so far as the design, the development or the use of AI systems involves the pro - cessing of personal data; and • to affect the rights and guarantees awarded to data subjects by such EU law, including the rights related to solely automated individ - ual decision-making, including profiling. On the contrary, the AI Act should facilitate the effective implementation and exercise of the data subjects’ rights and other remedies guar - anteed under EU law on the protection of per - sonal data. There are no specific laws regarding AI in Greece that relate to or affect the protection of personal data.

2. Privacy Litigation 2.1 General Overview

In 2023, a total of 1,414 complaints were sub - mitted to the HDPA, resulting in 43 issued deci - sions. Specifically, the breakdown of complaints

153 CHAMBERS.COM

Powered by