Data Protection and Privacy 2025

GREECE Law and Practice Contributed by: Natasha Mezini, Lambros Katsiamagkos and Jenny Georgountzou, Psarras, Georgountzou, Gavrilis - GKP Law Firm

5.4 Blocking Statutes There are no “blocking” statutes, meaning there are no Greek laws or statutes that prohibit com - pliance with EU regulations. As already stated in 1.1 Overview of Data and Privacy-Related Laws , EU Regulations are directly applicable in Greece and supersede any provision of national law, including the Constitution. 5.5 Recent Developments Greece closely follows the EU developments in the international transfer of data. Recently, Law 5169/2025 ratified the Protocol amending the Convention for the Protection of Individuals regarding Automatic Processing of Personal Data, also known as Convention 108. The Protocol modernises the Council of Europe Convention, eg, definitions are updated to ensure the uniform application of its terms; its scope is extended to include application in the public and private sectors; the basic principles of pro - portionality in relation to the legitimate purpose pursued, transparency, prior consent or other legitimate bases for processing, adequacy and accuracy of the personal data have been sup - plemented; the rights of the data subjects have been extended. Moreover, the Protocol strength - ens the safeguards for cross-border data trans - fers, requiring the member parties to set stricter evaluation and approval procedures. Finally, it defines the powers of the supervisory authorities, who are responsible for ensuring compliance with the provisions of the Convention and providing co-operation and mutual assistance among the supervisory authorities of the member parties.

sation do not require any notification or prior approval by a government authority. The data controller or data processor must enter the trans - fers in the records of processing activities (Arti - cle 30 of the GDPR), stating at least the recipient and the documentation proving the existence of appropriate safeguards. Such records, including records of transfers, should be made available to the HDPA upon request. 5.3 Data Localisation Requirements The data controller must inform the data subject upon collection of their personal data, among others, about the purpose of the processing, the recipients of the processing, and any trans - fers of the data outside the EU on the basis of an adequacy decision, appropriate safeguards or other mechanisms discussed above under Transfers of Personal Data to a Non-EU Coun - try or International Organisation (Articles 13 and 14 of the GDPR). Given the above, if the information notice does not include the transfer of personal data to a non- EU state or international organisation, the data controller must inform the data subject anew about such intended transfer prior to the actual transfer of personal data. The data controller is not obliged to inform the data subject about the transfer of personal data within the EU. The data controller must enter the transfer in the records of processing activities (Article 30 of the GDPR), stating at least the recipient and the documentation proving the existence of appro - priate safeguards. Apart from the above, there are no data localisa - tion requirements.

161 CHAMBERS.COM

Powered by