Compliance Node Overview
Greece's Data Protection Law 4624/2019 (Νόμος 4624/2019, published in Government Gazette I/137 of 29 August 2019, 'On Personal Data Protection and Implementation of EU Regulation 2016/679') is Greece's primary national legislation supplementing the EU General Data Protection Regulation (GDPR - Regulation (EU) 2016/679) in Greece. The GDPR is directly applicable Greek law by virtue of Greece's EU membership. Law 4624/2019 provides national derogations, additions, and specifications that the GDPR permits EU member states to adopt and repeals the prior Greek Personal Data Protection Act (Law 2472/1997). Enforcement: the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα - APDPCH, in English: HDPA - Hellenic Data Protection Authority) is Greece's independent data protection supervisory authority. The HDPA is Greece's representative on the European Data Protection Board (EDPB) and participates in the EDPB's one-stop-shop mechanism for cross-border processing. Key Greek national provisions: (1) Age of digital consent: Greece has set the age of consent for information society services at 15 years (GDPR Art. 8 permits member states to set between 13 and 16); data subjects under 15 require parental or guardian consent; (2) Criminal data - Law 4624/2019 provides that processing of personal data relating to criminal convictions and offences by private entities is permitted in limited circumstances specified by law; public authorities may process criminal data under applicable Greek legislation; (3) Employment context - Law 4624/2019 contains specific provisions on processing personal data in employment contexts, including the processing of employee data by employers subject to Greek labour law; (4) Special categories - processing of sensitive personal data (health, biometric, genetic, racial, religious, political, sexual orientation, trade union membership) in Greece is subject to additional safeguards under Law 4624/2019 beyond GDPR's baseline; (5) Public sector - Greek public authorities are subject to Law 4624/2019 provisions on public authority processing, including specific rules for judicial, law enforcement, and intelligence processing; (6) Research and statistics - specific provisions permitting extended processing for scientific research, statistics, and archiving in the public interest. Fines: GDPR administrative fines apply in Greece - up to EUR 20 million or 4% of global annual turnover for the most serious violations. The HDPA has imposed significant GDPR fines across multiple sectors including banking, telecommunications, and insurance. The HDPA is one of the more active EU data protection authorities and has issued landmark enforcement decisions.
Pillar: Cybersecurity · Authority: Hellenic Data Protection Authority (HDPA / APDPCH, Greece) · Version: 1.0.0 · Last updated:
Primary source: https://www.dpa.gr/
SHA-256 integrity: 8d103843dd394909f077ea4704f0686d72dcfbcfee709b8a490d72c61041a5fe
Primary Citations — 6 traced to source
- Law 4624/2019 (Νόμος 4624/2019, Greece) - published Government Gazette I/137 of 29 August 2019; supplements EU GDPR; national derogations: age of digital consent 15 years; criminal data restrictions for private entities; employment data processing provisions; sensitive data additional safeguards; research derogations; repeals Law 2472/1997 (prior Greek data protection law)
- EU GDPR (Regulation (EU) 2016/679) - directly applicable in Greece; fines up to EUR 20 million or 4% of global annual turnover; HDPA is Greece's supervisory authority and EDPB member; 72-hour breach notification to HDPA under Art. 33; DPIA mandatory for high-risk processing (large-scale sensitive data, biometric, systematic monitoring) under Art. 35
+ 4 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access