Cyprus
Part of the European Union, so bloc-wide rules apply here too. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Cyprus — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
For most businesses Cyprus works like a normal European country. Data can leave, as long as you use one of the standard European transfer tools. Two things make Cyprus stricter than its neighbours. If you move sensitive data such as health records out of Europe, you must tell the privacy regulator first. And breaking the privacy law in Cyprus is a crime, not just a fine.
Data governance in Cyprus
The eight things that decide how you handle data about people in Cyprus. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. You may have no office anywhere in Europe. If you sell to people in Cyprus, or watch what they do online, the European privacy rules still apply to you. The Cypriot regulator can act against you. There is no minimum size or turnover that gets you out. A company with no European base must name a written representative inside Europe. Cypriot law adds its own duties on top for anyone using data here.
- What you have to do here:
- Appoint a representative
The European General Data Protection Regulation applies directly in Cyprus under its Article 3. No Cypriot law is needed to extend it. Law 125(I)/2018 supplies the national exceptions, the rules for the regulator's office, and the criminal offences. It was published in the Official Gazette on 31 July 2018 and amended by Law 26(I)/2022. Law 44(I)/2019, published 27 March 2019, brings the Law Enforcement Directive into Cypriot law. It names the Police, the Customs Department, the anti-money-laundering unit MOKAS and the Tax Department as competent authorities. The duty to name a representative inside the European Union comes from Article 27 of the Regulation, not from Cyprus. Cyprus has no separate requirement for a local representative in Cyprus, checked 18 August 2026.
Sources
- Official sourceOffice of the Commissioner for Personal Data ProtectionLaw 125(I)/2018 — Law providing for the Protection of Natural Persons with regard to the Processing of Personal Data and for the Free Movement of such Data (official English translation)
gov.cy
Link checked 18 August 2026
- Official sourceOffice of the Commissioner for Personal Data ProtectionLaw 125(I)/2018 — legislation page, confirming publication in the Official Gazette on 31 July 2018 and amendment by Law 26(I)/2022
gov.cy
Link checked 18 August 2026
- Official sourceOffice of the Commissioner for Personal Data ProtectionSpecial legislation in the law-enforcement field — Law 44(I)/2019, published 27 March 2019, naming the Police, Customs, the anti-money-laundering unit MOKAS and the Tax Department as competent authorities
gov.cy
Link checked 18 August 2026
- Official sourceEUR-LexRegulation (EU) 2016/679 — General Data Protection Regulation, consolidated text
eur-lex.europa.eu
Link checked 18 August 2026
Where the data is allowed to live
Yes, in general, with paperwork. Ordinary personal data leaves Cyprus on the same European terms as anywhere else in the bloc. But three Cypriot rules override that. Sensitive data going outside Europe must be reported to the regulator before it moves. Online betting operators must keep a mirror copy on a server inside Cyprus. And insurers cannot use genetic or fingerprint data at all for health or life cover.
- What you have to do here:
- Keep the data in the country
Industry by industry, checked 18 August 2026: - ALL INDUSTRIES, sensitive data: conditions apply, and the regulator can step in. Sections 17 and 18 of Law 125(I)/2018 apply. If the transfer rests on Article 46 safeguards or on binding corporate rules, you must tell the Commissioner first. If it rests on an Article 49 exception, you must do a risk assessment and consult her first. In both cases she may set explicit limits for important reasons of public interest. Ignoring those limits is a crime. - ONLINE BETTING: you must keep a copy in Cyprus. Class B licensees, the online ones, must install a backup server inside Cyprus connected in parallel to the main server. Class A licensees, the shops, must install and keep both their main and backup servers in the Republic. - INSURANCE: banned outright, in one narrow area. Using genetic and biometric data for health and life insurance is prohibited. So the transfer question never arises for that data. - BANKING, PAYMENTS, SECURITIES: we found no Cypriot rule requiring data to stay in the country. The Digital Operational Resilience Act has applied to financial firms since 17 January 2025 and is the governing set of rules. The Cyprus Securities and Exchange Commission handles technology resilience under a dedicated Digital Resilience heading, not under any storage-location rule. - HEALTH: we found no rule requiring data to stay in the country. The Commissioner's own 2024 opinion let a private hospital give a United States cloud provider remote access to patient records. That was under the EU-US Data Privacy Framework, and it needed a proper supplier contract. - TELECOMS: we found no rule requiring data to stay in the country in the electronic communications privacy law, Law 112(I)/2004. - GOVERNMENT, EDUCATION, MAPPING, DEFENCE: we found no rule on a Cypriot government website. See the unconfirmed list. Regulation (EU) 2018/1807 separately bars Cyprus from making non-personal data stay in the country, except on public security grounds.
Sources
- Official sourceOffice of the Commissioner for Personal Data ProtectionLaw 125(I)/2018 — Law providing for the Protection of Natural Persons with regard to the Processing of Personal Data and for the Free Movement of such Data (official English translation)
gov.cy
Link checked 18 August 2026
- Official sourceNational Betting AuthorityThe Betting Law of 2019, Law 37(I)/2019 (official English text), articles 32(3), 53, 56 and 72-73
nba.gov.cy
Link checked 18 August 2026
- Official sourceNational Betting AuthorityDirective 03.2020 — data and information on the installation of a backup server for Class B licensed bookmakers
nba.gov.cy
Link checked 18 August 2026
- Official sourceOffice of the Commissioner for Personal Data ProtectionAnnual Report 2024 of the Commissioner for Personal Data Protection — 531 complaints, 94 breach notifications, 88 decisions, 21 fines totalling EUR 133,900
gov.cy
Link checked 18 August 2026
- Official sourceCyprus Securities and Exchange CommissionCyprus Securities and Exchange Commission — circulars index, which routes technology-resilience matters to a dedicated Digital Resilience (DORA) heading rather than to any Cypriot storage-location rule
cysec.gov.cy
Link checked 18 August 2026
- Official sourceEUR-LexRegulation (EU) 2018/1807 — free flow of non-personal data; bans member-state localisation except on public-security grounds
eur-lex.europa.eu
Link checked 18 August 2026
What to do: Check your own industry against the restricted list before you pick a hosting region.
Sending data out of the country
Cyprus uses an approved-destination list. You can send data to a country the European Commission has approved. Or you sign the European standard contract. Or you use approved group-wide rules. Cyprus adds one step of its own. If the data is sensitive, tell the regulator before it goes. If you rely on a narrow exception rather than a contract, do a written risk assessment and consult her first.
- What you have to do here:
- Put a transfer safeguard in place · Assess high-risk projects
- Ways to send data out:
- Official 'this country is safe' decision · Standard contract clauses · Approved group rules
The approved list is full and current. It covers Andorra, Argentina, Brazil, Canada for commercial bodies, the Faroe Islands, Guernsey and the Isle of Man. It also covers Israel, Japan, Jersey, New Zealand, South Korea, Switzerland, the United Kingdom, Uruguay and the European Patent Organisation. It also covers the United States for organisations self-certified under the EU-US Data Privacy Framework. The 2021 Standard Contractual Clauses are still the set to use. Sections 17 and 18 of Law 125(I)/2018 are the Cypriot addition. They apply only to special categories of personal data. That means health, genetic and biometric data, racial or ethnic origin, political opinions, religious beliefs, trade union membership, sex life and sexual orientation. Section 17 requires you to tell the Commissioner about the intended transfer before the data moves. Section 18 requires an impact assessment plus consultation with her first. The assessment must contain the information listed in Article 35(7), plus a description of your security measures. The Commissioner can set explicit limits at any time. That power needs no consultation and no new law. Her 2024 annual report shows her giving a reasoned opinion on exactly this kind of question. It concerned a private hospital using a United States cloud provider. So the power does get used.
Sources
- Official sourceOffice of the Commissioner for Personal Data ProtectionLaw 125(I)/2018 — Law providing for the Protection of Natural Persons with regard to the Processing of Personal Data and for the Free Movement of such Data (official English translation)
gov.cy
Link checked 18 August 2026
- Official sourceOffice of the Commissioner for Personal Data ProtectionAnnual Report 2024 of the Commissioner for Personal Data Protection — 531 complaints, 94 breach notifications, 88 decisions, 21 fines totalling EUR 133,900
gov.cy
Link checked 18 August 2026
- Official sourceEuropean CommissionAdequacy decisions — the current approved-destination list
commission.europa.eu
Link checked 18 August 2026
- Official sourceEUR-LexCommission Implementing Decision (EU) 2021/914 — Standard Contractual Clauses
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceEuropean Data Protection BoardEuropean Data Protection Board — FAQ for European businesses on the EU-US Data Privacy Framework, cited by the Cypriot Commissioner in her 2024 opinion
edpb.europa.eu
Link checked 18 August 2026
What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.
The regulator, and whether it actually acts
The Commissioner for Personal Data Protection, and she is working. In 2024 her office took 531 complaints and 94 breach reports. It issued 88 decisions and fined in 21 of them. The fines totalled about 133,900 euros (roughly 146,000 US dollars). The biggest single penalty was 46,500 euros, against the state health services organisation. The current Commissioner is Maria Christofidou. A separate Digital Security Authority handles cyber incidents and is also active.
Fines are small by European standards, but the volume is real. The office publishes decisions in batches. The most recent published batch covers January to April 2025. The Council of Ministers appoints the Commissioner for a renewable six-year term. She must hold the qualifications of a Supreme Court judge. The office changed hands during the period covered here. Irini Loizidou Nicolaidou signed the 2024 annual report and served as Deputy Chair of the European Data Protection Board. The office's own management page names Maria Christofidou as Commissioner as at 18 August 2026. Announcements from January 2026 onwards are issued in her name. The Digital Security Authority enforces the network security law. It is an independent agency supervised by the Commissioner of Communications. It is staffed and visibly operating. It ran a chief information security officer training programme in August 2026. It took part in European cybersecurity exercises in June 2026. But its own public NIS page still describes the categories of operator used before 2025. So its published guidance is behind its own law. The National Betting Authority is operational and issues binding directives. It holds ISO 27001 certification and keeps a live register of licensees.
Sources
- Official sourceOffice of the Commissioner for Personal Data ProtectionAnnual Report 2024 of the Commissioner for Personal Data Protection — 531 complaints, 94 breach notifications, 88 decisions, 21 fines totalling EUR 133,900
gov.cy
Link checked 18 August 2026
- Official sourceOffice of the Commissioner for Personal Data ProtectionOffice of the Commissioner for Personal Data Protection — 'Management' page naming Maria Christofidou as Commissioner
gov.cy
Link checked 18 August 2026
- Official sourceOffice of the Commissioner for Personal Data ProtectionOffice of the Commissioner for Personal Data Protection — official site, news items running to July 2026
gov.cy
Link checked 18 August 2026
- Official sourceDigital Security AuthorityDigital Security Authority — official site, activity announcements running to August 2026
dsa.cy
Link checked 18 August 2026
- Official sourceDigital Security AuthorityDigital Security Authority — NIS Directive implementation page, still describing the older operator categories
dsa.cy
Link checked 18 August 2026
- Official sourceNational Betting AuthorityNational Betting Authority — list of directives in force, including Directive 03.2020 on the backup server and Directive 13.2020 on books and records
nba.gov.cy
Link checked 18 August 2026
How long you must keep it — and when to delete it
There is no single national rule. The European maximum applies. Delete personal data once you no longer need it for the purpose you collected it for. Minimum periods come from industry law. Betting operators must keep betting slips and related documents for five years. After that they still cannot destroy them without the regulator's permission. Where a minimum and a maximum clash, the specific legal duty to keep the data wins. That only covers the data the duty actually applies to.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period
Cyprus has no general legal keeping schedule, and Law 125(I)/2018 sets none. Article 53 of the Betting Law of 2019 sets a five-year minimum for betting slips. It covers any other document about the supply of betting services too. It adds a second lock that most keeping schedules miss. You need the National Betting Authority's approval before you destroy them. Books and records under that law may be kept electronically only with the Authority's prior approval. Under the network security law, essential and important entities must file a final incident report within one month. For an incident that is still running, they must file progress reports every fifteen days. That implies keeping incident evidence at least that long. Cyprus also has tax and company law minimum periods. We could not confirm their length or their storage location against a Cypriot government source. See the unconfirmed list.
Sources
- Official sourceNational Betting AuthorityThe Betting Law of 2019, Law 37(I)/2019 (official English text), articles 32(3), 53, 56 and 72-73
nba.gov.cy
Link checked 18 August 2026
- Official sourceDigital Security AuthoritySecurity of Networks and Information Systems Laws of 2020 and 2025, Law 89(I)/2020 consolidated with Law 60(I)/2025 (official English text), articles 35B, 43 and 44
dsa.cy
Link checked 18 August 2026
- Official sourceOffice of the Commissioner for Personal Data ProtectionLaw 125(I)/2018 — Law providing for the Protection of Natural Persons with regard to the Processing of Personal Data and for the Free Movement of such Data (official English translation)
gov.cy
Link checked 18 August 2026
- Official sourceEUR-LexRegulation (EU) 2016/679 — General Data Protection Regulation, consolidated text
eur-lex.europa.eu
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
Not fully verified — see “What we're not sure about” below.If something goes wrong
Three deadlines apply, and you should start with the shortest. If you run an essential or important service, you have six hours to send a first warning to the Digital Security Authority. That is one of the tightest deadlines in Europe. It is far shorter than the 24 hours the European directive asked for. A full report follows within 72 hours, and a final one within a month. Separately, a personal data breach goes to the privacy regulator within 72 hours. You must also tell the affected people if the risk to them is high.
- What you have to do here:
- Report cyber incidents · Report breaches to the regulator · Tell affected people
The six-hour deadline comes from Article 35B(4)(a) of the Security of Networks and Information Systems Laws of 2020 and 2025. Trust service providers get 24 hours instead. The 72-hour report must include a first assessment of how serious the incident is, plus any indicators of compromise. The Authority is meant to reply within 24 hours of the early warning. A final report is due within one month. While an incident is still running, you file progress reports every fifteen days. The privacy deadline is the European 72 hours to the Commissioner. You must also tell the affected people where the risk is high. In Cyprus, failing to report is not just a fine. It is a crime under section 33 of Law 125(I)/2018. Failing to report a severe cyber incident is a separate crime, carrying up to two years in prison. The overlap is the trap. A ransomware attack on a Cypriot hospital or bank starts all three deadlines at once. The six-hour one runs out before most incident response teams have worked out what happened.
Sources
- Official sourceDigital Security AuthoritySecurity of Networks and Information Systems Laws of 2020 and 2025, Law 89(I)/2020 consolidated with Law 60(I)/2025 (official English text), articles 35B, 43 and 44
dsa.cy
“without undue delay and in any event within six (6) hours of becoming aware of the significant incident, a warning, which, where applicable, shall indicate whether the significant incident is suspected of being caused by unlawful or malicious acts or could have a cross-border impact”
Link checked 18 August 2026
- Official sourceDigital Security AuthorityDigital Security Authority — Laws page publishing the consolidated NIS2 law
dsa.cy
Link checked 18 August 2026
- Official sourceOffice of the Commissioner for Personal Data ProtectionLaw 125(I)/2018 — Law providing for the Protection of Natural Persons with regard to the Processing of Personal Data and for the Free Movement of such Data (official English translation)
gov.cy
Link checked 18 August 2026
- Official sourceOffice of the Commissioner for Personal Data ProtectionAnnual Report 2024 of the Commissioner for Personal Data Protection — 531 complaints, 94 breach notifications, 88 decisions, 21 fines totalling EUR 133,900
gov.cy
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
Five things are not in the summary. (1) Breaking the privacy law in Cyprus is a crime. You face up to three years in prison, or five where national security is involved. The law puts the blame on the company's most senior executive personally. (2) A child is anyone under 14 here, not 16 as in some neighbouring countries. (3) Insurers may not use genetic or fingerprint-type data at all for health or life cover. (4) Sensitive data leaving Europe must be reported to the regulator first. (5) The cyber warning deadline is six hours, not 24.
- What you have to do here:
- Get a parent's consent for children · Put a transfer safeguard in place · Report cyber incidents · Keep records of how you use data
- What it costs if you get it wrong:
- Criminal liability
(1) Section 33 of Law 125(I)/2018 makes fourteen kinds of conduct crimes. These include failing to keep a record of your data activities, failing to report a breach, and obstructing the data protection officer. They also include sending data abroad in breach of Chapter V, or in breach of limits the Commissioner has set. The penalty is up to three years in prison, or a fine of up to 30,000 euros (about 33,000 US dollars), or both. It rises to five years or 50,000 euros (about 54,000 US dollars) where the offence damages the interests of the Republic or compromises national security. The remaining offences carry up to one year or 10,000 euros (about 11,000 US dollars). Section 33(5) is the sting. Where a company decides how data is used, the legal responsibility sits with the person named as the top executive of the business. So getting this wrong exposes the chief executive personally, not just the company budget. (2) Section 8 sets the age of digital consent at 14. A service aimed at 12 and 13 year olds that relies on the child's own consent elsewhere in Europe will be unlawful in Cyprus. (3) Section 9(1) is a flat ban, not a consent rule. Genetic and biometric data may not be used for health and life insurance purposes. Section 9(2) adds that any further use of such data needs separate fresh consent. (4) Sections 17 and 18, described above. Note this catches ordinary company setups. It covers a human resources system holding sickness records. It also covers a customer database with health flags, copied to a data centre outside Europe. (5) The six-hour warning under the network security law. (6) A smaller one. Administrative fines on public authorities are capped at 200,000 euros (about 217,000 US dollars) where the activity is not for profit. That badly limits the regulator's leverage over Cypriot ministries and state bodies.
Sources
- Official sourceOffice of the Commissioner for Personal Data ProtectionLaw 125(I)/2018 — Law providing for the Protection of Natural Persons with regard to the Processing of Personal Data and for the Free Movement of such Data (official English translation)
gov.cy
“The processing of genetic and biometric data for purposes of health and life insurance is prohibited.”
Link checked 18 August 2026
- Official sourceDigital Security AuthoritySecurity of Networks and Information Systems Laws of 2020 and 2025, Law 89(I)/2020 consolidated with Law 60(I)/2025 (official English text), articles 35B, 43 and 44
dsa.cy
Link checked 18 August 2026
- Official sourceOffice of the Commissioner for Personal Data ProtectionLaw 125(I)/2018 — legislation page, confirming publication in the Official Gazette on 31 July 2018 and amendment by Law 26(I)/2022
gov.cy
Link checked 18 August 2026
What's changing next
One European date matters most. From 12 January 2027 cloud providers must let customers move away with no exit or switching fees. Cyprus is also still bedding in its newest laws. The digital services law passed in 2025. The artificial intelligence rules are handled by the same privacy regulator, who now has three jobs instead of one. Also watch three powers the government can use with no warning.
- What you have to do here:
- Make switching cloud provider possible
Coming in the next twelve months: - 12 January 2027: the European Data Act requires no charge for switching cloud provider and for moving data out. This is a deadline for renegotiating contracts, not for filing anything. - The Commissioner has taken on supervision under the Artificial Intelligence Act. She has also taken on Law 122(I)/2025, which implements the Digital Services Act. That is on top of privacy. Her own 2024 report says the office needs more staff to do this. Expect slower handling times rather than new rules. - The network security law expects the Digital Security Authority to merge with the Office of the Commissioner of Electronic Communications. That will trigger changes to the Authority's structure when it happens. No date is set. POWERS ALREADY HELD, USABLE WITH NO CONSULTATION: 1. The Commissioner may set explicit limits on any transfer of sensitive data out of Europe, for important reasons of public interest. That comes from sections 17(2) and 18(3) of Law 125(I)/2018. She has not published such an order. But the power needs no new law, and breaking a limit is a crime. 2. Article 8 of Law 60(I)/2025 has not started yet. It starts on a date the Council of Ministers sets by notice in the Official Gazette. That is why we record the network security law as only partly in force. 3. The National Betting Authority may change the backup server specification at any time by issuing a new directive. That includes the maximum lag allowed between the main server and the Cypriot mirror. At European level the EU-US Data Privacy Framework is still valid. But it is under appeal at the Court of Justice. The European Data Protection Board queried it in a letter to the Commission on 31 July 2026. If it is your only route, you carry that risk. The hospital in the Commissioner's 2024 opinion is an example.
Sources
- Official sourceDigital Security AuthoritySecurity of Networks and Information Systems Laws of 2020 and 2025, Law 89(I)/2020 consolidated with Law 60(I)/2025 (official English text), articles 35B, 43 and 44
dsa.cy
Link checked 18 August 2026
- Official sourceOffice of the Commissioner for Personal Data ProtectionOther relevant laws — the Commissioner's own list, including Law 112(I)/2004 on privacy in electronic communications, the Artificial Intelligence Act implementation page and Law 122(I)/2025 implementing the Digital Services Act
gov.cy
Link checked 18 August 2026
- Official sourceOffice of the Commissioner for Personal Data ProtectionAnnual Report 2024 of the Commissioner for Personal Data Protection — 531 complaints, 94 breach notifications, 88 decisions, 21 fines totalling EUR 133,900
gov.cy
Link checked 18 August 2026
- Official sourceEUR-LexRegulation (EU) 2023/2854 (Data Act) — zero cloud switching charges from 12 January 2027
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceOffice of the Commissioner for Personal Data ProtectionLaw 125(I)/2018 — Law providing for the Protection of Natural Persons with regard to the Processing of Personal Data and for the Free Movement of such Data (official English translation)
gov.cy
Link checked 18 August 2026
What to do: Diarise 12 January 2027 — that is the date this changes.
Not fully verified — see “What we're not sure about” below.The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries4 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Insurance rules
Official name: Νόμος 125(Ι)/2018, άρθρο 9 — Επεξεργασία γενετικών και βιομετρικών δεδομένων · Law 125(I)/2018, section 9 · Act of parliament
Health and life insurers in Cyprus may not use genetic or biometric data at all for insurance. The use itself is banned. No consent, contract or transfer tool makes it lawful.
Enforced by Commissioner for Personal Data Protection
How this country controls where data goes: Not allowed
What you have to do
- Get consentEven outside insurance, any further use of genetic or biometric data first collected with consent needs separate fresh consent.
What it costs if you get it wrong
- Criminal liability: 1 year's imprisonment or €10,000, or both — about $11 thousandProcessing in breach of the Law where not covered by a heavier listed offence
Sources
- Official sourceOffice of the Commissioner for Personal Data ProtectionLaw 125(I)/2018 — Law providing for the Protection of Natural Persons with regard to the Processing of Personal Data and for the Free Movement of such Data (official English translation)
gov.cy
“The processing of genetic and biometric data for purposes of health and life insurance is prohibited.”
Link checked 18 August 2026
- Official sourceOffice of the Commissioner for Personal Data ProtectionLaw 125(I)/2018 — legislation page, confirming publication in the Official Gazette on 31 July 2018 and amendment by Law 26(I)/2022
gov.cy
Link checked 18 August 2026
Online gaming data needs a copy kept in the country
Official name: Ο περί Στοιχημάτων Νόμος του 2019 · Law 37(I)/2019 (in force since 2019), articles 32(3), 53 and 56(1)(c), with National Betting Authority Directive 03.2020 (issued 2020, replacing Directive 13/2016) · Act of parliament
This is Cyprus's one real storage-location rule. An online bookmaker must run a backup server physically inside Cyprus. It must mirror the main server in parallel. You must prove where that machine sits before you get a licence. Betting records stay five years and cannot be deleted without permission.
Enforced by National Betting Authority
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryClass B licensees, the online ones, must install a backup server inside Cyprus, connected in parallel to the main server. The Authority sets the maximum copying lag allowed, by directive, and may change it at any time. Class A licensees, the shops, must install and keep both their main and backup servers in the Republic.
- Keep data for a minimum period — 5 yearsBetting slips and related documents. They may not be destroyed after five years without the Authority's prior approval.
- Register or notifyYour licence application is incomplete without three things. The physical storage location of the backup server. The storage contract. And a monthly invoice from the storage provider.
- Secure the dataThe Authority must be given real-time access to the operator's computerised betting system through a web portal.
What it costs if you get it wrong
- Criminal liability: 1 year's imprisonment or €150,000, or both — about $163 thousandBreach of the record-keeping and system-approval articles
- Loss of your licenceFailure to meet licence conditions
Sources
- Official sourceNational Betting AuthorityThe Betting Law of 2019, Law 37(I)/2019 (official English text), articles 32(3), 53, 56 and 72-73
nba.gov.cy
“the equipment needed, including the electromechanical parts, the main and backup server and the software of the computerised betting slip marking system are and will remain installed in the Republic.”
Link checked 18 August 2026
- Official sourceNational Betting AuthorityDirective 03.2020 — data and information on the installation of a backup server for Class B licensed bookmakers
nba.gov.cy
“his obligation to install, in the territory of the Republic of Cyprus, a backup server, which will be connected in parallel with the main server”
Link checked 18 August 2026
- Official sourceNational Betting AuthorityNational Betting Authority — list of directives in force, including Directive 03.2020 on the backup server and Directive 13.2020 on books and records
nba.gov.cy
Link checked 18 August 2026
Telecoms rules
Official name: Ο περί Επεξεργασίας Δεδομένων Προσωπικού Χαρακτήρα και της Προστασίας της Ιδιωτικής Ζωής στον Τομέα των Ηλεκτρονικών Επικοινωνιών Νόμος του 2004 · Law 112(I)/2004 (in force since 2004), transposing Directive 2002/58/EC · Act of parliament
Cyprus's electronic communications privacy law covers cookies, marketing calls and messages, and phone and internet connection records. It does not require connection records to be stored on the island.
Enforced by Commissioner for Personal Data Protection
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses
What you have to do
- Get consentYou need consent for cookies and for unsolicited marketing. Unwanted messages made up 120 of the 531 complaints the Commissioner received in 2024. That was the largest single category.
- Secure the data
- Delete data after a periodTraffic data must be erased or anonymised once no longer needed for transmission or billing.
Sources
- Official sourceOffice of the Commissioner for Personal Data ProtectionOther relevant laws — the Commissioner's own list, including Law 112(I)/2004 on privacy in electronic communications, the Artificial Intelligence Act implementation page and Law 122(I)/2025 implementing the Digital Services Act
gov.cy
Link checked 18 August 2026
- Official sourceOffice of the Commissioner for Personal Data ProtectionAnnual Report 2024 of the Commissioner for Personal Data Protection — 531 complaints, 94 breach notifications, 88 decisions, 21 fines totalling EUR 133,900
gov.cy
Link checked 18 August 2026
Payment data rules
Official name: Κανονισμός για την Ψηφιακή Επιχειρησιακή Ανθεκτικότητα (DORA) · Regulation (EU) 2022/2554 · Directly binding regulation
The European digital resilience rules cover technology risk for Cypriot banks, payment firms, insurers and investment firms. There is no Cypriot storage-location rule. You must say where the data sits. You do not have to keep it in Cyprus.
Enforced by Cyprus Securities and Exchange Commission
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Written vendor contractOutsourcing contracts must say where data is used and stored. They must give audit and exit rights. This is about telling people, not about keeping data in the country.
- Report cyber incidents
- Independent audit
Sources
- Official sourceEUR-LexRegulation (EU) 2022/2554 (DORA) — applies to financial entities since 17 January 2025
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceCyprus Securities and Exchange CommissionCyprus Securities and Exchange Commission — circulars index, which routes technology-resilience matters to a dedicated Digital Resilience (DORA) heading rather than to any Cypriot storage-location rule
cysec.gov.cy
Link checked 18 August 2026
- Official sourceCentral Bank of CyprusCentral Bank of Cyprus — banking supervision pages; no Cypriot data-localisation directive listed
centralbank.cy
Link checked 18 August 2026
Applies to every company3 rules
These bind you whatever business you are in, once the country's rules reach you.
General data protection law (2018)
Official name: Ο περί της Προστασίας των Φυσικών Προσώπων Έναντι της Επεξεργασίας των Δεδομένων Προσωπικού Χαρακτήρα και της Ελεύθερης Κυκλοφορίας των Δεδομένων αυτών Νόμος του 2018 · Law 125(I)/2018, as amended by Law 26(I)/2022 · Act of parliament
Cyprus's national privacy law. It adds criminal liability on top of European fines. It puts that liability on the company's most senior executive. It sets the age of digital consent at 14.
Enforced by Commissioner for Personal Data Protection
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules
What you have to do
- Get a parent's consent for children — applies at: Under 14 years oldCyprus sets the age of digital consent at 14. That is lower than in several nearby European Union countries.
- Keep records of how you use dataFailing to keep or produce your record of data activities is a crime, not just a paperwork breach.
- Appoint a data protection officer
- Assess high-risk projectsThis is also required before two or more public bodies combine large filing systems. It applies where those systems hold sensitive data or the identity card number.
What it costs if you get it wrong
- Criminal liability: 3 years' imprisonment or €30,000, or both — about $33 thousandFourteen listed failures, including no processing record, no breach notification, obstructing the data protection officer, unlawful transfer abroad
- Criminal liability: 5 years' imprisonment or €50,000, or both — about $54 thousandWhere the offence damages the interests of the Republic or compromises national security
- Fixed maximum fine: €200,000 — about $217 thousandCeiling on administrative fines against a public authority for non-profitable activities
Sources
- Official sourceOffice of the Commissioner for Personal Data ProtectionLaw 125(I)/2018 — Law providing for the Protection of Natural Persons with regard to the Processing of Personal Data and for the Free Movement of such Data (official English translation)
gov.cy
“If a person is convicted for committing any of the offenses referred to in subsection (1) paragraphs (a) to (l) he or she shall be subject to imprisonment which shall not exceed three (3) years or to a fine which shall not exceed thirty thousand (30,000) euro or to both of these penalties.”
Link checked 18 August 2026
- Official sourceOffice of the Commissioner for Personal Data ProtectionLaw 125(I)/2018 — legislation page, confirming publication in the Official Gazette on 31 July 2018 and amendment by Law 26(I)/2022
gov.cy
Link checked 18 August 2026
Health data rules
Official name: Νόμος 125(Ι)/2018, Μέρος VII — Διαβίβαση ειδικών κατηγοριών δεδομένων σε τρίτη χώρα · Law 125(I)/2018, sections 17 and 18 · Act of parliament
This is Cyprus's own check on sensitive data leaving Europe. Health, genetic, biometric and similar data must be reported to the Commissioner before it moves. In some cases you must assess it and clear it with her first. She can set limits at any time.
Enforced by Commissioner for Personal Data Protection
How this country controls where data goes: Approval each time · Accepted routes: Standard contract clauses, Approved group rules, Government sign-off needed, Explicit consent, Legal claims
What you have to do
- Put a transfer safeguard in placeTell the Commissioner BEFORE sensitive data leaves. This applies where the transfer rests on standard contractual clauses or binding corporate rules.
- Assess high-risk projectsWhere the transfer rests on a narrow exception instead, you need a written impact assessment. You must also consult the Commissioner first.
What it costs if you get it wrong
- Criminal liability: 3 years' imprisonment or €30,000, or both — about $33 thousandTransferring in breach of limits the Commissioner has imposed under section 17 or 18
- Order to stopThe Commissioner may impose explicit limits on the transfer for important reasons of public interest
Sources
- Official sourceOffice of the Commissioner for Personal Data ProtectionLaw 125(I)/2018 — Law providing for the Protection of Natural Persons with regard to the Processing of Personal Data and for the Free Movement of such Data (official English translation)
gov.cy
“the controller or the processor shall inform the Commissioner for the intended transfer before the said data are transferred.”
Link checked 18 August 2026
- Official sourceOffice of the Commissioner for Personal Data ProtectionAnnual Report 2024 of the Commissioner for Personal Data Protection — 531 complaints, 94 breach notifications, 88 decisions, 21 fines totalling EUR 133,900
gov.cy
Link checked 18 August 2026
Cyber security rules
Official name: Οι περί Ασφάλειας Δικτύων και Συστημάτων Πληροφοριών Νόμοι του 2020 και 2025 · Law 89(I)/2020 (Official Gazette No. 4770, 12 August 2020) as amended by Law 60(I)/2025, transposing Directive (EU) 2022/2555 · Act of parliament
Cyprus's cybersecurity law, updated in 2025 for the European NIS2 rules. It says nothing about where data must be stored. It sets a six-hour deadline for a first warning, one of the shortest in Europe. Breaking it is a crime. One part of the law is still waiting on a government notice before it starts.
Enforced by Digital Security Authority
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Report cyber incidents — within 6 hoursSend a first warning to the Digital Security Authority. Trust service providers get 24 hours. This is far shorter than the 24 hours the European directive sets. It is the deadline people miss most often in Cyprus.
- Report cyber incidents — within 72 hoursSend the full incident report. Include a first assessment of how serious it is, plus any indicators of compromise.
- Report cyber incidents — 1 monthFinal report. While an incident continues, progress reports every fifteen days.
- Secure the data
- Register or notifyEssential and important entities must be registered with the Authority.
What it costs if you get it wrong
- Percentage of global turnover: €10 million or 2% of worldwide annual turnover, whichever is higher — about $11 millionEssential entities breaching the risk-management or reporting duties
- Percentage of global turnover: €7 million or 1.4% of worldwide annual turnover, whichever is higher — about $8 millionImportant entities breaching the same duties
- Criminal liability: 2 years' imprisonment or €10,000, or both — about $11 thousandFailing to notify an incident with a severe impact on an essential service
- Criminal liability: 3 years' imprisonment or €15,000, or both — about $16 thousandFailing to take appropriate technical and organisational security measures
Sources
- Official sourceDigital Security AuthoritySecurity of Networks and Information Systems Laws of 2020 and 2025, Law 89(I)/2020 consolidated with Law 60(I)/2025 (official English text), articles 35B, 43 and 44
dsa.cy
“without undue delay and in any event within six (6) hours of becoming aware of the significant incident, a warning”
Link checked 18 August 2026
- Official sourceDigital Security AuthorityDigital Security Authority — Laws page publishing the consolidated NIS2 law
dsa.cy
Link checked 18 August 2026
- Official sourceDigital Security AuthorityDigital Security Authority — official site, activity announcements running to August 2026
dsa.cy
Link checked 18 August 2026
Applies across the European Union2 rules
Written once for the whole bloc, and in force in every member country.
Europe's main privacy law
Official name: Γενικός Κανονισμός για την Προστασία Δεδομένων (General Data Protection Regulation) · Regulation (EU) 2016/679 · Directly binding regulation
The European privacy rulebook applies directly in Cyprus. It does not require data to stay in Europe. It sets the conditions for sending it out. Fines rise with the worldwide turnover of your group.
Enforced by Commissioner for Personal Data Protection
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims
What you have to do
- Tell people what you do
- Get consent
- Document a legitimate interest
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people take their data elsewhere
- Let people object
- Limit automated decisions
- Secure the data
- Keep records of how you use data
- Assess high-risk projects
- Written vendor contract
- Put a transfer safeguard in place
- Appoint a representativeThis applies only if you have no office anywhere in the European Union.
- Report breaches to the regulator — within 72 hours
- Tell affected people
- Delete data after a period
What it costs if you get it wrong
- Percentage of global turnover: €20 million or 4% of worldwide group turnover, whichever is higher — about $22 millionBasic principles, individual rights, unlawful international transfers, defying a regulator order
- Percentage of global turnover: €10 million or 2% of worldwide group turnover, whichever is higher — about $11 millionSecurity, records, breach notification and similar duties
- Order to stopOrder to stop processing or to suspend flows outside Europe
- Claims by individualsCompensation claims by affected individuals
Sources
- Official sourceEUR-LexRegulation (EU) 2016/679 — General Data Protection Regulation, consolidated text
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceEuropean CommissionAdequacy decisions — the current approved-destination list
commission.europa.eu
Link checked 18 August 2026
- Official sourceEUR-LexCommission Implementing Decision (EU) 2021/914 — Standard Contractual Clauses
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceOffice of the Commissioner for Personal Data ProtectionLaw 125(I)/2018 — legislation page, confirming publication in the Official Gazette on 31 July 2018 and amendment by Law 26(I)/2022
gov.cy
Link checked 18 August 2026
General data protection law
Official name: Κανονισμός για την ελεύθερη ροή δεδομένων μη προσωπικού χαρακτήρα · Regulation (EU) 2018/1807 · Directly binding regulation
Cyprus may not require non-personal data to be stored on the island. The only exception is where it can show a real public security reason. That is why Cypriot storage-location rules are so rare.
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Make switching cloud provider possible
Sources
- Official sourceEUR-LexRegulation (EU) 2018/1807 — free flow of non-personal data; bans member-state localisation except on public-security grounds
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceEUR-LexRegulation (EU) 2016/679 — General Data Protection Regulation, consolidated text
eur-lex.europa.eu
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
The status of Cyprus's telecoms data-retention law, Law 183(I)/2007 (six-month retention of connection records for serious crime investigations)
We could not confirm whether Cyprus still enforces blanket telecoms data retention. The law is still on the statute book, and we found its text on a non-government legal database. But the European directive it implements was annulled by the Court of Justice in 2014. Cypriot courts are widely reported to have limited its access rules. We found neither the law nor any judgment on it on a Cyprus government or court website. So we assert no rule here. If you are a telecoms operator, check before you rely on this.
Whether Cypriot public bodies are required to use a Cyprus-hosted government cloud
We could not confirm whether government data must stay in Cyprus. The Deputy Ministry of Research, Innovation and Digital Policy's document pages were blocked by the gov.cy web firewall on every attempt on 18 August 2026. We assert no public sector storage-location rule. Checked 18 August 2026, with medium confidence that none exists in binding form.
The exact publication date of Law 60(I)/2025, which brought the NIS2 rules into Cypriot law
We could not confirm the exact start date of the amending law. The consolidated text says it starts on the day it is published in the Official Gazette. It refers to a correction at Gazette Annex I(I) No. 5043. But the Digital Security Authority's page gives no date. We are confident the law dates from 2025. The exact day is unconfirmed.
Cypriot minimum retention periods for tax records, company books and anti-money-laundering files, and whether any of them must be held physically in Cyprus
We could not confirm Cyprus's tax and company law record-keeping periods. The Tax Department site was unreachable through the proxy. The Ministry of Finance site failed certificate checks on 18 August 2026. The Registrar of Companies publishes the Companies Law only behind a search box we could not resolve to a document. The five-year betting records minimum is confirmed. The rest is not. Check with a Cypriot adviser.
Whether any Cypriot banking or payments directive imposes a storage location beyond the European digital resilience rules
We found no rule of this kind, but we could not search thoroughly. We reviewed the Central Bank of Cyprus banking supervision index and the Cyprus Securities and Exchange Commission circulars index and found nothing. Neither site offers a full-text search we could use. So this is missing evidence rather than proof that no rule exists. Confidence medium.
Whether the Commissioner has ever actually imposed 'explicit limits' on a transfer of sensitive data under section 17(2) or 18(3) of Law 125(I)/2018
We could not confirm that the Commissioner has ever used this power. Her 2024 annual report shows her giving opinions on transfers to other countries. We found no published order setting limits. The power itself is confirmed. Its use is not.
Whether any Cypriot rule governs mapping, geospatial or defence data storage
We could not confirm whether any rule applies here. We found no searchable government source for the Department of Lands and Surveys or the Ministry of Defence. We assert no rule. Checked 18 August 2026.
Health-sector storage rules beyond the general law
We could not confirm whether health data must stay in Cyprus. The Ministry of Health site failed certificate checks through the proxy. The only health-specific evidence we have is the Commissioner's 2024 opinion allowing a private hospital to use a United States cloud provider. We also have her 46,500 euro fine against the State Health Services Organisation. We assert no health storage-location rule. If you handle patient data, check with the ministry.
The exact commencement dates of the Betting Law of 2019 (Law 37(I)/2019) and of the electronic-communications privacy law (Law 112(I)/2004)
We could not confirm the exact start dates of these two laws. Neither official text we retrieved carries a start article we could read. The Cyprus Official Gazette is not freely searchable. We are confident both are in force. The Betting Authority licenses under the 2019 law today, and the Commissioner lists the 2004 law as current. We have left the day-level dates out rather than guess them.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 90 days. Next check due 16 November 2026.