Cyprus
Part of the European Union, so bloc-wide rules apply here too. Checked today.
The answer
For most businesses Cyprus behaves like a normal European country: data can leave, provided you use one of the standard European transfer tools. Two things make it stricter than its neighbours. If you move sensitive data such as health records out of Europe, you must tell the privacy regulator first. And breaking the privacy law in Cyprus is a crime, not just a fine.
Eight questions about Cyprus
The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.
Do Cyprus' rules apply to my company?
Yes. If you have no office anywhere in Europe but you sell to people in Cyprus, or you watch what they do online, the European privacy rules reach you and the Cypriot regulator can act. There is no minimum size or turnover that lets you escape. A company with no European base must name a written representative inside Europe, and the Cypriot law adds its own duties on top for anyone processing data here.
The European General Data Protection Regulation applies directly in Cyprus by virtue of Article 3, so no Cypriot statute needs to extend it. Law 125(I)/2018 (published in the Official Gazette on 31 July 2018, amended by Law 26(I)/2022) supplies the national derogations, the supervisory-authority framework and the criminal offences. Law 44(I)/2019 (published 27 March 2019) transposes the Law Enforcement Directive and names the Police, the Customs Department, the anti-money-laundering unit MOKAS and the Tax Department as competent authorities. The Article 27 in-Union representative obligation is the Regulation's, not a Cypriot addition; Cyprus imposes no separate 'local representative in Cyprus' requirement, checked 18 August 2026.
Sources
- Official sourceOffice of the Commissioner for Personal Data ProtectionLaw 125(I)/2018 — Law providing for the Protection of Natural Persons with regard to the Processing of Personal Data and for the Free Movement of such Data (official English translation)
gov.cy
Link checked 18 August 2026
- Official sourceOffice of the Commissioner for Personal Data ProtectionLaw 125(I)/2018 — legislation page, confirming publication in the Official Gazette on 31 July 2018 and amendment by Law 26(I)/2022
gov.cy
Link checked 18 August 2026
- Official sourceOffice of the Commissioner for Personal Data ProtectionSpecial legislation in the law-enforcement field — Law 44(I)/2019, published 27 March 2019, naming the Police, Customs, the anti-money-laundering unit MOKAS and the Tax Department as competent authorities
gov.cy
Link checked 18 August 2026
- Official sourceEUR-LexRegulation (EU) 2016/679 — General Data Protection Regulation, consolidated text
eur-lex.europa.eu
Link checked 18 August 2026
Can I store my users' data outside Cyprus?
In general yes, with paperwork. Ordinary personal data leaves Cyprus on the same European terms as anywhere else in the bloc. But three Cypriot rules override that. Sensitive data going outside Europe must be notified to the regulator before it moves. Online betting operators must keep a mirror copy on a server inside Cyprus. And insurers cannot process genetic or fingerprint data for health or life cover at all.
Sector by sector, checked 18 August 2026: - ALL SECTORS, sensitive data: conditional but with a live regulator gate. Sections 17 and 18 of Law 125(I)/2018 require prior notification (where the transfer rests on Article 46 safeguards or binding corporate rules) or a risk assessment plus prior consultation (where it rests on an Article 49 derogation). In both cases the Commissioner may impose 'explicit limits' for important reasons of public interest. Ignoring those limits is a criminal offence. - ONLINE BETTING: mirror. Class B (online) licensees must install a backup server in the territory of Cyprus connected in parallel to the main server; Class A (shop) licensees' main and backup servers must be and remain installed in the Republic. - INSURANCE: closed, in a narrow slice. Processing genetic and biometric data for health and life insurance purposes is prohibited outright, so the transfer question never arises for that data. - BANKING, PAYMENTS, SECURITIES: no Cypriot localisation rule found. The Digital Operational Resilience Act has applied to financial entities since 17 January 2025 and is the operative regime; the Cyprus Securities and Exchange Commission routes technology-resilience matters to a dedicated Digital Resilience heading rather than to any storage-location rule. - HEALTH: no localisation rule found. The Commissioner's own 2024 opinion allowed a private hospital to give a United States cloud provider remote access to patient records under the EU-US Data Privacy Framework, subject to a proper processor contract. - TELECOMS: no localisation rule found in the electronic-communications privacy law, Law 112(I)/2004. - GOVERNMENT, EDUCATION, MAPPING, DEFENCE: no rule found on a Cypriot government domain; see the unconfirmed list. Regulation (EU) 2018/1807 separately forbids Cyprus from imposing localisation on non-personal data except on public-security grounds.
Sources
- Official sourceOffice of the Commissioner for Personal Data ProtectionLaw 125(I)/2018 — Law providing for the Protection of Natural Persons with regard to the Processing of Personal Data and for the Free Movement of such Data (official English translation)
gov.cy
Link checked 18 August 2026
- Official sourceNational Betting AuthorityThe Betting Law of 2019, Law 37(I)/2019 (official English text), articles 32(3), 53, 56 and 72-73
nba.gov.cy
Link checked 18 August 2026
- Official sourceNational Betting AuthorityDirective 03.2020 — data and information on the installation of a backup server for Class B licensed bookmakers
nba.gov.cy
Link checked 18 August 2026
- Official sourceOffice of the Commissioner for Personal Data ProtectionAnnual Report 2024 of the Commissioner for Personal Data Protection — 531 complaints, 94 breach notifications, 88 decisions, 21 fines totalling EUR 133,900
gov.cy
Link checked 18 August 2026
- Official sourceCyprus Securities and Exchange CommissionCyprus Securities and Exchange Commission — circulars index, which routes technology-resilience matters to a dedicated Digital Resilience (DORA) heading rather than to any Cypriot storage-location rule
cysec.gov.cy
Link checked 18 August 2026
- Official sourceEUR-LexRegulation (EU) 2018/1807 — free flow of non-personal data; bans member-state localisation except on public-security grounds
eur-lex.europa.eu
Link checked 18 August 2026
What do I need in place before data leaves Cyprus?
The model is an approved-destination list. Data may go to a country the European Commission has approved, or you sign the European standard contract, or you use approved group-wide rules. Cyprus adds one step of its own: if the data is sensitive, tell the regulator before it goes, and if you are relying on a narrow exception rather than a contract, do a written risk assessment and consult her first.
The approved list is populated and current: Andorra, Argentina, Brazil, Canada (commercial bodies), the Faroe Islands, Guernsey, the Isle of Man, Israel, Japan, Jersey, New Zealand, South Korea, Switzerland, the United Kingdom, Uruguay, the European Patent Organisation, and the United States for organisations self-certified under the EU-US Data Privacy Framework. The 2021 Standard Contractual Clauses remain the operative set. Sections 17 and 18 of Law 125(I)/2018 are the Cypriot addition and apply only to special categories of personal data — health, genetic, biometric, racial or ethnic origin, political opinions, religious beliefs, trade-union membership, sex life and sexual orientation. Section 17 requires the controller or processor to 'inform the Commissioner for the intended transfer before the said data are transferred'. Section 18 requires an impact assessment containing the Article 35(7) information plus a description of the security measures, and prior consultation. The Commissioner's power to impose explicit limits is a dormant switch: it needs no consultation and no new law. The Commissioner's 2024 annual report shows her giving a reasoned opinion on exactly this kind of question for a private hospital using a United States cloud provider, so the gate is used in practice.
Sources
- Official sourceOffice of the Commissioner for Personal Data ProtectionLaw 125(I)/2018 — Law providing for the Protection of Natural Persons with regard to the Processing of Personal Data and for the Free Movement of such Data (official English translation)
gov.cy
Link checked 18 August 2026
- Official sourceOffice of the Commissioner for Personal Data ProtectionAnnual Report 2024 of the Commissioner for Personal Data Protection — 531 complaints, 94 breach notifications, 88 decisions, 21 fines totalling EUR 133,900
gov.cy
Link checked 18 August 2026
- Official sourceEuropean CommissionAdequacy decisions — the current approved-destination list
commission.europa.eu
Link checked 18 August 2026
- Official sourceEUR-LexCommission Implementing Decision (EU) 2021/914 — Standard Contractual Clauses
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceEuropean Data Protection BoardEuropean Data Protection Board — FAQ for European businesses on the EU-US Data Privacy Framework, cited by the Cypriot Commissioner in her 2024 opinion
edpb.europa.eu
Link checked 18 August 2026
Who enforces the rules in Cyprus, and what can they do?
The Commissioner for Personal Data Protection, and she is genuinely working. In 2024 her office took 531 complaints and 94 breach reports, issued 88 decisions, and fined in 21 of them, totalling about 133,900 euros (roughly $146,000). The biggest single penalty, 46,500 euros, went to the state health services organisation. The current Commissioner is Maria Christofidou. A separate Digital Security Authority handles cyber incidents and is also active.
Fine sizes are small by European standards but the volume is real and the office publishes decisions in batches; the most recent published batch covers January to April 2025. The Commissioner is appointed by the Council of Ministers for a renewable six-year term and must hold the qualifications of a Supreme Court judge. The office changed hands during the period covered here: Irini Loizidou Nicolaidou signed the 2024 annual report and served as Deputy Chair of the European Data Protection Board; the office's own management page names Maria Christofidou as Commissioner as at 18 August 2026, and announcements from January 2026 onwards are issued in her name. The Digital Security Authority, an independent agency supervised by the Commissioner of Communications, enforces the network-security law. It is staffed and visibly operating — running a chief information security officer training programme in August 2026 and taking part in European cybersecurity exercises in June 2026 — but its own public NIS implementation page still describes the pre-2025 categories of operator, so its published guidance lags its statute. The National Betting Authority is operational and issues binding directives; it holds ISO 27001 certification and maintains a live register of licensees.
Sources
- Official sourceOffice of the Commissioner for Personal Data ProtectionAnnual Report 2024 of the Commissioner for Personal Data Protection — 531 complaints, 94 breach notifications, 88 decisions, 21 fines totalling EUR 133,900
gov.cy
Link checked 18 August 2026
- Official sourceOffice of the Commissioner for Personal Data ProtectionOffice of the Commissioner for Personal Data Protection — 'Management' page naming Maria Christofidou as Commissioner
gov.cy
Link checked 18 August 2026
- Official sourceOffice of the Commissioner for Personal Data ProtectionOffice of the Commissioner for Personal Data Protection — official site, news items running to July 2026
gov.cy
Link checked 18 August 2026
- Official sourceDigital Security AuthorityDigital Security Authority — official site, activity announcements running to August 2026
dsa.cy
Link checked 18 August 2026
- Official sourceDigital Security AuthorityDigital Security Authority — NIS Directive implementation page, still describing the older operator categories
dsa.cy
Link checked 18 August 2026
- Official sourceNational Betting AuthorityNational Betting Authority — list of directives in force, including Directive 03.2020 on the backup server and Directive 13.2020 on books and records
nba.gov.cy
Link checked 18 August 2026
How long do I have to keep the data?
There is no single national rule. The European ceiling applies: delete personal data once you no longer need it for the purpose you collected it for. The floors come from sector law. Betting operators must keep betting slips and related documents for five years, and may not destroy them afterwards without the regulator's permission. Where a floor and the ceiling collide, the specific legal duty to keep wins, but only for the data that duty actually covers.
Cyprus has no general statutory retention schedule and Law 125(I)/2018 sets none. Article 53 of the Betting Law of 2019 sets a five-year floor for betting slips and any other document relating to the provision of betting services, with a further requirement of prior approval from the National Betting Authority before destruction — an unusual second lock that most retention schedules miss. Books and records under that law may be kept electronically only with the Authority's prior approval. Under the network-security law, essential and important entities must file a final incident report within one month and, for a continuing incident, progress reports every fifteen days, which implies retaining incident evidence for at least that long. Tax and company-law floors exist in Cyprus but we could not verify their length or their storage location against a Cypriot government source during this run — see the unconfirmed list.
Sources
- Official sourceNational Betting AuthorityThe Betting Law of 2019, Law 37(I)/2019 (official English text), articles 32(3), 53, 56 and 72-73
nba.gov.cy
Link checked 18 August 2026
- Official sourceDigital Security AuthoritySecurity of Networks and Information Systems Laws of 2020 and 2025, Law 89(I)/2020 consolidated with Law 60(I)/2025 (official English text), articles 35B, 43 and 44
dsa.cy
Link checked 18 August 2026
- Official sourceOffice of the Commissioner for Personal Data ProtectionLaw 125(I)/2018 — Law providing for the Protection of Natural Persons with regard to the Processing of Personal Data and for the Free Movement of such Data (official English translation)
gov.cy
Link checked 18 August 2026
- Official sourceEUR-LexRegulation (EU) 2016/679 — General Data Protection Regulation, consolidated text
eur-lex.europa.eu
Link checked 18 August 2026
What happens if there is a breach?
Count three clocks and start with the shortest. If you run an essential or important service, Cyprus gives you SIX HOURS to send a first warning to the Digital Security Authority — one of the tightest deadlines in Europe, and far shorter than the 24 hours the European directive asked for. A full report follows within 72 hours and a final one within a month. Separately, a personal data breach goes to the privacy regulator within 72 hours, and to affected people if the risk to them is high.
The six-hour clock comes from Article 35B(4)(a) of the Security of Networks and Information Systems Laws of 2020 and 2025. Trust service providers get 24 hours instead. The 72-hour incident notification must include an initial severity assessment and any indicators of compromise; the Authority is meant to reply within 24 hours of the early warning. A final report is due within one month, and while an incident is still running, progress reports every fifteen days. The privacy clock is the European 72 hours to the Commissioner plus communication to individuals where the risk is high. In Cyprus, failing to notify is not merely a fine: it is a criminal offence under section 33 of Law 125(I)/2018. Failing to notify a severe cyber incident is separately a criminal offence carrying up to two years' imprisonment. The overlap is the trap. A ransomware attack on a Cypriot hospital or bank starts all three clocks at once, and the six-hour one expires before most incident-response teams have finished triage.
Sources
- Official sourceDigital Security AuthoritySecurity of Networks and Information Systems Laws of 2020 and 2025, Law 89(I)/2020 consolidated with Law 60(I)/2025 (official English text), articles 35B, 43 and 44
dsa.cy
“without undue delay and in any event within six (6) hours of becoming aware of the significant incident, a warning, which, where applicable, shall indicate whether the significant incident is suspected of being caused by unlawful or malicious acts or could have a cross-border impact”
Link checked 18 August 2026
- Official sourceDigital Security AuthorityDigital Security Authority — Laws page publishing the consolidated NIS2 law
dsa.cy
Link checked 18 August 2026
- Official sourceOffice of the Commissioner for Personal Data ProtectionLaw 125(I)/2018 — Law providing for the Protection of Natural Persons with regard to the Processing of Personal Data and for the Free Movement of such Data (official English translation)
gov.cy
Link checked 18 August 2026
- Official sourceOffice of the Commissioner for Personal Data ProtectionAnnual Report 2024 of the Commissioner for Personal Data Protection — 531 complaints, 94 breach notifications, 88 decisions, 21 fines totalling EUR 133,900
gov.cy
Link checked 18 August 2026
What trips people up in Cyprus?
Five things that are not in the summary. (1) Breaking the privacy law in Cyprus is a crime — up to three years in prison, or five where national security is touched — and the law puts the blame on the company's most senior executive personally. (2) A child is anyone under 14 here, not 16 as in some neighbours. (3) Insurers may not use genetic or fingerprint-type data for health or life cover at all. (4) Sensitive data leaving Europe must be notified to the regulator first. (5) The cyber warning deadline is six hours, not 24.
(1) Section 33 of Law 125(I)/2018 makes fourteen categories of conduct criminal offences, including failing to keep a record of processing activities, failing to notify a breach, obstructing the data protection officer, and transferring data abroad in breach of Chapter V or of limits the Commissioner has imposed. The penalty is up to three years' imprisonment or a fine of up to EUR 30,000 (about $33,000) or both; up to five years or EUR 50,000 (about $54,000) where the offence damages the interests of the Republic or compromises national security; up to one year or EUR 10,000 (about $11,000) for the residual offences. Section 33(5) is the sting: where the controller is a company, 'the legal responsibility lays with the person designated as the supreme executive instrument or body of the enterprise'. Compliance failure is therefore personal exposure for the chief executive, not just a corporate cost line. (2) Section 8 sets the age of digital consent at 14. Services aimed at 12- and 13-year-olds that rely on the child's own consent elsewhere in Europe will be unlawful in Cyprus. (3) Section 9(1) is an outright prohibition, not a consent-based restriction: genetic and biometric data may not be processed for health and life insurance purposes. Section 9(2) adds that further processing of such data needs separate fresh consent. (4) Sections 17 and 18, above. Note this bites on ordinary corporate architecture — a human-resources system holding sickness records, or a customer database with health flags, replicated to a data centre outside Europe. (5) The six-hour warning under the network-security law. (6) A smaller one: administrative fines on public authorities are capped at EUR 200,000 (about $217,000) where the activity is non-profitable, which materially limits the regulator's leverage over Cypriot ministries and state bodies.
Sources
- Official sourceOffice of the Commissioner for Personal Data ProtectionLaw 125(I)/2018 — Law providing for the Protection of Natural Persons with regard to the Processing of Personal Data and for the Free Movement of such Data (official English translation)
gov.cy
“The processing of genetic and biometric data for purposes of health and life insurance is prohibited.”
Link checked 18 August 2026
- Official sourceDigital Security AuthoritySecurity of Networks and Information Systems Laws of 2020 and 2025, Law 89(I)/2020 consolidated with Law 60(I)/2025 (official English text), articles 35B, 43 and 44
dsa.cy
Link checked 18 August 2026
- Official sourceOffice of the Commissioner for Personal Data ProtectionLaw 125(I)/2018 — legislation page, confirming publication in the Official Gazette on 31 July 2018 and amendment by Law 26(I)/2022
gov.cy
Link checked 18 August 2026
What is changing soon in Cyprus?
One hard European date matters most: from 12 January 2027 cloud providers must let customers move away with no exit or switching fees. Cyprus is also still building out its newest laws — the digital services law passed in 2025 and the artificial intelligence rules are being bedded in by the same privacy regulator, who now has three jobs instead of one. Watch three switches the government can flip with no warning.
Coming in the next twelve months: - 12 January 2027: the European Data Act requires zero charges for switching cloud provider and for moving data out. This is a contract-renegotiation deadline, not a filing deadline. - The Commissioner has taken on supervision under the Artificial Intelligence Act and under Law 122(I)/2025 implementing the Digital Services Act, on top of privacy. Her own 2024 report flags that the office needs more staff to do this. Expect slower handling times rather than new rules. - A consolidation of the Digital Security Authority with the Office of the Commissioner of Electronic Communications is expressly anticipated in the network-security law's transitional provisions and will trigger amendments to the Authority's structure when it happens. No date is set. DORMANT SWITCHES — powers already held, exercisable without consultation: 1. The Commissioner may impose 'explicit limits' on any transfer of sensitive data out of Europe, for important reasons of public interest, under sections 17(2) and 18(3) of Law 125(I)/2018. She has not published such an order, but the power needs no new law and breaching a limit is a criminal offence. 2. Article 8 of Law 60(I)/2025 has not commenced: it enters into force on a date the Council of Ministers sets by notice in the Official Gazette, which is why the network-security law is recorded here as only partly in force. 3. The National Betting Authority may revise the backup-server specification, including the maximum permitted lag between the main and the Cypriot mirror, by issuing a new directive at any time. At European level the EU-US Data Privacy Framework remains valid but is under appeal at the Court of Justice and was queried by the European Data Protection Board in a letter to the Commission on 31 July 2026. Cypriot controllers relying on it as their only mechanism — as the hospital in the Commissioner's 2024 opinion did — carry that risk.
Sources
- Official sourceDigital Security AuthoritySecurity of Networks and Information Systems Laws of 2020 and 2025, Law 89(I)/2020 consolidated with Law 60(I)/2025 (official English text), articles 35B, 43 and 44
dsa.cy
Link checked 18 August 2026
- Official sourceOffice of the Commissioner for Personal Data ProtectionOther relevant laws — the Commissioner's own list, including Law 112(I)/2004 on privacy in electronic communications, the Artificial Intelligence Act implementation page and Law 122(I)/2025 implementing the Digital Services Act
gov.cy
Link checked 18 August 2026
- Official sourceOffice of the Commissioner for Personal Data ProtectionAnnual Report 2024 of the Commissioner for Personal Data Protection — 531 complaints, 94 breach notifications, 88 decisions, 21 fines totalling EUR 133,900
gov.cy
Link checked 18 August 2026
- Official sourceEUR-LexRegulation (EU) 2023/2854 (Data Act) — zero cloud switching charges from 12 January 2027
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceOffice of the Commissioner for Personal Data ProtectionLaw 125(I)/2018 — Law providing for the Protection of Natural Persons with regard to the Processing of Personal Data and for the Free Movement of such Data (official English translation)
gov.cy
Link checked 18 August 2026
The rules, layer by layer
Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.
Layer 1
Bloc rules
Made by a group of countries together. Applies inside every member country.
2 rules here
Layer 2
National rules
Added by this country on top of any bloc rules.
3 rules here
Layer 3
Industry rules
Made by an industry regulator. These usually beat the general position.
4 rules here
Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.
Bloc rules2 rules
Γενικός Κανονισμός για την Προστασία Δεδομένων (General Data Protection Regulation)
Directly binding regulation · Regulation (EU) 2016/679
The European privacy rulebook applies directly in Cyprus. It does not require data to stay in Europe; it sets the conditions for sending it out. Fines scale with worldwide group turnover.
Enforced by Commissioner for Personal Data Protection
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims
What it makes you do
- Tell people what you do
- Get consent
- Document a legitimate interest
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people take their data elsewhere
- Let people object
- Limit automated decisions
- Secure the data
- Keep records of processing
- Assess high-risk projects
- Written vendor contract
- Put a transfer safeguard in place
- Appoint a local representativeOnly where the organisation has no establishment anywhere in the European Union.
- Report breaches to the regulator — within 72 hours
- Tell affected people
- Delete data after a period
What it costs if you get it wrong
- Percentage of global turnover: €20 million or 4% of worldwide group turnover, whichever is higher — about $22 millionBasic principles, individual rights, unlawful international transfers, defying a regulator order
- Percentage of global turnover: €10 million or 2% of worldwide group turnover, whichever is higher — about $11 millionSecurity, records, breach notification and similar duties
- Order to stopOrder to stop processing or to suspend flows outside Europe
- Claims by individualsCompensation claims by affected individuals
Sources
- Official sourceEUR-LexRegulation (EU) 2016/679 — General Data Protection Regulation, consolidated text
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceEuropean CommissionAdequacy decisions — the current approved-destination list
commission.europa.eu
Link checked 18 August 2026
- Official sourceEUR-LexCommission Implementing Decision (EU) 2021/914 — Standard Contractual Clauses
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceOffice of the Commissioner for Personal Data ProtectionLaw 125(I)/2018 — legislation page, confirming publication in the Official Gazette on 31 July 2018 and amendment by Law 26(I)/2022
gov.cy
Link checked 18 August 2026
Κανονισμός για την ελεύθερη ροή δεδομένων μη προσωπικού χαρακτήρα
Directly binding regulation · Regulation (EU) 2018/1807
Cyprus is forbidden from requiring non-personal data to be stored on the island, except where it can show a genuine public-security reason. This is why Cypriot storage-location rules are so rare.
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Make switching cloud provider possible
Sources
- Official sourceEUR-LexRegulation (EU) 2018/1807 — free flow of non-personal data; bans member-state localisation except on public-security grounds
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceEUR-LexRegulation (EU) 2016/679 — General Data Protection Regulation, consolidated text
eur-lex.europa.eu
Link checked 18 August 2026
National rules3 rules
Ο περί της Προστασίας των Φυσικών Προσώπων Έναντι της Επεξεργασίας των Δεδομένων Προσωπικού Χαρακτήρα και της Ελεύθερης Κυκλοφορίας των Δεδομένων αυτών Νόμος του 2018
Act of parliament · Law 125(I)/2018, as amended by Law 26(I)/2022
Cyprus's national privacy statute. It adds criminal liability on top of European fines, pins that liability on the company's most senior executive, and sets the age of digital consent at 14.
Enforced by Commissioner for Personal Data Protection
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules
What it makes you do
- Get a parent's consent for children — applies at: Under 14 years oldCyprus sets the age of digital consent at 14, lower than several EU neighbours.
- Keep records of processingFailing to keep or produce the record of processing activities is a criminal offence, not just an administrative breach.
- Appoint a data protection officer
- Assess high-risk projectsAlso required before two or more public bodies combine large-scale filing systems involving sensitive data or the identity-card number.
What it costs if you get it wrong
- Criminal liability: 3 years' imprisonment or €30,000, or both — about $33 thousandFourteen listed failures, including no processing record, no breach notification, obstructing the data protection officer, unlawful transfer abroad
- Criminal liability: 5 years' imprisonment or €50,000, or both — about $54 thousandWhere the offence damages the interests of the Republic or compromises national security
- Fixed maximum fine: €200,000 — about $217 thousandCeiling on administrative fines against a public authority for non-profitable activities
Sources
- Official sourceOffice of the Commissioner for Personal Data ProtectionLaw 125(I)/2018 — Law providing for the Protection of Natural Persons with regard to the Processing of Personal Data and for the Free Movement of such Data (official English translation)
gov.cy
“If a person is convicted for committing any of the offenses referred to in subsection (1) paragraphs (a) to (l) he or she shall be subject to imprisonment which shall not exceed three (3) years or to a fine which shall not exceed thirty thousand (30,000) euro or to both of these penalties.”
Link checked 18 August 2026
- Official sourceOffice of the Commissioner for Personal Data ProtectionLaw 125(I)/2018 — legislation page, confirming publication in the Official Gazette on 31 July 2018 and amendment by Law 26(I)/2022
gov.cy
Link checked 18 August 2026
Νόμος 125(Ι)/2018, Μέρος VII — Διαβίβαση ειδικών κατηγοριών δεδομένων σε τρίτη χώρα
Act of parliament · Law 125(I)/2018, sections 17 and 18
Cyprus's own gate on sensitive data leaving Europe. Health, genetic, biometric and similar data must be notified to the Commissioner before it moves, or assessed and cleared with her first, and she can order limits at any time.
Enforced by Commissioner for Personal Data Protection
Transfer model: Approval each time · Accepted routes: Standard contract clauses, Approved group rules, Government sign-off needed, Explicit consent, Legal claims
What it makes you do
- Put a transfer safeguard in placeNotify the Commissioner BEFORE sensitive data leaves, where the transfer rests on standard contractual clauses or binding corporate rules.
- Assess high-risk projectsWhere the transfer rests on a narrow derogation instead, a written impact assessment and prior consultation with the Commissioner are required.
What it costs if you get it wrong
- Criminal liability: 3 years' imprisonment or €30,000, or both — about $33 thousandTransferring in breach of limits the Commissioner has imposed under section 17 or 18
- Order to stopThe Commissioner may impose explicit limits on the transfer for important reasons of public interest
Sources
- Official sourceOffice of the Commissioner for Personal Data ProtectionLaw 125(I)/2018 — Law providing for the Protection of Natural Persons with regard to the Processing of Personal Data and for the Free Movement of such Data (official English translation)
gov.cy
“the controller or the processor shall inform the Commissioner for the intended transfer before the said data are transferred.”
Link checked 18 August 2026
- Official sourceOffice of the Commissioner for Personal Data ProtectionAnnual Report 2024 of the Commissioner for Personal Data Protection — 531 complaints, 94 breach notifications, 88 decisions, 21 fines totalling EUR 133,900
gov.cy
Link checked 18 August 2026
Οι περί Ασφάλειας Δικτύων και Συστημάτων Πληροφοριών Νόμοι του 2020 και 2025
Act of parliament · Law 89(I)/2020 (Official Gazette No. 4770, 12 August 2020) as amended by Law 60(I)/2025, transposing Directive (EU) 2022/2555
Cyprus's cybersecurity law, updated in 2025 for the European NIS2 rules. It imposes no storage-location duty but sets a six-hour first-warning deadline, one of the shortest in Europe, backed by criminal liability. One provision is still waiting on a government notice to commence.
Enforced by Digital Security Authority
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Report cyber incidents — within 6 hoursFirst warning to the Digital Security Authority. Trust service providers get 24 hours. This is far shorter than the 24 hours the European directive sets and is the single most-missed deadline in Cyprus.
- Report cyber incidents — within 72 hoursFull incident notification with an initial severity assessment and any indicators of compromise.
- Report cyber incidents — 1 monthFinal report. While an incident continues, progress reports every fifteen days.
- Secure the data
- Register or notifyEssential and important entities must be registered with the Authority.
What it costs if you get it wrong
- Percentage of global turnover: €10 million or 2% of worldwide annual turnover, whichever is higher — about $11 millionEssential entities breaching the risk-management or reporting duties
- Percentage of global turnover: €7 million or 1.4% of worldwide annual turnover, whichever is higher — about $8 millionImportant entities breaching the same duties
- Criminal liability: 2 years' imprisonment or €10,000, or both — about $11 thousandFailing to notify an incident with a severe impact on an essential service
- Criminal liability: 3 years' imprisonment or €15,000, or both — about $16 thousandFailing to take appropriate technical and organisational security measures
Sources
- Official sourceDigital Security AuthoritySecurity of Networks and Information Systems Laws of 2020 and 2025, Law 89(I)/2020 consolidated with Law 60(I)/2025 (official English text), articles 35B, 43 and 44
dsa.cy
“without undue delay and in any event within six (6) hours of becoming aware of the significant incident, a warning”
Link checked 18 August 2026
- Official sourceDigital Security AuthorityDigital Security Authority — Laws page publishing the consolidated NIS2 law
dsa.cy
Link checked 18 August 2026
- Official sourceDigital Security AuthorityDigital Security Authority — official site, activity announcements running to August 2026
dsa.cy
Link checked 18 August 2026
Industry rules4 rules
Νόμος 125(Ι)/2018, άρθρο 9 — Επεξεργασία γενετικών και βιομετρικών δεδομένων
Act of parliament · Law 125(I)/2018, section 9 · Insurance
Health and life insurers in Cyprus may not process genetic or biometric data at all for insurance purposes. Because the processing itself is banned, no consent, contract or transfer tool makes it lawful.
Enforced by Commissioner for Personal Data Protection
Transfer model: Not allowed
What it makes you do
- Get consentEven outside insurance, any further use of genetic or biometric data first collected with consent needs separate fresh consent.
What it costs if you get it wrong
- Criminal liability: 1 year's imprisonment or €10,000, or both — about $11 thousandProcessing in breach of the Law where not covered by a heavier listed offence
Sources
- Official sourceOffice of the Commissioner for Personal Data ProtectionLaw 125(I)/2018 — Law providing for the Protection of Natural Persons with regard to the Processing of Personal Data and for the Free Movement of such Data (official English translation)
gov.cy
“The processing of genetic and biometric data for purposes of health and life insurance is prohibited.”
Link checked 18 August 2026
- Official sourceOffice of the Commissioner for Personal Data ProtectionLaw 125(I)/2018 — legislation page, confirming publication in the Official Gazette on 31 July 2018 and amendment by Law 26(I)/2022
gov.cy
Link checked 18 August 2026
Ο περί Στοιχημάτων Νόμος του 2019
Act of parliament · Law 37(I)/2019 (in force since 2019), articles 32(3), 53 and 56(1)(c), with National Betting Authority Directive 03.2020 (issued 2020, replacing Directive 13/2016) · Online gaming
Cyprus's one true storage-location rule. An online bookmaker must run a backup server physically inside Cyprus mirroring its main server in parallel, and prove where that machine sits before it gets a licence. Betting records stay five years and cannot be deleted without permission.
Enforced by National Betting Authority
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the countryClass B (online) licensees must install a backup server inside Cyprus, connected in parallel to the main server. The Authority sets the maximum permitted copying lag by directive and may revise it at any time. Class A (shop) licensees' main and backup servers must be and remain installed in the Republic.
- Keep data for a minimum period — 5 yearsBetting slips and related documents. They may not be destroyed after five years without the Authority's prior approval.
- Register or notifyLicence applications are treated as incomplete without the physical storage location of the backup server, the storage contract and a monthly invoice from the storage provider.
- Secure the dataThe Authority must be given real-time access to the operator's computerised betting system through a web portal.
What it costs if you get it wrong
- Criminal liability: 1 year's imprisonment or €150,000, or both — about $163 thousandBreach of the record-keeping and system-approval articles
- Loss of your licenceFailure to meet licence conditions
Sources
- Official sourceNational Betting AuthorityThe Betting Law of 2019, Law 37(I)/2019 (official English text), articles 32(3), 53, 56 and 72-73
nba.gov.cy
“the equipment needed, including the electromechanical parts, the main and backup server and the software of the computerised betting slip marking system are and will remain installed in the Republic.”
Link checked 18 August 2026
- Official sourceNational Betting AuthorityDirective 03.2020 — data and information on the installation of a backup server for Class B licensed bookmakers
nba.gov.cy
“his obligation to install, in the territory of the Republic of Cyprus, a backup server, which will be connected in parallel with the main server”
Link checked 18 August 2026
- Official sourceNational Betting AuthorityNational Betting Authority — list of directives in force, including Directive 03.2020 on the backup server and Directive 13.2020 on books and records
nba.gov.cy
Link checked 18 August 2026
Ο περί Επεξεργασίας Δεδομένων Προσωπικού Χαρακτήρα και της Προστασίας της Ιδιωτικής Ζωής στον Τομέα των Ηλεκτρονικών Επικοινωνιών Νόμος του 2004
Act of parliament · Law 112(I)/2004 (in force since 2004), transposing Directive 2002/58/EC · Telecoms
Cyprus's electronic-communications privacy law governs cookies, marketing calls and messages, and phone and internet connection records. It contains no requirement that connection records be stored on the island.
Enforced by Commissioner for Personal Data Protection
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses
What it makes you do
- Get consentConsent for cookies and for unsolicited marketing. Unsolicited-communication complaints were 120 of the 531 complaints the Commissioner received in 2024 — the single largest category.
- Secure the data
- Delete data after a periodTraffic data must be erased or anonymised once no longer needed for transmission or billing.
Sources
- Official sourceOffice of the Commissioner for Personal Data ProtectionOther relevant laws — the Commissioner's own list, including Law 112(I)/2004 on privacy in electronic communications, the Artificial Intelligence Act implementation page and Law 122(I)/2025 implementing the Digital Services Act
gov.cy
Link checked 18 August 2026
- Official sourceOffice of the Commissioner for Personal Data ProtectionAnnual Report 2024 of the Commissioner for Personal Data Protection — 531 complaints, 94 breach notifications, 88 decisions, 21 fines totalling EUR 133,900
gov.cy
Link checked 18 August 2026
Κανονισμός για την Ψηφιακή Επιχειρησιακή Ανθεκτικότητα (DORA)
Directly binding regulation · Regulation (EU) 2022/2554 · Finance
Cypriot banks, payment firms, insurers and investment firms are governed on technology risk by the European digital resilience rules, not by any Cypriot storage-location rule. You must disclose where data sits; you do not have to keep it in Cyprus.
Enforced by Cyprus Securities and Exchange Commission
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Written vendor contractOutsourcing contracts must state the locations where data is processed and stored, and give audit and exit rights. This is disclosure, not localisation.
- Report cyber incidents
- Independent audit
Sources
- Official sourceEUR-LexRegulation (EU) 2022/2554 (DORA) — applies to financial entities since 17 January 2025
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceCyprus Securities and Exchange CommissionCyprus Securities and Exchange Commission — circulars index, which routes technology-resilience matters to a dedicated Digital Resilience (DORA) heading rather than to any Cypriot storage-location rule
cysec.gov.cy
Link checked 18 August 2026
- Official sourceCentral Bank of CyprusCentral Bank of Cyprus — banking supervision pages; no Cypriot data-localisation directive listed
centralbank.cy
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
The status of Cyprus's telecoms data-retention law, Law 183(I)/2007 (six-month retention of connection records for serious crime investigations)
The law is still on the statute book and we found its text on a non-government legal database, but the European directive it implements was annulled by the Court of Justice in 2014 and Cypriot courts are widely reported to have limited its access provisions. We could not locate either the law or any judgment on it on a Cyprus government or court domain during this run, so no rule is asserted for it here. Treat any claim that Cyprus enforces blanket telecoms retention as unverified.
Whether Cypriot public bodies are required to use a Cyprus-hosted government cloud
The Deputy Ministry of Research, Innovation and Digital Policy's document pages were blocked by the gov.cy web application firewall on every attempt on 18 August 2026. No public-sector localisation rule is asserted. Checked 18 August 2026, confidence medium that none exists in binding form.
The exact publication date of Law 60(I)/2025, which brought the NIS2 rules into Cypriot law
The consolidated text states the amending law enters into force on the date of its publication in the Official Gazette, and references a correction at Gazette Annex I(I) No. 5043, but the Digital Security Authority's page gives no date. The instrument is dated 2025 with high confidence and the exact day is unverified.
Cypriot minimum retention periods for tax records, company books and anti-money-laundering files, and whether any of them must be held physically in Cyprus
The Tax Department site was unreachable through the proxy and the Ministry of Finance site failed certificate validation on 18 August 2026. The Registrar of Companies publishes the Companies Law only behind a search interface we could not resolve to a document. The five-year betting-records floor is verified; the rest is not.
Whether any Cypriot banking or payments directive imposes a storage location beyond the European digital resilience rules
We reviewed the Central Bank of Cyprus banking supervision index and the Cyprus Securities and Exchange Commission circulars index and found no such rule, but neither site exposes a full-text search we could use, so this is an absence of evidence rather than evidence of absence. Confidence medium.
Whether the Commissioner has ever actually imposed 'explicit limits' on a transfer of sensitive data under section 17(2) or 18(3) of Law 125(I)/2018
The 2024 annual report shows her giving opinions on third-country transfers but we found no published order imposing limits. The power is verified; its use is not.
Whether any Cypriot rule governs mapping, geospatial or defence data storage
No searchable government source located for the Department of Lands and Surveys or the Ministry of Defence within this run. No rule asserted. Checked 18 August 2026.
Health-sector storage rules beyond the general law
The Ministry of Health site failed certificate validation through the proxy. The only health-specific evidence we have is the Commissioner's own 2024 opinion permitting a private hospital to use a United States cloud provider, and her EUR 46,500 fine against the State Health Services Organisation. No health localisation rule is asserted.
The exact commencement dates of the Betting Law of 2019 (Law 37(I)/2019) and of the electronic-communications privacy law (Law 112(I)/2004)
Neither official text we retrieved carries a commencement article we could read, and the Cyprus Official Gazette is not freely searchable. Both are in force with high confidence — the Betting Authority licenses under the 2019 law today, and the Commissioner lists the 2004 law as current — but the day-level dates are omitted rather than guessed.
90-day cadence: stable EU member with an active regulator and no phased commencement in the general law. Three dormant switches justify not going longer — the Commissioner's unused power to limit sensitive-data transfers, the uncommenced Article 8 of Law 60(I)/2025, and the Betting Authority's power to revise the backup-server specification by directive.
Freshness and refresh
Freshness
Checked today — on 18 August 2026.
Re-checked every 90 days. Next check due 16 November 2026.
Compare with
- Cyprus versus Argentina
- Cyprus versus Armenia
- Cyprus versus Australia
- Cyprus versus Austria
- Cyprus versus Azerbaijan
- Cyprus versus Brazil
- Cyprus versus Bulgaria
- Cyprus versus Cambodia
- Cyprus versus Canada
- Cyprus versus China
- Cyprus versus Croatia
- Cyprus versus Estonia
- Cyprus versus France
- Cyprus versus Georgia
- Cyprus versus Germany
- Cyprus versus Greece
- Cyprus versus Hong Kong SAR
- Cyprus versus Hungary
- Cyprus versus Iceland
- Cyprus versus India
- Cyprus versus Indonesia
- Cyprus versus Ireland
- Cyprus versus Israel
- Cyprus versus Italy
- Cyprus versus Japan
- Cyprus versus Latvia
- Cyprus versus Lithuania
- Cyprus versus Luxembourg
- Cyprus versus Malta
- Cyprus versus Mexico
- Cyprus versus Mongolia
- Cyprus versus Nepal
- Cyprus versus Netherlands
- Cyprus versus Poland
- Cyprus versus Russia
- Cyprus versus Saudi Arabia
- Cyprus versus Serbia
- Cyprus versus Singapore
- Cyprus versus Slovakia
- Cyprus versus Slovenia
- Cyprus versus South Korea
- Cyprus versus Spain
- Cyprus versus Sri Lanka
- Cyprus versus Sweden
- Cyprus versus Switzerland
- Cyprus versus Taiwan
- Cyprus versus Thailand
- Cyprus versus Turkey
- Cyprus versus Ukraine
- Cyprus versus United Arab Emirates
- Cyprus versus United Kingdom
- Cyprus versus United States
- Cyprus versus Uzbekistan