Skip to the content
Global Data RulesData governance rules, country by country

Cyprus

Part of the European Union, so bloc-wide rules apply here too. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Cyprus — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Depends on your industryWork: HighEnforcement: Active

For most businesses Cyprus works like a normal European country. Data can leave, as long as you use one of the standard European transfer tools. Two things make Cyprus stricter than its neighbours. If you move sensitive data such as health records out of Europe, you must tell the privacy regulator first. And breaking the privacy law in Cyprus is a crime, not just a fine.

Data governance in Cyprus

The eight things that decide how you handle data about people in Cyprus. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. You may have no office anywhere in Europe. If you sell to people in Cyprus, or watch what they do online, the European privacy rules still apply to you. The Cypriot regulator can act against you. There is no minimum size or turnover that gets you out. A company with no European base must name a written representative inside Europe. Cypriot law adds its own duties on top for anyone using data here.

What you have to do here:
Appoint a representative

Where the data is allowed to live

Yes, in general, with paperwork. Ordinary personal data leaves Cyprus on the same European terms as anywhere else in the bloc. But three Cypriot rules override that. Sensitive data going outside Europe must be reported to the regulator before it moves. Online betting operators must keep a mirror copy on a server inside Cyprus. And insurers cannot use genetic or fingerprint data at all for health or life cover.

What you have to do here:
Keep the data in the country

What to do: Check your own industry against the restricted list before you pick a hosting region.

Sending data out of the country

Cyprus uses an approved-destination list. You can send data to a country the European Commission has approved. Or you sign the European standard contract. Or you use approved group-wide rules. Cyprus adds one step of its own. If the data is sensitive, tell the regulator before it goes. If you rely on a narrow exception rather than a contract, do a written risk assessment and consult her first.

What you have to do here:
Put a transfer safeguard in place · Assess high-risk projects
Ways to send data out:
Official 'this country is safe' decision · Standard contract clauses · Approved group rules

What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.

The regulator, and whether it actually acts

The Commissioner for Personal Data Protection, and she is working. In 2024 her office took 531 complaints and 94 breach reports. It issued 88 decisions and fined in 21 of them. The fines totalled about 133,900 euros (roughly 146,000 US dollars). The biggest single penalty was 46,500 euros, against the state health services organisation. The current Commissioner is Maria Christofidou. A separate Digital Security Authority handles cyber incidents and is also active.

How long you must keep it — and when to delete it

There is no single national rule. The European maximum applies. Delete personal data once you no longer need it for the purpose you collected it for. Minimum periods come from industry law. Betting operators must keep betting slips and related documents for five years. After that they still cannot destroy them without the regulator's permission. Where a minimum and a maximum clash, the specific legal duty to keep the data wins. That only covers the data the duty actually applies to.

What you have to do here:
Keep data for a minimum period · Delete data after a period

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

Not fully verified — see “What we're not sure about” below.

If something goes wrong

Three deadlines apply, and you should start with the shortest. If you run an essential or important service, you have six hours to send a first warning to the Digital Security Authority. That is one of the tightest deadlines in Europe. It is far shorter than the 24 hours the European directive asked for. A full report follows within 72 hours, and a final one within a month. Separately, a personal data breach goes to the privacy regulator within 72 hours. You must also tell the affected people if the risk to them is high.

What you have to do here:
Report cyber incidents · Report breaches to the regulator · Tell affected people

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five things are not in the summary. (1) Breaking the privacy law in Cyprus is a crime. You face up to three years in prison, or five where national security is involved. The law puts the blame on the company's most senior executive personally. (2) A child is anyone under 14 here, not 16 as in some neighbouring countries. (3) Insurers may not use genetic or fingerprint-type data at all for health or life cover. (4) Sensitive data leaving Europe must be reported to the regulator first. (5) The cyber warning deadline is six hours, not 24.

What you have to do here:
Get a parent's consent for children · Put a transfer safeguard in place · Report cyber incidents · Keep records of how you use data
What it costs if you get it wrong:
Criminal liability

What's changing next

One European date matters most. From 12 January 2027 cloud providers must let customers move away with no exit or switching fees. Cyprus is also still bedding in its newest laws. The digital services law passed in 2025. The artificial intelligence rules are handled by the same privacy regulator, who now has three jobs instead of one. Also watch three powers the government can use with no warning.

What you have to do here:
Make switching cloud provider possible

What to do: Diarise 12 January 2027 — that is the date this changes.

Not fully verified — see “What we're not sure about” below.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries4 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Insurance

Insurance rules

Official name: Νόμος 125(Ι)/2018, άρθρο 9 — Επεξεργασία γενετικών και βιομετρικών δεδομένων · Law 125(I)/2018, section 9 · Act of parliament

In forceNo — it stays put

Health and life insurers in Cyprus may not use genetic or biometric data at all for insurance. The use itself is banned. No consent, contract or transfer tool makes it lawful.

In force since 31 July 2018

Enforced by Commissioner for Personal Data Protection

How this country controls where data goes: Not allowed

Online gaming

Online gaming data needs a copy kept in the country

Official name: Ο περί Στοιχημάτων Νόμος του 2019 · Law 37(I)/2019 (in force since 2019), articles 32(3), 53 and 56(1)(c), with National Betting Authority Directive 03.2020 (issued 2020, replacing Directive 13/2016) · Act of parliament

In forceA copy must stay

This is Cyprus's one real storage-location rule. An online bookmaker must run a backup server physically inside Cyprus. It must mirror the main server in parallel. You must prove where that machine sits before you get a licence. Betting records stay five years and cannot be deleted without permission.

Enforced by National Betting Authority

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Telecoms

Telecoms rules

Official name: Ο περί Επεξεργασίας Δεδομένων Προσωπικού Χαρακτήρα και της Προστασίας της Ιδιωτικής Ζωής στον Τομέα των Ηλεκτρονικών Επικοινωνιών Νόμος του 2004 · Law 112(I)/2004 (in force since 2004), transposing Directive 2002/58/EC · Act of parliament

In forceYes, with paperwork

Cyprus's electronic communications privacy law covers cookies, marketing calls and messages, and phone and internet connection records. It does not require connection records to be stored on the island.

Enforced by Commissioner for Personal Data Protection

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses

Not fully verified — see “What we're not sure about” below.

Applies to every company3 rules

These bind you whatever business you are in, once the country's rules reach you.

General data protection law (2018)

Official name: Ο περί της Προστασίας των Φυσικών Προσώπων Έναντι της Επεξεργασίας των Δεδομένων Προσωπικού Χαρακτήρα και της Ελεύθερης Κυκλοφορίας των Δεδομένων αυτών Νόμος του 2018 · Law 125(I)/2018, as amended by Law 26(I)/2022 · Act of parliament

In forceYes, with paperwork

Cyprus's national privacy law. It adds criminal liability on top of European fines. It puts that liability on the company's most senior executive. It sets the age of digital consent at 14.

In force since 31 July 2018

Enforced by Commissioner for Personal Data Protection

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules

Health data rules

Official name: Νόμος 125(Ι)/2018, Μέρος VII — Διαβίβαση ειδικών κατηγοριών δεδομένων σε τρίτη χώρα · Law 125(I)/2018, sections 17 and 18 · Act of parliament

In forceYes, with paperwork

This is Cyprus's own check on sensitive data leaving Europe. Health, genetic, biometric and similar data must be reported to the Commissioner before it moves. In some cases you must assess it and clear it with her first. She can set limits at any time.

In force since 31 July 2018

Enforced by Commissioner for Personal Data Protection

How this country controls where data goes: Approval each time · Accepted routes: Standard contract clauses, Approved group rules, Government sign-off needed, Explicit consent, Legal claims

Cyber security rules

Official name: Οι περί Ασφάλειας Δικτύων και Συστημάτων Πληροφοριών Νόμοι του 2020 και 2025 · Law 89(I)/2020 (Official Gazette No. 4770, 12 August 2020) as amended by Law 60(I)/2025, transposing Directive (EU) 2022/2555 · Act of parliament

Partly in forceYes — store it anywhere

Cyprus's cybersecurity law, updated in 2025 for the European NIS2 rules. It says nothing about where data must be stored. It sets a six-hour deadline for a first warning, one of the shortest in Europe. Breaking it is a crime. One part of the law is still waiting on a government notice before it starts.

In force since 12 August 2020

Enforced by Digital Security Authority

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Applies across the European Union2 rules

Written once for the whole bloc, and in force in every member country.

Europe's main privacy law

Official name: Γενικός Κανονισμός για την Προστασία Δεδομένων (General Data Protection Regulation) · Regulation (EU) 2016/679 · Directly binding regulation

In forceYes, with paperwork

The European privacy rulebook applies directly in Cyprus. It does not require data to stay in Europe. It sets the conditions for sending it out. Fines rise with the worldwide turnover of your group.

In force since 24 May 2016Enforced from 25 May 2018

Enforced by Commissioner for Personal Data Protection

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims

General data protection law

Official name: Κανονισμός για την ελεύθερη ροή δεδομένων μη προσωπικού χαρακτήρα · Regulation (EU) 2018/1807 · Directly binding regulation

In forceYes — store it anywhere

Cyprus may not require non-personal data to be stored on the island. The only exception is where it can show a real public security reason. That is why Cypriot storage-location rules are so rare.

In force since 18 December 2018Enforced from 28 May 2019

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Who you would hear from

  • Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα

    General privacy law, the electronic-communications privacy law, the law-enforcement data law, and now the Artificial Intelligence Act and the Digital Services Act

    Fully operational. In 2024 the office handled 531 complaints and 94 breach reports. It issued 88 decisions and imposed fines in 21 of them, totalling 133,900 euros. The largest was 46,500 euros against the State Health Services Organisation. Decisions are published in batches. The latest published batch covers January to April 2025. The current Commissioner is Maria Christofidou. Her predecessor, Irini Loizidou Nicolaidou, served as Deputy Chair of the European Data Protection Board and signed the 2024 annual report.

  • Αρχή Ψηφιακής Ασφάλειας

    Cybersecurity, essential and important entities, electronic communications providers

    Staffed and visibly active. It ran a chief information security officer training programme in August 2026. It took part in European cybersecurity exercises in June 2026. One caveat. Its public NIS page still describes the categories of operator used before 2025, so its published guidance is behind the amended law. The law expects a merger with the Office of the Commissioner of Electronic Communications, but no date is set.

  • Εθνική Αρχή Στοιχημάτων

    Betting and online gambling, including the Cyprus backup-server requirement

    Operational and issuing binding directives. It keeps live registers of licensees and a blocking list of unlicensed sites.

  • Επιτροπή Κεφαλαιαγοράς Κύπρου

    Investment firms, funds, crypto-asset service providers, administrative service providers

    Active. It publishes circulars, board decisions and penalties. It runs a dedicated digital resilience workstream under the European Digital Operational Resilience Act.

  • Κεντρική Τράπεζα της Κύπρου

    Banks, payment and electronic money institutions

  • Γραφείο Επιτρόπου Ρυθμίσεως Ηλεκτρονικών Επικοινωνιών και Ταχυδρομείων

    Telecoms and postal regulation; supervises the Digital Security Authority

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • The status of Cyprus's telecoms data-retention law, Law 183(I)/2007 (six-month retention of connection records for serious crime investigations)

    We could not confirm whether Cyprus still enforces blanket telecoms data retention. The law is still on the statute book, and we found its text on a non-government legal database. But the European directive it implements was annulled by the Court of Justice in 2014. Cypriot courts are widely reported to have limited its access rules. We found neither the law nor any judgment on it on a Cyprus government or court website. So we assert no rule here. If you are a telecoms operator, check before you rely on this.

  • Whether Cypriot public bodies are required to use a Cyprus-hosted government cloud

    We could not confirm whether government data must stay in Cyprus. The Deputy Ministry of Research, Innovation and Digital Policy's document pages were blocked by the gov.cy web firewall on every attempt on 18 August 2026. We assert no public sector storage-location rule. Checked 18 August 2026, with medium confidence that none exists in binding form.

  • The exact publication date of Law 60(I)/2025, which brought the NIS2 rules into Cypriot law

    We could not confirm the exact start date of the amending law. The consolidated text says it starts on the day it is published in the Official Gazette. It refers to a correction at Gazette Annex I(I) No. 5043. But the Digital Security Authority's page gives no date. We are confident the law dates from 2025. The exact day is unconfirmed.

  • Cypriot minimum retention periods for tax records, company books and anti-money-laundering files, and whether any of them must be held physically in Cyprus

    We could not confirm Cyprus's tax and company law record-keeping periods. The Tax Department site was unreachable through the proxy. The Ministry of Finance site failed certificate checks on 18 August 2026. The Registrar of Companies publishes the Companies Law only behind a search box we could not resolve to a document. The five-year betting records minimum is confirmed. The rest is not. Check with a Cypriot adviser.

  • Whether any Cypriot banking or payments directive imposes a storage location beyond the European digital resilience rules

    We found no rule of this kind, but we could not search thoroughly. We reviewed the Central Bank of Cyprus banking supervision index and the Cyprus Securities and Exchange Commission circulars index and found nothing. Neither site offers a full-text search we could use. So this is missing evidence rather than proof that no rule exists. Confidence medium.

  • Whether the Commissioner has ever actually imposed 'explicit limits' on a transfer of sensitive data under section 17(2) or 18(3) of Law 125(I)/2018

    We could not confirm that the Commissioner has ever used this power. Her 2024 annual report shows her giving opinions on transfers to other countries. We found no published order setting limits. The power itself is confirmed. Its use is not.

  • Whether any Cypriot rule governs mapping, geospatial or defence data storage

    We could not confirm whether any rule applies here. We found no searchable government source for the Department of Lands and Surveys or the Ministry of Defence. We assert no rule. Checked 18 August 2026.

  • Health-sector storage rules beyond the general law

    We could not confirm whether health data must stay in Cyprus. The Ministry of Health site failed certificate checks through the proxy. The only health-specific evidence we have is the Commissioner's 2024 opinion allowing a private hospital to use a United States cloud provider. We also have her 46,500 euro fine against the State Health Services Organisation. We assert no health storage-location rule. If you handle patient data, check with the ministry.

  • The exact commencement dates of the Betting Law of 2019 (Law 37(I)/2019) and of the electronic-communications privacy law (Law 112(I)/2004)

    We could not confirm the exact start dates of these two laws. Neither official text we retrieved carries a start article we could read. The Cyprus Official Gazette is not freely searchable. We are confident both are in force. The Betting Authority licenses under the 2019 law today, and the Commissioner lists the 2004 law as current. We have left the day-level dates out rather than guess them.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 90 days. Next check due 16 November 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.