Skip to the content
Global Data RulesData governance rules, country by country

Cyprus

Part of the European Union, so bloc-wide rules apply here too. Checked today.

The answer

Depends on your industryWork: HighEnforcement: Active

For most businesses Cyprus behaves like a normal European country: data can leave, provided you use one of the standard European transfer tools. Two things make it stricter than its neighbours. If you move sensitive data such as health records out of Europe, you must tell the privacy regulator first. And breaking the privacy law in Cyprus is a crime, not just a fine.

Eight questions about Cyprus

The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.

Do Cyprus' rules apply to my company?

Yes. If you have no office anywhere in Europe but you sell to people in Cyprus, or you watch what they do online, the European privacy rules reach you and the Cypriot regulator can act. There is no minimum size or turnover that lets you escape. A company with no European base must name a written representative inside Europe, and the Cypriot law adds its own duties on top for anyone processing data here.

High confidenceBloc rulesNational rulesAppoint a local representative

Can I store my users' data outside Cyprus?

In general yes, with paperwork. Ordinary personal data leaves Cyprus on the same European terms as anywhere else in the bloc. But three Cypriot rules override that. Sensitive data going outside Europe must be notified to the regulator before it moves. Online betting operators must keep a mirror copy on a server inside Cyprus. And insurers cannot process genetic or fingerprint data for health or life cover at all.

High confidenceDepends on your industryAllowlistKeep the data in the country

What do I need in place before data leaves Cyprus?

The model is an approved-destination list. Data may go to a country the European Commission has approved, or you sign the European standard contract, or you use approved group-wide rules. Cyprus adds one step of its own: if the data is sensitive, tell the regulator before it goes, and if you are relying on a narrow exception rather than a contract, do a written risk assessment and consult her first.

High confidenceAllowlistOfficial 'this country is safe' decisionStandard contract clausesApproved group rulesPut a transfer safeguard in placeAssess high-risk projects

Who enforces the rules in Cyprus, and what can they do?

The Commissioner for Personal Data Protection, and she is genuinely working. In 2024 her office took 531 complaints and 94 breach reports, issued 88 decisions, and fined in 21 of them, totalling about 133,900 euros (roughly $146,000). The biggest single penalty, 46,500 euros, went to the state health services organisation. The current Commissioner is Maria Christofidou. A separate Digital Security Authority handles cyber incidents and is also active.

High confidenceActive

How long do I have to keep the data?

There is no single national rule. The European ceiling applies: delete personal data once you no longer need it for the purpose you collected it for. The floors come from sector law. Betting operators must keep betting slips and related documents for five years, and may not destroy them afterwards without the regulator's permission. Where a floor and the ceiling collide, the specific legal duty to keep wins, but only for the data that duty actually covers.

Medium confidenceKeep data for a minimum periodDelete data after a period

What happens if there is a breach?

Count three clocks and start with the shortest. If you run an essential or important service, Cyprus gives you SIX HOURS to send a first warning to the Digital Security Authority — one of the tightest deadlines in Europe, and far shorter than the 24 hours the European directive asked for. A full report follows within 72 hours and a final one within a month. Separately, a personal data breach goes to the privacy regulator within 72 hours, and to affected people if the risk to them is high.

High confidenceReport cyber incidentsReport breaches to the regulatorTell affected people

What trips people up in Cyprus?

Five things that are not in the summary. (1) Breaking the privacy law in Cyprus is a crime — up to three years in prison, or five where national security is touched — and the law puts the blame on the company's most senior executive personally. (2) A child is anyone under 14 here, not 16 as in some neighbours. (3) Insurers may not use genetic or fingerprint-type data for health or life cover at all. (4) Sensitive data leaving Europe must be notified to the regulator first. (5) The cyber warning deadline is six hours, not 24.

High confidenceCriminal liabilityGet a parent's consent for childrenPut a transfer safeguard in placeReport cyber incidentsKeep records of processing

What is changing soon in Cyprus?

One hard European date matters most: from 12 January 2027 cloud providers must let customers move away with no exit or switching fees. Cyprus is also still building out its newest laws — the digital services law passed in 2025 and the artificial intelligence rules are being bedded in by the same privacy regulator, who now has three jobs instead of one. Watch three switches the government can flip with no warning.

Medium confidencePartly in forceMake switching cloud provider possible

The rules, layer by layer

Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.

  1. Layer 1

    Bloc rules

    Made by a group of countries together. Applies inside every member country.

    2 rules here

  2. Layer 2

    National rules

    Added by this country on top of any bloc rules.

    3 rules here

  3. Layer 3

    Industry rules

    Made by an industry regulator. These usually beat the general position.

    4 rules here

Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.

Bloc rules2 rules

Γενικός Κανονισμός για την Προστασία Δεδομένων (General Data Protection Regulation)

Directly binding regulation · Regulation (EU) 2016/679

In forceYes, with paperwork

The European privacy rulebook applies directly in Cyprus. It does not require data to stay in Europe; it sets the conditions for sending it out. Fines scale with worldwide group turnover.

In force since 24 May 2016But only enforceable from 25 May 2018

Enforced by Commissioner for Personal Data Protection

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims

High confidence

Κανονισμός για την ελεύθερη ροή δεδομένων μη προσωπικού χαρακτήρα

Directly binding regulation · Regulation (EU) 2018/1807

In forceYes — store it anywhere

Cyprus is forbidden from requiring non-personal data to be stored on the island, except where it can show a genuine public-security reason. This is why Cypriot storage-location rules are so rare.

In force since 18 December 2018But only enforceable from 28 May 2019

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

National rules3 rules

Ο περί της Προστασίας των Φυσικών Προσώπων Έναντι της Επεξεργασίας των Δεδομένων Προσωπικού Χαρακτήρα και της Ελεύθερης Κυκλοφορίας των Δεδομένων αυτών Νόμος του 2018

Act of parliament · Law 125(I)/2018, as amended by Law 26(I)/2022

In forceYes, with paperwork

Cyprus's national privacy statute. It adds criminal liability on top of European fines, pins that liability on the company's most senior executive, and sets the age of digital consent at 14.

In force since 31 July 2018

Enforced by Commissioner for Personal Data Protection

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules

High confidence

Νόμος 125(Ι)/2018, Μέρος VII — Διαβίβαση ειδικών κατηγοριών δεδομένων σε τρίτη χώρα

Act of parliament · Law 125(I)/2018, sections 17 and 18

In forceYes, with paperwork

Cyprus's own gate on sensitive data leaving Europe. Health, genetic, biometric and similar data must be notified to the Commissioner before it moves, or assessed and cleared with her first, and she can order limits at any time.

In force since 31 July 2018

Enforced by Commissioner for Personal Data Protection

Transfer model: Approval each time · Accepted routes: Standard contract clauses, Approved group rules, Government sign-off needed, Explicit consent, Legal claims

High confidence

Οι περί Ασφάλειας Δικτύων και Συστημάτων Πληροφοριών Νόμοι του 2020 και 2025

Act of parliament · Law 89(I)/2020 (Official Gazette No. 4770, 12 August 2020) as amended by Law 60(I)/2025, transposing Directive (EU) 2022/2555

Partly in forceYes — store it anywhere

Cyprus's cybersecurity law, updated in 2025 for the European NIS2 rules. It imposes no storage-location duty but sets a six-hour first-warning deadline, one of the shortest in Europe, backed by criminal liability. One provision is still waiting on a government notice to commence.

In force since 12 August 2020

Enforced by Digital Security Authority

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Industry rules4 rules

Νόμος 125(Ι)/2018, άρθρο 9 — Επεξεργασία γενετικών και βιομετρικών δεδομένων

Act of parliament · Law 125(I)/2018, section 9 · Insurance

In forceNo — it stays put

Health and life insurers in Cyprus may not process genetic or biometric data at all for insurance purposes. Because the processing itself is banned, no consent, contract or transfer tool makes it lawful.

In force since 31 July 2018

Enforced by Commissioner for Personal Data Protection

Transfer model: Not allowed

High confidence

Ο περί Στοιχημάτων Νόμος του 2019

Act of parliament · Law 37(I)/2019 (in force since 2019), articles 32(3), 53 and 56(1)(c), with National Betting Authority Directive 03.2020 (issued 2020, replacing Directive 13/2016) · Online gaming

In forceA copy must stay

Cyprus's one true storage-location rule. An online bookmaker must run a backup server physically inside Cyprus mirroring its main server in parallel, and prove where that machine sits before it gets a licence. Betting records stay five years and cannot be deleted without permission.

Enforced by National Betting Authority

Transfer model: Approval each time · Accepted routes: Government sign-off needed

High confidence

Ο περί Επεξεργασίας Δεδομένων Προσωπικού Χαρακτήρα και της Προστασίας της Ιδιωτικής Ζωής στον Τομέα των Ηλεκτρονικών Επικοινωνιών Νόμος του 2004

Act of parliament · Law 112(I)/2004 (in force since 2004), transposing Directive 2002/58/EC · Telecoms

In forceYes, with paperwork

Cyprus's electronic-communications privacy law governs cookies, marketing calls and messages, and phone and internet connection records. It contains no requirement that connection records be stored on the island.

Enforced by Commissioner for Personal Data Protection

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses

Medium confidence

Who you would hear from

  • Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα

    General privacy law, the electronic-communications privacy law, the law-enforcement data law, and now the Artificial Intelligence Act and the Digital Services Act

    Fully operational. In 2024 the office handled 531 complaints and 94 breach notifications, issued 88 decisions and imposed fines in 21 of them totalling EUR 133,900, the largest being EUR 46,500 against the State Health Services Organisation. Decisions are published in batches; the latest published batch covers January to April 2025. Current Commissioner: Maria Christofidou. Her predecessor, Irini Loizidou Nicolaidou, served as Deputy Chair of the European Data Protection Board and signed the 2024 annual report.

  • Αρχή Ψηφιακής Ασφάλειας

    Cybersecurity, essential and important entities, electronic communications providers

    Staffed and visibly active — running a chief information security officer training programme in August 2026 and taking part in European cybersecurity exercises in June 2026. Caveat: its public NIS implementation page still describes the pre-2025 categories of operator, so published guidance lags the amended statute. A merger with the Office of the Commissioner of Electronic Communications is anticipated in the law's transitional provisions but has no date.

  • Εθνική Αρχή Στοιχημάτων

    Betting and online gambling, including the Cyprus backup-server requirement

    Operational and issuing binding directives; maintains live licensee registers and a blocking list of unlicensed sites.

  • Επιτροπή Κεφαλαιαγοράς Κύπρου

    Investment firms, funds, crypto-asset service providers, administrative service providers

    Active. Publishes circulars, board decisions and administrative sanctions, and runs a dedicated digital-resilience workstream under the European DORA regime.

  • Κεντρική Τράπεζα της Κύπρου

    Banks, payment and electronic money institutions

  • Γραφείο Επιτρόπου Ρυθμίσεως Ηλεκτρονικών Επικοινωνιών και Ταχυδρομείων

    Telecoms and postal regulation; supervises the Digital Security Authority

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • The status of Cyprus's telecoms data-retention law, Law 183(I)/2007 (six-month retention of connection records for serious crime investigations)

    The law is still on the statute book and we found its text on a non-government legal database, but the European directive it implements was annulled by the Court of Justice in 2014 and Cypriot courts are widely reported to have limited its access provisions. We could not locate either the law or any judgment on it on a Cyprus government or court domain during this run, so no rule is asserted for it here. Treat any claim that Cyprus enforces blanket telecoms retention as unverified.

  • Whether Cypriot public bodies are required to use a Cyprus-hosted government cloud

    The Deputy Ministry of Research, Innovation and Digital Policy's document pages were blocked by the gov.cy web application firewall on every attempt on 18 August 2026. No public-sector localisation rule is asserted. Checked 18 August 2026, confidence medium that none exists in binding form.

  • The exact publication date of Law 60(I)/2025, which brought the NIS2 rules into Cypriot law

    The consolidated text states the amending law enters into force on the date of its publication in the Official Gazette, and references a correction at Gazette Annex I(I) No. 5043, but the Digital Security Authority's page gives no date. The instrument is dated 2025 with high confidence and the exact day is unverified.

  • Cypriot minimum retention periods for tax records, company books and anti-money-laundering files, and whether any of them must be held physically in Cyprus

    The Tax Department site was unreachable through the proxy and the Ministry of Finance site failed certificate validation on 18 August 2026. The Registrar of Companies publishes the Companies Law only behind a search interface we could not resolve to a document. The five-year betting-records floor is verified; the rest is not.

  • Whether any Cypriot banking or payments directive imposes a storage location beyond the European digital resilience rules

    We reviewed the Central Bank of Cyprus banking supervision index and the Cyprus Securities and Exchange Commission circulars index and found no such rule, but neither site exposes a full-text search we could use, so this is an absence of evidence rather than evidence of absence. Confidence medium.

  • Whether the Commissioner has ever actually imposed 'explicit limits' on a transfer of sensitive data under section 17(2) or 18(3) of Law 125(I)/2018

    The 2024 annual report shows her giving opinions on third-country transfers but we found no published order imposing limits. The power is verified; its use is not.

  • Whether any Cypriot rule governs mapping, geospatial or defence data storage

    No searchable government source located for the Department of Lands and Surveys or the Ministry of Defence within this run. No rule asserted. Checked 18 August 2026.

  • Health-sector storage rules beyond the general law

    The Ministry of Health site failed certificate validation through the proxy. The only health-specific evidence we have is the Commissioner's own 2024 opinion permitting a private hospital to use a United States cloud provider, and her EUR 46,500 fine against the State Health Services Organisation. No health localisation rule is asserted.

  • The exact commencement dates of the Betting Law of 2019 (Law 37(I)/2019) and of the electronic-communications privacy law (Law 112(I)/2004)

    Neither official text we retrieved carries a commencement article we could read, and the Cyprus Official Gazette is not freely searchable. Both are in force with high confidence — the Betting Authority licenses under the 2019 law today, and the Commissioner lists the 2004 law as current — but the day-level dates are omitted rather than guessed.

90-day cadence: stable EU member with an active regulator and no phased commencement in the general law. Three dormant switches justify not going longer — the Commissioner's unused power to limit sensitive-data transfers, the uncommenced Article 8 of Law 60(I)/2025, and the Betting Authority's power to revise the backup-server specification by directive.

Freshness and refresh

Freshness

Checked today — on 18 August 2026.

Re-checked every 90 days. Next check due 16 November 2026.

Read the exact prompt used to research this page

Compare with

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.