Skip to the content
Global Data RulesData governance rules, country by country

Greece

Part of the European Union, so bloc-wide rules apply here too. Checked today.

The answer

Depends on your industryWork: HighEnforcement: Active

For most businesses Greece is a normal European country: personal data can leave, as long as you use one of the standard European transfer tools. But Greece has two hard walls that Europe does not. Phone and internet connection records must physically sit on machines inside Greece. Online gambling operators must keep their records on a server inside Greece too. The privacy regulator is fully staffed and fining companies today.

Eight questions about Greece

The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.

Do Greece's rules apply to my company?

Yes, it reaches a foreign company with no office in Greece. The European privacy rules apply to anyone anywhere who offers goods or services to people in Greece, or who watches what they do online. The Greek national law adds that it also covers anyone processing data on Greek soil. There is no size or revenue threshold that lets you off. If you have no establishment anywhere in Europe, you must appoint a written representative inside the European Union.

High confidenceNational rulesBloc rulesAppoint a local representative

Can I store my users' data outside Greece?

In general, yes. Greece adds no storage-location rule of its own to the European baseline, so ordinary business data can be sent abroad once you have the right European transfer paperwork. Three industries break that rule completely. Telecoms companies must keep their connection records on machines physically inside Greece. Online gambling operators must keep their records on a server inside Greece. And Greek government bodies must run their main systems on state-operated clouds. Health, banking and insurance have extra hoops but no location rule.

High confidenceDepends on your industryNo — it stays putYes, with paperworkTelecomsOnline gamingGovernmentHealth and social careFinance

What do I need in place before data leaves Greece?

You need one of the standard European transfer tools before data leaves Europe. The simplest is sending it to a country the European Commission has already approved. If the destination is not approved, you sign the European Commission's standard contract with the recipient, or use approved group-wide internal rules, and you write down why you think the data will still be safe there. Greece adds no extra permission, filing or fee of its own.

High confidenceAllowlistOfficial 'this country is safe' decisionStandard contract clausesApproved group rulesExplicit consentNeeded for a contractLegal claims

Who enforces the rules in Greece, and what can they do?

Six bodies, and all six are genuinely working. The Hellenic Data Protection Authority is the main privacy regulator and is issuing numbered decisions and fines every month — its most recent published decisions run to July 2026 and include fines on a bank and an electricity supplier. A separate constitutional authority polices the secrecy of communications. There is also a national cybersecurity authority, a telecoms regulator, the central bank for finance and insurance, and a gambling regulator. This is not a paper regime.

High confidenceActive

How long do I have to keep the data?

Both directions apply, and they collide. Business books must be kept five years. Medical files must be kept ten years in a private practice and twenty years everywhere else. Online gambling records must be kept ten years. Telecoms connection records must be kept exactly twelve months and then automatically deleted. In the other direction, the European rule says you must not keep personal data longer than you need it. When a specific keeping rule and the general deleting rule clash, the specific keeping rule wins.

High confidenceKeep data for a minimum periodDelete data after a periodKeep logsAllowed because the law requires it

What happens if there is a breach?

Count three clocks, not one. If personal data is lost or exposed, you have 72 hours to tell the privacy regulator. If you run important infrastructure, you have only 24 hours to send a first warning to the national cybersecurity authority, then 72 hours for a fuller report and one month for the final one. If you are a phone or internet provider, you have 24 hours to report a personal data breach and a separate duty to tell the communications secrecy authority. Missing the 24-hour clocks is the most common failure.

High confidenceReport breaches to the regulatorTell affected peopleReport cyber incidents

What trips people up in Greece?

Five things that will cost you a weekend. First, a child in Greece can consent to an online service at fifteen, not sixteen — so an age gate built to the European default is set wrong. Second, misusing personal data is a crime here, with prison time, not just a fine. Third, several articles of the Greek privacy law are printed in the statute but the regulator has formally said they must not be applied, because they clash with European law. Fourth, telecoms connection records must physically stay in Greece. Fifth, government bodies cannot simply pick a commercial cloud.

High confidenceGet a parent's consent for childrenCriminal liabilityUnenforceableKeep the data in the countryChildren's dataTelecom network data

What is changing soon in Greece?

Three dated changes. Electronic invoicing between businesses became compulsory for large Greek companies on 2 March 2026 and becomes compulsory for everyone else on 1 October 2026. Greece's new artificial intelligence law took effect on 22 July 2026 and forces public bodies to register every artificial intelligence system before switching it on. And from 12 January 2027 European law bans cloud providers from charging you to move your data out.

High confidenceIn forceProposedArtificial intelligence

The rules, layer by layer

Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.

  1. Layer 1

    Bloc rules

    Made by a group of countries together. Applies inside every member country.

    1 rule here

  2. Layer 2

    National rules

    Added by this country on top of any bloc rules.

    4 rules here

  3. Layer 3

    Industry rules

    Made by an industry regulator. These usually beat the general position.

    7 rules here

Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.

Bloc rules1 rule

Γενικός Κανονισμός για την Προστασία Δεδομένων (General Data Protection Regulation)

Directly binding regulation · Regulation (EU) 2016/679

In forceYes, with paperwork

The European privacy rules apply in Greece directly. They do not require data to stay in Europe; they set conditions for letting it leave. Fines scale with the worldwide turnover of the whole group.

In force since 24 May 2016But only enforceable from 25 May 2018

Enforced by Hellenic Data Protection Authority

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims

High confidence

National rules4 rules

Νόμος 4624/2019 — Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα, μέτρα εφαρμογής του Κανονισμού (ΕΕ) 2016/679

Act of parliament · Law 4624/2019, Gazette A 137 of 29 August 2019

In forceYes, with paperwork

Greece's national privacy law sits on top of the European rules. It adds no storage-location requirement, but it lowers the age of a child's own consent to 15 and makes misuse of personal data a criminal offence with prison time attached.

In force since 29 August 2019

Enforced by Hellenic Data Protection Authority

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules

High confidence

Νόμος 4624/2019, άρθρα 5, 6 παρ. 6-8, 22, 24, 25, 26 και 27

Act of parliament · Law 4624/2019, Articles 5, 6(6)-(8), 22, 24, 25, 26, 27; assessed in HDPA Opinion 1/2020 of 24 January 2020

UnenforceableYes, with paperwork

Several articles of the Greek privacy law are still printed in the statute but the privacy regulator has formally said they clash with European law and must not be applied. They cover public-sector processing, data protection officers, special categories of data, reuse of data for new purposes, and employee data.

In force since 29 August 2019

Enforced by Hellenic Data Protection Authority

High confidence

Νόμος 5160/2024 — Ενσωμάτωση της Οδηγίας (ΕΕ) 2022/2555 (NIS2)

Act of parliament · Law 5160/2024, Gazette A 195 of 27 November 2024

In forceYes — store it anywhere

Greece's cybersecurity law applies to operators of important services and their suppliers. It imposes no storage-location rule, but it does impose a 24-hour first warning that runs faster than the 72-hour privacy clock.

In force since 27 November 2024

Enforced by National Cybersecurity Authority

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Industry rules7 rules

Νόμος 3917/2011 — Διατήρηση δεδομένων που παράγονται ή υποβάλλονται σε επεξεργασία σε συνάρτηση με την παροχή υπηρεσιών ηλεκτρονικών επικοινωνιών

Act of parliament · Law 3917/2011, Gazette A 22 of 21 February 2011, Article 6 (as amended by Article 96 of Law 4139/2013) · Telecoms

In forceNo — it stays put

Greek phone and internet providers must keep who-called-whom, where and when records for twelve months, and must keep them on machines physically inside Greece. This is a real localisation rule with no European equivalent.

In force since 21 February 2011

Enforced by Hellenic Authority for Communication Security and Privacy

Transfer model: Not allowed

High confidence

Νόμος 4002/2011 — Ρύθμιση της αγοράς παιγνίων, άρθρο 47, και Κανονισμοί Παιγνίων (ΥΑ 79305/2020 και 79835/2020)

Act of parliament · Law 4002/2011, Article 47, as amended by Law 4635/2019; Ministerial Decisions 79305 EX 2020 and 79835 EX 2020 · Online gaming

In forceNo — it stays put

An online gambling operator licensed in Greece must store its records on a server or safe physically located in Greece and keep them for ten years. A licence is required to serve Greek players at all.

In force since 22 August 2011But only enforceable from 5 August 2020

Enforced by Hellenic Gaming Commission

Transfer model: Not allowed

Medium confidence

Νόμος 4727/2020 — Ψηφιακή Διακυβέρνηση, άρθρο 87 (Κυβερνητικά νέφη)

Act of parliament · Law 4727/2020, Article 87, Gazette A 184 of 23 September 2020 · Government

In forceNo — it stays put

Greek public bodies had to move their central computer systems into the Greek state's own clouds by 1 January 2022. Defence, foreign affairs, the intelligence service, civil protection, the coastguard, the tax authority and academic bodies are exempt.

In force since 23 September 2020But only enforceable from 1 January 2022

Enforced by Ministry of Digital Governance

Transfer model: Approval each time

Medium confidence

Who you would hear from

  • Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα

    General privacy law, all sectors

    Fully constituted and issuing numbered decisions continuously. Published acts run to decision 14 of 15 July 2026. Decision 8 of 5 June 2026 imposed fines on an electricity supplier and a bank. It fined Clearview AI, a US company with no European establishment, EUR 20 million in July 2022. It also issues opinions that constrain the Greek legislature, most notably Opinion 1/2020.

  • Αρχή Διασφάλισης του Απορρήτου των Επικοινωνιών (ΑΔΑΕ)

    Secrecy of communications, telecoms data retention, lawful interception oversight

    A second constitutionally entrenched independent authority. Issued a new binding security regulation for providers in August 2025 (Decision 304/2025) and was convening enforcement hearings in January 2026.

  • Εθνική Αρχή Κυβερνοασφάλειας

    Cybersecurity, incident reporting under Law 5160/2024, national computer security incident response team

    Operating and publishing reporting guidance; designated as the national incident response team under Law 5160/2024.

  • Επιτροπή Εποπτείας και Ελέγχου Παιγνίων (ΕΕΕΠ)

    Licensing and supervision of gambling, including online gambling

    Runs the online licensing system and publishes licence and suitability decisions.

  • Τράπεζα της Ελλάδος

    Banking, insurance and payments supervision, including outsourcing arrangements

  • Ανεξάρτητη Αρχή Δημοσίων Εσόδων (ΑΑΔΕ)

    Tax records, electronic invoicing and the myDATA electronic books platform

  • Υπουργείο Ψηφιακής Διακυβέρνησης

    Digital governance policy, the government cloud programme, public-sector information systems

  • Ειδική Γραμματεία Τεχνητής Νοημοσύνης και Διακυβέρνησης Δεδομένων

    National implementation of the European artificial intelligence rules under Law 5321/2026

    Newly established. Announced the national artificial intelligence framework in July 2026; the supervisory machinery it creates is still bedding in.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • The exact wording of Article 47 of Law 4002/2011 requiring an online gambling operator to store records on a server or safe located in Greece

    The verbatim Greek text was verified only on a commercial consolidated-law database. The Hellenic Gaming Commission's own website blocks automated retrieval on most paths, so we could not obtain the gazette copy from a government host. The rule is therefore recorded at medium confidence, with the regulator's own licensing page as the government backlink.

  • Whether Article 87 of Law 4727/2020 imposes a geographic requirement, as opposed to a requirement to use named Greek state operators

    The article names the operators (the General Secretariat for Information Systems, the national research network body and the state health IT company) but does not spell out that the infrastructure must be physically in Greece. We rate the effect as closed because those clouds are state-run domestic infrastructure, but the statute itself is silent on geography and we could not retrieve the text from a government host.

  • Whether Greek courts are still applying the telecoms retention duty in Law 3917/2011 in full

    Independent analysis published in September 2025 argues Articles 1, 3, 5 and 6 are contrary to the EU Court's rulings on general and indiscriminate retention. We found no Greek court decision disapplying them, and no repeal. The duty is therefore recorded as in force, but a court could disapply it without warning, and we could not verify current prosecutorial practice from an official source.

  • The precise designated authorities, penalty levels and commencement dates under Law 5321/2026 on artificial intelligence

    The government announcement confirms the law and its date but does not name the market surveillance authority, the notifying authority or the single point of contact, and does not publish the transitional dates. The gazette text was not retrievable during this run.

  • Whether the Bank of Greece outsourcing act contains any data-location condition in its full text

    We verified the notification-not-approval rule from the Bank of Greece's own press release. We did not retrieve the full text of Executive Committee Act 178/5/2.10.2020, so a location condition buried in an annex cannot be excluded.

  • Whether any Greece-specific restriction applies to detailed mapping, aerial imagery or geospatial data leaving the country

    No such restriction was found, checked 18 August 2026. The Hellenic Military Geographical Service publishes copyright and licensing terms rather than a residency rule, and we did not verify whether military-sensitive imagery carries separate export controls.

  • Whether any sector rule applies to securities firms or account aggregation beyond the directly applicable European financial resilience rules

    We did not separately search the Hellenic Capital Market Commission's rulebook within this run's budget. No localisation rule is expected, but this is an untested gap rather than a verified negative.

Freshness and refresh

Freshness

Checked today — on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

Compare with

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.