Greece
Part of the European Union, so bloc-wide rules apply here too. Checked today.
The answer
For most businesses Greece is a normal European country: personal data can leave, as long as you use one of the standard European transfer tools. But Greece has two hard walls that Europe does not. Phone and internet connection records must physically sit on machines inside Greece. Online gambling operators must keep their records on a server inside Greece too. The privacy regulator is fully staffed and fining companies today.
Eight questions about Greece
The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.
Do Greece's rules apply to my company?
Yes, it reaches a foreign company with no office in Greece. The European privacy rules apply to anyone anywhere who offers goods or services to people in Greece, or who watches what they do online. The Greek national law adds that it also covers anyone processing data on Greek soil. There is no size or revenue threshold that lets you off. If you have no establishment anywhere in Europe, you must appoint a written representative inside the European Union.
Article 3 of Law 4624/2019 extends the national rules to controllers and processors processing personal data in Greek territory, to processing at a Greek establishment, and otherwise where the General Data Protection Regulation applies. Article 3(2) GDPR supplies the extraterritorial hook (offering goods or services, or monitoring behaviour); Article 27 GDPR supplies the EU-representative duty, with the narrow exemptions in Article 27(2). Greece has not legislated any additional Greece-specific representative or registration requirement for foreign controllers. The Hellenic Data Protection Authority has in practice asserted jurisdiction over foreign controllers with no Greek establishment — its EUR 20 million fine on Clearview AI, a US company with no EU presence, is the clearest example.
Sources
- Official sourceHellenic Data Protection AuthorityLaw 4624/2019, Article 3 (scope) — English translation published by the regulator
dpa.gr
“the controller or processor processes personal data in the Greek territory”
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679 (General Data Protection Regulation), Articles 3 and 27
eur-lex.europa.eu
Link checked 18 August 2026
Can I store my users' data outside Greece?
In general, yes. Greece adds no storage-location rule of its own to the European baseline, so ordinary business data can be sent abroad once you have the right European transfer paperwork. Three industries break that rule completely. Telecoms companies must keep their connection records on machines physically inside Greece. Online gambling operators must keep their records on a server inside Greece. And Greek government bodies must run their main systems on state-operated clouds. Health, banking and insurance have extra hoops but no location rule.
Sector-by-sector, checked 18 August 2026. TELECOMS — closed Law 3917/2011, Article 6, is explicit: the retained traffic and location data 'are generated and stored on physical media which are located inside the borders of Greek Territory'. Twelve-month retention. This is a genuine localisation mandate and it has no European equivalent. ONLINE GAMBLING — closed Law 4002/2011 requires a licensed online operator to store the relevant records on a physical device located in Greece (a server or a 'safe'), and to keep them for ten years, reproducible on demand for the regulator and the courts. GOVERNMENT AND PUBLIC SECTOR — data must stay in the country in practice. Article 87 of Law 4727/2020 required all central public-sector electronic applications to migrate by 1 January 2022 into one of three state clouds: G-Cloud (run by the General Secretariat for Information Systems), RECloud (research and education) and H-Cloud (health, run by the state health IT company). Defence, foreign affairs, the intelligence service, civil protection, the coastguard, the tax authority and academic bodies are carved out. HEALTH — conditional No general localisation rule found for private health providers, checked 18 August 2026. Public health bodies fall inside the H-Cloud duty above. Medical records must be kept 10 years in private practice and 20 years elsewhere. BANKING, PAYMENTS, INSURANCE, SECURITIES — conditional No localisation rule found, checked 18 August 2026. The Bank of Greece requires prior notification before outsourcing critical or important functions, but does not require approval and does not require the data to stay in Greece. The EU financial resilience rules that apply directly since 17 January 2025 require you to disclose where data is processed and to keep audit and exit rights — but again impose no location rule. EDUCATION, GAMING (non-gambling), E-COMMERCE, SOCIAL MEDIA, MAPPING — conditional No Greece-specific localisation rule found, checked 18 August 2026. Mapping is governed by copyright and licensing conditions of the Hellenic Military Geographical Service rather than by a data-residency rule. DEFENCE — not researched in depth; classified-information handling rules are outside this record's scope.
Sources
- Official sourceHellenic Authority for Communication Security and Privacy (ADAE)Law 3917/2011, Article 6 (place and duration of retention) — official copy hosted by the communications privacy regulator
adae.gov.gr
“Τα δεδομένα του άρθρου 5 παράγονται και αποθηκεύονται σε φυσικά μέσα, τα οποία βρίσκονται μέσα στα όρια της Ελληνικής Επικρατείας, εντός της οποίας και διατηρούνται για τους σκοπούς του παρόντος κεφαλαίου επί 12 μήνες από την ημερομηνία της επικοινωνίας”
Link checked 18 August 2026
- Official sourceHellenic Gaming Commission (EEEP)Hellenic Gaming Commission — official site; its online licensing pages set out the regime under Law 4002/2011 and Ministerial Decisions 79305/2020 and 79835/2020
gamingcommission.gov.gr
Link checked 18 August 2026
- Official sourceBank of GreeceThe Bank of Greece specifies the regulatory framework governing outsourcing of supervised institutions — Executive Committee Act 178/5/2.10.2020
bankofgreece.gr
“institutions are required to inform the Bank of Greece of their intended arrangements for the outsourcing of critical or important functions before they enter into any outsourcing agreement, but without the need for a relevant approval decision”
Link checked 18 August 2026
- Secondary sourceNomoskopioLaw 4002/2011, Article 47 — consolidated text (non-government database used to verify the wording)
nomoskopio.gr
“υποχρεούται να αποθηκεύει σε υλικό μηχανισμό που βρίσκεται στην Ελλάδα (διακομιστή server ή safe)”
Link checked 18 August 2026
What do I need in place before data leaves Greece?
You need one of the standard European transfer tools before data leaves Europe. The simplest is sending it to a country the European Commission has already approved. If the destination is not approved, you sign the European Commission's standard contract with the recipient, or use approved group-wide internal rules, and you write down why you think the data will still be safe there. Greece adds no extra permission, filing or fee of its own.
The model is closest to an allowlist with escape hatches: the European Commission maintains a populated list of approved destinations, and transfers to anywhere else need a safeguard. The approved list as at 18 August 2026 covers Andorra, Argentina, Brazil, Canada (commercial bodies only), the Faroe Islands, Guernsey, the Isle of Man, Israel, Japan, Jersey, New Zealand, South Korea, Switzerland, the United Kingdom, Uruguay, the United States (only for organisations self-certified under the EU-US Data Privacy Framework) and the European Patent Organisation. Nothing has been withdrawn or suspended. The 2021 Standard Contractual Clauses remain the operative set; the promised new clauses for importers already directly caught by the GDPR are still not adopted. Binding Corporate Rules remain available. Article 49 derogations are narrow and are not a lawful route for routine or bulk transfers. A transfer impact assessment is still expected. The single most time-sensitive item is the EU-US Data Privacy Framework: still in force and legally valid, but the Latombe appeal is pending before the EU's top court, and on 31 July 2026 the European Data Protection Board formally asked the European Commission to examine whether US developments affect the decision's validity. Usable today; never as your only mechanism. Greece's own contribution is a warning rather than a permission: unlawfully passing personal data to someone not entitled to it is a criminal offence in Greece, not merely a fine.
Sources
- Official sourceEuropean CommissionAdequacy decisions — the European Commission's own list of approved destinations
commission.europa.eu
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionCommission Implementing Decision (EU) 2021/914 — Standard Contractual Clauses
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceHellenic Data Protection AuthorityLaw 4624/2019, Article 38 — criminal offence of transmitting personal data to unauthorised persons
dpa.gr
Link checked 18 August 2026
Who enforces the rules in Greece, and what can they do?
Six bodies, and all six are genuinely working. The Hellenic Data Protection Authority is the main privacy regulator and is issuing numbered decisions and fines every month — its most recent published decisions run to July 2026 and include fines on a bank and an electricity supplier. A separate constitutional authority polices the secrecy of communications. There is also a national cybersecurity authority, a telecoms regulator, the central bank for finance and insurance, and a gambling regulator. This is not a paper regime.
The Hellenic Data Protection Authority (Arhi Prostasias Dedomenon Prosopikou Haraktira) is a constitutionally entrenched independent authority. Its published register of acts shows a continuous flow of decisions through 2026 — decision 14 of 15 July 2026 on a university data breach, decision 8 of 5 June 2026 imposing fines on an energy supplier and a bank, decision 6 of 21 April 2026 on transparency. Its best-known action remains the EUR 20 million fine on Clearview AI in July 2022, imposed on a US company with no European establishment. The Hellenic Authority for Communication Security and Privacy (ADAE) is a second constitutional authority, covering the confidentiality of communications; it issued a new binding security regulation for providers in August 2025 (Decision 304/2025) and was still convening hearings in January 2026. The National Cybersecurity Authority runs the network-and-information-security regime and publishes reporting guidance. The Hellenic Telecommunications and Post Commission regulates the telecoms market. The Bank of Greece supervises banks and insurers, including their outsourcing. The Hellenic Gaming Commission licenses and supervises online gambling. Rating: active rather than aggressive — steady output and real fines, but not the volume or the headline values seen in Ireland, France or Spain.
Sources
- Official sourceHellenic Data Protection AuthorityActs of the Authority — the regulator's own register of decisions, showing decisions through July 2026
dpa.gr
Link checked 18 August 2026
- Official sourceHellenic Authority for Communication Security and Privacy (ADAE)ADAE Decision 304/2025 on safeguarding the confidentiality of electronic communications, Gazette B 4268 of 7 August 2025
adae.gov.gr
Link checked 18 August 2026
- Official sourceNational Cybersecurity Authority of GreeceThe network and information security regime in Greece — National Cybersecurity Authority
cyber.gov.gr
Link checked 18 August 2026
How long do I have to keep the data?
Both directions apply, and they collide. Business books must be kept five years. Medical files must be kept ten years in a private practice and twenty years everywhere else. Online gambling records must be kept ten years. Telecoms connection records must be kept exactly twelve months and then automatically deleted. In the other direction, the European rule says you must not keep personal data longer than you need it. When a specific keeping rule and the general deleting rule clash, the specific keeping rule wins.
FLOORS. Accounting records: five years from the end of the accounting period, or longer where other law requires it (Law 4308/2014, Article 7). Medical records: ten years from the last visit for a private practice, twenty years otherwise (Law 3418/2005, Article 14(4)). Online gambling: ten years, with the data reproducible on demand for the supervisory, audit and judicial authorities (Law 4002/2011). Telecoms traffic and location data: twelve months, and this is a duty to retain, not a permission (Law 3917/2011, Article 6). CEILINGS. The general storage-limitation principle in Article 5(1)(e) GDPR. Telecoms retained data must be destroyed automatically once the twelve months expire, and within ten days of notification where the data was lawfully accessed — so here the floor and the ceiling are the same date, which is unusual and easy to get wrong. CONFLICT RULE. A specific statutory retention duty is a legal obligation under Article 6(1)(c) GDPR and therefore overrides an individual's erasure request under Article 17(3)(b). Greek practice follows this. The awkward cases are backups and log archives, where the specific rule says keep and the general rule says purge.
Sources
- Official sourceMinistry of National Economy and FinanceLaw 4308/2014 (Greek Accounting Standards), Article 7 — five-year retention of accounting records
minfin.gov.gr
“Το σύνολο των λογιστικών αρχείων ... διαφυλάσσονται για το μεγαλύτερο χρονικό διάστημα από: α) Πέντε (5) έτη από τη λήξη της περιόδου”
Link checked 18 August 2026
- Official sourceEuropean Commission, Directorate-General for HealthOverview of the national laws on electronic health records — Greece: Code of Medical Ethics (Law 3418/2005), Article 14(4)
health.ec.europa.eu
“10 (ten) years from the last visit ... 20 (twenty) years from the last visit”
Link checked 18 August 2026
- Official sourceHellenic Authority for Communication Security and Privacy (ADAE)Law 3917/2011, Article 6 — twelve-month telecoms retention and automatic destruction
adae.gov.gr
Link checked 18 August 2026
What happens if there is a breach?
Count three clocks, not one. If personal data is lost or exposed, you have 72 hours to tell the privacy regulator. If you run important infrastructure, you have only 24 hours to send a first warning to the national cybersecurity authority, then 72 hours for a fuller report and one month for the final one. If you are a phone or internet provider, you have 24 hours to report a personal data breach and a separate duty to tell the communications secrecy authority. Missing the 24-hour clocks is the most common failure.
Clock 1 — general privacy: 72 hours from awareness to the Hellenic Data Protection Authority under Article 33 GDPR, plus notification to affected individuals without undue delay under Article 34 where the risk is high. Clock 2 — cybersecurity: Law 5160/2024, which transposed the EU network-and-information-security directive and was published on 27 November 2024, requires an early warning to the National Cybersecurity Authority 'without undue delay and in any event within twenty-four (24) hours', an incident notification within 72 hours, and a final report within one month. Clock 3 — telecoms: providers of publicly available electronic communications services must notify a personal data breach within 24 hours under Commission Regulation (EU) 611/2013, and must additionally deal with ADAE where the secrecy of communications is engaged. These clocks run in parallel from different trigger points — 'awareness' for the privacy clock, 'becoming aware of a significant incident' for the cybersecurity clock. One event routinely starts all three, and the 24-hour ones start first.
Sources
- Official sourceNational Cybersecurity Authority of GreeceReporting guide to Law 5160/2024, Article 16 — 24-hour early warning, 72-hour notification, one-month final report
cyber.gov.gr
“χωρίς αδικαιολόγητη καθυστέρηση και σε κάθε περίπτωση εντός είκοσι τεσσάρων (24) ωρών”
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679, Articles 33 and 34 — 72-hour breach notification
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionCommission Regulation (EU) 611/2013 — 24-hour breach notification by electronic communications providers
eur-lex.europa.eu
Link checked 18 August 2026
What trips people up in Greece?
Five things that will cost you a weekend. First, a child in Greece can consent to an online service at fifteen, not sixteen — so an age gate built to the European default is set wrong. Second, misusing personal data is a crime here, with prison time, not just a fine. Third, several articles of the Greek privacy law are printed in the statute but the regulator has formally said they must not be applied, because they clash with European law. Fourth, telecoms connection records must physically stay in Greece. Fifth, government bodies cannot simply pick a commercial cloud.
1. AGE FIFTEEN. Article 21(1) of Law 4624/2019 sets the age at which a minor can consent to an information society service at 15. The European default is 16, and other member states range from 13 to 16. A single global age gate set to 16 over-blocks in Greece; one set to 13 is unlawful here. 2. CRIMINAL LIABILITY. Article 38 of Law 4624/2019 makes it a criminal offence to transmit or make personal data available to someone not entitled to it. For special categories of data — health, biometrics, political opinions and the like — the penalty rises to imprisonment of at least one year plus a fine of up to EUR 100,000 (about $110,000). This attaches to individuals, not only to the company, and it is prosecuted by the criminal courts, not the privacy regulator. 3. PRINTED BUT UNENFORCEABLE. In Opinion 1/2020 the Hellenic Data Protection Authority concluded that Article 5, Article 6(6)-(8), Articles 22, 24, 25, 26 and Article 27 of Law 4624/2019 do not meet the conditions the European rules impose on national law and must not be applied. Those provisions are still printed in the statute. A naive reading of the Greek text — for example relying on Article 5 as a standalone legal basis for public-sector processing, or on Article 27 for employee data — will produce advice the regulator itself rejects. 4. TELECOMS LOCALISATION. Law 3917/2011 requires retained traffic and location data to sit on physical media inside Greek territory. A pan-European telecoms architecture that centralises metadata in one non-Greek data centre breaks Greek law. 5. STATE CLOUD FOR THE PUBLIC SECTOR. Article 87 of Law 4727/2020 obliged public bodies to move their central applications into the Greek state's own clouds by 1 January 2022. If you sell software to Greek ministries, hospitals or universities, your hosting model is decided for you. 6. Bonus, for telecoms and anyone handling interception requests: Law 5002/2022 governs the lifting of communications confidentiality and was rewritten after the 2022 surveillance scandal. Subscriber notification is delayed and conditional, and the rules are policed by a separate constitutional authority.
Sources
- Official sourceHellenic Data Protection AuthorityLaw 4624/2019, Articles 21 and 38 — age 15 for a minor's consent; criminal penalties
dpa.gr
“the processing of the personal data of a minor shall be lawful where the minor is at least 15 years old”
Link checked 18 August 2026
- Official sourceHellenic Data Protection AuthorityOpinion 1/2020 of the Hellenic Data Protection Authority on the provisions of Law 4624/2019
dpa.gr
“δεν πληρούν καμία από τις ανωτέρω ουσιαστικές και διαδικαστικές προϋποθέσεις”
Link checked 18 August 2026
- Official sourceHellenic Authority for Communication Security and Privacy (ADAE)Law 5002/2022 on the procedure for lifting the confidentiality of communications, Gazette A 228 of 9 December 2022
adae.gov.gr
Link checked 18 August 2026
What is changing soon in Greece?
Three dated changes. Electronic invoicing between businesses became compulsory for large Greek companies on 2 March 2026 and becomes compulsory for everyone else on 1 October 2026. Greece's new artificial intelligence law took effect on 22 July 2026 and forces public bodies to register every artificial intelligence system before switching it on. And from 12 January 2027 European law bans cloud providers from charging you to move your data out.
DATED. - 1 October 2026: mandatory business-to-business electronic invoicing extends to all remaining Greek businesses, with a phase-in window to 31 December 2026. Large businesses (over EUR 1 million of 2023 revenue) were originally due on 2 February 2026 and were pushed to 2 March 2026 by the tax authority on 17 February 2026, with a phase-in to 3 May 2026. - 22 July 2026: Law 5321/2026 published, creating Greece's national framework for the European artificial intelligence rules. It replaces the relevant provisions of Law 4961/2022, names the competent national authorities, and creates a single registry in which public bodies must record artificial intelligence systems before they go live. It contains transitional provisions for public bodies. - 12 January 2027: under the European Data Act, cloud switching charges and data egress fees must fall to zero. This is a hard deadline and it is not negotiable by contract. DORMANT SWITCHES — powers already held that could change the picture with no consultation. - Law 3917/2011 telecoms localisation could be repealed or narrowed at any time by Parliament, and could equally be disapplied overnight by a Greek court applying EU case law. Independent legal analysis published in September 2025 argues Articles 1, 3, 5 and 6 of that law are contrary to the EU Court's rulings on general and indiscriminate retention. No Greek court has yet disapplied them, so the localisation duty still binds — but the ground is unstable in both directions. - ADAE can issue new binding security regulations for communications providers by decision alone; it did exactly that in August 2025. - The government can extend the state-cloud obligation, or narrow the carve-outs, by amending Article 87. - The EU-US Data Privacy Framework remains the biggest external switch. It is valid today, but the Latombe appeal is pending before the EU's top court and the European Data Protection Board formally asked the Commission on 31 July 2026 to re-examine its validity.
Sources
- Official sourceIndependent Authority for Public Revenue (AADE)Press release of 16 September 2025 — timetable for mandatory business-to-business electronic invoicing
aade.gr
“1/10: Έναρξη υποχρεωτικής εφαρμογής”
Link checked 18 August 2026
- Official sourceIndependent Authority for Public Revenue (AADE)Press release of 17 February 2026 — postponement of the first phase to 2 March 2026
aade.gr
“2/3/2026 : Έναρξη υποχρεωτικής εφαρμογής”
Link checked 18 August 2026
- Official sourceSpecial Secretariat for Artificial Intelligence and Data GovernanceGreece adopts its national framework for implementing the AI Act — Law 5321/2026, published 22 July 2026
ai.gov.gr
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2023/2854 (Data Act) — zero switching charges from 12 January 2027
eur-lex.europa.eu
Link checked 18 August 2026
The rules, layer by layer
Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.
Layer 1
Bloc rules
Made by a group of countries together. Applies inside every member country.
1 rule here
Layer 2
National rules
Added by this country on top of any bloc rules.
4 rules here
Layer 3
Industry rules
Made by an industry regulator. These usually beat the general position.
7 rules here
Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.
Bloc rules1 rule
Γενικός Κανονισμός για την Προστασία Δεδομένων (General Data Protection Regulation)
Directly binding regulation · Regulation (EU) 2016/679
The European privacy rules apply in Greece directly. They do not require data to stay in Europe; they set conditions for letting it leave. Fines scale with the worldwide turnover of the whole group.
Enforced by Hellenic Data Protection Authority
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims
What it makes you do
- Tell people what you do
- Get consent
- Document a legitimate interest
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people take their data elsewhere
- Let people object
- Limit automated decisions
- Secure the data
- Keep records of processing
- Assess high-risk projects
- Written vendor contract
- Put a transfer safeguard in place
- Appoint a local representativeOnly where the organisation has no establishment anywhere in the European Union.
- Report breaches to the regulator — within 72 hours
- Tell affected people
- Delete data after a period
What it costs if you get it wrong
- Percentage of global turnover: €20 million or 4% of worldwide group turnover, whichever is higher — about $22 millionBasic principles, individual rights, unlawful international transfers, defying a regulator order
- Percentage of global turnover: €10 million or 2% of worldwide group turnover, whichever is higher — about $11 millionSecurity, records, breach notification and similar duties
- Order to stopOrder to stop processing or to suspend flows outside Europe
- Claims by individualsCompensation claims by individuals
Sources
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679 — General Data Protection Regulation, consolidated text
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceEuropean CommissionAdequacy decisions — the current approved-destination list
commission.europa.eu
Link checked 18 August 2026
National rules4 rules
Νόμος 4624/2019 — Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα, μέτρα εφαρμογής του Κανονισμού (ΕΕ) 2016/679
Act of parliament · Law 4624/2019, Gazette A 137 of 29 August 2019
Greece's national privacy law sits on top of the European rules. It adds no storage-location requirement, but it lowers the age of a child's own consent to 15 and makes misuse of personal data a criminal offence with prison time attached.
Enforced by Hellenic Data Protection Authority
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules
What it makes you do
- Get a parent's consent for children — applies at: under 15 years oldGreece set the age of a minor's own consent at 15, not the European default of 16.
- Appoint a data protection officerMandatory for public bodies; otherwise as under the European rules.
- Tell people what you do
- Secure the data
What it costs if you get it wrong
- Criminal liability: Imprisonment, rising to at least one year plus a fine up to €100,000 for special categories of data — about $110 thousandTransmitting or making personal data available to a person not entitled to receive it
- Fixed maximum fine: €10 million — about $11 millionInfringement by a public-sector body
Sources
- Official sourceHellenic Data Protection AuthorityLaw 4624/2019 — full English translation published by the Hellenic Data Protection Authority
dpa.gr
“the processing of the personal data of a minor shall be lawful where the minor is at least 15 years old”
Link checked 18 August 2026
- Official sourceHellenic Data Protection AuthorityPersonal data — legal framework page of the Hellenic Data Protection Authority
dpa.gr
Link checked 18 August 2026
Νόμος 4624/2019, άρθρα 5, 6 παρ. 6-8, 22, 24, 25, 26 και 27
Act of parliament · Law 4624/2019, Articles 5, 6(6)-(8), 22, 24, 25, 26, 27; assessed in HDPA Opinion 1/2020 of 24 January 2020
Several articles of the Greek privacy law are still printed in the statute but the privacy regulator has formally said they clash with European law and must not be applied. They cover public-sector processing, data protection officers, special categories of data, reuse of data for new purposes, and employee data.
Enforced by Hellenic Data Protection Authority
What it makes you do
- Allowed because the law requires itDo not rely on these articles as a legal basis. The regulator says they must not be applied.
Sources
- Official sourceHellenic Data Protection AuthorityOpinion 1/2020 of 24 January 2020 on the provisions of Law 4624/2019 (ref. G/EX/606/24-01-2020)
dpa.gr
“δεν πληρούν καμία από τις ανωτέρω ουσιαστικές και διαδικαστικές προϋποθέσεις”
Link checked 18 August 2026
- Official sourceHellenic Data Protection AuthorityOn the provisions of Law 4624/2019 — the regulator's own landing page for Opinion 1/2020
dpa.gr
Link checked 18 August 2026
Νόμος 5160/2024 — Ενσωμάτωση της Οδηγίας (ΕΕ) 2022/2555 (NIS2)
Act of parliament · Law 5160/2024, Gazette A 195 of 27 November 2024
Greece's cybersecurity law applies to operators of important services and their suppliers. It imposes no storage-location rule, but it does impose a 24-hour first warning that runs faster than the 72-hour privacy clock.
Enforced by National Cybersecurity Authority
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Report cyber incidents — within 24 hoursEarly warning within 24 hours; incident notification within 72 hours; final report within one month.
- Secure the data
- Register or notifyIn-scope entities must register with the National Cybersecurity Authority and name a security officer.
- Independent audit
What it costs if you get it wrong
- Percentage of global turnover: €10 million or 2% of worldwide annual turnover for essential entities — about $11 millionFailure to meet risk-management or incident-reporting duties
- Percentage of global turnover: €7 million or 1.4% of worldwide annual turnover for important entities — about $8 millionFailure to meet risk-management or incident-reporting duties
Sources
- Official sourceNational Cybersecurity Authority of GreeceReporting guide to Law 5160/2024 — Article 16 deadlines and penalty ceilings
cyber.gov.gr
“χωρίς αδικαιολόγητη καθυστέρηση και σε κάθε περίπτωση εντός είκοσι τεσσάρων (24) ωρών”
Link checked 18 August 2026
- Official sourceNational Cybersecurity Authority of GreeceThe NIS2 Directive in Greece — National Cybersecurity Authority
cyber.gov.gr
Link checked 18 August 2026
Νόμος 5321/2026 — Εθνικό εφαρμοστικό πλαίσιο του Κανονισμού (ΕΕ) 2024/1689 για την Τεχνητή Νοημοσύνη
Act of parliament · Law 5321/2026, published 22 July 2026; replaces the corresponding provisions of Law 4961/2022 · Artificial intelligence
Greece's national artificial intelligence law took effect on 22 July 2026. It names the Greek authorities that supervise the European artificial intelligence rules and forces public bodies to register every artificial intelligence system before switching it on. Transitional provisions mean not every duty bites yet.
Enforced by Special Secretariat for Artificial Intelligence and Data Governance
What it makes you do
- Register or notify — applies at: Public-sector bodies, from 22 July 2026Every artificial intelligence system used by a public body must be entered in a single national registry before it starts operating.
- Check your algorithms
- Assess high-risk projects
What it costs if you get it wrong
- Fixed maximum finePenalties under the national framework for the European artificial intelligence rules
Sources
- Official sourceSpecial Secretariat for Artificial Intelligence and Data GovernanceGreece adopts the national framework implementing the AI Act — Law 5321/2026
ai.gov.gr
Link checked 18 August 2026
- Official sourceHellenic Ministry of Digital GovernanceGreece acquires a complete national framework for implementing the EU Artificial Intelligence Regulation
mindigital.gr
Link checked 18 August 2026
Industry rules7 rules
Νόμος 3917/2011 — Διατήρηση δεδομένων που παράγονται ή υποβάλλονται σε επεξεργασία σε συνάρτηση με την παροχή υπηρεσιών ηλεκτρονικών επικοινωνιών
Act of parliament · Law 3917/2011, Gazette A 22 of 21 February 2011, Article 6 (as amended by Article 96 of Law 4139/2013) · Telecoms
Greek phone and internet providers must keep who-called-whom, where and when records for twelve months, and must keep them on machines physically inside Greece. This is a real localisation rule with no European equivalent.
Enforced by Hellenic Authority for Communication Security and Privacy
Transfer model: Not allowed
What it makes you do
- Keep the data in the countryThe retained data must be generated and stored on physical media located inside the borders of Greek territory.
- Keep data for a minimum period — 1 year
- Delete data after a period — 1 yearAutomatic destruction once the twelve months expire; within ten days of notification where the data was lawfully accessed.
- Secure the data
What it costs if you get it wrong
- Fixed maximum fineBreach of the retention and security duties, enforced by the communications privacy authority
- Loss of your licenceSerious or repeated breach by a licensed provider
Sources
- Official sourceHellenic Authority for Communication Security and Privacy (ADAE)Law 3917/2011, Article 6 — place and duration of retention
adae.gov.gr
“Τα δεδομένα του άρθρου 5 παράγονται και αποθηκεύονται σε φυσικά μέσα, τα οποία βρίσκονται μέσα στα όρια της Ελληνικής Επικρατείας, εντός της οποίας και διατηρούνται για τους σκοπούς του παρόντος κεφαλαίου επί 12 μήνες από την ημερομηνία της επικοινωνίας”
Link checked 18 August 2026
- Official sourceHellenic Authority for Communication Security and Privacy (ADAE)Law 3917/2011 in the communications privacy authority's own legal framework library
adae.gov.gr
Link checked 18 August 2026
- Secondary sourceHomo Digitalis / Digital Freedom FundCase-law analysis, September 2025 — argues Articles 1, 3, 5 and 6 of Law 3917/2011 are contrary to EU Court rulings on general and indiscriminate retention
digitalfreedomfund.org
Link checked 18 August 2026
Νόμος 4002/2011 — Ρύθμιση της αγοράς παιγνίων, άρθρο 47, και Κανονισμοί Παιγνίων (ΥΑ 79305/2020 και 79835/2020)
Act of parliament · Law 4002/2011, Article 47, as amended by Law 4635/2019; Ministerial Decisions 79305 EX 2020 and 79835 EX 2020 · Online gaming
An online gambling operator licensed in Greece must store its records on a server or safe physically located in Greece and keep them for ten years. A licence is required to serve Greek players at all.
Enforced by Hellenic Gaming Commission
Transfer model: Not allowed
What it makes you do
- Keep the data in the countryRecords must be stored on a physical device located in Greece — a server or a 'safe'.
- Keep data for a minimum period — 10 yearsTen years, reproducible on demand for the regulator, auditors and the courts.
- Register or notifyAn operating licence from the Hellenic Gaming Commission is required.
- Secure the data
What it costs if you get it wrong
- Loss of your licenceBreach of licence conditions
- Fixed maximum fineAdministrative penalties under Article 51 of Law 4002/2011
Sources
- Official sourceHellenic Gaming Commission (EEEP)Hellenic Gaming Commission — official site of the licensing and supervisory authority for online gambling under Law 4002/2011
gamingcommission.gov.gr
Link checked 18 August 2026
- Secondary sourceNomoskopioLaw 4002/2011, Article 47 — consolidated text (non-government database)
nomoskopio.gr
“υποχρεούται να αποθηκεύει σε υλικό μηχανισμό που βρίσκεται στην Ελλάδα (διακομιστή server ή safe)”
Link checked 18 August 2026
- Secondary sourcee-nomothesiaMinisterial Decision 79835 EX 2020, Gazette B 3265 of 5 August 2020 — consolidated online gaming regulation, ten-year retention
e-nomothesia.gr
“τηρεί τα στοιχεία, έγγραφα και δεδομένα για δέκα (10) τουλάχιστον έτη”
Link checked 18 August 2026
Νόμος 4727/2020 — Ψηφιακή Διακυβέρνηση, άρθρο 87 (Κυβερνητικά νέφη)
Act of parliament · Law 4727/2020, Article 87, Gazette A 184 of 23 September 2020 · Government
Greek public bodies had to move their central computer systems into the Greek state's own clouds by 1 January 2022. Defence, foreign affairs, the intelligence service, civil protection, the coastguard, the tax authority and academic bodies are exempt.
Enforced by Ministry of Digital Governance
Transfer model: Approval each time
What it makes you do
- Keep the data in the country — from 1 January 2022Central public-sector applications must run in one of three state clouds: G-Cloud for general government, RECloud for research and education, H-Cloud for health.
- Secure the data
Sources
- Official sourceHellenic Ministry of Digital GovernanceMinistry of Digital Governance — the ministry responsible for the government cloud programme under Law 4727/2020
mindigital.gr
Link checked 18 August 2026
- Secondary sourceLawspotLaw 4727/2020, Article 87 (government clouds) — consolidated text (non-government database)
lawspot.gr
“Στο Κυβερνητικό Νέφος Δημόσιου Τομέα πρέπει υποχρεωτικά να εγκατασταθούν έως την 1η.01.2022 όλες οι κεντρικές ηλεκτρονικές εφαρμογές”
Link checked 18 August 2026
Απόφαση ΑΔΑΕ 304/2025 — Κανονισμός για τη διασφάλιση του απορρήτου των ηλεκτρονικών επικοινωνιών
Directly binding regulation · ADAE Decision 304/2025, Gazette B 4268 of 7 August 2025 · Telecoms
A binding 2025 regulation setting the security measures Greek communications providers must take to protect the secrecy of communications, including encryption and contractor liability. Standard supplier contracts are not enough here.
Enforced by Hellenic Authority for Communication Security and Privacy
What it makes you do
- Secure the dataWritten security policy reviewed at least every two years, encryption of stored and transmitted communications data, two-factor authentication for critical systems, network segmentation.
- Extra vendor secrecy termsContracts with contractors must carry confidentiality and security terms; the provider stays liable for everything the contractor does.
- Keep logsPhysical and logical access to systems holding communications data must be pre-authorised and logged.
- Independent audit
What it costs if you get it wrong
- Fixed maximum fineBreach of the communications confidentiality regulation
Sources
- Official sourceHellenic Authority for Communication Security and Privacy (ADAE)ADAE Decision 304/2025, Gazette B 4268 of 7 August 2025
adae.gov.gr
Link checked 18 August 2026
- Official sourceHellenic Authority for Communication Security and Privacy (ADAE)Regulatory framework for electronic communications providers
adae.gov.gr
Link checked 18 August 2026
Πράξη Εκτελεστικής Επιτροπής 178/5/2.10.2020 — Εξωτερική ανάθεση δραστηριοτήτων
Regulator directive · Bank of Greece Executive Committee Act 178/5/2.10.2020 · Finance
Greek banks and insurers must tell the Bank of Greece before outsourcing anything critical, including to a cloud provider. No approval is needed and there is no rule that the data must stay in Greece.
Enforced by Bank of Greece
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Written vendor contractWritten outsourcing agreement with audit and access rights, following the European banking guidelines on outsourcing to cloud providers.
- Keep records of processingRegister of outsourcing arrangements.
- Independent audit
What it costs if you get it wrong
- Fixed maximum fineSupervisory measures and penalties under the banking supervision framework
Sources
- Official sourceBank of GreeceThe Bank of Greece specifies the regulatory framework governing outsourcing of supervised institutions
bankofgreece.gr
“without the need for a relevant approval decision”
Link checked 18 August 2026
Νόμος 3418/2005 — Κώδικας Ιατρικής Δεοντολογίας, άρθρο 14 (τήρηση ιατρικού αρχείου)
Act of parliament · Law 3418/2005, Article 14(4) · Health and social care
Greek medical records must be kept for ten years in a private practice and twenty years in a hospital, counted from the patient's last visit. No rule was found requiring private health data to stay in Greece.
Enforced by Hellenic Data Protection Authority
What it makes you do
- Keep data for a minimum period — applies at: Private medical practice, 10 yearsTen years from the last visit.
- Keep data for a minimum period — applies at: Hospitals and all other cases, 20 yearsTwenty years from the last visit.
- Extra vendor secrecy termsMedical confidentiality is a professional duty backed by criminal law, so a standard supplier data agreement is not sufficient on its own.
What it costs if you get it wrong
- Criminal liabilityBreach of medical confidentiality
Sources
- Official sourceEuropean Commission, Directorate-General for HealthOverview of the national laws on electronic health records — Greece
health.ec.europa.eu
“10 (ten) years from the last visit ... 20 (twenty) years from the last visit”
Link checked 18 August 2026
Νόμος 4308/2014 — Ελληνικά Λογιστικά Πρότυπα, άρθρα 5 και 7
Act of parliament · Law 4308/2014, Gazette A 251 of 24 November 2014, Articles 5 and 7
Business books and records must be kept for five years and produced to the tax authorities on request. The law does not say they have to be stored in Greece, but it does require them to be available quickly, which in practice means an auditor must be able to reach them from Greece.
Enforced by Independent Authority for Public Revenue
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Keep data for a minimum period — 5 yearsFive years from the end of the accounting period, or longer where other law requires it.
- Keep records of processingThe records must be made available to the tax and audit authorities within a reasonable time.
What it costs if you get it wrong
- Fixed maximum fine: €500 to €1,000 per audit for e-invoicing failures, or 50% of the VAT involved — about $1 thousandFailure to issue compliant electronic invoices
Sources
- Official sourceMinistry of National Economy and FinanceLaw 4308/2014 (Greek Accounting Standards), Articles 5 and 7
minfin.gov.gr
“Τα λογιστικά αρχεία πρέπει να είναι διαθέσιμα στα αρμόδια ελεγκτικά όργανα”
Link checked 18 August 2026
- Official sourceIndependent Authority for Public Revenue (AADE)Mandatory electronic invoicing and digital delivery documents — frequently asked questions
aade.gr
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
The exact wording of Article 47 of Law 4002/2011 requiring an online gambling operator to store records on a server or safe located in Greece
The verbatim Greek text was verified only on a commercial consolidated-law database. The Hellenic Gaming Commission's own website blocks automated retrieval on most paths, so we could not obtain the gazette copy from a government host. The rule is therefore recorded at medium confidence, with the regulator's own licensing page as the government backlink.
Whether Article 87 of Law 4727/2020 imposes a geographic requirement, as opposed to a requirement to use named Greek state operators
The article names the operators (the General Secretariat for Information Systems, the national research network body and the state health IT company) but does not spell out that the infrastructure must be physically in Greece. We rate the effect as closed because those clouds are state-run domestic infrastructure, but the statute itself is silent on geography and we could not retrieve the text from a government host.
Whether Greek courts are still applying the telecoms retention duty in Law 3917/2011 in full
Independent analysis published in September 2025 argues Articles 1, 3, 5 and 6 are contrary to the EU Court's rulings on general and indiscriminate retention. We found no Greek court decision disapplying them, and no repeal. The duty is therefore recorded as in force, but a court could disapply it without warning, and we could not verify current prosecutorial practice from an official source.
The precise designated authorities, penalty levels and commencement dates under Law 5321/2026 on artificial intelligence
The government announcement confirms the law and its date but does not name the market surveillance authority, the notifying authority or the single point of contact, and does not publish the transitional dates. The gazette text was not retrievable during this run.
Whether the Bank of Greece outsourcing act contains any data-location condition in its full text
We verified the notification-not-approval rule from the Bank of Greece's own press release. We did not retrieve the full text of Executive Committee Act 178/5/2.10.2020, so a location condition buried in an annex cannot be excluded.
Whether any Greece-specific restriction applies to detailed mapping, aerial imagery or geospatial data leaving the country
No such restriction was found, checked 18 August 2026. The Hellenic Military Geographical Service publishes copyright and licensing terms rather than a residency rule, and we did not verify whether military-sensitive imagery carries separate export controls.
Whether any sector rule applies to securities firms or account aggregation beyond the directly applicable European financial resilience rules
We did not separately search the Hellenic Capital Market Commission's rulebook within this run's budget. No localisation rule is expected, but this is an untested gap rather than a verified negative.
Freshness and refresh
Freshness
Checked today — on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.