Skip to the content
Global Data RulesData governance rules, country by country

Greece

Part of the European Union, so bloc-wide rules apply here too. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Greece — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Depends on your industryWork: HighEnforcement: Active

For most businesses Greece is a normal European country. Personal data can leave, as long as you use one of the standard European transfer tools. But Greece has two strict rules that Europe does not. Phone and internet connection records must physically sit on machines inside Greece. Online gambling operators must keep their records on a server inside Greece too. The privacy regulator is fully staffed and fining companies today.

Data governance in Greece

The eight things that decide how you handle data about people in Greece. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes, it reaches a foreign company with no office in Greece. The European privacy rules apply to anyone, anywhere, who offers goods or services to people in Greece. They also apply if you watch what those people do online. The Greek national law adds that it covers anyone handling data on Greek soil. There is no size or revenue threshold that lets you off. If you have no office anywhere in Europe, you must appoint a written representative inside the European Union.

What you have to do here:
Appoint a representative

Where the data is allowed to live

In general, yes. Greece adds no storage-location rule of its own to the European baseline. So ordinary business data can be sent abroad once you have the right European transfer paperwork. Three industries break that rule completely. Telecoms companies must keep their connection records on machines physically inside Greece. Online gambling operators must keep their records on a server inside Greece. And Greek government bodies must run their main systems on state-operated clouds. Health, banking and insurance have extra hoops but no location rule.

What to do: Plan for a database inside Greece: this data is not allowed to leave.

Sending data out of the country

You need one of the standard European transfer tools before data leaves Europe. The simplest is sending it to a country the European Commission has already approved. If the destination is not approved, you sign the European Commission's standard contract with the recipient. Or you use approved group-wide internal rules. Either way, you write down why you think the data will still be safe there. Greece adds no extra permission, filing or fee of its own.

Ways to send data out:
Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Explicit consent · Needed for a contract · Legal claims

What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.

The regulator, and whether it actually acts

Six bodies enforce the rules, and all six are working. The Hellenic Data Protection Authority is the main privacy regulator. It issues numbered decisions and fines every month. Its most recent published decisions run to July 2026 and include fines on a bank and an electricity supplier. A separate constitutional authority polices the secrecy of communications. There is also a national cybersecurity authority, a telecoms regulator, the central bank for finance and insurance, and a gambling regulator. This is not enforcement on paper only.

How long you must keep it — and when to delete it

Both directions apply, and they collide. Business books must be kept five years. Medical files must be kept ten years in a private practice and twenty years everywhere else. Online gambling records must be kept ten years. Telecoms connection records must be kept exactly twelve months and then automatically deleted. In the other direction, the European rule says you must not keep personal data longer than you need it. When a specific keeping rule and the general deleting rule clash, the specific keeping rule wins.

What you have to do here:
Keep data for a minimum period · Delete data after a period · Keep logs · Allowed because the law requires it

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

There are three clocks, not one. If personal data is lost or exposed, you have 72 hours to tell the privacy regulator. If you run important infrastructure, you have only 24 hours to send a first warning to the national cybersecurity authority. You then have 72 hours for a fuller report and one month for the final one. If you are a phone or internet provider, you have 24 hours to report a personal data breach. You also have a separate duty to tell the communications secrecy authority. Missing the 24-hour clocks is the most common failure.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five things will cost you a weekend. First, a child in Greece can consent to an online service at fifteen, not sixteen. An age gate built to the European default is set wrong. Second, misusing personal data is a crime here, with prison time, not just a fine. Third, several articles of the Greek privacy law are printed in the statute, but the regulator has formally said they must not be applied. They clash with European law. Fourth, telecoms connection records must physically stay in Greece. Fifth, government bodies cannot simply pick a commercial cloud.

What you have to do here:
Get a parent's consent for children · Keep the data in the country
What it costs if you get it wrong:
Criminal liability

What's changing next

Three dated changes. Electronic invoicing between businesses became compulsory for large Greek companies on 2 March 2026 and becomes compulsory for everyone else on 1 October 2026. Greece's new artificial intelligence law took effect on 22 July 2026 and forces public bodies to register every artificial intelligence system before switching it on. And from 12 January 2027 European law bans cloud providers from charging you to move your data out.

What to do: Diarise 12 January 2027 — that is the date this changes.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries7 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Telecoms

Telecoms data must stay in the country

Official name: Νόμος 3917/2011 — Διατήρηση δεδομένων που παράγονται ή υποβάλλονται σε επεξεργασία σε συνάρτηση με την παροχή υπηρεσιών ηλεκτρονικών επικοινωνιών · Law 3917/2011, Gazette A 22 of 21 February 2011, Article 6 (as amended by Article 96 of Law 4139/2013) · Act of parliament

In forceNo — it stays put

Greek phone and internet providers must keep records of who called whom, where and when for twelve months. They must keep them on machines physically inside Greece. This is a real must-stay-here rule with no European equivalent.

In force since 21 February 2011

Enforced by Hellenic Authority for Communication Security and Privacy

How this country controls where data goes: Not allowed

Online gaming

Online gaming data must stay in the country

Official name: Νόμος 4002/2011 — Ρύθμιση της αγοράς παιγνίων, άρθρο 47, και Κανονισμοί Παιγνίων (ΥΑ 79305/2020 και 79835/2020) · Law 4002/2011, Article 47, as amended by Law 4635/2019; Ministerial Decisions 79305 EX 2020 and 79835 EX 2020 · Act of parliament

In forceNo — it stays put

An online gambling operator licensed in Greece must store its records on a server or safe physically located in Greece. It must keep them for ten years. You need a licence to serve Greek players at all.

In force since 22 August 2011Enforced from 5 August 2020

Enforced by Hellenic Gaming Commission

How this country controls where data goes: Not allowed

Not fully verified — see “What we're not sure about” below.
Government

Cloud and outsourcing rules

Official name: Νόμος 4727/2020 — Ψηφιακή Διακυβέρνηση, άρθρο 87 (Κυβερνητικά νέφη) · Law 4727/2020, Article 87, Gazette A 184 of 23 September 2020 · Act of parliament

In forceNo — it stays put

Greek public bodies had to move their central computer systems into the Greek state's own clouds by 1 January 2022. Defence, foreign affairs, the intelligence service, civil protection, the coastguard, the tax authority and academic bodies are exempt.

In force since 23 September 2020Enforced from 1 January 2022

Enforced by Ministry of Digital Governance

How this country controls where data goes: Approval each time

Not fully verified — see “What we're not sure about” below.

Applies to every company3 rules

These bind you whatever business you are in, once the country's rules reach you.

Europe's main privacy law (2019)

Official name: Νόμος 4624/2019 — Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα, μέτρα εφαρμογής του Κανονισμού (ΕΕ) 2016/679 · Law 4624/2019, Gazette A 137 of 29 August 2019 · Act of parliament

In forceYes, with paperwork

Greece's national privacy law sits on top of the European rules. It adds no storage-location requirement. But it lowers the age of a child's own consent to 15. It also makes misuse of personal data a crime, with prison time attached.

In force since 29 August 2019

Enforced by Hellenic Data Protection Authority

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules

Cyber security rules

Official name: Νόμος 5160/2024 — Ενσωμάτωση της Οδηγίας (ΕΕ) 2022/2555 (NIS2) · Law 5160/2024, Gazette A 195 of 27 November 2024 · Act of parliament

In forceYes — store it anywhere

Greece's cybersecurity law applies to operators of important services and their suppliers. It imposes no storage-location rule, but it does impose a 24-hour first warning that runs faster than the 72-hour privacy clock.

In force since 27 November 2024

Enforced by National Cybersecurity Authority

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Artificial intelligence

AI rules

Official name: Νόμος 5321/2026 — Εθνικό εφαρμοστικό πλαίσιο του Κανονισμού (ΕΕ) 2024/1689 για την Τεχνητή Νοημοσύνη · Law 5321/2026, published 22 July 2026; replaces the corresponding provisions of Law 4961/2022 · Act of parliament

Partly in forceYes, with paperwork

Greece's national artificial intelligence law took effect on 22 July 2026. It names the Greek authorities that supervise the European artificial intelligence rules. It forces public bodies to register every artificial intelligence system before switching it on. Transitional rules mean not every duty applies yet.

In force since 22 July 2026

Enforced by Special Secretariat for Artificial Intelligence and Data Governance

Not fully verified — see “What we're not sure about” below.

Applies across the European Union1 rule

Written once for the whole bloc, and in force in every member country.

Europe's main privacy law

Official name: Γενικός Κανονισμός για την Προστασία Δεδομένων (General Data Protection Regulation) · Regulation (EU) 2016/679 · Directly binding regulation

In forceYes, with paperwork

The European privacy rules apply in Greece directly. They do not require data to stay in Europe. They set the conditions for letting it leave. Fines scale with the worldwide turnover of the whole group.

In force since 24 May 2016Enforced from 25 May 2018

Enforced by Hellenic Data Protection Authority

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims

On the books, but not enforceable1 rule

These rules are still printed in the law, but a court struck them down or the regulator has said it will not apply them. You do not have to comply today. They are here because text nobody deleted can come back without warning.

General data protection law

Official name: Νόμος 4624/2019, άρθρα 5, 6 παρ. 6-8, 22, 24, 25, 26 και 27 · Law 4624/2019, Articles 5, 6(6)-(8), 22, 24, 25, 26, 27; assessed in HDPA Opinion 1/2020 of 24 January 2020 · Act of parliament

UnenforceableYes, with paperwork

Several articles of the Greek privacy law are still printed in the statute. But the privacy regulator has formally said they clash with European law and must not be applied. They cover public-sector work, data protection officers, special categories of data, reuse of data for new purposes, and employee data.

In force since 29 August 2019

Enforced by Hellenic Data Protection Authority

Who you would hear from

  • Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα

    General privacy law, all sectors

    Fully constituted and issuing numbered decisions continuously. Published acts run to decision 14 of 15 July 2026. Decision 8 of 5 June 2026 fined an electricity supplier and a bank. It fined Clearview AI 20 million euros in July 2022. Clearview AI is a US company with no European office. It also issues opinions that constrain the Greek legislature. Opinion 1/2020 is the best known.

  • Αρχή Διασφάλισης του Απορρήτου των Επικοινωνιών (ΑΔΑΕ)

    Secrecy of communications, telecoms data retention, lawful interception oversight

    A second constitutionally entrenched independent authority. Issued a new binding security regulation for providers in August 2025 (Decision 304/2025) and was convening enforcement hearings in January 2026.

  • Εθνική Αρχή Κυβερνοασφάλειας

    Cybersecurity, incident reporting under Law 5160/2024, national computer security incident response team

    Operating and publishing reporting guidance; designated as the national incident response team under Law 5160/2024.

  • Επιτροπή Εποπτείας και Ελέγχου Παιγνίων (ΕΕΕΠ)

    Licensing and supervision of gambling, including online gambling

    Runs the online licensing system and publishes licence and suitability decisions.

  • Τράπεζα της Ελλάδος

    Banking, insurance and payments supervision, including outsourcing arrangements

  • Ανεξάρτητη Αρχή Δημοσίων Εσόδων (ΑΑΔΕ)

    Tax records, electronic invoicing and the myDATA electronic books platform

  • Υπουργείο Ψηφιακής Διακυβέρνησης

    Digital governance policy, the government cloud programme, public-sector information systems

  • Ειδική Γραμματεία Τεχνητής Νοημοσύνης και Διακυβέρνησης Δεδομένων

    National implementation of the European artificial intelligence rules under Law 5321/2026

    Newly established. It announced Greece's national artificial intelligence rules in July 2026. The supervisory machinery those rules create is still bedding in.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • The exact wording of Article 47 of Law 4002/2011 requiring an online gambling operator to store records on a server or safe located in Greece

    We could not confirm this against a government source. We verified the exact Greek text only on a commercial consolidated-law database. The Hellenic Gaming Commission's own website blocks automated retrieval on most paths, so we could not get the gazette copy. We record the rule at medium confidence, with the regulator's own licensing page as the government link.

  • Whether Article 87 of Law 4727/2020 imposes a geographic requirement, as opposed to a requirement to use named Greek state operators

    We could not confirm that the law requires this infrastructure to be physically in Greece. The article names the operators: the General Secretariat for Information Systems, the national research network body and the state health IT company. It says nothing about geography. We rate the effect as closed because those clouds are state-run domestic infrastructure. We could not get the text from a government host.

  • Whether Greek courts are still applying the telecoms retention duty in Law 3917/2011 in full

    We could not confirm how safe this duty is to rely on. Independent analysis published in September 2025 argues Articles 1, 3, 5 and 6 conflict with the European Court's rulings on general and indiscriminate retention. We found no Greek court decision setting them aside, and no repeal. So we record the duty as in force. But a court could set it aside without warning, and we could not verify current prosecution practice from an official source.

  • The precise designated authorities, penalty levels and commencement dates under Law 5321/2026 on artificial intelligence

    We could not confirm who supervises this law. The government announcement confirms the law and its date. It does not name the market surveillance authority, the notifying authority or the single point of contact. It does not publish the transitional dates. We could not retrieve the gazette text.

  • Whether the Bank of Greece outsourcing act contains any data-location condition in its full text

    We could not confirm the full text of Executive Committee Act 178/5/2.10.2020. We verified the notify-but-no-approval rule from the Bank of Greece's own press release. A location condition buried in an annex cannot be ruled out.

  • Whether any Greece-specific restriction applies to detailed mapping, aerial imagery or geospatial data leaving the country

    We found no such restriction, checked 18 August 2026. The Hellenic Military Geographical Service publishes copyright and licensing terms, not a rule about where data must sit. We did not check whether military-sensitive imagery carries separate export controls.

  • Whether any sector rule applies to securities firms or account aggregation beyond the directly applicable European financial resilience rules

    We could not confirm this for securities firms. We did not search the Hellenic Capital Market Commission's rulebook. We expect no rule forcing data to stay in Greece, but this is an untested gap rather than a verified answer. If you work in securities, check before you rely on it.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.