Greece
Part of the European Union, so bloc-wide rules apply here too. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Greece — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
For most businesses Greece is a normal European country. Personal data can leave, as long as you use one of the standard European transfer tools. But Greece has two strict rules that Europe does not. Phone and internet connection records must physically sit on machines inside Greece. Online gambling operators must keep their records on a server inside Greece too. The privacy regulator is fully staffed and fining companies today.
Data governance in Greece
The eight things that decide how you handle data about people in Greece. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes, it reaches a foreign company with no office in Greece. The European privacy rules apply to anyone, anywhere, who offers goods or services to people in Greece. They also apply if you watch what those people do online. The Greek national law adds that it covers anyone handling data on Greek soil. There is no size or revenue threshold that lets you off. If you have no office anywhere in Europe, you must appoint a written representative inside the European Union.
- What you have to do here:
- Appoint a representative
Article 3 of Law 4624/2019 extends the national rules to companies and their suppliers that handle personal data in Greek territory. It also covers handling at a Greek office. And it covers anything else the General Data Protection Regulation reaches. The European rules reach you even if you have no office in Europe. That happens when you offer goods or services to people there, or monitor what they do. European law also requires you to appoint a representative in the European Union if you have no office there. There are narrow exemptions. Greece has not added any Greece-specific representative or registration requirement for foreign companies. The Hellenic Data Protection Authority has claimed authority over foreign companies with no Greek office. Its 20 million euro fine on Clearview AI, a US company with no European presence, is the clearest example.
Sources
- Official sourceHellenic Data Protection AuthorityLaw 4624/2019, Article 3 (scope) — English translation published by the regulator
dpa.gr
“the controller or processor processes personal data in the Greek territory”
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679 (General Data Protection Regulation), Articles 3 and 27
eur-lex.europa.eu
Link checked 18 August 2026
Where the data is allowed to live
In general, yes. Greece adds no storage-location rule of its own to the European baseline. So ordinary business data can be sent abroad once you have the right European transfer paperwork. Three industries break that rule completely. Telecoms companies must keep their connection records on machines physically inside Greece. Online gambling operators must keep their records on a server inside Greece. And Greek government bodies must run their main systems on state-operated clouds. Health, banking and insurance have extra hoops but no location rule.
Industry by industry, checked 18 August 2026. TELECOMS — data must stay in the country Article 6 of Law 3917/2011 is explicit. The retained traffic and location data 'are generated and stored on physical media which are located inside the borders of Greek Territory'. You keep them twelve months. This is a real must-stay-here rule and it has no European equivalent. ONLINE GAMBLING — data must stay in the country Law 4002/2011 requires a licensed online operator to store the relevant records on a physical device located in Greece. That is a server or a 'safe'. You keep them for ten years and must be able to produce them on demand for the regulator and the courts. GOVERNMENT AND PUBLIC SECTOR — data must stay in the country, in effect. Article 87 of Law 4727/2020 required all central public-sector electronic applications to move by 1 January 2022 into one of three state clouds. Those are G-Cloud, run by the General Secretariat for Information Systems. RECloud covers research and education. H-Cloud covers health and is run by the state health IT company. Defence, foreign affairs, the intelligence service, civil protection, the coastguard, the tax authority and academic bodies are exempt. HEALTH — data can leave only if conditions are met We found no general rule forcing private health providers to keep data in Greece, checked 18 August 2026. Public health bodies fall inside the H-Cloud duty above. Medical records must be kept 10 years in private practice and 20 years elsewhere. BANKING, PAYMENTS, INSURANCE, SECURITIES — data can leave only if conditions are met We found no rule forcing data to stay in Greece, checked 18 August 2026. The Bank of Greece requires you to notify it before outsourcing critical or important functions. It does not require approval, and it does not require the data to stay in Greece. The EU financial resilience rules have applied directly since 17 January 2025. They require you to disclose where data is handled, and to keep audit and exit rights. They impose no location rule either. EDUCATION, GAMING (non-gambling), E-COMMERCE, SOCIAL MEDIA, MAPPING — data can leave only if conditions are met We found no Greece-specific rule forcing data to stay in Greece, checked 18 August 2026. Mapping is governed by the copyright and licensing conditions of the Hellenic Military Geographical Service, not by a rule about where data sits. DEFENCE — not researched in depth. Rules on handling classified information are outside what this record covers.
Sources
- Official sourceHellenic Authority for Communication Security and Privacy (ADAE)Law 3917/2011, Article 6 (place and duration of retention) — official copy hosted by the communications privacy regulator
adae.gov.gr
“Τα δεδομένα του άρθρου 5 παράγονται και αποθηκεύονται σε φυσικά μέσα, τα οποία βρίσκονται μέσα στα όρια της Ελληνικής Επικρατείας, εντός της οποίας και διατηρούνται για τους σκοπούς του παρόντος κεφαλαίου επί 12 μήνες από την ημερομηνία της επικοινωνίας”
Link checked 18 August 2026
- Official sourceHellenic Gaming Commission (EEEP)Hellenic Gaming Commission — official site; its online licensing pages set out the regime under Law 4002/2011 and Ministerial Decisions 79305/2020 and 79835/2020
gamingcommission.gov.gr
Link checked 18 August 2026
- Official sourceBank of GreeceThe Bank of Greece specifies the regulatory framework governing outsourcing of supervised institutions — Executive Committee Act 178/5/2.10.2020
bankofgreece.gr
“institutions are required to inform the Bank of Greece of their intended arrangements for the outsourcing of critical or important functions before they enter into any outsourcing agreement, but without the need for a relevant approval decision”
Link checked 18 August 2026
- Secondary sourceNomoskopioLaw 4002/2011, Article 47 — consolidated text (non-government database used to verify the wording)
nomoskopio.gr
“υποχρεούται να αποθηκεύει σε υλικό μηχανισμό που βρίσκεται στην Ελλάδα (διακομιστή server ή safe)”
Link checked 18 August 2026
What to do: Plan for a database inside Greece: this data is not allowed to leave.
Sending data out of the country
You need one of the standard European transfer tools before data leaves Europe. The simplest is sending it to a country the European Commission has already approved. If the destination is not approved, you sign the European Commission's standard contract with the recipient. Or you use approved group-wide internal rules. Either way, you write down why you think the data will still be safe there. Greece adds no extra permission, filing or fee of its own.
- Ways to send data out:
- Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Explicit consent · Needed for a contract · Legal claims
The model is closest to a list of approved countries, with escape routes. The European Commission keeps a well-populated list of approved destinations. Transfers anywhere else need a safeguard. Here is the approved list as at 18 August 2026. Andorra, Argentina, Brazil and Canada, for commercial bodies only. The Faroe Islands, Guernsey, the Isle of Man, Israel, Japan and Jersey. New Zealand, South Korea, Switzerland, the United Kingdom and Uruguay. Also the European Patent Organisation. It also covers the United States, but only for organisations self-certified under the EU-US Data Privacy Framework. Nothing has been withdrawn or suspended. The 2021 Standard Contractual Clauses are still the ones you use. The promised new clauses, for recipients already directly caught by European privacy law, have still not been adopted. Binding Corporate Rules remain available. The narrow exceptions in European law are not a lawful route for routine or bulk transfers. A transfer impact assessment is still expected. The most time-sensitive item is the EU-US Data Privacy Framework. It is still in force and legally valid. But the Latombe appeal is pending before the European Union's top court. On 31 July 2026 the European Data Protection Board formally asked the European Commission to examine whether US developments affect the decision's validity. You can use it today. Never make it your only route. Greece's own contribution is a warning rather than a permission. Passing personal data unlawfully to someone not entitled to it is a crime in Greece, not merely a fine.
Sources
- Official sourceEuropean CommissionAdequacy decisions — the European Commission's own list of approved destinations
commission.europa.eu
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionCommission Implementing Decision (EU) 2021/914 — Standard Contractual Clauses
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceHellenic Data Protection AuthorityLaw 4624/2019, Article 38 — criminal offence of transmitting personal data to unauthorised persons
dpa.gr
Link checked 18 August 2026
What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.
The regulator, and whether it actually acts
Six bodies enforce the rules, and all six are working. The Hellenic Data Protection Authority is the main privacy regulator. It issues numbered decisions and fines every month. Its most recent published decisions run to July 2026 and include fines on a bank and an electricity supplier. A separate constitutional authority polices the secrecy of communications. There is also a national cybersecurity authority, a telecoms regulator, the central bank for finance and insurance, and a gambling regulator. This is not enforcement on paper only.
The Hellenic Data Protection Authority (Arhi Prostasias Dedomenon Prosopikou Haraktira) is an independent authority written into the constitution. Its published register of acts shows a continuous flow of decisions through 2026. Decision 14 of 15 July 2026 dealt with a university data breach. Decision 8 of 5 June 2026 fined an energy supplier and a bank. Decision 6 of 21 April 2026 dealt with transparency. Its best-known action remains the 20 million euro fine on Clearview AI in July 2022. That was a US company with no European office. The Hellenic Authority for Communication Security and Privacy (ADAE) is a second constitutional authority. It covers the confidentiality of communications. It issued a new binding security regulation for providers in August 2025 (Decision 304/2025). It was still holding hearings in January 2026. The National Cybersecurity Authority runs the network and information security rules and publishes reporting guidance. The Hellenic Telecommunications and Post Commission regulates the telecoms market. The Bank of Greece supervises banks and insurers, including their outsourcing. The Hellenic Gaming Commission licenses and supervises online gambling. Rating: active rather than aggressive. There is steady output and there are real fines. But not the volume or the very large amounts seen in Ireland, France or Spain.
Sources
- Official sourceHellenic Data Protection AuthorityActs of the Authority — the regulator's own register of decisions, showing decisions through July 2026
dpa.gr
Link checked 18 August 2026
- Official sourceHellenic Authority for Communication Security and Privacy (ADAE)ADAE Decision 304/2025 on safeguarding the confidentiality of electronic communications, Gazette B 4268 of 7 August 2025
adae.gov.gr
Link checked 18 August 2026
- Official sourceNational Cybersecurity Authority of GreeceThe network and information security regime in Greece — National Cybersecurity Authority
cyber.gov.gr
Link checked 18 August 2026
How long you must keep it — and when to delete it
Both directions apply, and they collide. Business books must be kept five years. Medical files must be kept ten years in a private practice and twenty years everywhere else. Online gambling records must be kept ten years. Telecoms connection records must be kept exactly twelve months and then automatically deleted. In the other direction, the European rule says you must not keep personal data longer than you need it. When a specific keeping rule and the general deleting rule clash, the specific keeping rule wins.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period · Keep logs · Allowed because the law requires it
MINIMUMS. Accounting records: five years from the end of the accounting period, or longer where other law requires it (Law 4308/2014, Article 7). Medical records: ten years from the last visit for a private practice, twenty years otherwise (Law 3418/2005, Article 14(4)). Online gambling: ten years, and you must be able to reproduce the data on demand for the supervisory, audit and judicial authorities (Law 4002/2011). Telecoms traffic and location data: twelve months. That is a duty to keep, not a permission (Law 3917/2011, Article 6). MAXIMUMS. The general European rule is that you must not keep personal data longer than you need it. Telecoms retained data must be destroyed automatically once the twelve months expire. Where the data was lawfully accessed, destruction follows within ten days of notification. So here the minimum and the maximum are the same date. That is unusual and easy to get wrong. WHICH WINS. A specific legal duty to keep data is a legal duty under European law. It overrides an individual's request to erase. Greek practice follows this. The awkward cases are backups and log archives. There the specific rule says keep and the general rule says purge.
Sources
- Official sourceMinistry of National Economy and FinanceLaw 4308/2014 (Greek Accounting Standards), Article 7 — five-year retention of accounting records
minfin.gov.gr
“Το σύνολο των λογιστικών αρχείων ... διαφυλάσσονται για το μεγαλύτερο χρονικό διάστημα από: α) Πέντε (5) έτη από τη λήξη της περιόδου”
Link checked 18 August 2026
- Official sourceEuropean Commission, Directorate-General for HealthOverview of the national laws on electronic health records — Greece: Code of Medical Ethics (Law 3418/2005), Article 14(4)
health.ec.europa.eu
“10 (ten) years from the last visit ... 20 (twenty) years from the last visit”
Link checked 18 August 2026
- Official sourceHellenic Authority for Communication Security and Privacy (ADAE)Law 3917/2011, Article 6 — twelve-month telecoms retention and automatic destruction
adae.gov.gr
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
If something goes wrong
There are three clocks, not one. If personal data is lost or exposed, you have 72 hours to tell the privacy regulator. If you run important infrastructure, you have only 24 hours to send a first warning to the national cybersecurity authority. You then have 72 hours for a fuller report and one month for the final one. If you are a phone or internet provider, you have 24 hours to report a personal data breach. You also have a separate duty to tell the communications secrecy authority. Missing the 24-hour clocks is the most common failure.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents
Clock 1, general privacy. 72 hours from awareness to the Hellenic Data Protection Authority. You must also tell affected individuals without undue delay where the risk to them is high. Clock 2, cybersecurity. Law 5160/2024 brought the European network and information security directive into Greek law. It was published on 27 November 2024. It requires an early warning to the National Cybersecurity Authority 'without undue delay and in any event within twenty-four (24) hours'. Then an incident notification within 72 hours, and a final report within one month. Clock 3, telecoms. Providers of publicly available electronic communications services must notify a personal data breach within 24 hours under Commission Regulation (EU) 611/2013. They must also deal with ADAE where the secrecy of communications is involved. These clocks run in parallel from different starting points. The privacy clock starts at 'awareness'. The cybersecurity clock starts at 'becoming aware of a significant incident'. One event routinely starts all three, and the 24-hour ones start first.
Sources
- Official sourceNational Cybersecurity Authority of GreeceReporting guide to Law 5160/2024, Article 16 — 24-hour early warning, 72-hour notification, one-month final report
cyber.gov.gr
“χωρίς αδικαιολόγητη καθυστέρηση και σε κάθε περίπτωση εντός είκοσι τεσσάρων (24) ωρών”
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679, Articles 33 and 34 — 72-hour breach notification
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionCommission Regulation (EU) 611/2013 — 24-hour breach notification by electronic communications providers
eur-lex.europa.eu
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
Five things will cost you a weekend. First, a child in Greece can consent to an online service at fifteen, not sixteen. An age gate built to the European default is set wrong. Second, misusing personal data is a crime here, with prison time, not just a fine. Third, several articles of the Greek privacy law are printed in the statute, but the regulator has formally said they must not be applied. They clash with European law. Fourth, telecoms connection records must physically stay in Greece. Fifth, government bodies cannot simply pick a commercial cloud.
- What you have to do here:
- Get a parent's consent for children · Keep the data in the country
- What it costs if you get it wrong:
- Criminal liability
1. AGE FIFTEEN. Article 21(1) of Law 4624/2019 sets the age at which a minor can consent to an information society service at 15. The European default is 16, and other member states range from 13 to 16. A single global age gate set to 16 over-blocks in Greece. One set to 13 is unlawful here. 2. CRIMINAL LIABILITY. Article 38 of Law 4624/2019 makes it a crime to pass personal data to someone not entitled to it. For special categories of data, such as health, biometrics and political opinions, the penalty rises. It becomes imprisonment of at least one year plus a fine of up to 100,000 euros (about 110,000 US dollars). This attaches to individuals, not only to the company. The criminal courts prosecute it, not the privacy regulator. 3. PRINTED BUT UNENFORCEABLE. In Opinion 1/2020 the Hellenic Data Protection Authority concluded that several parts of Law 4624/2019 must not be applied. They are Article 5, Article 6(6)-(8), Articles 22, 24, 25, 26 and Article 27. They do not meet the conditions European rules impose on national law. Those articles are still printed in the statute. A naive reading of the Greek text will produce advice the regulator itself rejects. An example is relying on Article 5 as a standalone legal basis for public-sector work, or on Article 27 for employee data. 4. TELECOMS DATA MUST STAY IN GREECE. Law 3917/2011 requires retained traffic and location data to sit on physical media inside Greek territory. A pan-European telecoms design that centralises this data in one non-Greek data centre breaks Greek law. 5. STATE CLOUD FOR THE PUBLIC SECTOR. Article 87 of Law 4727/2020 obliged public bodies to move their central applications into the Greek state's own clouds by 1 January 2022. If you sell software to Greek ministries, hospitals or universities, your hosting model is decided for you. 6. BONUS, for telecoms and anyone handling interception requests. Law 5002/2022 governs the lifting of communications confidentiality. It was rewritten after the 2022 surveillance scandal. Telling the subscriber is delayed and conditional. A separate constitutional authority polices the rules.
Sources
- Official sourceHellenic Data Protection AuthorityLaw 4624/2019, Articles 21 and 38 — age 15 for a minor's consent; criminal penalties
dpa.gr
“the processing of the personal data of a minor shall be lawful where the minor is at least 15 years old”
Link checked 18 August 2026
- Official sourceHellenic Data Protection AuthorityOpinion 1/2020 of the Hellenic Data Protection Authority on the provisions of Law 4624/2019
dpa.gr
“δεν πληρούν καμία από τις ανωτέρω ουσιαστικές και διαδικαστικές προϋποθέσεις”
Link checked 18 August 2026
- Official sourceHellenic Authority for Communication Security and Privacy (ADAE)Law 5002/2022 on the procedure for lifting the confidentiality of communications, Gazette A 228 of 9 December 2022
adae.gov.gr
Link checked 18 August 2026
What's changing next
Three dated changes. Electronic invoicing between businesses became compulsory for large Greek companies on 2 March 2026 and becomes compulsory for everyone else on 1 October 2026. Greece's new artificial intelligence law took effect on 22 July 2026 and forces public bodies to register every artificial intelligence system before switching it on. And from 12 January 2027 European law bans cloud providers from charging you to move your data out.
DATED. - 1 October 2026: compulsory business-to-business electronic invoicing extends to all remaining Greek businesses. There is a phase-in window to 31 December 2026. Large businesses, meaning over 1 million euros of 2023 revenue, were originally due on 2 February 2026. The tax authority pushed them to 2 March 2026 on 17 February 2026, with a phase-in to 3 May 2026. - 22 July 2026: Law 5321/2026 was published. It creates Greece's national rules for the European artificial intelligence law. It replaces the relevant parts of Law 4961/2022. It names the competent national authorities. It creates a single registry in which public bodies must record artificial intelligence systems before they go live. It contains transitional rules for public bodies. - 12 January 2027: under the European Data Act, cloud switching charges and data export fees must fall to zero. This is a firm deadline and you cannot contract out of it. THINGS THAT COULD CHANGE WITH NO CONSULTATION. - The Law 3917/2011 rule that telecoms data must stay in Greece could be repealed or narrowed at any time by Parliament. A Greek court applying European case law could also stop applying it overnight. Independent legal analysis published in September 2025 looked at Articles 1, 3, 5 and 6 of that law. It argues they conflict with the European Court's rulings on general and indiscriminate retention. No Greek court has yet stopped applying them, so the duty still binds. But the ground is unstable in both directions. - ADAE can issue new binding security rules for communications providers by decision alone. It did exactly that in August 2025. - The government can extend the state-cloud duty, or narrow the exemptions, by amending Article 87. - The EU-US Data Privacy Framework remains the biggest outside risk. It is valid today. But the Latombe appeal is pending before the European Union's top court. On 31 July 2026 the European Data Protection Board formally asked the Commission to re-examine its validity.
Sources
- Official sourceIndependent Authority for Public Revenue (AADE)Press release of 16 September 2025 — timetable for mandatory business-to-business electronic invoicing
aade.gr
“1/10: Έναρξη υποχρεωτικής εφαρμογής”
Link checked 18 August 2026
- Official sourceIndependent Authority for Public Revenue (AADE)Press release of 17 February 2026 — postponement of the first phase to 2 March 2026
aade.gr
“2/3/2026 : Έναρξη υποχρεωτικής εφαρμογής”
Link checked 18 August 2026
- Official sourceSpecial Secretariat for Artificial Intelligence and Data GovernanceGreece adopts its national framework for implementing the AI Act — Law 5321/2026, published 22 July 2026
ai.gov.gr
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2023/2854 (Data Act) — zero switching charges from 12 January 2027
eur-lex.europa.eu
Link checked 18 August 2026
What to do: Diarise 12 January 2027 — that is the date this changes.
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries7 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Telecoms data must stay in the country
Official name: Νόμος 3917/2011 — Διατήρηση δεδομένων που παράγονται ή υποβάλλονται σε επεξεργασία σε συνάρτηση με την παροχή υπηρεσιών ηλεκτρονικών επικοινωνιών · Law 3917/2011, Gazette A 22 of 21 February 2011, Article 6 (as amended by Article 96 of Law 4139/2013) · Act of parliament
Greek phone and internet providers must keep records of who called whom, where and when for twelve months. They must keep them on machines physically inside Greece. This is a real must-stay-here rule with no European equivalent.
Enforced by Hellenic Authority for Communication Security and Privacy
How this country controls where data goes: Not allowed
What you have to do
- Keep the data in the countryThe retained data must be generated and stored on physical media located inside the borders of Greek territory.
- Keep data for a minimum period — 1 year
- Delete data after a period — 1 yearAutomatic destruction once the twelve months expire; within ten days of notification where the data was lawfully accessed.
- Secure the data
What it costs if you get it wrong
- Fixed maximum fineBreach of the retention and security duties, enforced by the communications privacy authority
- Loss of your licenceSerious or repeated breach by a licensed provider
Sources
- Official sourceHellenic Authority for Communication Security and Privacy (ADAE)Law 3917/2011, Article 6 — place and duration of retention
adae.gov.gr
“Τα δεδομένα του άρθρου 5 παράγονται και αποθηκεύονται σε φυσικά μέσα, τα οποία βρίσκονται μέσα στα όρια της Ελληνικής Επικρατείας, εντός της οποίας και διατηρούνται για τους σκοπούς του παρόντος κεφαλαίου επί 12 μήνες από την ημερομηνία της επικοινωνίας”
Link checked 18 August 2026
- Official sourceHellenic Authority for Communication Security and Privacy (ADAE)Law 3917/2011 in the communications privacy authority's own legal framework library
adae.gov.gr
Link checked 18 August 2026
- Secondary sourceHomo Digitalis / Digital Freedom FundCase-law analysis, September 2025 — argues Articles 1, 3, 5 and 6 of Law 3917/2011 are contrary to EU Court rulings on general and indiscriminate retention
digitalfreedomfund.org
Link checked 18 August 2026
Online gaming data must stay in the country
Official name: Νόμος 4002/2011 — Ρύθμιση της αγοράς παιγνίων, άρθρο 47, και Κανονισμοί Παιγνίων (ΥΑ 79305/2020 και 79835/2020) · Law 4002/2011, Article 47, as amended by Law 4635/2019; Ministerial Decisions 79305 EX 2020 and 79835 EX 2020 · Act of parliament
An online gambling operator licensed in Greece must store its records on a server or safe physically located in Greece. It must keep them for ten years. You need a licence to serve Greek players at all.
Enforced by Hellenic Gaming Commission
How this country controls where data goes: Not allowed
What you have to do
- Keep the data in the countryRecords must be stored on a physical device located in Greece. That is a server or a 'safe'.
- Keep data for a minimum period — 10 yearsTen years, reproducible on demand for the regulator, auditors and the courts.
- Register or notifyAn operating licence from the Hellenic Gaming Commission is required.
- Secure the data
What it costs if you get it wrong
- Loss of your licenceBreach of licence conditions
- Fixed maximum fineAdministrative penalties under Article 51 of Law 4002/2011
Sources
- Official sourceHellenic Gaming Commission (EEEP)Hellenic Gaming Commission — official site of the licensing and supervisory authority for online gambling under Law 4002/2011
gamingcommission.gov.gr
Link checked 18 August 2026
- Secondary sourceNomoskopioLaw 4002/2011, Article 47 — consolidated text (non-government database)
nomoskopio.gr
“υποχρεούται να αποθηκεύει σε υλικό μηχανισμό που βρίσκεται στην Ελλάδα (διακομιστή server ή safe)”
Link checked 18 August 2026
- Secondary sourcee-nomothesiaMinisterial Decision 79835 EX 2020, Gazette B 3265 of 5 August 2020 — consolidated online gaming regulation, ten-year retention
e-nomothesia.gr
“τηρεί τα στοιχεία, έγγραφα και δεδομένα για δέκα (10) τουλάχιστον έτη”
Link checked 18 August 2026
Cloud and outsourcing rules
Official name: Νόμος 4727/2020 — Ψηφιακή Διακυβέρνηση, άρθρο 87 (Κυβερνητικά νέφη) · Law 4727/2020, Article 87, Gazette A 184 of 23 September 2020 · Act of parliament
Greek public bodies had to move their central computer systems into the Greek state's own clouds by 1 January 2022. Defence, foreign affairs, the intelligence service, civil protection, the coastguard, the tax authority and academic bodies are exempt.
Enforced by Ministry of Digital Governance
How this country controls where data goes: Approval each time
What you have to do
- Keep the data in the country — from 1 January 2022Central public-sector applications must run in one of three state clouds: G-Cloud for general government, RECloud for research and education, H-Cloud for health.
- Secure the data
Sources
- Official sourceHellenic Ministry of Digital GovernanceMinistry of Digital Governance — the ministry responsible for the government cloud programme under Law 4727/2020
mindigital.gr
Link checked 18 August 2026
- Secondary sourceLawspotLaw 4727/2020, Article 87 (government clouds) — consolidated text (non-government database)
lawspot.gr
“Στο Κυβερνητικό Νέφος Δημόσιου Τομέα πρέπει υποχρεωτικά να εγκατασταθούν έως την 1η.01.2022 όλες οι κεντρικές ηλεκτρονικές εφαρμογές”
Link checked 18 August 2026
Telecoms rules
Official name: Απόφαση ΑΔΑΕ 304/2025 — Κανονισμός για τη διασφάλιση του απορρήτου των ηλεκτρονικών επικοινωνιών · ADAE Decision 304/2025, Gazette B 4268 of 7 August 2025 · Directly binding regulation
This is a binding 2025 regulation. It sets the security measures Greek communications providers must take to protect the secrecy of communications. That includes encryption and liability for contractors. Standard supplier contracts are not enough here.
Enforced by Hellenic Authority for Communication Security and Privacy
What you have to do
- Secure the dataWritten security policy reviewed at least every two years, encryption of stored and transmitted communications data, two-factor authentication for critical systems, network segmentation.
- Extra vendor secrecy termsContracts with contractors must carry confidentiality and security terms; the provider stays liable for everything the contractor does.
- Keep logsPhysical and logical access to systems holding communications data must be pre-authorised and logged.
- Independent audit
What it costs if you get it wrong
- Fixed maximum fineBreach of the communications confidentiality regulation
Sources
- Official sourceHellenic Authority for Communication Security and Privacy (ADAE)ADAE Decision 304/2025, Gazette B 4268 of 7 August 2025
adae.gov.gr
Link checked 18 August 2026
- Official sourceHellenic Authority for Communication Security and Privacy (ADAE)Regulatory framework for electronic communications providers
adae.gov.gr
Link checked 18 August 2026
Cloud and outsourcing rules (Finance)
Official name: Πράξη Εκτελεστικής Επιτροπής 178/5/2.10.2020 — Εξωτερική ανάθεση δραστηριοτήτων · Bank of Greece Executive Committee Act 178/5/2.10.2020 · Regulator directive
Greek banks and insurers must tell the Bank of Greece before outsourcing anything critical, including to a cloud provider. No approval is needed and there is no rule that the data must stay in Greece.
Enforced by Bank of Greece
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Written vendor contractWritten outsourcing agreement with audit and access rights, following the European banking guidelines on outsourcing to cloud providers.
- Keep records of how you use dataRegister of outsourcing arrangements.
- Independent audit
What it costs if you get it wrong
- Fixed maximum fineSupervisory measures and penalties under the banking supervision framework
Sources
- Official sourceBank of GreeceThe Bank of Greece specifies the regulatory framework governing outsourcing of supervised institutions
bankofgreece.gr
“without the need for a relevant approval decision”
Link checked 18 August 2026
Health data rules
Official name: Νόμος 3418/2005 — Κώδικας Ιατρικής Δεοντολογίας, άρθρο 14 (τήρηση ιατρικού αρχείου) · Law 3418/2005, Article 14(4) · Act of parliament
Greek medical records must be kept for ten years in a private practice and twenty years in a hospital, counted from the patient's last visit. No rule was found requiring private health data to stay in Greece.
Enforced by Hellenic Data Protection Authority
What you have to do
- Keep data for a minimum period — applies at: Private medical practice, 10 yearsTen years from the last visit.
- Keep data for a minimum period — applies at: Hospitals and all other cases, 20 yearsTwenty years from the last visit.
- Extra vendor secrecy termsMedical confidentiality is a professional duty backed by criminal law, so a standard supplier data agreement is not sufficient on its own.
What it costs if you get it wrong
- Criminal liabilityBreach of medical confidentiality
Sources
- Official sourceEuropean Commission, Directorate-General for HealthOverview of the national laws on electronic health records — Greece
health.ec.europa.eu
“10 (ten) years from the last visit ... 20 (twenty) years from the last visit”
Link checked 18 August 2026
Record-keeping rules for tax and accounts
Official name: Νόμος 4308/2014 — Ελληνικά Λογιστικά Πρότυπα, άρθρα 5 και 7 · Law 4308/2014, Gazette A 251 of 24 November 2014, Articles 5 and 7 · Act of parliament
Business books and records must be kept for five years. You must produce them to the tax authorities on request. The law does not say they have to be stored in Greece. But it does require them to be available quickly. That means an auditor must be able to reach them from Greece.
Enforced by Independent Authority for Public Revenue
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Keep data for a minimum period — 5 yearsFive years from the end of the accounting period, or longer where other law requires it.
- Keep records of how you use dataThe records must be made available to the tax and audit authorities within a reasonable time.
What it costs if you get it wrong
- Fixed maximum fine: €500 to €1,000 per audit for e-invoicing failures, or 50% of the VAT involved — about $1 thousandFailure to issue compliant electronic invoices
Sources
- Official sourceMinistry of National Economy and FinanceLaw 4308/2014 (Greek Accounting Standards), Articles 5 and 7
minfin.gov.gr
“Τα λογιστικά αρχεία πρέπει να είναι διαθέσιμα στα αρμόδια ελεγκτικά όργανα”
Link checked 18 August 2026
- Official sourceIndependent Authority for Public Revenue (AADE)Mandatory electronic invoicing and digital delivery documents — frequently asked questions
aade.gr
Link checked 18 August 2026
Applies to every company3 rules
These bind you whatever business you are in, once the country's rules reach you.
Europe's main privacy law (2019)
Official name: Νόμος 4624/2019 — Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα, μέτρα εφαρμογής του Κανονισμού (ΕΕ) 2016/679 · Law 4624/2019, Gazette A 137 of 29 August 2019 · Act of parliament
Greece's national privacy law sits on top of the European rules. It adds no storage-location requirement. But it lowers the age of a child's own consent to 15. It also makes misuse of personal data a crime, with prison time attached.
Enforced by Hellenic Data Protection Authority
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules
What you have to do
- Get a parent's consent for children — applies at: under 15 years oldGreece set the age of a minor's own consent at 15, not the European default of 16.
- Appoint a data protection officerMandatory for public bodies; otherwise as under the European rules.
- Tell people what you do
- Secure the data
What it costs if you get it wrong
- Criminal liability: Imprisonment, rising to at least one year plus a fine up to €100,000 for special categories of data — about $110 thousandTransmitting or making personal data available to a person not entitled to receive it
- Fixed maximum fine: €10 million — about $11 millionInfringement by a public-sector body
Sources
- Official sourceHellenic Data Protection AuthorityLaw 4624/2019 — full English translation published by the Hellenic Data Protection Authority
dpa.gr
“the processing of the personal data of a minor shall be lawful where the minor is at least 15 years old”
Link checked 18 August 2026
- Official sourceHellenic Data Protection AuthorityPersonal data — legal framework page of the Hellenic Data Protection Authority
dpa.gr
Link checked 18 August 2026
Cyber security rules
Official name: Νόμος 5160/2024 — Ενσωμάτωση της Οδηγίας (ΕΕ) 2022/2555 (NIS2) · Law 5160/2024, Gazette A 195 of 27 November 2024 · Act of parliament
Greece's cybersecurity law applies to operators of important services and their suppliers. It imposes no storage-location rule, but it does impose a 24-hour first warning that runs faster than the 72-hour privacy clock.
Enforced by National Cybersecurity Authority
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Report cyber incidents — within 24 hoursEarly warning within 24 hours; incident notification within 72 hours; final report within one month.
- Secure the data
- Register or notifyCovered organisations must register with the National Cybersecurity Authority and name a security officer.
- Independent audit
What it costs if you get it wrong
- Percentage of global turnover: €10 million or 2% of worldwide annual turnover for essential entities — about $11 millionFailure to meet risk-management or incident-reporting duties
- Percentage of global turnover: €7 million or 1.4% of worldwide annual turnover for important entities — about $8 millionFailure to meet risk-management or incident-reporting duties
Sources
- Official sourceNational Cybersecurity Authority of GreeceReporting guide to Law 5160/2024 — Article 16 deadlines and penalty ceilings
cyber.gov.gr
“χωρίς αδικαιολόγητη καθυστέρηση και σε κάθε περίπτωση εντός είκοσι τεσσάρων (24) ωρών”
Link checked 18 August 2026
- Official sourceNational Cybersecurity Authority of GreeceThe NIS2 Directive in Greece — National Cybersecurity Authority
cyber.gov.gr
Link checked 18 August 2026
AI rules
Official name: Νόμος 5321/2026 — Εθνικό εφαρμοστικό πλαίσιο του Κανονισμού (ΕΕ) 2024/1689 για την Τεχνητή Νοημοσύνη · Law 5321/2026, published 22 July 2026; replaces the corresponding provisions of Law 4961/2022 · Act of parliament
Greece's national artificial intelligence law took effect on 22 July 2026. It names the Greek authorities that supervise the European artificial intelligence rules. It forces public bodies to register every artificial intelligence system before switching it on. Transitional rules mean not every duty applies yet.
Enforced by Special Secretariat for Artificial Intelligence and Data Governance
What you have to do
- Register or notify — applies at: Public-sector bodies, from 22 July 2026Every artificial intelligence system used by a public body must be entered in a single national registry before it starts operating.
- Check your algorithms
- Assess high-risk projects
What it costs if you get it wrong
- Fixed maximum finePenalties under the national framework for the European artificial intelligence rules
Sources
- Official sourceSpecial Secretariat for Artificial Intelligence and Data GovernanceGreece adopts the national framework implementing the AI Act — Law 5321/2026
ai.gov.gr
Link checked 18 August 2026
- Official sourceHellenic Ministry of Digital GovernanceGreece acquires a complete national framework for implementing the EU Artificial Intelligence Regulation
mindigital.gr
Link checked 18 August 2026
Applies across the European Union1 rule
Written once for the whole bloc, and in force in every member country.
Europe's main privacy law
Official name: Γενικός Κανονισμός για την Προστασία Δεδομένων (General Data Protection Regulation) · Regulation (EU) 2016/679 · Directly binding regulation
The European privacy rules apply in Greece directly. They do not require data to stay in Europe. They set the conditions for letting it leave. Fines scale with the worldwide turnover of the whole group.
Enforced by Hellenic Data Protection Authority
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims
What you have to do
- Tell people what you do
- Get consent
- Document a legitimate interest
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people take their data elsewhere
- Let people object
- Limit automated decisions
- Secure the data
- Keep records of how you use data
- Assess high-risk projects
- Written vendor contract
- Put a transfer safeguard in place
- Appoint a representativeYou only need this if you have no office anywhere in the European Union.
- Report breaches to the regulator — within 72 hours
- Tell affected people
- Delete data after a period
What it costs if you get it wrong
- Percentage of global turnover: €20 million or 4% of worldwide group turnover, whichever is higher — about $22 millionBasic principles, individual rights, unlawful international transfers, defying a regulator order
- Percentage of global turnover: €10 million or 2% of worldwide group turnover, whichever is higher — about $11 millionSecurity, records, breach notification and similar duties
- Order to stopOrder to stop processing or to suspend flows outside Europe
- Claims by individualsCompensation claims by individuals
Sources
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679 — General Data Protection Regulation, consolidated text
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceEuropean CommissionAdequacy decisions — the current approved-destination list
commission.europa.eu
Link checked 18 August 2026
On the books, but not enforceable1 rule
These rules are still printed in the law, but a court struck them down or the regulator has said it will not apply them. You do not have to comply today. They are here because text nobody deleted can come back without warning.
General data protection law
Official name: Νόμος 4624/2019, άρθρα 5, 6 παρ. 6-8, 22, 24, 25, 26 και 27 · Law 4624/2019, Articles 5, 6(6)-(8), 22, 24, 25, 26, 27; assessed in HDPA Opinion 1/2020 of 24 January 2020 · Act of parliament
Several articles of the Greek privacy law are still printed in the statute. But the privacy regulator has formally said they clash with European law and must not be applied. They cover public-sector work, data protection officers, special categories of data, reuse of data for new purposes, and employee data.
Enforced by Hellenic Data Protection Authority
What you have to do
- Allowed because the law requires itDo not rely on these articles as a legal basis. The regulator says they must not be applied.
Sources
- Official sourceHellenic Data Protection AuthorityOpinion 1/2020 of 24 January 2020 on the provisions of Law 4624/2019 (ref. G/EX/606/24-01-2020)
dpa.gr
“δεν πληρούν καμία από τις ανωτέρω ουσιαστικές και διαδικαστικές προϋποθέσεις”
Link checked 18 August 2026
- Official sourceHellenic Data Protection AuthorityOn the provisions of Law 4624/2019 — the regulator's own landing page for Opinion 1/2020
dpa.gr
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
The exact wording of Article 47 of Law 4002/2011 requiring an online gambling operator to store records on a server or safe located in Greece
We could not confirm this against a government source. We verified the exact Greek text only on a commercial consolidated-law database. The Hellenic Gaming Commission's own website blocks automated retrieval on most paths, so we could not get the gazette copy. We record the rule at medium confidence, with the regulator's own licensing page as the government link.
Whether Article 87 of Law 4727/2020 imposes a geographic requirement, as opposed to a requirement to use named Greek state operators
We could not confirm that the law requires this infrastructure to be physically in Greece. The article names the operators: the General Secretariat for Information Systems, the national research network body and the state health IT company. It says nothing about geography. We rate the effect as closed because those clouds are state-run domestic infrastructure. We could not get the text from a government host.
Whether Greek courts are still applying the telecoms retention duty in Law 3917/2011 in full
We could not confirm how safe this duty is to rely on. Independent analysis published in September 2025 argues Articles 1, 3, 5 and 6 conflict with the European Court's rulings on general and indiscriminate retention. We found no Greek court decision setting them aside, and no repeal. So we record the duty as in force. But a court could set it aside without warning, and we could not verify current prosecution practice from an official source.
The precise designated authorities, penalty levels and commencement dates under Law 5321/2026 on artificial intelligence
We could not confirm who supervises this law. The government announcement confirms the law and its date. It does not name the market surveillance authority, the notifying authority or the single point of contact. It does not publish the transitional dates. We could not retrieve the gazette text.
Whether the Bank of Greece outsourcing act contains any data-location condition in its full text
We could not confirm the full text of Executive Committee Act 178/5/2.10.2020. We verified the notify-but-no-approval rule from the Bank of Greece's own press release. A location condition buried in an annex cannot be ruled out.
Whether any Greece-specific restriction applies to detailed mapping, aerial imagery or geospatial data leaving the country
We found no such restriction, checked 18 August 2026. The Hellenic Military Geographical Service publishes copyright and licensing terms, not a rule about where data must sit. We did not check whether military-sensitive imagery carries separate export controls.
Whether any sector rule applies to securities firms or account aggregation beyond the directly applicable European financial resilience rules
We could not confirm this for securities firms. We did not search the Hellenic Capital Market Commission's rulebook. We expect no rule forcing data to stay in Greece, but this is an untested gap rather than a verified answer. If you work in securities, check before you rely on it.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.