Country:希腊 · Data Privacy
Greece · Data Privacy
Greece implements EU GDPR through Law 4624/2019, regulated by the HDPA (Hellenic Data Protection Authority). Law 5160/2024 transposes the NIS2 Directive, establishing cybersecurity obligations for essential entities. Non-EU enterprises offering goods or services to Greek users or monitoring their behavior must appoint an EU representative under GDPR Article 27 (as in HDPA's enforcement against DeepSeek). No mandatory data localization, but cross-border transfers require adequacy determinations or standard contractual clauses.
Key points
- Core laws: Law 4624/2019 (GDPR implementation), Law 3471/2006 (ePrivacy).
- Regulator: HDPA (Hellenic Data Protection Authority).
- NIS2: Law 5160/2024 (essential-entity cybersecurity and incident reporting).
- Non-EU controllers or processors must appoint an EU representative (GDPR Article 27).
- No mandatory data localization; cross-border transfers require adequacy or SCCs.
- DPO: required for large-scale sensitive data processing.
- China data outbound obligations (pkulaw verified 2026-07): transfers back to China must use security assessment (CAC Order 11), standard contract (Order 13) or certification (CAC-SAMR Order 20, effective 2025-10-14); 2024-2025 scope eased - Provisions on Promoting and Regulating Cross-border Data Flows (Order 16) and Regulations on Network Data Security Administration (State Council Order 790) exempt certain cases.
Procedure
- Data mapping and processing records (ROPA).
- If applicable, appoint a DPO and EU representative.
- Conduct a DPIA for high-risk processing.
- Establish cross-border transfer mechanisms (SCCs or adequacy).
Hard requirements
- EU representative (non-EU enterprises); DPO (large-scale sensitive processing).
Costs
Compliance and agency costs; violations fined up to 4% of global revenue or €20 million.⏱ ⏱ Timeline:Continuous compliance.⚠ Common risks
- HDPA enforcement strengthening (transparency, insufficient security measures).
- Missing GDPR Article 27 EU representative ordered to remediate.
- Cross-border transfers without lawful mechanisms fined.
Handbook
📘 Step-by-Step Handbook (with owner / timeline / cost / penalties)
Applies to:Chinese enterprises processing EU residents' personal data in Greece (EU), or without a Greek entity offering goods/services to Greek users or monitoring their behavior, and transferring data back to China (GDPR + Law 4624/2019 + NIS2).
Prerequisites
- GDPR extraterritorial applicability triggers clarified
- No EU entity: EU representative required (Article 27)
- DPO requirement assessed (large-scale sensitive data processing)
| Step | Action | Owner | Timeline | Cost | Official form / system | Notes & penalties |
|---|---|---|---|---|---|---|
| 1 | Data mapping and processing records (ROPA) Map processing activities, legal bases, data categories and recipients; build a ROPA | Legal/compliance | 2-3 weeks | Internal cost | ROPA, data inventory | GDPR Article 30 Penalty:Up to 4% of global revenue or €20 million |
| 2 | Determine legal basis and publish privacy policy Determine legal basis under GDPR; publish Greek/English privacy policy with transparent notice | Legal | 1-2 weeks | Internal cost | Privacy policy | ePrivacy (Law 3471/2006) supplementary requirements Penalty:Same cap as step 1 |
| 3 | No EU entity: appoint an EU representative (Article 27) Designate a written representative within the EU (referencing HDPA's enforcement precedent against DeepSeek) | Management/legal | 1-2 weeks | Representative service fees | EU representative authorization | Penalty:Missing representative: order to remediate and fines |
| 4 | Cross-border transfer mechanism (SCC/adequacy) Transfers back to China require SCCs with a TIA; also complete the China-side PIPL outbound mechanism | Legal | 3-6 weeks | Internal/lawyer fees | SCCs, TIA, PIPL outbound documents | China has no adequacy determination Penalty:Transfers without lawful mechanism penalized |
| 5 | Appoint a DPO (if applicable) Large-scale sensitive data processing requires a DPO with HDPA liaison duties | Management | Continuous | DPO headcount | DPO appointment | Must be independent Penalty:Failure to appoint penalized |
| 6 | High-risk processing requires DPIA Conduct a data protection impact assessment (DPIA) for monitoring, large-scale sensitive processing, etc. | Compliance/IT | 2-4 weeks | Internal cost | DPIA report | NIS2 (Law 5160/2024) incident reporting obligations Penalty:No DPIA penalized |
| 7 | 72-hour breach notification and continuous compliance Report breaches to HDPA within 72 hours; annual review and training | DPO/IT | 72 hours + annual | Internal cost | HDPA breach report, annual audit | HDPA enforcement strengthening Penalty:Late reporting/continuous violations accumulate |
✅ Self-check list
⚠ Common pitfalls
No Greek entity, EU representative obligation ignored影响:Ordered to remediate and fined规避:Appoint a representative under Article 27
No SCCs for transfers back to China影响:Heavy GDPR fines规避:Sign SCCs and conduct TIA
NIS2 incident reporting ignored影响:Extra penalties for essential entities规避:Build an NIS2 reporting line
PIPL outbound ignored for transfers back to China影响:Dual violations规避:Complete the China-side mechanism in parallel
High-risk processing without DPIA影响:Fined规避:DPIA upfront
No processing records影响:Aggravated liability on inspection规避:Maintain ROPA continuously
📅 Ongoing post-incorporation obligations
- EU representative continuously in service
- DPO duties (if applicable)
- 72-hour breach notification (HDPA)
- SCC/TIA and China PIPL outbound mechanism continuously valid
- Annual review, DPIA updates and training
🔗 Official portals
📎 Source:Hellenic Data Protection Authority (HDPA); Law 4624/2019 (GDPR implementation); Law 5160/2024 (NIS2); GDPR Article 27; https://www.cac.gov.cn
Want to turn this into an actionable compliance workflow?
CompliGo · Outbound Compliance Automation
You now have the essentials. Hand it to CompliGo: auto-generate compliance documents, real-time validation, and one-click regulatory alerts. Free trial for new users.
CompliGo is an independent SaaS operated by the outbound team. This knowledge base only drives acquisition and never handles funds or collects/pays on your behalf.