Country:希腊 · Data Privacy
High confidenceUpdated 2026-08-03Handbook

Greece · Data Privacy

Greece implements EU GDPR through Law 4624/2019, regulated by the HDPA (Hellenic Data Protection Authority). Law 5160/2024 transposes the NIS2 Directive, establishing cybersecurity obligations for essential entities. Non-EU enterprises offering goods or services to Greek users or monitoring their behavior must appoint an EU representative under GDPR Article 27 (as in HDPA's enforcement against DeepSeek). No mandatory data localization, but cross-border transfers require adequacy determinations or standard contractual clauses.

Key points

Procedure

  1. Data mapping and processing records (ROPA).
  2. If applicable, appoint a DPO and EU representative.
  3. Conduct a DPIA for high-risk processing.
  4. Establish cross-border transfer mechanisms (SCCs or adequacy).

Hard requirements

Costs

Compliance and agency costs; violations fined up to 4% of global revenue or €20 million.⏱ ⏱ Timeline:Continuous compliance.

⚠ Common risks

  • HDPA enforcement strengthening (transparency, insufficient security measures).
  • Missing GDPR Article 27 EU representative ordered to remediate.
  • Cross-border transfers without lawful mechanisms fined.
Handbook

📘 Step-by-Step Handbook (with owner / timeline / cost / penalties)

Applies to:Chinese enterprises processing EU residents' personal data in Greece (EU), or without a Greek entity offering goods/services to Greek users or monitoring their behavior, and transferring data back to China (GDPR + Law 4624/2019 + NIS2).

Prerequisites

  • GDPR extraterritorial applicability triggers clarified
  • No EU entity: EU representative required (Article 27)
  • DPO requirement assessed (large-scale sensitive data processing)
StepActionOwnerTimelineCostOfficial form / systemNotes & penalties
1Data mapping and processing records (ROPA)
Map processing activities, legal bases, data categories and recipients; build a ROPA
Legal/compliance2-3 weeksInternal costROPA, data inventoryGDPR Article 30
Penalty:Up to 4% of global revenue or €20 million
2Determine legal basis and publish privacy policy
Determine legal basis under GDPR; publish Greek/English privacy policy with transparent notice
Legal1-2 weeksInternal costPrivacy policyePrivacy (Law 3471/2006) supplementary requirements
Penalty:Same cap as step 1
3No EU entity: appoint an EU representative (Article 27)
Designate a written representative within the EU (referencing HDPA's enforcement precedent against DeepSeek)
Management/legal1-2 weeksRepresentative service feesEU representative authorization
Penalty:Missing representative: order to remediate and fines
4Cross-border transfer mechanism (SCC/adequacy)
Transfers back to China require SCCs with a TIA; also complete the China-side PIPL outbound mechanism
Legal3-6 weeksInternal/lawyer feesSCCs, TIA, PIPL outbound documentsChina has no adequacy determination
Penalty:Transfers without lawful mechanism penalized
5Appoint a DPO (if applicable)
Large-scale sensitive data processing requires a DPO with HDPA liaison duties
ManagementContinuousDPO headcountDPO appointmentMust be independent
Penalty:Failure to appoint penalized
6High-risk processing requires DPIA
Conduct a data protection impact assessment (DPIA) for monitoring, large-scale sensitive processing, etc.
Compliance/IT2-4 weeksInternal costDPIA reportNIS2 (Law 5160/2024) incident reporting obligations
Penalty:No DPIA penalized
772-hour breach notification and continuous compliance
Report breaches to HDPA within 72 hours; annual review and training
DPO/IT72 hours + annualInternal costHDPA breach report, annual auditHDPA enforcement strengthening
Penalty:Late reporting/continuous violations accumulate

✅ Self-check list

⚠ Common pitfalls

No Greek entity, EU representative obligation ignored影响:Ordered to remediate and fined规避:Appoint a representative under Article 27
No SCCs for transfers back to China影响:Heavy GDPR fines规避:Sign SCCs and conduct TIA
NIS2 incident reporting ignored影响:Extra penalties for essential entities规避:Build an NIS2 reporting line
PIPL outbound ignored for transfers back to China影响:Dual violations规避:Complete the China-side mechanism in parallel
High-risk processing without DPIA影响:Fined规避:DPIA upfront
No processing records影响:Aggravated liability on inspection规避:Maintain ROPA continuously

📅 Ongoing post-incorporation obligations

  • EU representative continuously in service
  • DPO duties (if applicable)
  • 72-hour breach notification (HDPA)
  • SCC/TIA and China PIPL outbound mechanism continuously valid
  • Annual review, DPIA updates and training

🔗 Official portals

📎 Source:Hellenic Data Protection Authority (HDPA); Law 4624/2019 (GDPR implementation); Law 5160/2024 (NIS2); GDPR Article 27; https://www.cac.gov.cn
Want to turn this into an actionable compliance workflow?

CompliGo · Outbound Compliance Automation

You now have the essentials. Hand it to CompliGo: auto-generate compliance documents, real-time validation, and one-click regulatory alerts. Free trial for new users.

CompliGo is an independent SaaS operated by the outbound team. This knowledge base only drives acquisition and never handles funds or collects/pays on your behalf.