Key Data & Cybersecurity Laws
Jump to
Key Data & Cybersecurity Laws Start Comparison
How are data and cybersecurity laws/regulations implemented?

Last review date: 19 December 2024

☒ omnibus – all personal data

☒ sector-specific

Law 3471/2006 governs the Electronic communications sector

What are the key data privacy laws and regulations?

Last review date: 19 December 2024

Please refer to the EU Chapter for detailed information regarding EU-wide legislation.

  • EU General Data Protection Regulation ("GDPR")
  • Law 4624/2019 on "Hellenic Data Protection Authority ("HDPA"), measures for implementing GDPR and transposition of Directive (EU) 2016/680 and other provisions"
  • Law 3471/2006 on "protection of personal data and privacy in the electronic communications sector" [incorporation of Directive (EU) 2002/58]
What are the key cybersecurity laws and regulations?

Last review date: 19 December 2024

Please refer to the EU Chapter for detailed information regarding EU-wide legislation.

  • Law 5160/2024 incorporating into Greek legislation Directive (EU) 2022/2555 (“NIS2”) of the European Parliament and of the Council of 14 December 2022 concerning measures to achieve a high common level of cybersecurity across the Union, amending Regulation (EU) 910/2014 and Directive (EU) 2018/1972 and repealing Directive (EU) 2016/1148 (“NIS”);
  • Law 5099/2024 on adoption of measures for the implementation of Regulation (EU) 2022/2065 of the European Parliament and of the Council of 19 October 2022 on the single market for digital services (“Digital Services Act” or “DSA”); The National Telecommunications and Post Commission (EETT) is the National Digital Services Coordinator and is responsible for supervising and checking compliance with the rules of the DSA in Greece and the Hellenic Data Protection Authority (HDPA) has been designated as competent authority for the supervision of intermediary service providers and the enforcement of point d of paragraph 1 & paragraph 3 of article 26 of the DSA (on advertising on online platforms) and Article 28 of the DSA (on online protection of minors).
  • Law 5086/2024 on the establishment of National Cybersecurity Authority.
  • Law 5002/2022 on "communications de-privacy process, cyber security and protection of citizens’ personal data", whereby provisions of Law 4624/2019 and Law 4577/2018 are amended;
  • Law 4961/2022 on “emerging information & communication technologies, reinforcement of digital governance and other provisions”.
  • Law 4537/2018 incorporating into Greek legislation Directive (EU) 2015/2366 on payment services in the internal market (“PSD2 Directive”)
What are the key laws and regulations relating to non-personal data?

Last review date: 19 December 2024

Law 4727/2020 on Digital Governance incorporating into Greek legislation Directive (EU) 2016/2102 and Directive (EU) 2019/1024– Electronic Communications incorporating into Greek legislation Directive (EU) 2018/1972.

Are new or material changes to those key data and cybersecurity laws anticipated in the near future?

Last review date: 19 December 2024

National (Greece) anticipated developments.

Nothing has been announced in this respect.