Instruments
Each one links to its
LexLint note, which carries what it requires and what it flags on.
Biometric privacy
cite Regulation (EU) 2016/679, Art. 9; Law 125(I)/2018
stage In effect
since 2018-07-31
source Secondary commentary (Harris Kyriakides), not independently confirmed against Law 125(I)/2018's own text this pass
General Data Protection Regulation (GDPR) Article 9(1) classifies biometric data processed for unique identification as a special category. Secondary commentary (Harris Kyriakides) describes Law 125(I)/2018 as prohibiting the processing of genetic and biometric data for life and health insurance purposes, and as requiring separate, specific consent, over and above the ordinary GDPR consent standard, where a controller relies on consent as the lawful basis for processing genetic or biometric data.
The provision's own text and article number were not independently confirmed this pass; neither addition distinguishes voice or face capture from any other biometric modality in the commentary consulted. No Cyprus-specific voiceprint or faceprint case or regulatory guidance was located.
What it asks of an app →
Breach notification
cite Regulation (EU) 2016/679, Arts. 33-34
stage In effect
since 2018-05-25
source Official Journal text, EUR-Lex, Regulation (EU) 2016/679
A controller must notify the ODPC without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Cyprus, and must notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms. No Law 125(I)/2018 derogation from this timeline was identified in this pass.
What it asks of an app →
Comprehensive regime
cite Law 125(I)/2018 of 2018
stage In effect
since 2018-07-31
source Official Gazette of the Republic of Cyprus, 31 July 2018
Cyprus's private-sector regime is the General Data Protection Regulation (GDPR) plus Law 125(I)/2018 (The Protection of Natural Persons with regard to the Processing of Personal Data and for the Free Movement of such Data Law of 2018), published in the Official Gazette of the Republic of Cyprus on 31 July 2018, supplying domestic derogations and procedural rules. The Office of the Commissioner for Personal Data Protection (ODPC) is the supervisory authority.
The law's official English translation PDF was not reachable at its previously published URL this pass (now redirecting to a general landing page), so article-level detail below is commentary sourced rather than a primary-text read.
What it asks of an app →
Cross border transfer
cite Regulation (EU) 2016/679, Arts. 44-49
stage In effect
since 2018-05-25
source Official Journal text, EUR-Lex, Regulation (EU) 2016/679
Transferring personal data of a person in Cyprus outside the European Economic Area requires a European Commission adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation, backed by the Article 83(5) top fine tier. No Law 125(I)/2018 derogation broadening or narrowing this was identified in this pass.
What it asks of an app →
Data subject rights
cite Regulation (EU) 2016/679, Art. 22; Law 125(I)/2018
stage In effect
since 2018-07-31
source Official Journal text, EUR-Lex, Regulation (EU) 2016/679
General Data Protection Regulation (GDPR) Articles 12 to 23 apply, including Article 22 rights against a decision based solely on automated processing, restated by Law 125(I)/2018 without narrowing per its own summary. No Cyprus-specific broadening of data-subject rights beyond the GDPR baseline was identified in this pass.
What it asks of an app →
Enforcement supervision
cite Regulation (EU) 2016/679, Arts. 82-83
stage In effect
since 2018-05-25
source Official Journal text, EUR-Lex, Regulation (EU) 2016/679
The Office of the Commissioner for Personal Data Protection (ODPC) is the supervisory authority and enforces General Data Protection Regulation (GDPR) Article 83 fines. No Cyprus-specific fine ceiling beyond the GDPR Article 83 maximum, and no dedicated collective-redress statute, was identified in this pass. GDPR Article 82 gives any person who suffered material or non-material damage a right to compensation from the controller or processor.
What it asks of an app →