Law / Cyprus

Cyprus

privacy

Cyprus's private-sector regime is the General Data Protection Regulation (GDPR) plus Law 125(I)/2018, published in the Official Gazette on 31 July 2018, supplying domestic derogations and procedural rules.

Its most consequential national addition, per secondary commentary not independently confirmed against the Law's own text this pass, is a prohibition on processing genetic and biometric data for life and health insurance purposes, and a heightened, separate-consent requirement wherever consent is the lawful basis for processing genetic or biometric data. The Office of the Commissioner for Personal Data Protection (ODPC) is the supervisory authority. As at 2026-08-24; later amendment is not independently confirmed.

14 instruments named 6 researched in detail As of 2026-08-24

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Biometric privacy

GDPR Article 9 and Law 125(I)/2018, Genetic and Biometric Data in Cyprus

cite Regulation (EU) 2016/679, Art. 9; Law 125(I)/2018 stage In effect since 2018-07-31 source Secondary commentary (Harris Kyriakides), not independently confirmed against Law 125(I)/2018's own text this pass

General Data Protection Regulation (GDPR) Article 9(1) classifies biometric data processed for unique identification as a special category. Secondary commentary (Harris Kyriakides) describes Law 125(I)/2018 as prohibiting the processing of genetic and biometric data for life and health insurance purposes, and as requiring separate, specific consent, over and above the ordinary GDPR consent standard, where a controller relies on consent as the lawful basis for processing genetic or biometric data.

The provision's own text and article number were not independently confirmed this pass; neither addition distinguishes voice or face capture from any other biometric modality in the commentary consulted. No Cyprus-specific voiceprint or faceprint case or regulatory guidance was located.

What it asks of an app

Breach notification

GDPR Articles 33-34, Breach Notification in Cyprus

cite Regulation (EU) 2016/679, Arts. 33-34 stage In effect since 2018-05-25 source Official Journal text, EUR-Lex, Regulation (EU) 2016/679

A controller must notify the ODPC without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Cyprus, and must notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms. No Law 125(I)/2018 derogation from this timeline was identified in this pass.

What it asks of an app

Comprehensive regime

Law 125(I)/2018, Cyprus GDPR Supplement

cite Law 125(I)/2018 of 2018 stage In effect since 2018-07-31 source Official Gazette of the Republic of Cyprus, 31 July 2018

Cyprus's private-sector regime is the General Data Protection Regulation (GDPR) plus Law 125(I)/2018 (The Protection of Natural Persons with regard to the Processing of Personal Data and for the Free Movement of such Data Law of 2018), published in the Official Gazette of the Republic of Cyprus on 31 July 2018, supplying domestic derogations and procedural rules. The Office of the Commissioner for Personal Data Protection (ODPC) is the supervisory authority.

The law's official English translation PDF was not reachable at its previously published URL this pass (now redirecting to a general landing page), so article-level detail below is commentary sourced rather than a primary-text read.

What it asks of an app

Cross border transfer

GDPR Chapter V, Cross-Border Transfer of Personal Data from Cyprus

cite Regulation (EU) 2016/679, Arts. 44-49 stage In effect since 2018-05-25 source Official Journal text, EUR-Lex, Regulation (EU) 2016/679

Transferring personal data of a person in Cyprus outside the European Economic Area requires a European Commission adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation, backed by the Article 83(5) top fine tier. No Law 125(I)/2018 derogation broadening or narrowing this was identified in this pass.

What it asks of an app

Data subject rights

GDPR Article 22 and Law 125(I)/2018, Automated Decisions in Cyprus

cite Regulation (EU) 2016/679, Art. 22; Law 125(I)/2018 stage In effect since 2018-07-31 source Official Journal text, EUR-Lex, Regulation (EU) 2016/679

General Data Protection Regulation (GDPR) Articles 12 to 23 apply, including Article 22 rights against a decision based solely on automated processing, restated by Law 125(I)/2018 without narrowing per its own summary. No Cyprus-specific broadening of data-subject rights beyond the GDPR baseline was identified in this pass.

What it asks of an app

Enforcement supervision

GDPR Articles 82-83 and ODPC Enforcement in Cyprus

cite Regulation (EU) 2016/679, Arts. 82-83 stage In effect since 2018-05-25 source Official Journal text, EUR-Lex, Regulation (EU) 2016/679

The Office of the Commissioner for Personal Data Protection (ODPC) is the supervisory authority and enforces General Data Protection Regulation (GDPR) Article 83 fines. No Cyprus-specific fine ceiling beyond the GDPR Article 83 maximum, and no dedicated collective-redress statute, was identified in this pass. GDPR Article 82 gives any person who suffered material or non-material damage a right to compensation from the controller or processor.

What it asks of an app

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.