Law / Greece

Greece

privacy

Greece's private-sector regime is the General Data Protection Regulation (GDPR) plus Law 4624/2019 (FEK A' 137/29-08-2019), in force from its 29 August 2019 publication, which supplies national derogations, an employment chapter, and procedural rules. The Hellenic Data Protection Authority (HDPA) is the supervisory authority.

Two attempts to extract the HDPA's own official English translation PDF through WebFetch failed this pass, so Law 4624/2019's specific provisions, including its employment consent narrowing, workplace surveillance notice duty, and its biometric-adjacent social-security derogation, rest on secondary legal commentary rather than a primary-text read, and are described only in general terms here. As at 2026-08-24; later amendment is not independently confirmed.

16 instruments named 6 researched in detail As of 2026-08-24

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Biometric privacy

GDPR Article 9 and Law 4624/2019, Special Categories in Greece

cite Regulation (EU) 2016/679, Art. 9; Law 4624/2019 stage In effect since 2019-08-29 source Secondary commentary (Centraleyes, Practical Law), not independently confirmed against Law 4624/2019's own text this pass

General Data Protection Regulation (GDPR) Article 9(1) classifies biometric data processed for unique identification as a special category. Secondary commentary (Centraleyes, Practical Law) describes Law 4624/2019 as adding a derogation grouping genetic, biometric, and health data together, permitting their processing where necessary for social security or social protection purposes, or to assess an employee's fitness for work.

The HDPA's own official translation PDF did not extract through WebFetch this pass, so the provision's exact article number and whether it enumerates biometric modalities individually are not independently confirmed and are not asserted; the grouping itself is recorded at medium confidence, commentary sourced. No Greece-specific voiceprint or faceprint case or regulatory guidance was located.

What it asks of an app

Breach notification

GDPR Articles 33-34, Breach Notification in Greece

cite Regulation (EU) 2016/679, Arts. 33-34 stage In effect since 2019-08-29 source Official Journal text, EUR-Lex, Regulation (EU) 2016/679

A controller must notify the Hellenic Data Protection Authority (HDPA) without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Greece, and must notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms. No Law 4624/2019 derogation from this timeline was identified in this pass.

What it asks of an app

Comprehensive regime

Law 4624/2019, Greek GDPR Implementation Law (Nomos 4624/2019, N. 4624/2019)

cite Law 4624/2019, FEK A' 137/29-08-2019 stage In effect since 2019-08-29 source HDPA official English translation PDF (dpa.gr), not independently extracted this pass

Greece's private-sector regime is the General Data Protection Regulation (GDPR) plus Law 4624/2019 (Greek: Nomos 4624/2019), FEK A' 137/29-08-2019, in force from publication on 29 August 2019, which supplies domestic derogations and procedural rules, including an employment chapter narrowing consent as a lawful basis for employee data processing and separately regulating workplace video surveillance. The Hellenic Data Protection Authority (HDPA) is the supervisory authority.

The HDPA's own official English translation PDF could not be extracted through WebFetch this pass, so the employment chapter's exact article numbers and text are not independently confirmed and are described here only in general terms, per secondary legal commentary.

What it asks of an app

Cross border transfer

GDPR Chapter V, Cross-Border Transfer of Personal Data from Greece

cite Regulation (EU) 2016/679, Arts. 44-49 stage In effect since 2019-08-29 source Official Journal text, EUR-Lex, Regulation (EU) 2016/679

Transferring personal data of a person in Greece outside the European Economic Area requires a European Commission adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation, backed by the Article 83(5) top fine tier. No Law 4624/2019 derogation broadening or narrowing this was identified in this pass.

What it asks of an app

Data subject rights

GDPR Article 22 and Law 4624/2019 Article 27, Data Subject Rights and Employment in Greece

cite Regulation (EU) 2016/679, Arts. 12-23; Law 4624/2019, Art. 27 stage In effect since 2019-08-29 source Secondary commentary (activeMind.legal, Metaxopoulos Law), not independently confirmed against Law 4624/2019's own text this pass

General Data Protection Regulation (GDPR) Articles 12 to 23 apply, including Article 22 rights against a decision based solely on automated processing, restated without narrowing by Law 4624/2019.

Secondary commentary describes an employment chapter, commonly cited as Article 27, that makes employee consent lawful only in exceptional cases assessed against the employee's dependence in the employment relationship, and separately requires written notice to employees before workplace video surveillance is installed, limited to protection of persons and property.

This chapter's exact article numbers and text were not independently confirmed this pass, since two WebFetch attempts on the HDPA's own official translation PDF failed to extract readable text.

What it asks of an app

Enforcement supervision

GDPR Articles 82-83 and HDPA Enforcement in Greece

cite Regulation (EU) 2016/679, Arts. 82-83 stage In effect since 2019-08-29 source Official Journal text, EUR-Lex, Regulation (EU) 2016/679

The Hellenic Data Protection Authority (HDPA) is the supervisory authority and enforces General Data Protection Regulation (GDPR) Article 83 fines. In 2024 the HDPA issued an administrative fine and compliance order against the Ministry of Migration and Asylum, reported by the European Data Protection Board (EDPB)'s national news feed. No Greece-specific fine ceiling beyond the GDPR Article 83 maximum, and no dedicated collective-redress statute for data-protection claims, was identified in this pass.

GDPR Article 82 gives any person who suffered material or non-material damage a right to compensation from the controller or processor.

What it asks of an app

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.