Skip to content
NewOFAC Watcher checks your watchlist each day and emails you when a sanctions-list change looks like a possible match.See OFAC Watcher · $29 / month
Covered
  • OFAC SDN list
  • UN sanctions list
  • EU sanctions list
  • Public on-chain data
  • MiCA
  • EU AI Act
  • GDPR
  • DORA
  • FinCEN BOI
  • VARA
  • SOC 2
  • AML / KYC

GDPR compliance in Greece: who is in scope and what is owed

How GDPR applies to companies operating in or serving Greece — scope tests, the obligations that follow, and the primary sources to verify each one against.

Organisations established in Greece, or those targeting individuals located in Greece by offering goods and services or monitoring their behavior, are subject to the General Data Protection Regulation. This regulatory framework sets strict rules regarding the handling of personal data under the supervision of European authorities and the supervisory authority. Entities must implement appropriate technical and organizational measures to demonstrate adherence.

Extraterritorial Scope and the Greek Market

The application of data protection rules in Greece is governed by Regulation (EU) 2016/679, which applies to the processing of personal data in the context of the activities of an establishment of a data controller or a data processor in the Union, regardless of whether the processing takes place in the Union or not. When an organisation is not established within the European Union, the rules still apply if the processing activities relate to the offering of goods or services to data subjects in Greece, or the monitoring of their behavior as far as their behavior takes place within the Union. Organisations selling software, retail goods, or digital services to residents in this territory must evaluate whether their targeting activities bring them within the scope of EU rules. Compliance teams should consult the primary text found in the Regulation (EU) 2016/679 (GDPR) — full text to verify specific jurisdictional thresholds and exemptions.

Entities that utilize a joint controller arrangement must determine respective responsibilities for compliance with data protection obligations. The mere accessibility of a website from Greece is generally insufficient to trigger jurisdiction, but active marketing, language localization, or currency targeting directed at Greek residents will typically establish the necessary nexus. Businesses must map their data flows to ascertain whether processing operations meet the material and territorial criteria outlined in the regulation.

Failure to establish proper jurisdictional oversight can result in severe financial penalties, which can be estimated using the tools/gdpr-fine-estimator tool for risk assessment purposes. Organisations must systematically verify their touchpoints with Greek consumers, including IP tracking, shipping logs, and localized customer support operations, to ensure they do not inadvertently fall within the regulatory reach of the national supervisory body.

Core Obligations for Controllers and Processors

Once an entity is determined to be in scope, it must adhere to foundational data protection principles, including lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, and confidentiality. A data controller bears primary responsibility for demonstrating compliance with these principles. When engaging third-party vendors, organisations must establish binding legal agreements pursuant to GDPR Article 28 — Processor to govern the processing of personal data on their behalf.

Processors are prohibited from engaging another sub-processor without prior specific or general written authorization of the controller. If a general written authorization is used, the processor must inform the controller of any intended changes concerning the addition or replacement of processors, giving the controller an opportunity to object to such changes. These contractual safeguards ensure that data protection standards flow down the entire supply chain of digital service providers operating within or for the Greek market.

To assist compliance operations, teams can review standard contractual frameworks or utilize the tools/contract-fixer utility to identify deficient vendor terms. Documenting these processing relationships is a mandatory prerequisite for demonstrating accountability to the relevant supervisory authority during an audit or investigation.

Documentation and Record-Keeping Requirements

Accountability is a central tenet of the regulatory framework, requiring organisations to maintain detailed documentation of their processing activities. Under GDPR Article 30 — Records of processing activities, each controller and, where applicable, the controller's representative, shall maintain a record of processing activities under its responsibility. This record must contain mandatory information such as the name and contact details of the controller, purposes of the processing, categories of data subjects and personal data, categories of recipients, and envisaged time limits for erasure.

Organisations employing more than a specific headcount or engaging in high-risk processing must formalize these inventories. The following table summarizes key documentation artifacts typically required for operational compliance:

| Artifact Type | Governing Standard | Primary Function | |---|---|---| | Processing Register | Article 30 | Documents data flows and categories | | Impact Assessment | Article 35 | Evaluates high-risk processing operations | | Vendor Agreements | Article 28 | Imposes obligations on processors |

When processing operations are likely to result in a high risk to the rights and freedoms of natural persons, a data protection impact assessment must be conducted prior to the processing. This assessment helps identify and mitigate risks associated with new technologies or large-scale profiling activities.

International Data Transfers and Standard Contractual Clauses

When organisations transfer personal data from Greece to countries outside the European Economic Area that lack an adequacy decision, they must implement appropriate safeguards. The European Commission provides standardized instruments for this purpose, detailed in the Commission Implementing Decision (EU) 2021/914 — Standard Contractual Clauses. These clauses establish contractual commitments between data exporters and importers to protect personal data in line with European standards.

Before executing transfers, parties must verify whether the destination country's legal framework impairs the effectiveness of the Standard Contractual Clauses. Supplementary technical, contractual, and organisational measures may be required to protect data against unauthorized access by foreign intelligence or law enforcement agencies. Compliance teams must periodically review transfer impact assessments to ensure ongoing protection levels remain adequate.

Tools such as the tools/saas-risk-scanner can assist organisations in identifying third-party SaaS vendors that transfer data across international borders. Ensuring transparency in international data flows is critical to avoiding enforcement actions by European supervisory bodies.

Guidance from Supervisory Authorities and the EDPB

Interpretation and enforcement of the regulation are guided by consistent application across Member States, heavily influenced by the European Data Protection Board. Guidance documents published via the EDPB — guidelines, recommendations and best practices provide authoritative interpretations on complex topics such as consent, transparency, profiling, and international transfers. Organisations operating in Greece must align their internal policies with these published recommendations to mitigate regulatory exposure.

When cross-border processing occurs across multiple Member States, the one-stop-shop-mechanism coordinates regulatory oversight through a lead supervisory authority. However, local authorities retain competence for matters that affect only local establishments or local data subjects. Organisations must therefore remain attentive to both pan-European supervisory pronouncements and localized enforcement priorities.

To maintain structured oversight, companies frequently appoint a data-protection-officer to monitor compliance, inform management, and act as the primary contact point for supervisory authorities. Regular training and policy updates driven by EDPB publications help maintain an effective compliance posture across all business units.

BizLegal AI is regulatory research software, not a law firm. This page is general information, not legal advice, and does not create a lawyer-client relationship. Verify every deadline, threshold and obligation against the primary source cited before you act on it, and consult qualified counsel in the relevant jurisdiction.

Frequently asked questions

Does a non-EU company need a local representative in Greece?

Entities established outside the EU that process personal data of individuals in Greece must designate a written representative in the Union if their processing activities are related to offering goods or services or monitoring behavior, unless specific narrow exemptions apply.

What triggers the appointment of a data protection officer?

Appointment is mandatory if processing is carried out by a public authority, or if core activities consist of processing operations requiring regular and systematic monitoring of data subjects on a large scale, or processing special categories of data on a large scale.

How do companies handle data subject access requests?

Data subjects have the right to obtain confirmation as to whether personal data concerning them is being processed, along with access to that data and supplementary information. Requests must be answered without undue delay and generally within one month.

What happens if a personal data breach occurs?

Controllers must notify the competent supervisory authority without undue delay and, where feasible, not later than a specified timeframe after becoming aware of it, unless the breach is unlikely to result in a risk to individuals' rights and freedoms.

Sources

BizLegal AI is regulatory research software, not a law firm. This page is general information, not legal advice, and does not create a lawyer-client relationship. Verify every deadline, threshold and obligation against the primary source cited before you act on it, and consult qualified counsel in the relevant jurisdiction.

Last reviewed 2026-10-08.

Contact