EnglishEL
Cyprus flag

Cyprus

Cyprus Data Privacy Laws: GDPR, Law 125(I)/2018 and OCPDP Guide (2026)

Independently fact-checked against primary sources (last audited September 10, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 10, 2026. · 15 primary sources cited on this page. How we verify our legal content

Cyprus Data Privacy Laws: GDPR, Law 125(I)/2018 and OCPDP Guide (2026)

Frequently Asked Questions

What is the main data protection law in Cyprus?

Cyprus data protection law rests on two core instruments. The EU General Data Protection Regulation (GDPR), Regulation (EU) 2016/679, applies directly as law throughout Cyprus as an EU Member State. Law 125(I)/2018 is the national supplementing statute that adds Cyprus-specific provisions on the supervisory authority (the OCPDP), children's consent age (14), criminal offenses under Section 33, and the transfer controls in Sections 17 and 18. Those two are not the whole framework: cookie and electronic direct-marketing rules sit in Sections 97 to 107 of Law 112(I)/2004, Directive (EU) 2016/680 is transposed by Law 44(I)/2019, and the same Commissioner acts as Information Commissioner under Law 184(I)/2017.

Who enforces data protection law in Cyprus?

The Office of the Commissioner for Personal Data Protection (OCPDP), based in Nicosia, is the independent supervisory authority. It handles complaints from individuals, conducts investigations and audits, issues guidance, and imposes administrative fines of up to EUR 20 million or 4% of worldwide turnover for the most serious GDPR violations. The OCPDP is a full member of the European Data Protection Board. Maria Manolis Christofidou has served as Commissioner since 28 September 2025.

What is the age of consent for data processing in Cyprus?

Cyprus set the threshold for children's consent to information society services at 14 years, using the derogation permitted by GDPR Article 8(1). Children aged 14 and above can provide valid consent for online services such as social media and apps. For children below 14, consent must be given or authorized by a holder of parental responsibility. Controllers must make reasonable efforts to verify age and consent, taking account of available technology.

Does Cyprus require pre-notification to the OCPDP before transferring data abroad?

Yes, but only for transfers of special categories of personal data (health, biometric, genetic, racial or ethnic origin, political opinion, religious belief, trade union, sex life, or sexual orientation data) to third countries where the transfer relies on GDPR Article 46 safeguards such as standard contractual clauses, or on Article 47 binding corporate rules. Section 17(1) of Law 125(I)/2018 requires advance notification to the OCPDP before such transfers take place. Section 18(1) goes further for the other route: a special-category transfer relying on a GDPR Article 49 derogation requires an impact assessment and prior consultation with the Commissioner, not just a notification. Both are Cyprus-specific requirements not found in the GDPR itself.

What are the maximum GDPR fines in Cyprus?

Upper-tier GDPR violations (unlawful processing, invalid consent, violations of data subjects' rights, unlawful international transfers) carry fines of up to EUR 20 million or 4% of total worldwide annual turnover, whichever is higher. Lower-tier violations (failures in record-keeping, breach notification, or DPO designation) carry fines of up to EUR 10 million or 2% of turnover. Law 125(I)/2018, Section 32(3) adds no fining power. It sets a ceiling: an administrative fine imposed on a public authority or public body, in respect of non-profit-making activities, may not exceed EUR 200,000. Both conditions must be met, so private-sector non-profits are not covered and remain exposed to the full GDPR maxima. Separately, Section 33 creates criminal offences carrying up to three years imprisonment or EUR 30,000, and up to five years or EUR 50,000 in aggravated cases.

When must a Data Protection Officer be appointed in Cyprus?

A DPO is mandatory under GDPR Article 37 for: public authorities and bodies; controllers or processors whose core activities consist of large-scale, regular, and systematic monitoring of individuals; and controllers or processors whose core activities consist of large-scale processing of special categories of data or data relating to criminal convictions. Law 125(I)/2018, Section 14(2) empowers the OCPDP to require DPOs in additional contexts, but no such list has been published as of 10 September 2026. External DPO arrangements are permitted under GDPR Article 37(6).

What does the EU AI Act mean for organizations in Cyprus?

The EU AI Act (Regulation (EU) 2024/1689) applies directly in Cyprus. Prohibitions on unacceptable-risk AI practices have been in force since 2 February 2025. High-risk AI system obligations become applicable on 2 December 2027 for Annex III systems and 2 August 2028 for AI built into regulated products, moved by the July 2026 Digital Omnibus. Cyprus designated its Article 70 national competent authorities on 22 January 2025: the Deputy Ministry of Research, Innovation and Digital Policy coordinates implementation; the Commissioner of Electronic Communications is Notifying Authority, Market Surveillance Authority, and Single Point of Contact; and the Commissioner for Personal Data Protection is Market Surveillance Authority for the Annex III points 1, 6, 7 and 8 high-risk systems, covering biometrics, law enforcement, migration and border control, and the administration of justice. Separately, on 6 November 2024 Cyprus notified the Commission of three Article 77 fundamental rights authorities, the OCPDP among them, whose extra powers take effect on 2 August 2026.

What is the Cyprus constitutional basis for data protection?

The Cyprus Constitution does not contain an express fundamental right to the protection of personal data. Data privacy rights are anchored in Article 15 (right to respect for private and family life) and Article 17 (secrecy of correspondence). These provisions provide the domestic constitutional foundation for the GDPR and Law 125(I)/2018, alongside the EU Charter of Fundamental Rights Articles 7 and 8, which take precedence as EU law.

How does NIS2 relate to GDPR obligations in Cyprus?

The Network and Information Systems Security (Amendment) Law of 2025, which transposed the EU's NIS2 Directive, creates cybersecurity obligations that sit alongside the GDPR. Where a cybersecurity incident also constitutes a personal data breach, organizations face dual notification obligations: an initial report to the Digital Security Authority within six hours and a full incident report within 72 hours under NIS2, plus a breach notification to the OCPDP within 72 hours under GDPR Article 33. Organizations in critical sectors should integrate these reporting obligations into a single incident response procedure.

What is the significance of the Intellexa/Pegasus spyware case for Cyprus data privacy?

The Intellexa consortium, which developed the Predator surveillance tool, operated Cyprus as a primary hub and benefited from gaps in export licensing and corporate governance oversight. US Treasury sanctions were imposed on Intellexa and its founder in 2024. The European Parliament's PEGA Committee recommended Cyprus repeal export licenses not aligned with EU law. The episode highlighted the distinction between formal GDPR compliance and broader privacy governance, and has sharpened regulatory focus on technology businesses operating under Cyprus registration.

Updates

Corrected several statements about Cyprus law after re-checking the primary sources: Law 125(I)/2018 section 32(3) is a EUR 200,000 ceiling on fines against public authorities for non-profit-making activities, not an extra fine aimed at non-profits; Singapore has no EU adequacy decision and the transfer section now gives the Commission's actual list; the criminal provisions are section 33, not a non-existent section 84, and the article now states its three penalty tiers and the personal liability under section 33(5); the Aylo Freesites decision is dated 2024 and is no longer described as the largest fine on record, which is EUR 925,000 against WS WiSpear Systems Ltd in November 2021; a fine wrongly attributed to the Ministry of Education has been replaced with the 2023 Ministry of the Interior and Bank of Cyprus decisions; the articles breached in the Housing Finance Corporation, Senira, Brivio and Cyprus News Agency decisions have been corrected; and sections 9 and 18 of Law 125(I)/2018, the ban on genetic and biometric data in health and life insurance and the impact assessment required for Article 49 transfers, have been added. Two dead links to the Commissioner's old website were replaced with the current gov.cy sources. Corrected the employment section: Cyprus took no GDPR Article 88 employment derogation, so employee data is governed by the GDPR directly plus the Commissioner's Opinions and Directives, not by Law 125(I)/2018. Removed a research-approval test that does not exist in Cypriot law and replaced it with Section 31 as the text reads, relabelled the DPO provision as Section 14(2) rather than Article 14(2), and clarified that the EUR 8,000 Ministry of the Interior fine followed an ex officio investigation into a disclosure to the House of Representatives rather than a complaint.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

AI Act dates updated for the July 2026 Digital Omnibus (Regulation (EU) 2026/1744): high-risk obligations now apply 2 December 2027 for Annex III systems and 2 August 2028 for AI built into regulated products, and the Article 50 transparency date has been corrected to 2 August 2026.

Full audit-and-evolve refresh: expanded from ~2,380 to ~6,200 words. Added constitutional basis (Articles 15 and 17), OCPDP enforcement timeline with named decisions (Aylo Freesites EUR 58,400; Housing Finance Corporation EUR 10,000; Senira Limited EUR 3,000; Open University of Cyprus EUR 45,000; Cyprus News Agency reprimand), EU AI Act overlay with Cyprus national authority designation (January 2025), NIS2 transposition (April 2025), Pegasus/Intellexa governance backdrop, UpdatesLog component, expanded FAQ to 10 items, and fuller DPO and cross-border transfer coverage.

Reviewed and approved by an editor

Sources and References

  1. Law 125(I)/2018 - Office of the Commissioner for Personal Data Protection (gov.cy)(gov.cy).gov
  2. Regulation (EU) 2016/679 (GDPR) - EUR-Lex(eur-lex.europa.eu).gov
  3. Commissioner (Cyprus) - GDPRhub(gdprhub.eu)
  4. Data Protection in Cyprus - GDPRhub(gdprhub.eu)
  5. Commissioner (Cyprus) - Aylo Freesites Ltd - GDPRhub(gdprhub.eu)
  6. Commissioner (Cyprus) - Housing Finance Corporation - GDPRhub(gdprhub.eu)
  7. Commissioner fines Open University of Cyprus EUR 45,000 - DataGuidance(dataguidance.com)
  8. Cyprus: Commissioner fines Aylo Freesites EUR 58,400 - DataGuidance(dataguidance.com)
  9. ICLG Data Protection Laws Cyprus 2024-2025(iclg.com)
  10. CEF 2025 Right to Erasure - EDPB(edpb.europa.eu).gov
  11. EU AI Act Regulation (EU) 2024/1689 - EUR-Lex(eur-lex.europa.eu).gov
  12. Cyprus AI Act national authority designation - gov.cy(gov.cy).gov
  13. Cyprus NIS2 adoption 2025 - Harneys(harneys.com)
  14. NIS2 Directive implementation Cyprus - European Commission(digital-strategy.ec.europa.eu).gov
  15. Intellexa US sanctions - ICIJ Cyprus Confidential(icij.org)
  16. Christofidou new OCPDP Commissioner - Cyprus Mail(cyprus-mail.com)
  17. Law 125(I)/2018 - unofficial English translation (PDF) - gov.cy(gov.cy).gov
  18. Commissioner (Cyprus) - 11.17.001.010.239 (Senira) - GDPRhub(gdprhub.eu)
  19. Cyprus - Data Protection Overview - DataGuidance(dataguidance.com)
  20. Data Protection in Cyprus - DLA Piper Data Protection Laws of the World(dlapiperdataprotection.com)
  21. CEF 2026: EDPB launches coordinated enforcement action on transparency - EDPB(edpb.europa.eu)
  22. Greek court convicts Intellexa founder Tal Dilian - ICIJ(icij.org)
  23. Regulation (EU) 2026/1744 of 8 July 2026 amending Regulation (EU) 2024/1689 (Digital Omnibus on AI), OJ L 2026/1744, 24.7.2026(eur-lex.europa.eu).gov
  24. Law 125(I)/2018, consolidated text with amendment history (125(I)/2018 and 26(I)/2022) - CyLaw(cylaw.org)
  25. Law 26(I)/2022 amending Law 125(I)/2018, Official Gazette No. 4878, 11 March 2022 - gov.cy(gov.cy).gov
  26. OCPDP Annual Report 2024 (88 decisions, 21 fines totalling EUR 133,900; Aylo Freesites at s. 7.12) - gov.cy(gov.cy).gov
  27. OCPDP Annual Report 2021 (EUR 925,000 fine on WS WiSpear Systems Ltd, announced 12 November 2021) - gov.cy(gov.cy).gov
  28. OCPDP Annual Report 2023 (Open University of Cyprus EUR 45,000; Ministry of the Interior and Bank of Cyprus EUR 8,000) - gov.cy(gov.cy).gov
  29. Cyprus AI Act national competent authorities, Council of Ministers decision of 22 January 2025 - Deputy Ministry of Research, Innovation and Digital Policy(gov.cy).gov
  30. Adequacy decisions - European Commission(commission.europa.eu).gov
  31. Office of the Commissioner for Personal Data Protection - remit, including Law 44(I)/2019, Law 112(I)/2004 ss. 97-107 and Law 184(I)/2017(gov.cy).gov
Share: