Cyprus
Cyprus Data Privacy Laws: GDPR, Law 125(I)/2018 and OCPDP Guide (2026)
Independently fact-checked against primary sources (last audited September 10, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 10, 2026. · 15 primary sources cited on this page. How we verify our legal content

Cyprus data privacy law rests on two instruments: the EU GDPR (Regulation (EU) 2016/679), which applies directly in all EU Member States, and the national supplementing statute, Law 125(I)/2018, which sets the children's consent age at 14 and grants enforcement powers to the Office of the Commissioner for Personal Data Protection.
Cyprus Data Privacy Laws: GDPR, Law 125(I)/2018, and OCPDP Enforcement (2026)
Cyprus data privacy law is governed by the EU General Data Protection Regulation (GDPR), Regulation (EU) 2016/679, which applies directly as law in every EU Member State, and by Law 125(I)/2018, the national statute that supplements the GDPR with Cyprus-specific provisions on the supervisory authority, children's consent age, criminal penalties, and cross-border transfer notifications. The Office of the Commissioner for Personal Data Protection (OCPDP) supervises and enforces both instruments.
Information last verified on 10 September 2026. This article presents general legal information and has not been reviewed by a licensed lawyer. Statutes cited reflect their in-force versions as of 10 September 2026.
Jurisdiction scope: This article addresses the data protection law of the Republic of Cyprus, covering the EU GDPR (Regulation (EU) 2016/679), Law 125(I)/2018, and OCPDP enforcement guidance and decisions. It does not address the data protection law of the Turkish-administered northern part of Cyprus. For the broader EU GDPR framework see EU Data Privacy Laws. For Cyprus recording consent rules see Cyprus Recording Laws.
Quick Answer: What Data Privacy Laws Apply in Cyprus?
Cyprus is an EU Member State. The GDPR applies directly and in full, covering every organization that processes the personal data of individuals in Cyprus, regardless of where the organization is established. Law 125(I)/2018 fills the GDPR's national-discretion spaces: it establishes the OCPDP and its powers, sets the children's consent age at 14, creates criminal offenses for certain data violations, adds a pre-transfer notification requirement for special-category data sent abroad, and sets the national rules for processing carried out for journalistic, academic, artistic, or literary purposes. It does not regulate employment data: Cyprus took no GDPR Article 88 derogation. Those two instruments are not the whole of the framework. Cookie and electronic direct-marketing rules sit in Sections 97 to 107 of Law 112(I)/2004, Directive (EU) 2016/680 is transposed by a separate statute, Law 44(I)/2019, and the same Commissioner has acted as Information Commissioner under Law 184(I)/2017 since 22 December 2020. The OCPDP enforces all of these, handles complaints from individuals, and represents Cyprus on the European Data Protection Board (EDPB).

Constitutional Basis for Data Protection in Cyprus
Articles 15 and 17 of the Cyprus Constitution
Cyprus's 1960 Constitution does not contain an express right to the protection of personal data. The constitutional foundation for data privacy is built from two related but distinct provisions.
Article 15 of the Constitution protects the right to respect for private and family life. It guarantees every person the right to respect for their private and family life and prohibits interference with that right except where permitted by law and necessary in the interests of security, public safety, order, health, morals, or the rights of others. This provision has been interpreted by the Supreme Court of Cyprus to encompass informational privacy, providing the domestic constitutional grounding for legislative protection of personal data.
Article 17 protects the secrecy of correspondence and other communications. It prohibits interference with letters, communications, and correspondence except as authorized by law for criminal investigation purposes and under judicial oversight.
These two articles together underpin the legitimacy of the data protection framework. When Cyprus courts are asked to balance GDPR rights against competing interests, they draw on the Article 15 and Article 17 baseline in addition to the EU Charter of Fundamental Rights Articles 7 (private life) and 8 (personal data protection), which have primacy as EU law.

Law 125(I)/2018: Structure, Scope, and Key Provisions
The Relationship Between the GDPR and the National Law
Law 125(I)/2018, formally titled the Law on the Protection of Natural Persons with Regard to the Processing of Personal Data and on the Free Movement of Such Data, entered into force on 31 July 2018. It replaced the earlier Law 138(I)/2001, which had transposed Directive 95/46/EC.
The law does not replicate GDPR provisions. Because the GDPR is a directly applicable EU Regulation, Cyprus had no power or need to re-enact its substantive rules on lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, and integrity. Instead, Law 125(I)/2018 exercises the discretions that the GDPR leaves to Member States and creates the institutional architecture for enforcement. It covers:
- Establishment, independence, and powers of the OCPDP (Part VIII, Sections 19 to 28)
- Restrictions on data subject rights and controller obligations (Part III, Sections 11 and 12)
- Supplementary rules on processing by public authorities and for public interest tasks
- Derogations and conditions for processing special categories of data, including the Section 9 ban on processing genetic and biometric data for health and life insurance
- The consent age threshold for children and information society services
- Criminal offenses supplementing the GDPR's administrative penalty regime (Section 33)
- The pre-transfer notification for special-category data sent to third countries under Article 46 or Article 47 safeguards (Section 17(1)), and the impact assessment plus prior consultation required for Article 49 transfers (Section 18)
- Controls on combining large-scale public filing systems, including any combination carried out using the identity card number or another identifier of general application (Section 10)
The law applies to processing of personal data that is fully or partly automated and to non-automated processing of data forming part of a filing system. It covers both private-sector controllers and public-sector bodies established in Cyprus.
Law 125(I)/2018 does not transpose the Law Enforcement Directive. Directive (EU) 2016/680 was brought into Cypriot law by a separate statute, Law 44(I)/2019, which the OCPDP also supervises. The Commissioner additionally enforces Sections 97 to 107 of the Regulation of Electronic Communications and Postal Services Law 112(I)/2004, the source of Cyprus cookie and electronic direct-marketing rules, and has acted as Information Commissioner under Law 184(I)/2017 since 22 December 2020.
The law has been amended once, by Law 26(I)/2022, published in Official Gazette No. 4878 on 11 March 2022. That amendment rewrote Sections 2 and 3 to extend listed provisions of the law to the UK Sovereign Base Areas, implementing the Sovereign Base Areas Protocol to the UK Withdrawal Agreement, and excluding processing carried out solely for military purposes or for the administration of the Bases. No later amendment has been enacted.
Legal Bases for Processing Under GDPR Article 6
Cyprus follows the six legal bases in Article 6 of the GDPR without modification. A controller may process personal data where: (1) the data subject has given consent; (2) processing is necessary for performance of a contract; (3) processing is necessary for compliance with a legal obligation; (4) processing is necessary to protect vital interests; (5) processing is necessary for a task carried out in the public interest or in the exercise of official authority; or (6) processing is necessary for the purposes of the legitimate interests of the controller or a third party, except where overridden by the data subject's interests or fundamental rights.
For public-sector processing, Law 125(I)/2018 provides that the legal obligation and public interest bases are available to public authorities and bodies carrying out tasks assigned to them by law. The legitimate interests basis is not generally available to public authorities acting in their official capacity.
For special categories of data (health, genetic, biometric, racial, ethnic origin, political opinion, religious belief, trade union membership, sex life, sexual orientation), Article 9 of the GDPR applies directly. Cyprus did not enact a general set of national Article 9 conditions for healthcare, research, or employment. The Law adds two rules of its own: the Section 9(1) prohibition on processing genetic and biometric data for health and life insurance purposes, set out below, and the Section 31 bar on using data processed for archiving, scientific or historical research, or statistical purposes to take a decision producing legal effects for the data subject.
Genetic and Biometric Data: A Flat Prohibition in Insurance
Law 125(I)/2018, Section 9(1) prohibits the processing of genetic and biometric data for health insurance and life insurance purposes. The prohibition is absolute. No Article 6 legal basis and no Article 9 condition cures it, and consent cannot make such processing lawful.
Section 9(2) adds a separate rule for genetic and biometric data collected on the basis of consent: any further processing of that data requires a fresh, separate consent from the data subject.
This is one of the most consequential national derogations Cyprus has adopted, and it binds insurers, reinsurers, brokers, and any processor acting for them.
Children's Consent Age: 14 Years
GDPR Article 8(1) permits Member States to lower the default age of 16 for digital consent to a minimum of 13. Cyprus chose 14 as the threshold. A child aged 14 or above can provide valid consent for the processing of their personal data in connection with information society services such as social media platforms, online marketplaces, and subscription services. For children below 14, consent must be provided or authorized by the holder of parental responsibility. Controllers offering services to children must make reasonable efforts to verify that consent is given or authorized by the appropriate party, taking account of available technology.
Combining Public Filing Systems and the Identity Card Number
Law 125(I)/2018 sets no general rule on the use of national identification numbers by private controllers. What it regulates is the combination of filing systems in the public sector.
Section 10(1) permits two or more public authorities or bodies to combine large-scale filing systems only for reasons of public interest, and only where GDPR Article 6(1)(c) or (e), or Article 9(2)(g), (h) or (i), is satisfied.
Section 10(2) then requires a data protection impact assessment and prior consultation with the Commissioner where the combination involves special-category data or criminal-conviction data, or is to be carried out using the identity card number or any other identifier of general application. The assessment is carried out jointly by the authorities involved and must contain the information listed in GDPR Article 35(7).
Under Section 10(4) the Commissioner may authorize the combination and attach terms and conditions to it. A combination carried out in breach of Section 10 is a criminal offence under Section 33(1)(n).
Section 7, sometimes cited for this point, is about something else. It governs processing that a Decision of the Council of Ministers vests in a public authority or body for a task carried out in the public interest or in the exercise of official authority.
Criminal Offenses Under Section 33
Law 125(I)/2018 runs to 37 sections, and its criminal offences sit in Section 33, in Part X. Several of them criminalize conduct that a reader elsewhere in the EU would expect to be handled administratively. Under Section 33(1) an offence is committed by:
- a controller or processor that does not keep, update, or produce to the Commissioner the Article 30 record of processing activities, or that supplies false, inaccurate, incomplete, or misleading information about that record;
- a controller or processor that does not cooperate with the Commissioner under GDPR Article 31;
- a controller that does not notify a personal data breach to the Commissioner under GDPR Article 33(1);
- a processor that does not inform the controller of a breach without undue delay under GDPR Article 33(2);
- a controller that does not communicate a breach to the data subject under GDPR Article 34;
- a controller that does not carry out a data protection impact assessment required by GDPR Article 35(1) or by Section 13 of the Law;
- a controller or processor that prevents the data protection officer from performing their tasks, in particular cooperation with the Commissioner;
- a certification body that issues, or fails to withdraw, a certification contrary to GDPR Article 42;
- a controller or processor that transfers personal data to a third country or international organization in breach of Chapter V of the GDPR;
- a controller or processor that transfers such data in breach of express limits imposed by the Commissioner under Section 17 or Section 18;
- a person who without right interferes with a filing system, or obtains, removes, alters, damages, destroys, processes, uses, discloses, or makes its data accessible to unauthorized persons, whether for gain or not;
- a controller or processor that prevents or impairs the exercise of the Commissioner's powers under GDPR Article 58 or Section 17 of the Law;
- a controller or processor that fails to comply with the GDPR or the Law in a processing activity that is not otherwise an offence under this section;
- a public authority or body that combines large-scale filing systems in breach of Section 10.
Failing to notify a data breach and failing to run a required impact assessment are therefore criminal offences in Cyprus, not merely administrative failings. Criminal prosecution is handled by the police and the Attorney General's office, separate from the OCPDP's administrative enforcement track. The penalty tiers are set out under Criminal Penalties below.

The Office of the Commissioner for Personal Data Protection (OCPDP)
Independence, Appointment, and Current Leadership
The OCPDP was established under the predecessor 2001 law and continued with expanded powers under Law 125(I)/2018, consistent with the independence requirements of GDPR Article 52. The Commissioner is appointed by the Council of Ministers for a six-year term and operates without instruction from any government body, institution, or private entity.
Maria Manolis Christofidou was appointed Commissioner with effect from 28 September 2025, for a term ending 27 September 2031. She succeeded Commissioner Irenie Loizidou Nicolaidou, who led the office during the formative years of GDPR enforcement from 2018 to 2025.
The OCPDP is headquartered in Nicosia. It represents Cyprus as a full member of the European Data Protection Board and participates in the EDPB's consistency mechanism and joint enforcement actions. The office maintains a website at gov.cy/dataprotection with guidance documents, complaint forms, breach notification templates, and the text of Law 125(I)/2018 together with an unofficial English translation. The older dataprotection.gov.cy addresses now redirect to that site.
Powers: Investigative, Corrective, and Advisory
The OCPDP exercises the full powers available to supervisory authorities under GDPR Articles 57 and 58.
Investigative powers include the ability to order controllers and processors to provide all information needed for the performance of the Commissioner's tasks; to carry out data protection audits; to notify controllers or processors of alleged violations; to obtain access to all personal data and all information necessary to carry out its functions; and to obtain access to any premises of controllers and processors, including data processing equipment and storage.
Corrective powers include the authority to issue warnings; to issue reprimands; to order compliance with data subject requests; to order rectification, erasure, or restriction of processing; to order temporary or permanent bans on processing; to order suspension of data flows to a recipient in a third country; and to impose administrative fines up to the GDPR maxima.
Advisory powers include issuing opinions on legislative proposals, consulting on codes of conduct, providing guidance to sectoral bodies, approving certification mechanisms, and publishing annual reports.
Data Subject Rights in Cyprus
Individuals in Cyprus hold the complete set of data subject rights provided by the GDPR. The OCPDP can be approached directly by any individual who believes a controller has infringed their rights, and it will investigate complaints free of charge.
Right of Access (Article 15 GDPR)
Data subjects may obtain confirmation of whether their personal data is being processed, and if so, receive a copy of that data together with information about the purposes of processing, categories of data, recipients or categories of recipients, the envisaged retention period, the source of the data if not collected directly from the subject, and information about any automated decision-making including profiling. Controllers must respond within one month, extendable by two further months for complex or numerous requests.
Right to Rectification and Erasure (Articles 16 and 17 GDPR)
Individuals may request correction of inaccurate data and erasure of data that is no longer necessary for the purpose for which it was collected, where consent has been withdrawn and no other legal basis exists, or where processing was unlawful. The right to erasure does not apply where processing is necessary for compliance with a legal obligation, for public health purposes, for archiving in the public interest, or for the establishment or defense of legal claims.
Right to Restriction and Portability (Articles 18 and 20 GDPR)
Data subjects may request restriction of processing during a period in which accuracy is contested, or while an objection is being considered. Portability allows individuals to receive their data in a structured, commonly used, machine-readable format and to transmit it to another controller where the processing was based on consent or a contract.
Right to Object (Article 21 GDPR)
Individuals may object to processing based on public interest or legitimate interest grounds. Controllers must cease processing unless they demonstrate compelling legitimate grounds that override the individual's interests. The right to object to direct marketing is absolute: controllers must stop all such processing immediately and without qualification when an objection is raised.
Rights Related to Automated Decision-Making (Article 22 GDPR)
Data subjects have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects or similarly significantly affects them, unless the decision is necessary for a contract, authorized by EU or national law with appropriate safeguards, or based on explicit consent. This right is increasingly significant in Cyprus's financial sector and in employment contexts involving algorithmic screening.
Consent: Requirements and Practical Application
GDPR Article 7 Consent Standard
Consent in Cyprus must meet all four GDPR Article 7 requirements: it must be freely given, specific, informed, and unambiguous. Consent must be given by a clear affirmative act, such as ticking a box or clicking a button. Pre-ticked boxes, silence, and inactivity do not constitute consent. Where consent is bundled with other terms and conditions, the GDPR's requirement that consent be freely given will generally not be satisfied if the data subject cannot refuse consent without detriment.
Consent may be withdrawn at any time, and withdrawal must be as easy as giving consent. Controllers must be able to demonstrate that consent was obtained in a valid form.
Cookie Consent in Cyprus
Cyprus cookie and electronic direct-marketing rules do not come from the GDPR or from Law 125(I)/2018. They sit in Sections 97 to 107 of the Regulation of Electronic Communications and Postal Services Law 112(I)/2004, which the OCPDP enforces alongside her data protection mandate.
The OCPDP has published specific guidance on cookie consent and has taken enforcement action against organizations whose websites failed to obtain valid consent before placing non-essential cookies. The Aylo Freesites decision included a EUR 10,400 fine for unlawful cookie use, imposed under Section 99(5) of Law 112(I)/2004 rather than under the GDPR. In a separate matter the Cyprus News Agency received a reprimand in February 2024 over Google Analytics, though that decision turned on accountability and transfer obligations rather than on cookie consent.
Data Breach Notification
72-Hour Notification to the OCPDP (Article 33 GDPR)
Controllers must notify the OCPDP of a personal data breach within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of individuals. The notification must describe the nature of the breach, the categories and approximate number of individuals and records affected, the likely consequences, and the measures taken or proposed.
If a controller cannot provide all required information within 72 hours, it may provide the information in phases, with the initial notification sent within the deadline and further details provided without undue delay. A note must explain the reasons for the delay.
Notification to Affected Individuals (Article 34 GDPR)
Where a breach is likely to result in a high risk to individuals' rights and freedoms, controllers must notify affected individuals without undue delay. The notification must describe the nature of the breach, contact details for the data protection officer or other contact point, likely consequences, and recommended measures to mitigate potential harm.
Notification to individuals is not required if the controller has applied appropriate technical measures that render the data unintelligible to unauthorized persons, such as encryption, or if the controller has taken subsequent measures that ensure the high risk is no longer likely to materialize, or if individual notification would involve disproportionate effort, in which case a public communication or similar measure may be used instead.
The OCPDP's enforcement record shows that breach-related violations attract significant fines. In the Open University of Cyprus case, the OCPDP imposed a EUR 45,000 fine following a ransomware attack in March 2023 in which attackers published stolen data including student, graduate, and affiliate records after a failed ransom demand. The Commissioner's investigation found inadequate security measures and a breach of GDPR accountability obligations.
Data Protection Officers
When a DPO Is Mandatory
GDPR Article 37 requires designation of a Data Protection Officer in three circumstances: where processing is carried out by a public authority or body (with the exception of courts acting in a judicial capacity); where the core activities of the controller or processor consist of processing operations that, by their nature, scope, or purposes, require large-scale, regular, and systematic monitoring of individuals; or where the core activities consist of large-scale processing of special categories of data under Article 9 or personal data relating to criminal convictions and offenses under Article 10.
Law 125(I)/2018, Section 14(2) gives the OCPDP the additional power to publish a list of processing operations in which a DPO must be appointed beyond those categories in the GDPR. As of 2026, the OCPDP has not published such a list.
DPO Obligations and Confidentiality
DPOs in Cyprus are bound by the obligation of professional secrecy or confidentiality in the course of performing their duties under Law 125(I)/2018. They must be provided with resources necessary to carry out their tasks and to maintain their expert knowledge. The DPO must be involved in all matters relating to personal data protection from the earliest stage and must report directly to the highest level of management.
External DPO arrangements under a service contract are explicitly permitted by GDPR Article 37(6) and are widely used by small and medium enterprises in Cyprus.
Cross-Border Data Transfers
The GDPR Transfer Framework
Personal data may be transferred from Cyprus to a country outside the European Economic Area (EEA) only where the European Commission has adopted an adequacy decision for that country or territory, or where appropriate safeguards are in place, or where a specific derogation under GDPR Article 49 applies.
The European Commission's adequacy list currently covers Andorra, Argentina, Brazil, Canada (commercial organizations), the Faroe Islands, Guernsey, Israel, the Isle of Man, Japan, Jersey, New Zealand, the Republic of Korea, Switzerland, the United Kingdom, the United States (organizations participating in the EU-US Data Privacy Framework, adopted in July 2023), Uruguay, and the European Patent Organisation. The two UK decisions, under the GDPR and under the Law Enforcement Directive, were renewed in December 2025.
Singapore is not on that list and never has been. Transfers from Cyprus to Singapore need an Article 46 safeguard such as standard contractual clauses or binding corporate rules, or an Article 49 derogation. Getting this wrong carries more than GDPR exposure in Cyprus: transferring personal data to a third country in breach of Chapter V is a criminal offence under Section 33(1)(i) of Law 125(I)/2018.
Appropriate safeguards include standard contractual clauses (SCCs) in the form adopted by the European Commission on 4 June 2021, binding corporate rules (BCRs) approved by a lead supervisory authority, codes of conduct with binding and enforceable commitments, approved certification mechanisms, and ad hoc contractual clauses or administrative arrangements authorized by the relevant supervisory authority.
Where no adequacy decision exists and no SCCs or BCRs are in place, controllers must carry out a Transfer Impact Assessment (TIA) to determine whether the level of protection in the third country is essentially equivalent to that within the EEA, taking into account the laws and practices of the third country.
Cyprus-Specific Pre-Transfer Notification for Special-Category Data
Section 17(1) of Law 125(I)/2018 establishes a requirement not present in the GDPR itself. Where a controller or processor intends to transfer special categories of personal data (health, genetic, biometric, racial or ethnic origin, political opinion, religious belief, trade union membership, sex life, or sexual orientation data) to a third country or international organization on the basis of GDPR Article 46 safeguards or Article 47 BCRs, they must notify the OCPDP before the transfer takes place.
This obligation applies in addition to the standard GDPR transfer requirements. Its purpose is to give the OCPDP advance visibility into high-risk transfers of sensitive data. Organizations that operate in healthcare, biometrics, HR, or financial services and that use SCCs or BCRs for cross-border transfers of special-category data must build this notification step into their transfer governance procedures. Failure to notify is a distinct violation in the Cypriot legal order, separate from any deficiency in the underlying transfer mechanism.
Section 18: Impact Assessment and Prior Consultation for Article 49 Transfers
Section 18(1) imposes a heavier obligation on the route a smaller organization is most likely to reach for. Where special categories of personal data are transferred to a third country or international organization in reliance on a GDPR Article 49 derogation, Law 125(I)/2018 requires an impact assessment and prior consultation with the Commissioner before the transfer takes place. A notification is not enough. The assessment must contain the information listed in GDPR Article 35(7) and, where applicable, a description of the technical and organizational security measures under Articles 24, 25, 28 and 32.
Under Sections 17(2) and 18(3) the Commissioner may, for important reasons of public interest, impose express limits on either route. Transferring in breach of a limit imposed under Section 17 or Section 18 is a criminal offence under Section 33(1)(j).
The OCPDP has enforced the Google Analytics issue in this cross-border context. The Cyprus News Agency received a reprimand in February 2024 after the Commissioner found that it could not demonstrate compliance under Article 5(2) and had not shown that the transfer to Google servers in the United States left the level of protection guaranteed by the GDPR intact, contrary to Article 44. The agency was ordered to rely on the EU-US Data Privacy Framework or an Article 46 safeguard if it continued using the tool. The decision follows enforcement taken across multiple EU Member States in the wake of the European Court of Justice ruling in Schrems II and subsequent EDPB guidance.
Penalties and Sanctions
GDPR Administrative Fines
The GDPR's two-tier fine structure applies directly in Cyprus without modification.
Lower-tier violations (such as failure to maintain records of processing activities, failure to cooperate with the supervisory authority, failure to notify a breach, or failure to appoint a DPO where required) can attract fines of up to EUR 10 million or 2% of the total worldwide annual turnover of the preceding financial year, whichever is higher.
Upper-tier violations (such as processing without a legal basis, violating the conditions for valid consent, failing to respect data subjects' rights, and unlawful international transfers) can attract fines of up to EUR 20 million or 4% of total worldwide annual turnover, whichever is higher.
Law 125(I)/2018, Section 32(3) works in the other direction: it caps liability rather than adding to it. An administrative fine imposed on a public authority or public body, in respect of non-profit-making activities, may not exceed EUR 200,000. Both conditions must be met. The cap therefore does not reach private-sector charities, NGOs, or associations, which remain exposed to the full GDPR Article 83 maxima.
Criminal Penalties
Section 33 of Law 125(I)/2018 sets three penalty tiers.
For the offences in Section 33(1)(a) to (l), a convicted person faces imprisonment of up to three years, a fine of up to EUR 30,000, or both.
For the offences in Section 33(1)(m) and (n), the maximum is one year, EUR 10,000, or both.
Where an offence under Section 33(1)(g) to (j) damages the interests of the Republic, impairs its free governance, or compromises national security, the maximum rises to five years, EUR 50,000, or both.
Section 33(5) places that liability on a named person. Where the controller or processor is an enterprise or group of undertakings, legal responsibility rests with the person designated as its supreme executive body. Where it is a public authority or body, responsibility rests with the head of that authority, or with the person who exercises substantial administration of it.
Criminal enforcement requires a police investigation and prosecution through the courts rather than an administrative proceeding before the OCPDP.
OCPDP Enforcement: Key Decisions and Trends
Enforcement Record 2018-2025
Since the GDPR became applicable in May 2018, the OCPDP has handled over 2,500 complaints and imposed cumulative administrative fines exceeding EUR 1.5 million. The following decisions illustrate the range and focus of enforcement.
WS WiSpear Systems Ltd (12 November 2021) -- EUR 925,000. This is the largest fine in the OCPDP's published record, and it is why 2021 dwarfs every other year: total fines were EUR 1,069,500 in 2021 against EUR 133,900 in 2024. The Commissioner opened an ex officio investigation into the surveillance company behind the Cyprus surveillance van case and found a breach of the lawfulness, fairness, and transparency principle in GDPR Article 5(1)(a). The company paid the fine and, in a letter to the Office, accepted responsibility for the breach.
Open University of Cyprus (November 2023) -- EUR 45,000. A ransomware attack in March 2023 compromised data of students, graduates, and affiliates. Attackers demanded ransom; when the deadline passed, the stolen data were published on the dark web. The OCPDP found that the university had failed to apply appropriate security measures and had breached the accountability principle, imposing a EUR 45,000 fine and a six-month compliance order. The Office's other data-breach decisions that year were a reprimand to the Nicosia Sewerage Board, a reprimand and order to the Department of Lands and Surveys, and a EUR 8,000 fine on Bank of Cyprus, for a year total of EUR 53,000. A separate EUR 8,000 fine went to the Ministry of the Interior after an ex officio investigation the Office opened into the Ministry's disclosure of personal data to the House of Representatives, for breach of Article 5(1)(a), (c) and (f).
Cyprus News Agency (February 2024) -- Reprimand. The complaint, one of three brought by noyb, concerned Google Analytics on the agency's website sending visitor data to the United States. The Commissioner reprimanded the agency for breach of Article 5(2) (accountability) and Article 44 (the general principle for transfers), and ordered it to rely on the EU-US Data Privacy Framework or an Article 46 safeguard if it continued using the tool. She held that no administrative fine was warranted, and that no Article 44 breach could be established against Google LLC.
Brivio Limited (July 2024) -- EUR 2,000. The company failed to respond to a data subject access request within the one-month deadline under GDPR Article 12(3), because the employee handling incoming correspondence never passed it on. It satisfied the request once it learned of the complaint and retrained that staff, but the Commissioner weighed as an aggravating factor two earlier complaints of the same kind against the same company before setting the fine.
Housing Finance Corporation (2024-2025) -- EUR 10,000. The OCPDP fined the state-affiliated bank for retaining inaccurate personal data of a data subject beyond the statutory retention period and for failing to implement meaningful and effective measures to ensure GDPR compliance. The Commissioner found breaches of Article 5(1)(d) (accuracy), Article 5(1)(e) (storage limitation), and Article 24(1) (responsibility of the controller), and ordered deletion of the residual data within 10 days plus remedial technical and organizational measures within six months. The complaint was lodged on 24 October 2024 and the decision issued on 22 January 2025.
Senira Limited / nicelocal.com (September 2024) -- EUR 3,000. Two erasure complaints reached the OCPDP from the German and Polish supervisory authorities. The Commissioner issued a reprimand for breach of Article 12(3), because the company did not answer the erasure requests within the GDPR time limit, and imposed the EUR 3,000 fine for breach of Article 31, because it did not fully answer the Office's questions. She also ordered the company to comply with its data subject rights obligations. The fine was therefore for failing to cooperate with the supervisory authority, not for the erasure failure.
Aylo Freesites Ltd (2024) -- EUR 58,400. This is the largest fine of recent years, reported in the OCPDP's Annual Report 2024 and listed as item 60 in that year's table of decisions. The OCPDP conducted an ex officio inspection at the premises of the company, formerly Mindgeek, covering cookie consent, third-party biometric processing, impact assessments, and processor contracts. The Commissioner found that the company did not observe the Article 5 principles, with the principal findings being breach of Article 28(3) on processor contracts and Article 35 on impact assessments, and imposed a EUR 48,000 fine for those breaches. A further EUR 10,400 was imposed under Section 99(5) of Law 112(I)/2004 for unlawful cookie use, not under the GDPR. The company's cooperation with the Office was taken into account in setting both amounts.
EDPB Coordinated Enforcement Participation
The OCPDP participates in the EDPB's Coordinated Enforcement Framework (CEF). In 2025, 32 DPAs across Europe took part in a coordinated enforcement action focused on the right to erasure under GDPR Article 17. Nine DPAs opened new formal investigations and 23 conducted fact-finding exercises. The EDPB's February 2026 report on the CEF 2025 action identified challenges including technical barriers to erasure, inconsistent data inventory practices, and delays in controllers' responses to erasure requests.
On 19 March 2026 the EDPB launched its coordinated enforcement action for the year, focused on transparency and information obligations under GDPR Articles 12, 13 and 14. The EDPB says 25 data protection authorities are taking part but does not publish the participant list, so whether Cyprus is among them is not stated on the record.
The EU AI Act and Cyprus Data Protection
Overview of Regulation (EU) 2024/1689
The EU AI Act (Regulation (EU) 2024/1689) was published in the Official Journal of the European Union on 12 July 2024 and entered into force on 1 August 2024. It is the world's first comprehensive regulatory framework for artificial intelligence. The Act applies in Cyprus directly as EU law, without the need for national transposition of its substantive rules.
The Act's timeline applies as follows:
- Prohibitions on unacceptable-risk AI practices became applicable on 2 February 2025.
- General-purpose AI model obligations became applicable on 2 August 2025.
- Limited-risk AI transparency obligations under Article 50 apply from 2 August 2026.
- Annex III high-risk AI system obligations apply from 2 December 2027, and Annex I high-risk AI built into regulated products from 2 August 2028, both moved by the July 2026 Digital Omnibus.
GDPR and AI Act Interaction
The EU AI Act and the GDPR interact in significant ways. AI systems that process personal data are subject to both frameworks simultaneously. Key areas of overlap include:
Data governance obligations for high-risk AI systems (Article 10 AI Act) require that training, validation, and testing datasets be relevant, sufficiently representative, and free of errors where practicable. These obligations complement the GDPR's accuracy and data minimisation principles.
Data protection impact assessments required under GDPR Article 35 will often be required alongside the conformity assessments mandated for high-risk AI systems under the AI Act. In practice, organizations should integrate these assessments into a single compliance workflow where possible.
Automated decision-making rights under GDPR Article 22 provide an individual-level safeguard against solely automated decisions with legal or similarly significant effects. Where a high-risk AI system makes or informs such decisions, both the AI Act governance requirements and the GDPR Article 22 rights apply.
Cyprus has made two separate designations, and they are often run together.
On 6 November 2024 the Deputy Ministry of Research, Innovation and Digital Policy notified the European Commission, under AI Act Article 77, of three national public authorities that protect fundamental rights: the Commissioner for Personal Data Protection, the Commissioner for Administration and the Protection of Human Rights (the Ombudsman), and the Attorney-General of the Republic. The additional powers those authorities gain under the Act take effect on 2 August 2026.
Separately, by decision of 22 January 2025, the Council of Ministers designated the national competent authorities required by AI Act Article 70. The Deputy Ministry coordinates implementation nationally and represents Cyprus on the European Artificial Intelligence Board. The Commissioner of Electronic Communications is Notifying Authority, Market Surveillance Authority, and Single Point of Contact. The Commissioner for Personal Data Protection is Market Surveillance Authority for the high-risk systems in points 1, 6, 7 and 8 of Annex III, which cover biometrics, law enforcement, migration, asylum and border control, and the administration of justice, and is responsible for enforcing the Article 5 prohibitions so far as they fall within her competence. Further Market Surveillance Authorities may be designated for specific sectors.
An operator of a biometric, law-enforcement, border-control, or justice-sector AI system in Cyprus therefore answers to the data protection Commissioner, not to the Commissioner of Electronic Communications.
High-risk AI system obligations become applicable on 2 December 2027 for the Annex III use cases, moved by the July 2026 Digital Omnibus, and on 2 August 2028 for AI built into regulated products. Organizations in Cyprus deploying AI systems in healthcare, employment, education, critical infrastructure, law enforcement, or administration of justice should treat the period to December 2027 as a compliance preparation window.
NIS2 and Cybersecurity Obligations in Cyprus
On 25 April 2025, the Republic of Cyprus enacted the Network and Information Systems Security (Amendment) Law of 2025, transposing the EU's NIS2 Directive (Directive 2022/2555) into national law. The NIS2 framework operates alongside the GDPR and creates distinct but complementary obligations for cybersecurity risk management and incident notification.
The NIS2 Law covers organizations classified as "essential" or "important" based on a size threshold and sector. In Cyprus, the NIS2 Law brought approximately ten times more organizations into scope compared to the predecessor NIS1 regime, which covered only 70 entities.
Under NIS2, essential entities must report significant cybersecurity incidents within six hours of becoming aware (initial notification) and provide a full notification within 72 hours. Administrative fines for essential entities can reach EUR 10 million or 2% of global annual turnover, and for important entities EUR 7 million or 1.4% of global annual turnover.
Where a cybersecurity incident under NIS2 also constitutes a personal data breach, organizations face dual notification obligations: to the Digital Security Authority under the NIS2 Law and to the OCPDP under GDPR Article 33. Organizations in critical sectors should coordinate their incident response procedures to address both obligations simultaneously.
The Pegasus/Intellexa Backdrop: Privacy Governance and Surveillance
Cyprus as a Spyware Hub
The Intellexa consortium, which developed and marketed the Predator spyware, used Cyprus as a primary operational and export hub. Predator is a commercial surveillance tool capable of accessing personal data stored on or transmitted through a target device. The consortium's founder, Tal Dilian, established the business in Cyprus in part to bypass Israeli export controls while recruiting technical expertise from Israel's national security sector.
The International Consortium of Investigative Journalists (ICIJ) published extensive reporting on the Cyprus Confidential investigation, documenting how Intellexa's structure exploited Cyprus's corporate registry and licensing environment. In March and September 2024, the United States Treasury Department sanctioned Intellexa, Dilian, and associate Sara Hamou for enabling the proliferation of surveillance technologies to authoritarian regimes and for targeting US officials, journalists, and policy experts. The Greek courts convicted Dilian and three associates in a wiretapping scandal connected to Intellexa's operations.
Implications for Cyprus Data Privacy Governance
The OCPDP has enforced against this sector directly, and that case is the largest in its record. On 12 November 2021 the Commissioner announced a EUR 925,000 administrative fine against WS WiSpear Systems Ltd, the Cyprus surveillance company in the Tal Dilian orbit that operated the surveillance van, for breach of the lawfulness, fairness, and transparency principle in GDPR Article 5(1)(a). The Office had worked with the Police on the matter since November 2019, and the company accepted responsibility in writing after the investigation closed.
The Intellexa episode illuminated gaps between Cyprus's formal data protection legal framework and its practical privacy governance, particularly in export controls and corporate oversight. The European Parliament's PEGA Committee, which investigated the use of Pegasus and equivalent spyware across the EU, recommended that Cyprus repeal export licenses not aligned with EU legislation and strengthen oversight of surveillance technology companies operating under Cyprus registration.
The episode is relevant to any assessment of Cyprus data privacy law for three reasons. First, it demonstrates that formal compliance with the GDPR and Law 125(I)/2018 does not by itself ensure a high-trust privacy environment if corporate governance and export licensing regimes create opportunities for surveillance at scale. Second, it has sharpened political and regulatory attention to the intersection of data protection law, cybersecurity, and surveillance in Cyprus. Third, it provides context for understanding why the OCPDP and the EU institutions have applied increasing scrutiny to Cyprus-based technology businesses.
Special Processing Situations
Employment Data
Cyprus did not exercise the GDPR Article 88 discretion to legislate for the employment context. Law 125(I)/2018 contains no employment provision, so employee data is governed by the GDPR directly, supplemented by the Commissioner's published guidance and by general Cypriot labour law.
Employers therefore identify an Article 6 basis for each category of employee data. The legal obligation and contract bases are typically available for payroll, tax reporting, and social insurance purposes. Legitimate interests may support certain workplace monitoring activities, but must be balanced against employees' reasonable expectations of privacy. Employee health data still needs an Article 9 condition, typically explicit consent or necessity for occupational health purposes.
The Commissioner fills the gap with Opinions and Directives rather than statute. The Office's published guidance index lists Opinion 2/2018 on video surveillance in the workplace and the use of biometric systems (19 October 2018), Opinion 1/2019 on access to the email accounts of employees and former employees (17 May 2019), and Directive 1/2025 on the use of personal mobile phones for work purposes (26 May 2025). Earlier Directives issued under the former Law 138(I)/2001, among them the 2005 Directive on employment relations and the 2007 Directive on use of the internet and mobile telephones, remain in force until replaced, and the Office states that its Directives are binding.
Because these are regulator instruments and not provisions of Law 125(I)/2018, the Commissioner can revise them without an amendment to the Law. Check the guidance index for the current version before relying on any of them.
Journalism, Research, and Freedom of Expression
Law 125(I)/2018 provides exemptions for processing carried out for journalistic, academic, artistic, or literary purposes, consistent with GDPR Article 85. These exemptions reflect the constitutional protection of freedom of expression in Cyprus and allow data controllers in the media sector to operate without the full weight of data subject rights in circumstances where those rights would undermine public-interest reporting. The scope of the exemptions is calibrated by Cypriot law to the specific protections afforded by the Constitution.
Health and Research Data
Processing of health data for medical treatment, public health, scientific research, and statistical purposes rests on the Article 9(2) conditions in the GDPR itself. Law 125(I)/2018 creates no national approval step for research and no test that the Commissioner must be satisfied about.
What the Law does add is Section 31. Processing carried out for archiving in the public interest, for scientific or historical research, or for statistical purposes may not be used to take a decision that produces legal effects concerning the data subject or similarly significantly affects them.
The safeguards that research processing has to meet, including pseudonymisation and measures that minimise re-identification risk, come from GDPR Article 89(1), not from a Cypriot approval requirement. Section 30 is the other national rule in this area: personal data in official documents held by a public authority for a task carried out in the public interest are disclosed subject to the Law on the right of access to public sector documents.
Compliance Guidance for Organizations in Cyprus
Core Compliance Obligations
Organizations processing personal data in Cyprus under the GDPR and Law 125(I)/2018 should address the following core obligations:
Lawfulness mapping. Identify and document the legal basis for every processing activity. For consent-based processing, ensure consent meets all four GDPR Article 7 requirements. For legitimate interests, complete a legitimate interests assessment documenting the balance of interests test.
Records of processing activities. Maintain records under GDPR Article 30 covering all processing activities for which the organization is controller or processor. Records must be available to the OCPDP on request.
Privacy notices. Provide clear, transparent information to data subjects about all processing at the point of collection or within one month for data not obtained directly from the data subject.
Data subject rights procedures. Establish procedures for responding to access, rectification, erasure, portability, restriction, and objection requests within the GDPR deadlines.
Breach response. Maintain an incident response procedure that allows notification to the OCPDP within 72 hours of identifying a personal data breach.
Data protection by design and by default. Integrate privacy-protective measures into systems and processes from the outset rather than as an afterthought.
Cross-border transfer governance. For transfers of any personal data outside the EEA, verify the available transfer mechanism. For transfers of special-category data relying on GDPR Article 46 or Article 47 safeguards, complete the mandatory pre-transfer notification to the OCPDP under Section 17(1) of Law 125(I)/2018. For special-category transfers relying on a GDPR Article 49 derogation, Section 18(1) requires an impact assessment and prior consultation with the Commissioner before the transfer, which takes time to obtain and should be scheduled well ahead of the transfer date.
DPO designation. Appoint a DPO where the GDPR's mandatory criteria are met. Document the decision-making process whether or not a DPO is appointed.
Sector-Specific Priorities
Cyprus's economy includes significant tourism, shipping, financial services, technology, and professional services sectors. Each sector presents distinct data protection considerations.
Financial services firms holding large volumes of customer financial and identity data face elevated risk profiles and OCPDP scrutiny, as illustrated by the Housing Finance Corporation decision. Shipping companies that process seafarer personal data across jurisdictions must address both GDPR requirements and the pre-transfer notification obligation. Technology companies operating cookie-based advertising must obtain valid consent from users in Cyprus, as the Aylo Freesites and Cyprus News Agency decisions confirm.
This article presents general legal information about Cyprus data protection law as of 10 September 2026. It does not constitute legal advice. The GDPR and Law 125(I)/2018 are subject to amendment, and OCPDP enforcement practice continues to evolve. Organizations should consult a lawyer licensed in Cyprus for advice specific to their situation.
Frequently Asked Questions
What is the main data protection law in Cyprus?
Cyprus data protection law rests on two core instruments. The EU General Data Protection Regulation (GDPR), Regulation (EU) 2016/679, applies directly as law throughout Cyprus as an EU Member State. Law 125(I)/2018 is the national supplementing statute that adds Cyprus-specific provisions on the supervisory authority (the OCPDP), children's consent age (14), criminal offenses under Section 33, and the transfer controls in Sections 17 and 18. Those two are not the whole framework: cookie and electronic direct-marketing rules sit in Sections 97 to 107 of Law 112(I)/2004, Directive (EU) 2016/680 is transposed by Law 44(I)/2019, and the same Commissioner acts as Information Commissioner under Law 184(I)/2017.
Who enforces data protection law in Cyprus?
The Office of the Commissioner for Personal Data Protection (OCPDP), based in Nicosia, is the independent supervisory authority. It handles complaints from individuals, conducts investigations and audits, issues guidance, and imposes administrative fines of up to EUR 20 million or 4% of worldwide turnover for the most serious GDPR violations. The OCPDP is a full member of the European Data Protection Board. Maria Manolis Christofidou has served as Commissioner since 28 September 2025.
What is the age of consent for data processing in Cyprus?
Cyprus set the threshold for children's consent to information society services at 14 years, using the derogation permitted by GDPR Article 8(1). Children aged 14 and above can provide valid consent for online services such as social media and apps. For children below 14, consent must be given or authorized by a holder of parental responsibility. Controllers must make reasonable efforts to verify age and consent, taking account of available technology.
Does Cyprus require pre-notification to the OCPDP before transferring data abroad?
Yes, but only for transfers of special categories of personal data (health, biometric, genetic, racial or ethnic origin, political opinion, religious belief, trade union, sex life, or sexual orientation data) to third countries where the transfer relies on GDPR Article 46 safeguards such as standard contractual clauses, or on Article 47 binding corporate rules. Section 17(1) of Law 125(I)/2018 requires advance notification to the OCPDP before such transfers take place. Section 18(1) goes further for the other route: a special-category transfer relying on a GDPR Article 49 derogation requires an impact assessment and prior consultation with the Commissioner, not just a notification. Both are Cyprus-specific requirements not found in the GDPR itself.
What are the maximum GDPR fines in Cyprus?
Upper-tier GDPR violations (unlawful processing, invalid consent, violations of data subjects' rights, unlawful international transfers) carry fines of up to EUR 20 million or 4% of total worldwide annual turnover, whichever is higher. Lower-tier violations (failures in record-keeping, breach notification, or DPO designation) carry fines of up to EUR 10 million or 2% of turnover. Law 125(I)/2018, Section 32(3) adds no fining power. It sets a ceiling: an administrative fine imposed on a public authority or public body, in respect of non-profit-making activities, may not exceed EUR 200,000. Both conditions must be met, so private-sector non-profits are not covered and remain exposed to the full GDPR maxima. Separately, Section 33 creates criminal offences carrying up to three years imprisonment or EUR 30,000, and up to five years or EUR 50,000 in aggravated cases.
When must a Data Protection Officer be appointed in Cyprus?
A DPO is mandatory under GDPR Article 37 for: public authorities and bodies; controllers or processors whose core activities consist of large-scale, regular, and systematic monitoring of individuals; and controllers or processors whose core activities consist of large-scale processing of special categories of data or data relating to criminal convictions. Law 125(I)/2018, Section 14(2) empowers the OCPDP to require DPOs in additional contexts, but no such list has been published as of 10 September 2026. External DPO arrangements are permitted under GDPR Article 37(6).
What does the EU AI Act mean for organizations in Cyprus?
The EU AI Act (Regulation (EU) 2024/1689) applies directly in Cyprus. Prohibitions on unacceptable-risk AI practices have been in force since 2 February 2025. High-risk AI system obligations become applicable on 2 December 2027 for Annex III systems and 2 August 2028 for AI built into regulated products, moved by the July 2026 Digital Omnibus. Cyprus designated its Article 70 national competent authorities on 22 January 2025: the Deputy Ministry of Research, Innovation and Digital Policy coordinates implementation; the Commissioner of Electronic Communications is Notifying Authority, Market Surveillance Authority, and Single Point of Contact; and the Commissioner for Personal Data Protection is Market Surveillance Authority for the Annex III points 1, 6, 7 and 8 high-risk systems, covering biometrics, law enforcement, migration and border control, and the administration of justice. Separately, on 6 November 2024 Cyprus notified the Commission of three Article 77 fundamental rights authorities, the OCPDP among them, whose extra powers take effect on 2 August 2026.
What is the Cyprus constitutional basis for data protection?
The Cyprus Constitution does not contain an express fundamental right to the protection of personal data. Data privacy rights are anchored in Article 15 (right to respect for private and family life) and Article 17 (secrecy of correspondence). These provisions provide the domestic constitutional foundation for the GDPR and Law 125(I)/2018, alongside the EU Charter of Fundamental Rights Articles 7 and 8, which take precedence as EU law.
How does NIS2 relate to GDPR obligations in Cyprus?
The Network and Information Systems Security (Amendment) Law of 2025, which transposed the EU's NIS2 Directive, creates cybersecurity obligations that sit alongside the GDPR. Where a cybersecurity incident also constitutes a personal data breach, organizations face dual notification obligations: an initial report to the Digital Security Authority within six hours and a full incident report within 72 hours under NIS2, plus a breach notification to the OCPDP within 72 hours under GDPR Article 33. Organizations in critical sectors should integrate these reporting obligations into a single incident response procedure.
What is the significance of the Intellexa/Pegasus spyware case for Cyprus data privacy?
The Intellexa consortium, which developed the Predator surveillance tool, operated Cyprus as a primary hub and benefited from gaps in export licensing and corporate governance oversight. US Treasury sanctions were imposed on Intellexa and its founder in 2024. The European Parliament's PEGA Committee recommended Cyprus repeal export licenses not aligned with EU law. The episode highlighted the distinction between formal GDPR compliance and broader privacy governance, and has sharpened regulatory focus on technology businesses operating under Cyprus registration.
Updates
Corrected several statements about Cyprus law after re-checking the primary sources: Law 125(I)/2018 section 32(3) is a EUR 200,000 ceiling on fines against public authorities for non-profit-making activities, not an extra fine aimed at non-profits; Singapore has no EU adequacy decision and the transfer section now gives the Commission's actual list; the criminal provisions are section 33, not a non-existent section 84, and the article now states its three penalty tiers and the personal liability under section 33(5); the Aylo Freesites decision is dated 2024 and is no longer described as the largest fine on record, which is EUR 925,000 against WS WiSpear Systems Ltd in November 2021; a fine wrongly attributed to the Ministry of Education has been replaced with the 2023 Ministry of the Interior and Bank of Cyprus decisions; the articles breached in the Housing Finance Corporation, Senira, Brivio and Cyprus News Agency decisions have been corrected; and sections 9 and 18 of Law 125(I)/2018, the ban on genetic and biometric data in health and life insurance and the impact assessment required for Article 49 transfers, have been added. Two dead links to the Commissioner's old website were replaced with the current gov.cy sources. Corrected the employment section: Cyprus took no GDPR Article 88 employment derogation, so employee data is governed by the GDPR directly plus the Commissioner's Opinions and Directives, not by Law 125(I)/2018. Removed a research-approval test that does not exist in Cypriot law and replaced it with Section 31 as the text reads, relabelled the DPO provision as Section 14(2) rather than Article 14(2), and clarified that the EUR 8,000 Ministry of the Interior fine followed an ex officio investigation into a disclosure to the House of Representatives rather than a complaint.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
AI Act dates updated for the July 2026 Digital Omnibus (Regulation (EU) 2026/1744): high-risk obligations now apply 2 December 2027 for Annex III systems and 2 August 2028 for AI built into regulated products, and the Article 50 transparency date has been corrected to 2 August 2026.
Full audit-and-evolve refresh: expanded from ~2,380 to ~6,200 words. Added constitutional basis (Articles 15 and 17), OCPDP enforcement timeline with named decisions (Aylo Freesites EUR 58,400; Housing Finance Corporation EUR 10,000; Senira Limited EUR 3,000; Open University of Cyprus EUR 45,000; Cyprus News Agency reprimand), EU AI Act overlay with Cyprus national authority designation (January 2025), NIS2 transposition (April 2025), Pegasus/Intellexa governance backdrop, UpdatesLog component, expanded FAQ to 10 items, and fuller DPO and cross-border transfer coverage.
Reviewed and approved by an editor
Sources and References
- Law 125(I)/2018 - Office of the Commissioner for Personal Data Protection (gov.cy)(gov.cy).gov
- Regulation (EU) 2016/679 (GDPR) - EUR-Lex(eur-lex.europa.eu).gov
- Commissioner (Cyprus) - GDPRhub(gdprhub.eu)
- Data Protection in Cyprus - GDPRhub(gdprhub.eu)
- Commissioner (Cyprus) - Aylo Freesites Ltd - GDPRhub(gdprhub.eu)
- Commissioner (Cyprus) - Housing Finance Corporation - GDPRhub(gdprhub.eu)
- Commissioner fines Open University of Cyprus EUR 45,000 - DataGuidance(dataguidance.com)
- Cyprus: Commissioner fines Aylo Freesites EUR 58,400 - DataGuidance(dataguidance.com)
- ICLG Data Protection Laws Cyprus 2024-2025(iclg.com)
- CEF 2025 Right to Erasure - EDPB(edpb.europa.eu).gov
- EU AI Act Regulation (EU) 2024/1689 - EUR-Lex(eur-lex.europa.eu).gov
- Cyprus AI Act national authority designation - gov.cy(gov.cy).gov
- Cyprus NIS2 adoption 2025 - Harneys(harneys.com)
- NIS2 Directive implementation Cyprus - European Commission(digital-strategy.ec.europa.eu).gov
- Intellexa US sanctions - ICIJ Cyprus Confidential(icij.org)
- Christofidou new OCPDP Commissioner - Cyprus Mail(cyprus-mail.com)
- Law 125(I)/2018 - unofficial English translation (PDF) - gov.cy(gov.cy).gov
- Commissioner (Cyprus) - 11.17.001.010.239 (Senira) - GDPRhub(gdprhub.eu)
- Cyprus - Data Protection Overview - DataGuidance(dataguidance.com)
- Data Protection in Cyprus - DLA Piper Data Protection Laws of the World(dlapiperdataprotection.com)
- CEF 2026: EDPB launches coordinated enforcement action on transparency - EDPB(edpb.europa.eu)
- Greek court convicts Intellexa founder Tal Dilian - ICIJ(icij.org)
- Regulation (EU) 2026/1744 of 8 July 2026 amending Regulation (EU) 2024/1689 (Digital Omnibus on AI), OJ L 2026/1744, 24.7.2026(eur-lex.europa.eu).gov
- Law 125(I)/2018, consolidated text with amendment history (125(I)/2018 and 26(I)/2022) - CyLaw(cylaw.org)
- Law 26(I)/2022 amending Law 125(I)/2018, Official Gazette No. 4878, 11 March 2022 - gov.cy(gov.cy).gov
- OCPDP Annual Report 2024 (88 decisions, 21 fines totalling EUR 133,900; Aylo Freesites at s. 7.12) - gov.cy(gov.cy).gov
- OCPDP Annual Report 2021 (EUR 925,000 fine on WS WiSpear Systems Ltd, announced 12 November 2021) - gov.cy(gov.cy).gov
- OCPDP Annual Report 2023 (Open University of Cyprus EUR 45,000; Ministry of the Interior and Bank of Cyprus EUR 8,000) - gov.cy(gov.cy).gov
- Cyprus AI Act national competent authorities, Council of Ministers decision of 22 January 2025 - Deputy Ministry of Research, Innovation and Digital Policy(gov.cy).gov
- Adequacy decisions - European Commission(commission.europa.eu).gov
- Office of the Commissioner for Personal Data Protection - remit, including Law 44(I)/2019, Law 112(I)/2004 ss. 97-107 and Law 184(I)/2017(gov.cy).gov