EnglishEL
Greece flag

Greece

Greece Data Privacy Laws: GDPR, Law 4624/2019 & HDPA Guide (2026)

By Recording Law Editorial TeamReviewed September 9, 202624 min read
Greece Data Privacy Laws: GDPR, Law 4624/2019 & HDPA Guide (2026)

Frequently Asked Questions

What is Greece's main data privacy law?

Greece's data protection framework consists of two instruments operating in parallel. The GDPR (EU 2016/679) applies directly as EU law and is the primary source of obligations. Law 4624/2019 -- Greece's national GDPR implementing legislation, in force since 28 August 2019 -- supplements the GDPR with national choices including a digital age of consent of 15, criminal penalties for data offenses, and the organizational framework for the Hellenic Data Protection Authority. Constitutional protection is also provided by Article 9A of the Greek Constitution, added in the 2001 revision.

Who is the data protection authority in Greece?

The Hellenic Data Protection Authority (HDPA) is Greece's independent supervisory authority. It is an independent constitutional body based in Athens, composed of a President and six members appointed for four-year terms by the Greek Parliament. The HDPA investigates complaints, conducts audits, issues guidance, and can impose fines up to EUR 20 million or 4% of global annual turnover for serious GDPR violations.

What was the Clearview AI fine in Greece?

In July 2022, the HDPA imposed a EUR 20 million fine on Clearview AI -- the maximum possible under the GDPR's upper tier. Decision 35/2022 found that Clearview violated the lawfulness and transparency principles (Articles 5 and 6 GDPR), unlawfully processed biometric data (Article 9), and failed its transparency and access obligations (Articles 12, 14, 15, and 27). The HDPA also ordered Clearview to delete all personal data of Greek residents collected through its facial recognition service and prohibited future collection.

What are the cookie consent rules in Greece?

Under Law 3471/2006, Greece requires opt-in consent for all non-essential cookies. Technically necessary cookies (authentication, load-balancing, security, user preferences for the service requested) are exempt. All analytics, advertising, targeting, and social-media tracking cookies require prior informed consent meeting the full GDPR standard: freely given, specific, informed, and given before any tracking begins. Pre-ticked boxes and inferred consent from continued browsing are invalid. The HDPA conducts remote website audits for cookie compliance.

What is the age of digital consent in Greece?

Greece set the age of digital consent at 15 years old under Law 4624/2019. Children aged 15 and older can independently consent to information society services such as social media platforms. For children under 15, controllers must obtain and verify parental or guardian authorization before providing the service.

What is the Predator spyware scandal in Greece?

The Predator spyware scandal emerged in 2022 when it was discovered that Intellexa's Predator software had been used to target at least 87 individuals in Greece including journalists, politicians, military officials, and civil society figures. In February 2026, an Athens court sentenced Intellexa founder Tal Dilian and three others to 8-year prison terms. The U.S. Treasury sanctioned Intellexa in 2024. The scandal highlights the tension between Greece's formal data protection rules and state-adjacent surveillance practices.

Does Greece have constitutional data protection rights?

Yes. Article 9A of the Greek Constitution, added in the 2001 revision, explicitly guarantees every person the right to protection of their personal data and mandates an independent supervisory authority. This constitutional status means the HDPA's independence is protected at the fundamental-law level. Article 19(3) also provides that evidence obtained in violation of data protection or communications secrecy provisions is inadmissible in Greek courts.

How does the EU AI Act affect organizations in Greece?

The EU AI Act entered into force in August 2024 and applies directly in Greece. Prohibited AI practices have been enforceable since February 2025 -- including bans on real-time remote biometric identification in public spaces and mass scraping of facial images for recognition databases. Transparency obligations apply from August 2, 2026, and the high-risk AI system requirements apply from December 2, 2027 for Annex III systems and August 2, 2028 for high-risk AI embedded in regulated products, after the July 2026 Digital Omnibus moved those dates. AI systems processing personal data must comply with both the AI Act and the GDPR simultaneously. Non-compliance with prohibited AI practices can trigger fines up to EUR 35 million or 7% of global annual turnover.

Updates

AI Act dates updated for the July 2026 Digital Omnibus: high-risk obligations now apply 2 December 2027 (Annex III) and 2 August 2028 (Annex I); the 2 August 2026 transparency date is unchanged.

Major expansion: added constitutional basis (Article 9A), legal bases / consent framework, data subject rights, DPO requirements, ePrivacy / cookies (Law 3471/2006), EU AI Act overlay, Predatorgate / Intellexa spyware context, COSMOTE fine, and 2024-2026 enforcement decisions. Word count ~6,000.

Initial publication covering [GDPR](/world-laws/world-data-privacy-laws) implementation, HDPA overview, and CCTV enforcement.

Sources and References

  1. Hellenic Data Protection Authority(dpa.gr).gov
  2. Law 4624/2019 English Translation(dpa.gr).gov
  3. HDPA Clearview AI Fine Decision 35/2022(dpa.gr).gov
  4. EDPB Clearview AI Fine Announcement(edpb.europa.eu).gov
  5. EDPB COSMOTE OTE Fines(edpb.europa.eu).gov
  6. ICLG Data Protection Greece 2025-2026(iclg.com)
  7. Chambers Data Protection Greece 2026(practiceguides.chambers.com)
  8. DLA Piper Greece Data Protection(dlapiperdataprotection.com)
  9. GDPRhub HDPA Enforcement Decisions(gdprhub.eu)
  10. Amnesty International Predatorgate Convictions 2026(amnesty.org)
  11. EU AI Act Implementation Timeline(artificialintelligenceact.eu)
  12. HDPA Legal Framework Overview(dpa.gr).gov
  13. Regulation (EU) 2026/1744 of 8 July 2026 amending Regulation (EU) 2024/1689 (Digital Omnibus on AI), OJ L 2026/1744, 24.7.2026(eur-lex.europa.eu).gov
Share: