Law / Cyprus

Cyprus

European Union law applies in Cyprus Cyprus is a member state of the European Union, whose 37 researched instruments are listed on the European Union page, not here. The law of Cyprus, described on this page below, applies here too.

All 14 named instruments researched to a stage, across all six areas of law we track: 14 in force. As of 16 September 2026.

  1. AI law 1
  2. Privacy law 6
  3. Scraping law 2
  4. Cybersecurity law 3
  5. Age gating law 1
  6. News aggregation law 1

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law1 instrument, 1 in force

Research summary (115 words)

The EU AI Act (Regulation (EU) 2024/1689) applies directly in Cyprus and is not restated here; its Article 5 prohibitions, Article 50 transparency duties, and Article 53 general-purpose-model duties are covered by the eu document. Cyprus's own addition is Law 29(I)/2026, which amended the Intellectual Property and Related Rights Law to ban the non-consensual public dissemination of AI-generated deepfake imitations of a person's likeness, voice, or a performer's performance.

As of September 2026 Cyprus has not enacted an AI Act implementing statute; the Deputy Ministry of Research, Innovation and Digital Policy opened public consultation on a National Artificial Intelligence Strategy on 22 July 2026, which remains a policy document under consultation rather than binding law.

AI prohibited practices

Intellectual Property and Related Rights Law, Articles 49-50 (Non-Consensual Deepfake Imitation Ban)

L. 29(I)/2026, art. 4, inserting articles 49 and 50 into the Intellectual Property Rights and Related Rights Law (L. 59/1976, as amended)official text of Law 29(I)/2026, cylaw.org (Cyprus Bar Association consolidated law database)

In force. Binds public and private bodies.

What this law does

Law 29(I)/2026 inserted new articles 49 and 50 into Cyprus's Intellectual Property and Related Rights Law, defining a deepfake product by reference to Article 3(60) of the EU AI Act. A deepfake imitation of a performer's performance, or of a natural person's personal physical characteristics including voice and biometric data, may not be made available to the public without that person's explicit consent.

An exception exists for satire, parody, caricature, or political and social commentary, unless the imitation amounts to disinformation posing a serious risk to the rights or essential interests of the affected person or others. The right lasts until 50 years after the death of the performer or the person depicted.

What it requires

Privacy law6 instruments, 6 in force

Research summary (97 words)

Cyprus's private-sector regime is the General Data Protection Regulation (GDPR) plus Law 125(I)/2018, published in the Official Gazette on 31 July 2018, supplying domestic derogations and procedural rules.

Its most consequential national addition, per secondary commentary not independently confirmed against the Law's own text, is a prohibition on processing genetic and biometric data for life and health insurance purposes, and a heightened, separate-consent requirement wherever consent is the lawful basis for processing genetic or biometric data. The Office of the Commissioner for Personal Data Protection (ODPC) is the supervisory authority. As at 24 August 2026; later amendment is not independently confirmed.

Biometric privacy

GDPR Article 9 and Law 125(I)/2018, Genetic and Biometric Data in Cyprus

Regulation (EU) 2016/679, Art. 9; Law 125(I)/2018Secondary commentary (Harris Kyriakides), not independently confirmed against Law 125(I)/2018's own text

In force since 31 July 2018. Binds public and private bodies.

What this law does

General Data Protection Regulation (GDPR) Article 9(1) classifies biometric data processed for unique identification as a special category. Secondary commentary (Harris Kyriakides) describes Law 125(I)/2018 as prohibiting the processing of genetic and biometric data for life and health insurance purposes, and as requiring separate, specific consent, over and above the ordinary GDPR consent standard, where a controller relies on consent as the lawful basis for processing genetic or biometric data.

The provision's own text and article number are not independently confirmed; neither addition distinguishes voice or face capture from any other biometric modality in the commentary consulted. No Cyprus-specific voiceprint or faceprint case or regulatory guidance was located.

What it requires

Breach notification

GDPR Articles 33-34, Breach Notification in Cyprus

Regulation (EU) 2016/679, Arts. 33-34Official Journal text, EUR-Lex, Regulation (EU) 2016/679

In force since 25 May 2018. Binds public and private bodies.

What this law does

A controller must notify the ODPC without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Cyprus, and must notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms. No Law 125(I)/2018 derogation from this timeline is identified.

What it requires

Comprehensive regime

Law 125(I)/2018, Cyprus GDPR Supplement

Law 125(I)/2018 of 2018Official Gazette of the Republic of Cyprus, 31 July 2018

In force since 31 July 2018. Binds public and private bodies.

What this law does

Cyprus's private-sector regime is the General Data Protection Regulation (GDPR) plus Law 125(I)/2018 (The Protection of Natural Persons with regard to the Processing of Personal Data and for the Free Movement of such Data Law of 2018), published in the Official Gazette of the Republic of Cyprus on 31 July 2018, supplying domestic derogations and procedural rules. The Office of the Commissioner for Personal Data Protection (ODPC) is the supervisory authority. The law's official English translation has not been located, so the article-level detail below rests on commentary.

What it requires

Cross border transfer

GDPR Chapter V, Cross-Border Transfer of Personal Data from Cyprus

Regulation (EU) 2016/679, Arts. 44-49Official Journal text, EUR-Lex, Regulation (EU) 2016/679

In force since 25 May 2018. Binds public and private bodies.

What this law does

Transferring personal data of a person in Cyprus outside the European Economic Area requires a European Commission adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation, backed by the Article 83(5) top fine tier. No Law 125(I)/2018 derogation broadening or narrowing this is identified.

What it requires

Data subject rights

GDPR Article 22 and Law 125(I)/2018, Automated Decisions in Cyprus

Regulation (EU) 2016/679, Art. 22; Law 125(I)/2018Official Journal text, EUR-Lex, Regulation (EU) 2016/679

In force since 31 July 2018. Binds public and private bodies.

What this law does

General Data Protection Regulation (GDPR) Articles 12 to 23 apply, including Article 22 rights against a decision based solely on automated processing, restated by Law 125(I)/2018 without narrowing per its own summary. No Cyprus-specific broadening of data-subject rights beyond the GDPR baseline is identified.

What it requires

Enforcement supervision

GDPR Articles 82-83 and ODPC Enforcement in Cyprus

Regulation (EU) 2016/679, Arts. 82-83Official Journal text, EUR-Lex, Regulation (EU) 2016/679

In force since 25 May 2018. Binds public and private bodies.

What this law does

The Office of the Commissioner for Personal Data Protection (ODPC) is the supervisory authority and enforces General Data Protection Regulation (GDPR) Article 83 fines. Law 125(I)/2018 Article 32(3) narrows the ceiling only for a public authority or public body's non-profit-making activities, to EUR 200,000; no narrower Cyprus-specific ceiling applies to a private-sector controller or processor, and no dedicated collective-redress statute is identified.

GDPR Article 82 gives any person who suffered material or non-material damage a right to compensation from the controller or processor.

What it requires

Scraping law2 instruments, 2 in force

Research summary (116 words)

Cyprus criminalises unauthorised access to a computer system through the Convention on Cybercrime, given direct domestic force by the ratifying Law 22(III)/2004, binding any person who acts intentionally and without right.

The Intellectual Property and Related Rights Law, as amended by Law 155(I)/2022 transposing the EU Digital Single Market Copyright Directive, permits reproduction of lawfully accessible works for text-and-data mining unless the rightholder has expressly reserved that use by an appropriate machine-readable means.

No Cyprus-specific database right, terms-of-service enforceability doctrine, or robots.txt case law distinct from the general contract and copyright rules was located in the primary sources checked. Personal data reached by scraping falls under Cyprus's privacy-topic document (General Data Protection Regulation (GDPR) and Law 125(I)/2018) rather than here.

Computer misuse

Convention on Cybercrime Ratifying Law, Article 2 (Illegal Access)

L. 22(III)/2004, Schedule Article 2 (Council of Europe Convention on Cybercrime, ETS No. 185, Budapest, 23.11.2001)official text of Law 22(III)/2004, cylaw.org (Cyprus Bar Association consolidated law database)

In force. Binds public and private bodies.

What this law does

Cyprus ratified the Council of Europe Convention on Cybercrime by Law 22(III)/2004, which sets out the Convention's English and Greek texts as a schedule to the Law and gives them the force of domestic law. Article 2 of the Convention requires each Party to criminalise intentional access without right to the whole or part of a computer system, and Article 13 requires that offences under Articles 2 to 11 carry effective, proportionate and dissuasive sanctions involving deprivation of liberty. The ratifying Law does not itself state a domestic commencement day distinct from its Gazette publication.

What it requires

Copyright and text and data mining (TDM)

Intellectual Property and Related Rights Law, Article 25 (Text and Data Mining Exception)

L. 155(I)/2022, art. 15, inserting article 25 into the Intellectual Property Rights and Related Rights Law (L. 59/1976, as amended)official text of Law 155(I)/2022, cylaw.org (Cyprus Bar Association consolidated law database)

In force. Binds public and private bodies.

What this law does

Law 155(I)/2022, which its preamble states harmonises Cyprus law with EU Directive 2019/790 on copyright in the Digital Single Market, inserted new articles 24 and 25 into Cyprus's Intellectual Property Rights and Related Rights Law. Article 24 exempts reproduction and extraction by research organisations and cultural heritage institutions for scientific text-and-data mining.

Article 25 gives a general exception for reproduction and extraction of lawfully accessible works for text-and-data mining. That exception applies only where the rightholder has not expressly reserved the use in an appropriate manner, such as machine-readable means, for content made available online.

What it requires

Cybersecurity law3 instruments, 3 in force

Research summary (529 words)

Cyprus transposed the NIS2 Directive (Directive (EU) 2022/2555) through the Security of Networks and Information Systems (Amendment) Law of 2025, N. 60(I)/2025 (Official Gazette, Annex I(I), No. 5036, 25 April 2025), which amended the Security of Networks and Information Systems Law of 2020, N. 89(I)/2020 (Cyprus's original NIS1 transposition), and entered into force on 25 April 2025, after Cyprus missed the Directive's own 17 October 2024 transposition deadline.

The consolidated Law binds an essential or important entity established in Cyprus (public or private, sized at the medium-enterprise threshold of Commission Recommendation 2003/361/EC or above, or regardless of size for certain named categories) across the sectors of Annexes I and II, including the digital providers those Annexes name (an online marketplace, an online search engine, a cloud computing service), to risk-management measures under Article 35, a management-body governance and accountability duty under Article 35A, and a graduated incident-notification duty under Article 35B, all owed to the Digital Security Authority (Αρχή Ψηφιακής Ασφάλειας), formerly the Office of the Commissioner of Electronic Communications and Postal Regulation, acting through the national CSIRT.

Cyprus's incident-notification clock departs from the Directive's own floor in one respect worth flagging: Article 35B(4)(a) sets the early-warning deadline at six hours from becoming aware of a significant incident, stricter than NIS2 Article 23(4)(a)'s 24-hour baseline, while the 72-hour incident notification, the one-month final report, and (for a trust service provider, which reports within 24 hours instead of 72) the derogation from that 72-hour clock all track the Directive.

Article 43A's penalty tiers for a violation of Articles 35 or 35B match the Directive's own ceiling: at least EUR 10,000,000 or 2 percent of worldwide annual turnover for an essential entity and at least EUR 7,000,000 or 1.4 percent for an important entity, whichever is higher in each case, both administrative.

Article 54's natural- and legal-person liability regime names only Articles 22 (non-compliance with the Authority's decision-issuance hearing procedure) and 43 (the Law's general, non-NIS2 administrative fine, up to EUR 200,000 plus EUR 10,000 per day of continuing violation) as offences it reaches, and pointedly not 35, 35A, 35B or 43A. The same 2025 amendment also partially transposes the Radio Equipment Directive (Directive 2014/53/EU): Article 42A requires radio equipment of categories or classes the Authority designates by Decision to be constructed so that it does not degrade the network, safeguards users' and subscribers' personal data and privacy, protects against fraud, and verifies the compatibility of any software before that software can be installed on the equipment, enforced by the Authority with a market-surveillance seizure power and, through Article 54's reach into Article 43, a criminal-liability channel the Article 35 and 35B duties do not carry.

No Cypriot instrument reviewed here imposes a general product-security or market-placement duty on a software manufacturer independent of the directly applicable Cyber Resilience Act, which is documented at the European Union level and is not restated here.

Cyprus has no general reasonable-security or information-security-programme statute with no sector gate; the closest general duty is General Data Protection Regulation (GDPR) Article 32's security-of-processing obligation, and personal-data breach notification under GDPR Articles 33 and 34 to the Commissioner for Personal Data Protection sits in this jurisdiction's privacy row rather than here.

Product security requirements

Security of Networks and Information Systems Law, Radio Equipment Cybersecurity Requirements

Art. 42A of the Security of Networks and Information Systems Law of 2020 N. 89(I)/2020, as inserted by the Security of Networks and Information Systems (Amendment) Law of 2025, N. 60(I)/2025Security of Networks and Information Systems Law of 2020 (89(I)/2020), consolidated with Law 60(I)/2025, CyLaw

In force since 25 April 2025. Binds private bodies.

What this law does

Article 42A, inserted to partially harmonize with the Radio Equipment Directive (Directive 2014/53/EU), requires the Digital Security Authority to ensure that radio equipment of categories or classes it designates by Decision is constructed to meet essential requirements set by the European Commission.

In particular, the equipment must not harm the network or degrade service by misusing network resources, must incorporate safeguards protecting users' and subscribers' personal data and privacy, must support features protecting against fraud, and must support features ensuring that software can be installed on the equipment only once the compatibility of that hardware-software combination has been demonstrated.

The Authority sets the specific conformity-assessment procedure, notified-body approval criteria, and market-surveillance process, including a seizure power, by its own Decision, and orders compliance measures or the elimination of risk where equipment endangers health, personal safety, or network and information-system security.

What it requires

Sector security regimes

Security of Networks and Information Systems Law, Cybersecurity Risk-Management Measures and Governance

Arts. 35 and 35A of the Security of Networks and Information Systems Law of 2020 N. 89(I)/2020, as amended by the Security of Networks and Information Systems (Amendment) Law of 2025, N. 60(I)/2025Security of Networks and Information Systems Law of 2020 (89(I)/2020), consolidated with Law 60(I)/2025, CyLaw

In force since 25 April 2025. Binds public and private bodies.

What this law does

Article 35 requires an essential or important entity to take appropriate and proportionate technical, operational and organisational measures, proportionate to the risk, to manage the risks to the security of the network and information systems it uses for its activities or to provide its services, covering at least risk-analysis and security policy, incident handling, business continuity and disaster recovery, supply-chain security, secure system acquisition and development including vulnerability handling and disclosure, effectiveness-assessment policies, cyber hygiene and training, cryptography and encryption, human-resources security and access control, and multi-factor authentication, transposing NIS2 Article 21.

Article 35A requires the entity's senior management to approve these measures, oversee their implementation, and undergo (and offer staff) regular cybersecurity training, and it can be held accountable for the entity's breach of the Article 35 duty.

What it requires

Vulnerability and incident reporting

Security of Networks and Information Systems Law, Incident Notification Obligations

Art. 35B of the Security of Networks and Information Systems Law of 2020 N. 89(I)/2020, as amended by the Security of Networks and Information Systems (Amendment) Law of 2025, N. 60(I)/2025Security of Networks and Information Systems Law of 2020 (89(I)/2020), consolidated with Law 60(I)/2025, CyLaw

In force since 25 April 2025. Binds public and private bodies.

What this law does

Article 35B requires an essential or important entity to notify the Digital Security Authority, without undue delay, of any incident that has a significant impact on the provision of its services, on a graduated clock: an early warning within six hours of becoming aware of the significant incident (stricter than NIS2 Article 23(4)(a)'s 24-hour floor), a fuller incident notification within 72 hours, an intermediate report on the Authority's request, and a final report within one month of the incident notification (or, for an incident still ongoing at that point, a progress report every 15 days and a final report within 15 days of restoring the affected network or system).

A trust-service provider notifies within 24 hours rather than 72 for an incident affecting its trust services. The Authority responds to the early warning within 24 hours with initial feedback and, on request, guidance, and forwards the notification to the national CSIRT.

What it requires

Age gating law1 instrument, 1 in force

Research summary (101 words)

Cyprus transposed the revised EU Audiovisual Media Services Directive's video-sharing platform rules through Law 197(I)/2021, which inserted Article 32ΣΤ into the Radio and Television Organisations Law. A video-sharing platform provider under Cyprus's jurisdiction must install and operate age-verification systems for users, for content that may harm the physical, mental, or moral development of minors, alongside parental-control, flagging, and rating systems.

Breach can draw an administrative fine of up to 5 percent of the provider's turnover or 500,000 euros, imposed by the Cyprus Radio Television Authority. Cyprus's minor's digital-consent age under the General Data Protection Regulation (GDPR) is covered by the privacy-topic document rather than here.

Adult content age verification (AV)

Radio and Television Organisations Law, Article 32ΣΤ (Video-Sharing Platform Age Verification)

L. 197(I)/2021, art. 32ΣΤ(8)(στ), inserted into the Radio and Television Organisations Law (L. 7(I)/1998, as amended)official text of Law 197(I)/2021, cylaw.org (Cyprus Bar Association consolidated law database)

In force. Binds private bodies.

What this law does

A video-sharing platform provider under the jurisdiction of Cyprus must take appropriate measures to protect minors from content that may harm their physical, mental, or moral development, including the installation and operation of age-verification systems for users of the platform in relation to such content, per Article 32ΣΤ(8)(στ) of the Radio and Television Organisations Law.

Personal data of minors collected under these measures may not be processed for commercial purposes such as direct marketing, profiling, or behavioural advertising, per Article 32ΣΤ(9). The Cyprus Radio Television Authority may impose an administrative fine of up to 5 percent of the provider's turnover for the preceding financial year, or up to 500,000 euros, for breach of Article 32ΣΤ, per Article 32Ζ(2).

Note and primary source

News aggregation law1 instrument, 1 in force

Research summary (106 words)

Cyprus transposed the EU Digital Single Market Copyright Directive's press-publisher neighbouring right through Law 155(I)/2022, which inserted Article 36 into the Intellectual Property and Related Rights Law. Press publishers established in a member state hold an exclusive online reproduction and making-available right over their press publications for two years from publication, and the right does not reach mere hyperlinking or the use of individual words or very short extracts.

Cyprus has no compelled platform-to-publisher bargaining regime comparable to Australia's News Media Bargaining Code or Canada's Online News Act, and no hot-news or misappropriation doctrine distinct from ordinary unfair-competition law was located in the primary sources checked.

Press publishers' right

Intellectual Property and Related Rights Law, Article 36 (Press Publisher Online Rights)

L. 155(I)/2022, art. 15, inserting article 36 into the Intellectual Property Rights and Related Rights Law (L. 59/1976, as amended)official text of Law 155(I)/2022, cylaw.org (Cyprus Bar Association consolidated law database)

In force. Binds private bodies.

What this law does

Press publishers established in a member state hold an exclusive right to authorise or prohibit the reproduction and online making-available of their press publications by information-society service providers, per new Article 36(1) of Cyprus's Intellectual Property and Related Rights Law. The right does not reach private or non-commercial use by individual users, per Article 36(2).

Nor does it reach mere hyperlinks that only lead to the article, or the use of single words or very short extracts, per Article 36(3). The right lasts two years from the publication's release, calculated from 1 January of the following year, and does not apply to publications first published before 6 June 2019, per Article 36(7). Authors whose works are incorporated in a press publication are entitled to an appropriate share of the revenue publishers receive for its use, per Article 36(9).

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.