Law / Greece

Greece

European Union law applies in Greece Greece is a member state of the European Union, whose 37 researched instruments are listed on the European Union page, not here. The law of Greece, described on this page below, applies here too.

14 of 17 named instruments researched to a stage, across all six areas of law we track: 14 in force. As of 15 September 2026.

When they take effect13 of 14 carry a date, 1 does not.
2016: 1 instrument (1 in force) ’16 2017: 0 instruments 2018: 4 instruments (4 in force) 2019: 2 instruments (2 in force) 2020: 0 instruments ’20 2021: 1 instrument (1 in force) 2022: 2 instruments (2 in force) 2023: 0 instruments 2024: 2 instruments (2 in force) 2025: 0 instruments 2026: 1 instrument (1 in force) ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 1
  2. Privacy law 6
  3. Scraping law 2
  4. Cybersecurity law 2
  5. Age gating law 1
  6. News aggregation law 2

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law1 instrument, 1 in force

Research summary (195 words)

The EU AI Act (Regulation (EU) 2024/1689) applies directly in Greece and is not restated here as Greek law; its Article 5 prohibitions, Annex III high-risk duties, and Article 50 transparency and labelling duties are recorded in the eu document for this topic.

Greece's own addition is Law 5321/2026 (FEK A' 114/20.07.2026), which names the Hellenic Data Protection Authority (HDPA) as the market surveillance authority for prohibited practices, Annex III high-risk systems, and Article 50 transparency systems, and as the single point of contact under the AI Act, and names the Hellenic Telecommunications and Post Commission (EETT) as the notifying authority for conformity-assessment bodies.

Beyond institutional design, Law 5321/2026 adds a national criminal offence: removing or obstructing the machine-readable marking of AI-generated content, or a deployer's disclosure that content is a deepfake, is punished with imprisonment and a fine.

Law 5321/2026 Article 26 repealed Chapter B of Part A of Law 4961/2022, which had been Greece's own earlier, pre-AI-Act national attempt at regulating public-sector algorithmic decisions and private employers' use of AI in employment; that chapter's specific article-by-article content was not independently verified against primary text within this visit and is not separately recorded here.

AI transparency

Law 5321/2026, National AI Act Implementation Law

Law 5321/2026, arts. 3-5, 16, 23 (FEK A' 114/20.07.2026)The Government's bill for Law 5321/2026, signed 6 July 2026 and enacted two weeks later as Law 5321/2026 (FEK A' 114/20.07.2026)

In force 65 days, effective 20 July 2026. Binds public and private bodies.

What this law does

Article 3 designates the Hellenic Data Protection Authority (HDPA) as the market surveillance authority under AI Act Article 70(1) for systems within the Article 5 prohibited practices, the Annex III high-risk list, and the Article 50 transparency duties; Article 4 makes the HDPA the AI Act's single point of contact, and Article 5 names the Hellenic Telecommunications and Post Commission (EETT) as the notifying authority for conformity-assessment bodies.

Article 16 gives the HDPA and other market-surveillance authorities warning, reprimand, and Article 99 fining powers on top of the AI Act's own machinery, plus a periodic financial penalty of up to 2 percent of an undertaking's average daily worldwide turnover for continuing non-compliance.

Article 23 makes it a crime, punished by imprisonment and a fine unless a more severe provision applies, to remove or obstruct the machine-readable marking an AI system embeds in synthetic output under AI Act Article 50(1), or to remove or obstruct a deployer's disclosure under Article 50(4) that content is a deepfake or has been artificially generated or manipulated.

What it requires

Privacy law6 instruments, 6 in force

Research summary (100 words)

Greece's private-sector regime is the General Data Protection Regulation (GDPR) plus Law 4624/2019 (FEK A' 137/29-08-2019), in force from its 29 August 2019 publication, which supplies national derogations, an employment chapter, and procedural rules. The Hellenic Data Protection Authority (HDPA) is the supervisory authority.

The HDPA's own official English translation PDF does not yield extractable text, so Law 4624/2019's specific provisions, including its employment consent narrowing, workplace surveillance notice duty, and its biometric-adjacent social-security derogation, rest on secondary legal commentary rather than a primary-text read, and are described only in general terms here. As at 24 August 2026; later amendment is not independently confirmed.

Biometric privacy

GDPR Article 9 and Law 4624/2019, Special Categories in Greece

Regulation (EU) 2016/679, Art. 9; Law 4624/2019Secondary commentary (Centraleyes, Practical Law), not independently confirmed against Law 4624/2019's own text

In force since 25 May 2018. Binds public and private bodies.

What this law does

General Data Protection Regulation (GDPR) Article 9(1) classifies biometric data processed for unique identification as a special category. Secondary commentary (Centraleyes, Practical Law) describes Law 4624/2019 as adding a derogation grouping genetic, biometric, and health data together, permitting their processing where necessary for social security or social protection purposes, or to assess an employee's fitness for work.

The provision's exact article number, and whether it enumerates biometric modalities individually, are not asserted; the grouping itself is stated at medium confidence, commentary sourced. No Greece-specific voiceprint or faceprint case or regulatory guidance is known.

What it requires

Breach notification

GDPR Articles 33-34, Breach Notification in Greece

Regulation (EU) 2016/679, Arts. 33-34Official Journal text, EUR-Lex, Regulation (EU) 2016/679

In force since 25 May 2018. Binds public and private bodies.

What this law does

A controller must notify the Hellenic Data Protection Authority (HDPA) without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Greece, and must notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms. No Law 4624/2019 derogation from this timeline is identified.

What it requires

Comprehensive regime

Law 4624/2019, Greek GDPR Implementation Law (Nomos 4624/2019, N. 4624/2019)

Law 4624/2019, FEK A' 137/29-08-2019HDPA official English translation PDF (dpa.gr), not independently extracted

In force since 29 August 2019. Binds public and private bodies.

What this law does

Greece's private-sector regime is the General Data Protection Regulation (GDPR) plus Law 4624/2019 (Greek: Nomos 4624/2019), FEK A' 137/29-08-2019, in force from publication on 29 August 2019, which supplies domestic derogations and procedural rules, including an employment chapter narrowing consent as a lawful basis for employee data processing and separately regulating workplace video surveillance. The Hellenic Data Protection Authority (HDPA) is the supervisory authority.

The HDPA's own official English translation PDF does not yield extractable text, so the employment chapter's exact article numbers and text are not independently confirmed and are described here only in general terms, per secondary legal commentary.

What it requires

Cross border transfer

GDPR Chapter V, Cross-Border Transfer of Personal Data from Greece

Regulation (EU) 2016/679, Arts. 44-49Official Journal text, EUR-Lex, Regulation (EU) 2016/679

In force since 25 May 2018. Binds public and private bodies.

What this law does

Transferring personal data of a person in Greece outside the European Economic Area requires a European Commission adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation, backed by the Article 83(5) top fine tier. No Law 4624/2019 derogation broadening or narrowing this is identified.

What it requires

Data subject rights

GDPR Article 22 and Law 4624/2019 Article 27, Data Subject Rights and Employment in Greece

Regulation (EU) 2016/679, Arts. 12-23; Law 4624/2019, Art. 27Secondary commentary (activeMind.legal, Metaxopoulos Law), not independently confirmed against Law 4624/2019's own text

In force since 29 August 2019. Binds public and private bodies.

What this law does

General Data Protection Regulation (GDPR) Articles 12 to 23 apply, including Article 22 rights against a decision based solely on automated processing, restated without narrowing by Law 4624/2019.

Secondary commentary describes an employment chapter, commonly cited as Article 27, that makes employee consent lawful only in exceptional cases assessed against the employee's dependence in the employment relationship, and separately requires written notice to employees before workplace video surveillance is installed, limited to protection of persons and property.

This chapter's exact article numbers and text are not independently confirmed, since the HDPA's own official translation PDF does not yield readable text.

What it requires

Enforcement supervision

GDPR Articles 82-83 and HDPA Enforcement in Greece

Regulation (EU) 2016/679, Arts. 82-83Official Journal text, EUR-Lex, Regulation (EU) 2016/679

In force since 25 May 2018. Binds public and private bodies.

What this law does

The Hellenic Data Protection Authority (HDPA) is the supervisory authority and enforces General Data Protection Regulation (GDPR) Article 83 fines. In 2024 the HDPA issued an administrative fine and compliance order against the Ministry of Migration and Asylum, reported by the European Data Protection Board (EDPB)'s national news feed. No Greece-specific fine ceiling beyond the GDPR Article 83 maximum, and no dedicated collective-redress statute for data-protection claims, is identified.

GDPR Article 82 gives any person who suffered material or non-material damage a right to compensation from the controller or processor.

What it requires

Scraping law2 instruments, 2 in force

Research summary (210 words)

Greece has no scraping-specific statute, so general law governs each dimension separately.

The Penal Code's Article 370C criminalises gaining access to all or part of an information system, or to data transmitted over a telecommunications system, only where the actor violates a prohibition or a security measure the lawful holder has put in place, so crawling a public, unauthenticated page that carries neither a stated prohibition nor a technical access control falls outside a plain reading of the offence.

A related but distinct provision, Article 370B, punishes copying, using or disclosing computer data or programs that constitute a state, scientific, professional, or business secret, independent of any access-control requirement. No Greek statute or reported decision addresses whether a browsewrap or clickwrap terms-of-service restriction against scraping is enforceable as a matter of contract law, so that dimension is unsettled.

Greece's sui generis database right, its personal-data reach over scraped public data, its unfair-competition doctrine, and any robots.txt-specific or AI-training-specific rule are not addressed by the instruments below.

The text-and-data-mining exception in Law 2121/1993 Articles 21A-21B, and the press-publisher right in Article 51B, are recorded in the aggregation topic for this jurisdiction, since both bear directly on how a news aggregator, not merely a generic crawler, may reproduce or mine journalistic content.

Computer misuse

Penal Code Article 370B, Violation of Computer Data and Program Secrets

Poinikos Kodikas, art. 370B (370Β)Official codified Penal Code text published by the Hellenic Ministry of Justice

In force. Binds public and private bodies.

What this law does

Article 370B punishes copying, recording, using, disclosing to a third party, or otherwise violating computer data or programs that constitute a state, scientific, professional, or business secret of the public or private sector, without right, with imprisonment of at least three months.

The offence reaches data the lawful holder treats as secret from a justified interest, particularly where it has taken measures to keep third parties from learning of it, and paragraph 2 raises the minimum to one year where the offender is in the holder's service or the secret is of especially great economic significance.

What it requires

Penal Code Article 370C, Illegal Access to an Information System

Poinikos Kodikas, art. 370C, as replaced by Law 4411/2016, art. 2 para. 6 (FEK A' 142/3.8.2016)Official codified Penal Code text published by the Hellenic Ministry of Justice

In force since 3 August 2016. Binds public and private bodies.

What this law does

Article 370C of the Penal Code, titled Illegal Access to an Information System, punishes without-right copying or use of computer programs with up to six months' imprisonment and a fine of 290 to 5,900 euro (paragraph 1), and separately punishes without-right access to all or part of an information system, or to data transmitted by telecommunications systems, where the actor violates a prohibition or a security measure the lawful holder has put in place, with imprisonment (paragraph 2).

A neighbouring provision, Article 370D, is a separate offence: unauthorised technical interception of non-public data transmissions or electromagnetic emissions to, from or within an information system, punished with incarceration of up to ten years.

What it requires

Cybersecurity law2 instruments, 2 in force

Research summary (524 words)

Greece completed its NIS2 transposition through Law 5160/2024 (Ν. 5160/2024), «Ενσωμάτωση της Οδηγίας (ΕΕ) 2022/2555 ... (Οδηγία NIS 2) και άλλες διατάξεις» (Incorporation of Directive (EU) 2022/2555 ...

(NIS 2 Directive) and other provisions), published in the Government Gazette as FEK A' 195 of 27 November 2024 and in force from that same publication date under the law's own Article 45(1), with a one-year delay under Article 45(2) for a single narrow subprovision (Article 3(2)(στ)(στβ)) that is outside this topic's scope.

Chapter Δ' binds an essential or an important entity drawn from Annex I (high-criticality sectors) or Annex II (other critical sectors), each captioned in the law's own table of contents as corresponding directly to the Directive's own Annex I and Annex II, at the medium-enterprise threshold of Commission Recommendation 2003/361/EC or above (Article 3(1)), with trust service providers, top-level-domain registries and DNS service providers bound regardless of size (Article 4(1)(β)).

Article 14 requires the entity's management body to approve its cybersecurity risk-management measures within three months of the law's entry into force, supervise their implementation, and take annual cybersecurity training; Article 15 requires appropriate and proportionate technical, operational and organisational measures covering, at minimum, risk analysis and information-system security policy, incident handling, business continuity, supply-chain security, security in system acquisition and maintenance including vulnerability handling and disclosure, effectiveness-assessment policy, basic cyber hygiene and training, cryptography policy, personnel and access-management security and asset management, and multi-factor or continuous authentication and secure communications.

Article 16 sets a graduated significant-incident notification clock to the CSIRT of the National Cybersecurity Authority (Εθνική Αρχή Κυβερνοασφάλειας, EAK): a 24-hour early warning, a 72-hour incident notification, an interim report on request, and a final report within one month of the 72-hour notification (or a progress report plus a final report within one month of resolution for an incident still ongoing at that point).

Article 26 caps the administrative fine for an Article 15 or 16 violation at EUR 10,000,000 or 2% of worldwide annual turnover for an essential entity, and EUR 7,000,000 or 1.4% for an important entity, whichever is higher in each case, with smaller fixed caps for narrower violations (paragraphs 6, 8 and 9); no provision in Articles 15, 16 or 26 makes the infringement itself a criminal offence.

The EAK, established by Law 5086/2024 (FEK A' 23/14.02.2024), is the competent authority for supervision and enforcement here and, per legal commentary not confirmed against Law 5086/2024's own text, also coordinates Greece's market-surveillance role under the directly applicable EU Cyber Resilience Act, which is documented at the European Union level and is not restated here.

Where a significant incident under Articles 15 or 16 also amounts to a personal-data breach, Article 27 (transposing NIS2 Article 35) brings in the Hellenic Data Protection Authority; that breach-notification duty itself sits in the privacy topic under General Data Protection Regulation (GDPR) Articles 33-34 and Law 4624/2019, not here. The Greek Penal Code's computer-intrusion offences (Articles 370B, 370C and 370D) bind the intruder rather than the operator or manufacturer and already sit in the scraping topic, not here.

No instrument reviewed here imposes a product-security or market-placement duty on a manufacturer independent of the Cyber Resilience Act.

Sector security regimes

Law 5160/2024, Cybersecurity Risk-Management Measures and Governance

Law 5160/2024 (Ν. 5160/2024), Arts. 14-15Government Gazette (Εφημερίδα της Κυβερνήσεως)

In force since 27 November 2024. Binds public and private bodies.

What this law does

Article 14 requires the management body of an essential or important entity to approve, within three months of this law's entry into force, the cybersecurity risk-management measures the entity takes to comply with Article 15, to supervise their implementation, and holds the management body responsible for the entity's breach of this duty; its members must undergo training and ensure the entity provides equivalent training to its staff at least annually.

Article 15 requires appropriate and proportionate technical, operational and organisational measures to manage the risks to the network and information systems the entity uses for its activities or to provide its services, and to prevent or minimise the impact of an incident on the recipients of its services or on other services, at a level of security proportionate to the risk, covering at minimum: risk-analysis and information-system security policy; incident handling; business continuity including backup management, disaster recovery and crisis management; supply-chain security; security in the acquisition, development and maintenance of network and information systems, including vulnerability handling and disclosure; policies to assess the effectiveness of risk-management measures; basic cyber-hygiene practices and cybersecurity training; cryptography and, where relevant, encryption policy; human-resources security, access-control policy and asset management; and the use of multi-factor or continuous authentication, secure voice, video and text communications, and secure emergency-communications systems.

This law, Law 5160/2024 (FEK A' 195/27.11.2024), transposes NIS2 Directive Article 20 (Article 14) and Article 21 (Article 15).

What it requires

Vulnerability and incident reporting

Law 5160/2024, Significant-Incident Reporting Obligations

Law 5160/2024 (Ν. 5160/2024), Art. 16Government Gazette (Εφημερίδα της Κυβερνήσεως)

In force since 27 November 2024. Binds public and private bodies.

What this law does

Article 16 requires an essential or important entity to notify, without delay, the CSIRT of the National Cybersecurity Authority of every incident that has a significant impact on the provision of its services (a 'significant incident' under paragraph 3, gated on serious operational disruption or financial loss to the entity, or material harm to other persons).

The notification follows a graduated clock: an early warning within 24 hours of becoming aware of the significant incident, stating whether unlawful or malicious action is suspected and whether the incident may have cross-border effects; an incident notification within 72 hours, updating and adding an initial assessment of severity and effects; an interim report if the National Cybersecurity Authority requests one; and a final report no later than one month after the 72-hour notification, covering a detailed description, the type of threat or root cause, mitigating measures, and any cross-border impact, or, for an incident still ongoing at that point, a progress report followed by a final report within one month of its resolution.

The entity must also, without undue delay, notify service recipients of a significant incident likely to adversely affect the services they receive, and must inform recipients affected by a significant cyber threat of the threat and of measures they can take in response. This law, Law 5160/2024 (FEK A' 195/27.11.2024), transposes NIS2 Directive Article 23.

What it requires

Age gating law1 instrument, 1 in force

Research summary (124 words)

Greece's own age-gating addition to the EU baseline is Law 4779/2021 (FEK A' 27, 20.02.2021) Article 32, which transposes Article 28b of the Audiovisual Media Services Directive (2018/1808/EU) and assigns the National Council for Radio and Television (ESR) as the competent authority for video-sharing platforms and social networks with functionally separable video content established in Greece.

No dedicated Greek adult-content age-verification statute, social-media minimum-age statute, app-store age-verification statute, or age-appropriate design code beyond this Article 32 duty has been identified. The minor's digital-consent age for information-society services is set by Law 4624/2019 read with General Data Protection Regulation (GDPR) Article 8 and is recorded in the privacy document for this jurisdiction, not here, because the duty attaches to personal data rather than to age gating of a service.

Social media and minors

Law 4779/2021 Article 32, Video-Sharing Platform and Social Network Minor Protection Duties

Law 4779/2021 (Nomos 4779/2021), FEK A' 27/20.02.2021, art. 32, transposing AVMSD art. 28bESR (National Council for Radio and Television) official regulatory-framework page describing its Article 32 competencies

In force since 20 February 2021. Binds private bodies.

What this law does

Article 32 of Law 4779/2021 assigns the National Council for Radio and Television (ESR) to apply AVMSD Article 28b to video-sharing platforms and social networks established in Greece whose video content is functionally separable from the rest of the service.

The duty requires appropriate and feasible measures protecting minors from content that may impair their development, and separately protects the wider public from content inciting violence or hatred or amounting to child pornography, terrorism, xenophobia, or racism offences under EU law.

A covered provider must submit data to ESR annually under Article 32 paragraph 10, covering complaints received and resolved by category, out-of-court settlements, and the parental-control or age-verification systems and media-literacy measures adopted. ESR's competence reaches only providers established in Greece. ESR may impose sanctions for noncompliance under Article 36 of the same Law.

Note and primary source

News aggregation law2 instruments, 2 in force

Research summary (190 words)

As an EU member state, Greece carries the Digital Single Market (DSM) Copyright Directive's press-publisher right and text-and-data-mining exceptions through its own transposing statute rather than the Directive directly.

Law 4996/2022 inserted Article 51B into the Greek copyright act, Law 2121/1993, giving a press publisher established in Greece the exclusive right to authorise or prohibit online reproduction and making available of its press publications, with statutory exclusions for hyperlinks and very short extracts and a mandatory 25 or 15 percent share of the publisher's revenue owed to the journalists whose work is included.

The same Law 4996/2022 inserted Articles 21A and 21B into Law 2121/1993, giving research organisations and cultural-heritage institutions a non-waivable text-and-data-mining exception for scientific research, and giving everyone else a general text-and-data-mining exception over lawfully accessible content that a rightholder may defeat with a machine-readable reservation.

No compelled platform-to-publisher bargaining regime comparable to Australia's News Media Bargaining Code or Canada's Online News Act was found. Whether a hyperlink or an inline display of a press publication is itself a communication to the public, and whether a hot-news or misappropriation doctrine survives alongside these statutes, remain open questions under Greek law.

Press publishers' right

Law 2121/1993 Article 51B, Press Publisher Neighbouring Right

Law 2121/1993, art. 51B, as inserted by Law 4996/2022, art. 17 (FEK A' 215/22-11-2022)The Government's bill for Law 4996/2022

In force since 22 November 2022. Binds private bodies.

What this law does

A press publisher established in an EU member state has the exclusive right to authorise or prohibit the online reproduction, in whole or in part, and the making available to the public of its press publications by an information-society-service provider, under new Article 51B of Law 2121/1993.

The right excludes private or non-commercial use by individual users, hyperlinking, and the use of single words or very short extracts whose use does not harm the publisher's investment, and it does not affect the rights of the authors and other rightholders whose works are incorporated in the press publication. The right lasts two years from the first of January following the press publication's publication date.

Publishers owe the journalists who created the incorporated works a share of the annual revenue the publisher earns from information-society-service providers for the use of its press publications, set at 25 percent for a publisher whose enterprise employs fewer than 60 percent of its journalists under a subordinate employment contract, and 15 percent for a publisher above that threshold; this journalist share is non-assignable other than to a collective-management organisation, and a contrary contractual term is void.

Note and primary source

Text and data mining (TDM) opt-out

Law 2121/1993 Articles 21A-21B, Text and Data Mining Exception

Law 2121/1993, arts. 21A-21B, as inserted by Law 4996/2022, arts. 8-9 (FEK A' 215/22-11-2022)The Government's bill for Law 4996/2022

In force since 22 November 2022. Binds public and private bodies.

What this law does

Article 21A permits a research organisation or cultural-heritage institution to reproduce a work or other protected subject matter it lawfully accesses for the purpose of text and data mining for scientific research, without a rightholder opt-out, and any contrary contractual term is void.

Article 21B gives anyone else the same reproduction and extraction permission over lawfully accessible works and other material for the purpose of text and data mining, but only where the rightholder has not expressly reserved that use in an appropriate manner, such as machine-readable means for content made publicly available online; copies made under either article may be retained only as long as the mining purpose requires.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.