On 29/08/2019, Greece adopted the Data Protection Act 4624/2019, following the threat of sanctions by the European Commission. This law shows strong influences from the German Bundesdatenschutzgesetz (BDSG). These influences are, for example, evident in the regulations on special categories of personal data and in employee data protection. However, the Greek data protection law also contains further deviations resulting from making use of various opening clauses of the GDPR that are not found in the German BDSG. These include, for example, the consent of minors and the further requirements for the record of processing activities.
The Greek Data Protection Act is divided into five chapters:
- Chapter 1 – General Provisions
- Chapter 2 – Supervisory Authority
- Chapter 3 – Supplementary measures for the implementation of the GDPR
- Chapter 4 – Implementation of the Directive (2016/680).
- Chapter 5 – Final Provisions
Below you will find the additions and derogations from the GDPR on the most important topics of data protection that companies need to know. If topics are not linked, there are no derogating provisions in national data protection law
- Specific data protection law and official guidelines
- Substantive and territorial scope (no regulations deviating from the GDPR)
- Definitions
- Legal principles (no regulations deviating from the GDPR)
- Legal basis under Greek data protection law
- Sensitive data in Greek data protection law
- Informing requirements under Greek data protection law
- E-marketing (new regulation by ePrivacy Regulation remains to be seen)
- Cookies (no regulations deviating from the GDPR)
- Automated decision-making under Greek data protection law
- Data subjects’ rights under Greek data protection law
- Processing on behalf of a controller (no regulations deviating from the GDPR)
- Records of processing activities under Greek data protection law
- Data security (no regulations deviating from the GDPR)
- Data breaches (no regulations deviating from the GDPR)
- Data protection impact assessment (DPIA) under Greek law
- Data protection officer under Greek law
- Certification (no regulations deviating from the GDPR)
- Data transfer (no regulations deviating from the GDPR)
- Supervisory authorities under Greek data protection law
- Sanctions and penalties under Greek data protection law
- Data protection for employees under Greek law
- Archiving, scientific and historical research under Greek data protection law