Skip to content

Evidence request lists

Greece Law 4624/2019 - Hellenic Data Protection Authority (HDPA) Implementation Act

Evidence request list. 12 controls, 12 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Greece Law 4624/2019: 2024-2025 Pipeline, NIS2 + DORA + AI Act + Data Act + EDPB Coordination + EU Adequacy

GR-DPA-2024-2025-Pipeline-NIS2-DORA-AIAct-DataAct
Greece Law 4624/2019 2024-2025 Pipeline - NIS2 + DORA + AI Act + Data Act + EDPB Coordination

Greece Law 4624/2019 2024-2025 regulatory pipeline + EU integration. NIS2 TRANSPOSITION (deadline 17 October 2024 + Greek law expected 2024-2025): Directive (EU) 2022/2555 NIS2 transposition into Greek law expanding cybersecurity scope from NIS1 to 18 critical sectors covering ~5,000+ Greek entities; enhanced security measures + supply chain security + ICT-related incident notification (24-hour early warning + 72-hour notification + 1-month final report); executive accountability + GREEK NCSA enforcement; coordinates with Greek Cybersecurity Authority + HDPA on personal data breach notifications. DORA TRANSPOSITION (Regulation (EU) 2022/2554 - directly applicable 17 January 2025): Digital Operational Resilience Act for financial entities + ICT risk management + ICT third-party risk + cyber incident reporting + digital operational resilience testing + Greek financial-services sectoral imp

Artefacts an auditor will ask for
  • Pipeline-tracking + implementation roadmap
  • Sectoral compliance per regulation
  • HDPA enforcement-history monitoring
  • Cross-border transfer mechanisms
Where this commonly fails
  • Pipeline not tracked
  • Sectoral readiness gaps
  • HDPA monitoring absent
  • Cross-border transfers ad-hoc
GR-DPA-Implementation-Roles-DPO-Sectoral
Greece Law 4624/2019 Implementation Roadmap, Organizational Roles, DPO and Sectoral Application

Greece Law 4624/2019 implementation roadmap. ORGANIZATIONAL ROLES: (a) DATA PROTECTION OFFICER (DPO) - mandatory for public authorities + bodies with large-scale processing of special category data + criminal data + systematic monitoring (Greek Article 6); independent + reports to top management + HDPA-notified + adequate qualifications + resources; many Greek companies appoint outsourced/shared DPO; (b) PRIVACY OFFICER + COMPLIANCE OFFICER - operational; (c) LEGAL - HDPA cooperation + statutory interpretation + breach response; (d) CISO + INFOSEC - GDPR Art. 32 security + NIS2 + DORA security; (e) HR - employee data + Article 27 compliance + workplace monitoring + employee rights; (f) MARKETING + COMMUNICATIONS - consent + transparency + opt-out + e-marketing rules per ePrivacy Law 3471/2006; (g) IT + ENGINEERING - privacy-by-design + privacy-by-default + DPIA + technical security; (h)

Artefacts an auditor will ask for
  • Role inventory + RACI + DPO designation
  • Tooling adoption
  • Metrics + management review
  • Annual cycle documentation
Where this commonly fails
  • Roles undefined
  • Tooling fragmented
  • Metrics gaps
  • Annual cycle ad-hoc
GR-DPA-Sectoral-Banking-Telecom-Healthcare-PublicSector
Greece Law 4624/2019 Sectoral Application: Banking, Telecoms, Healthcare, Public Sector, Insurance

Greece Law 4624/2019 sectoral application. BANKING + FINANCIAL SERVICES: Bank of Greece supervisory authority + HDPA joint enforcement; specific guidance on AML + KYC + credit-reporting + collections + customer data; DORA transposition 2025; PSD2 + Open Banking + Greek payment services; Stricter penalties for financial-sector breaches. TELECOMMUNICATIONS: EETT (Hellenic Telecommunications + Post Commission) sectoral authority + HDPA cooperation; ePrivacy Law 3471/2006 implementation including cookies + caller ID + emergency services + lawful interception + traffic + location data + direct marketing. HEALTHCARE: Ministry of Health + EOPYY (National Healthcare Organization) + HDPA + medical confidentiality (medical privilege) + Greek Medical Code + e-prescription system + electronic health records + HIE coordination + biobanks + research processing + clinical trial regulation. INSURANCE: B

Artefacts an auditor will ask for
  • Sectoral compliance program per industry
  • Sectoral regulator engagement
  • Article-specific compliance evidence
Where this commonly fails
  • Sectoral compliance fragmented
  • Regulator coordination weak
  • Article-specific gaps
GR-DPA-Status-HDPA-Enforcement-Adequacy-EuropeanGovernance
Greece Law 4624/2019 Status, HDPA Enforcement, EU Adequacy and 2025+ European Governance

Greece Law 4624/2019 status + HDPA enforcement + adequacy + 2025+ European governance. HDPA ENFORCEMENT 2023-2025: numerous GDPR fines including major bank fines + telecom + retailer + healthcare + public sector enforcement; rising enforcement intensity + EDPB cooperation + cross-border one-stop-shop participation; significant cases on AI + cookies + employee monitoring + biometric data + retention + transparency. RECENT NOTABLE HDPA ACTIONS: (a) banking-sector fines for credit-data + customer profiling violations; (b) telecom fines for marketing without consent + data retention; (c) healthcare-sector fines for biometric + health-data breaches; (d) public-sector data leaks + HDPA enforcement against public bodies; (e) airline + tourism sector fines for cross-border transfers + customer data. EDPB COORDINATION: HDPA actively participates in EDPB plenaries + Working Groups + cross-border e

Artefacts an auditor will ask for
  • Enforcement-history monitoring
  • EDPB engagement evidence
  • Cross-border transfer mechanisms + TIAs
  • Regulatory pipeline tracking
Where this commonly fails
  • Enforcement monitoring absent
  • EDPB engagement weak
  • Cross-border TIAs missing
  • Regulatory pipeline not tracked

Greece Law 4624/2019: Chapter A - General Provisions, Scope, Greek-Specific Lawful Bases

GR-DPA-ChapterA-Scope-LawfulBasis-Defs
Greece Law 4624/2019 Chapter A - General Provisions, Scope, Definitions and Greek-Specific Lawful Bases

Greece Law 4624/2019 Chapter A - General Provisions (Articles 1-4). SCOPE: applies to processing of personal data by public + private bodies in Greece + extra-territorial application per GDPR Article 3 + supplements GDPR + transposes LEDP. DEFINITIONS: aligns with GDPR Article 4 definitions + adds Greek-specific terms (e.g. Hellenic Data Protection Authority + Greek tax identification number AFM + social security identification AMKA). LAWFUL BASIS: (a) per GDPR Art. 6(1) - consent + contract + legal obligation + vital interests + public task + legitimate interest; (b) GREEK-SPECIFIC LAWFUL BASES under Article 6(1)(e) (public interest + official authority) include processing by public authorities for specific Greek statutory functions; (c) processing in employment context with employee consent rebuttable + employee personal data processing restrictions under Article 27. UNIQUE IDENTIFICAT

Artefacts an auditor will ask for
  • Lawful basis assessment + documentation
  • AFM/AMKA processing necessity + proportionality
  • Special category data lawful basis + DPIA
Where this commonly fails
  • Lawful basis unclear
  • AFM/AMKA processing without basis
  • Special category data DPIA gaps

Greece Law 4624/2019: Chapter B - Hellenic Data Protection Authority (HDPA) Structure, Powers and Procedures

GR-DPA-ChapterB-HDPA-Structure-Powers
Greece Law 4624/2019 Chapter B - Hellenic Data Protection Authority (HDPA) Structure, Powers and Procedures

Greece Law 4624/2019 Chapter B - Hellenic Data Protection Authority (HDPA) governance. HDPA (Arhi Prostasias Dedomenon Prosopikou Charaktira) - independent Greek supervisory authority + constitutional body established by Law 2472/1997 + continued under Law 4624/2019 + Article 9A of the Greek Constitution. STRUCTURE: 9-member Board (President + Vice-President + 7 members) appointed by Greek Parliament with 4-year terms + independence guarantees + budget independence. POWERS: (a) investigative + audit + on-site inspection + document production + statement-taking; (b) corrective + warning + reprimand + order to comply + processing limitation + suspension + erasure + ban; (c) authorisation + accreditation of codes of conduct + certification bodies; (d) advisory + consultation + opinion + guidance + public awareness; (e) collaborative + EDPB + EDPS + GPEN + ICO + CNIL + other DPAs; (f) sancti

Artefacts an auditor will ask for
  • HDPA cooperation evidence
  • Complaint handling procedure
  • Documented investigation responses
Where this commonly fails
  • HDPA cooperation absent
  • Complaint procedure missing
  • Investigation responses inadequate

Greece Law 4624/2019: Chapter C - GDPR Implementation Provisions (Sensitive Data, Employee, Children Age 15, Special Processing)

GR-DPA-ChapterC-GDPR-Implementation-Employee-Children-Special
Greece Law 4624/2019 Chapter C - GDPR Implementation Provisions (Children Age 15, Employee Data, Special Processing)

Greece Law 4624/2019 Chapter C - GDPR implementation specifics. CHILDREN AGE OF CONSENT (Article 21): age of consent for information society services set at 15 YEARS OLD (lower than GDPR default 16; using GDPR Art. 8(1) derogation); below 15 requires parental/guardian consent + verification mechanisms. EMPLOYEE PERSONAL DATA PROCESSING (Article 27): specific rules for employment context including (a) consent rebuttable + presumption against consent as lawful basis due to employer-employee power imbalance; (b) limited monitoring + transparency + necessity + proportionality; (c) biometric + genetic + health data restrictions; (d) background check + criminal record processing rules; (e) employee monitoring + electronic-communication surveillance restrictions; (f) data minimisation in employment lifecycle. PROCESSING FOR ARCHIVING + SCIENTIFIC RESEARCH + STATISTICAL PURPOSES (Article 30): sp

Artefacts an auditor will ask for
  • Child-consent verification
  • Employee processing notice + restrictions
  • Research-archive DPIA
  • Journalistic balancing-test
  • DPO appointment + notification to HDPA
Where this commonly fails
  • Child-consent verification weak
  • Employee monitoring without basis
  • Research DPIA absent
  • DPO not appointed
GR-DPA-DataSubjectRights-Breach-DPIA-Transfers-Children
Greece Law 4624/2019 Data Subject Rights, Breach Notification, DPIA, International Transfers and Children's Data

Greece Law 4624/2019 operational provisions covering Data Subject Rights + Breach + DPIA + Transfers + Children. DATA SUBJECT RIGHTS (per GDPR Art. 12-22 + Greek Articles 28-35): access + rectification + erasure + restriction + portability + objection + ADM/profiling; 30-day SLA + 60-day extension for complex requests; identity verification; Greek-language + accessible response format; HDPA escalation if denied. BREACH NOTIFICATION (Art. 33 GDPR + Greek Article 33): 72-hour notification to HDPA from awareness; risk-assessment + remediation + affected-data-subject notification if high risk; breach register + records + lessons-learned. DPIA (Art. 35 GDPR + Greek Article 33): mandatory for high-risk processing including (a) systematic + extensive evaluation (profiling); (b) special category large-scale; (c) public-area systematic monitoring; (d) new technologies; (e) HDPA prior consultation

Artefacts an auditor will ask for
  • DSR procedure + Greek-language templates
  • Breach response procedure + register
  • DPIA library + HDPA consultations
  • Transfer mechanism evidence + TIAs
Where this commonly fails
  • DSR turnaround poor
  • Breach 72-hour SLA missed
  • DPIA library missing
  • Transfer mechanisms inadequate

Greece Law 4624/2019: Chapter D - LEDP Implementation (Directive (EU) 2016/680 for Law Enforcement)

GR-DPA-ChapterD-LEDP-LawEnforcement
Greece Law 4624/2019 Chapter D - LEDP Implementation (Directive (EU) 2016/680 for Law Enforcement)

Greece Law 4624/2019 Chapter D - implementation of EU LEDP Directive 2016/680 (Law Enforcement Data Protection Directive) into Greek law for processing by competent authorities for purposes of preventing + investigating + prosecuting criminal offences + executing criminal penalties + safeguarding against public security threats. COMPETENT AUTHORITIES: Hellenic Police + Hellenic Coast Guard + Greek Prosecutors + Courts + Greek National Intelligence Service (EYP) + Hellenic Anti-Corruption Authority + AADE Tax Authority (in specific criminal-investigation contexts) + Customs + Greek Financial Crimes Investigation. KEY LEDP PROVISIONS: (a) lawful basis restricted to criminal-law-enforcement-purposes + statutory + necessary + proportionate; (b) data subject rights similar to GDPR but with criminal-investigation restrictions + delayed/restricted notifications when prejudicial to ongoing inves

Artefacts an auditor will ask for
  • LEDP-specific compliance documentation
  • Restricted DSR procedures
  • Europol + INTERPOL cooperation evidence
Where this commonly fails
  • LEDP scope unclear
  • DSR restrictions over-applied
  • Cross-border transfers without basis

Greece Law 4624/2019: Chapter E - Administrative Sanctions, Criminal Offences, Civil Liability

GR-DPA-ChapterE-Sanctions-Criminal-CivilLiability
Greece Law 4624/2019 Chapter E - Administrative Sanctions, Criminal Offences and Civil Liability

Greece Law 4624/2019 Chapter E - sanctions + final provisions. ADMINISTRATIVE FINES (Article 68): HDPA may impose fines up to GDPR maximums of EUR 20 MILLION or 4 PERCENT global annual turnover (whichever higher) for serious violations + GDPR Art. 83(5) violations; for lesser violations + GDPR Art. 83(4) maximum EUR 10 MILLION or 2 PERCENT global annual turnover. Public bodies subject to administrative fines too (with limits). PROPORTIONALITY + MITIGATION + AGGRAVATION factors per GDPR Art. 83(2) applied. CRIMINAL OFFENCES (Article 38): criminal sanctions for (a) unauthorised access to personal data; (b) unauthorised processing of sensitive categories; (c) breach of confidentiality + secrecy obligations; (d) destruction/alteration of personal data with intent to damage; (e) misuse for unauthorised purposes; (f) failure to comply with HDPA orders; penalties include imprisonment up to 5 ye

Artefacts an auditor will ask for
  • Sanctions risk assessment + insurance
  • Criminal-offence compliance program
  • Civil-action defense + DPIA evidence
Where this commonly fails
  • Sanctions risk underestimated
  • Criminal-offence compliance gaps
  • Civil-action defense unprepared

Greece Law 4624/2019: Coordination with Greek Constitution Art. 9A, ePrivacy Law 3471/2006, NIS2, Whistleblower Law 4990/2022

GR-DPA-Coordination-Constitution-ePrivacy-NIS2-Whistleblower
Greece Law 4624/2019 Coordination with Greek Constitution Art. 9A, ePrivacy Law 3471/2006, NIS2, Whistleblower Law 4990/2022

Greece Law 4624/2019 coordination with adjacent Greek + EU statutes. GREEK CONSTITUTION ARTICLE 9A (2001 amendment): right to protection of personal data; constitutional foundation for Greek DP regime + HDPA independence. GREEK CONSTITUTION ARTICLES 9 (right to privacy + private life + correspondence) + 19 (secrecy of letters + free communications + provider obligations). ePRIVACY LAW 3471/2006: transposes EU Directive 2002/58/EC (ePrivacy Directive) on processing of personal data + protection of privacy in electronic communications sector; covers cookies + direct marketing + electronic communications + location data + caller ID + emergency services. GREEK WHISTLEBLOWER LAW 4990/2022 (transposing EU Directive 2019/1937): protections for reporting persons + obligation on public + private legal persons to establish reporting channels + retaliation prohibition + Whistleblower Officer + reme

Artefacts an auditor will ask for
  • Multi-statute compliance program
  • Sectoral compliance evidence
  • NIS2 + DORA readiness
  • Whistleblower channel + DP coordination
Where this commonly fails
  • Multi-statute coordination gaps
  • Sectoral compliance fragmented
  • NIS2 + DORA readiness gap
GR-DPA-Crosswalk-EU-Adjacent-MemberStates
Greece Law 4624/2019 Crosswalk to GDPR, LEDP, EU Adjacent Frameworks and Member State Implementations

Greece Law 4624/2019 crosswalk to adjacent EU + Member State frameworks. EU GDPR + LEDP: Law 4624/2019 transposes/implements both directly; Greek-specific provisions supplement + do not override GDPR core. EU MEMBER STATE GDPR IMPLEMENTATIONS: Germany BDSG-neu + France Loi Informatique et Libertés + UK GDPR + Spain LOPDGDD + Italy DLgs 196/2003 (modified) + Netherlands UAVG + Belgium Cadre Loi + Sweden Dataskyddslagen + Denmark Databeskyttelsesloven + Austria DSG + Poland UODO + Finland Tietosuojalaki (separately verified in this corpus) + Estonia EPDPA + Latvia DPL + Lithuania DPA + Czech ZZOOU + Slovak ZOOU + Slovenia ZVOP + Croatia ZPP + Hungary Info Act + Romania Legea 190 + Bulgaria ZBPD + Cyprus DP Law + Malta DPA + Luxembourg DPA + Portugal LRGPD + Ireland DPA 2018 - parallel Member State national supplements + each with adequate level + national variations in child consent (13-16

Artefacts an auditor will ask for
  • Multi-jurisdictional compliance program
  • EU + Member State crosswalk documentation
  • Schrems II + adequacy compliance
Where this commonly fails
  • Multi-jurisdictional gaps
  • Member-state crosswalk missing
  • Schrems II readiness gap
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.