Greece Law 4624/2019 - Hellenic Data Protection Authority (HDPA) Implementation Act
Evidence request list. 12 controls, 12 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Greece Law 4624/2019: 2024-2025 Pipeline, NIS2 + DORA + AI Act + Data Act + EDPB Coordination + EU Adequacy
Greece Law 4624/2019 2024-2025 regulatory pipeline + EU integration. NIS2 TRANSPOSITION (deadline 17 October 2024 + Greek law expected 2024-2025): Directive (EU) 2022/2555 NIS2 transposition into Greek law expanding cybersecurity scope from NIS1 to 18 critical sectors covering ~5,000+ Greek entities; enhanced security measures + supply chain security + ICT-related incident notification (24-hour early warning + 72-hour notification + 1-month final report); executive accountability + GREEK NCSA enforcement; coordinates with Greek Cybersecurity Authority + HDPA on personal data breach notifications. DORA TRANSPOSITION (Regulation (EU) 2022/2554 - directly applicable 17 January 2025): Digital Operational Resilience Act for financial entities + ICT risk management + ICT third-party risk + cyber incident reporting + digital operational resilience testing + Greek financial-services sectoral imp
- Pipeline-tracking + implementation roadmap
- Sectoral compliance per regulation
- HDPA enforcement-history monitoring
- Cross-border transfer mechanisms
- Pipeline not tracked
- Sectoral readiness gaps
- HDPA monitoring absent
- Cross-border transfers ad-hoc
Greece Law 4624/2019 implementation roadmap. ORGANIZATIONAL ROLES: (a) DATA PROTECTION OFFICER (DPO) - mandatory for public authorities + bodies with large-scale processing of special category data + criminal data + systematic monitoring (Greek Article 6); independent + reports to top management + HDPA-notified + adequate qualifications + resources; many Greek companies appoint outsourced/shared DPO; (b) PRIVACY OFFICER + COMPLIANCE OFFICER - operational; (c) LEGAL - HDPA cooperation + statutory interpretation + breach response; (d) CISO + INFOSEC - GDPR Art. 32 security + NIS2 + DORA security; (e) HR - employee data + Article 27 compliance + workplace monitoring + employee rights; (f) MARKETING + COMMUNICATIONS - consent + transparency + opt-out + e-marketing rules per ePrivacy Law 3471/2006; (g) IT + ENGINEERING - privacy-by-design + privacy-by-default + DPIA + technical security; (h)
- Role inventory + RACI + DPO designation
- Tooling adoption
- Metrics + management review
- Annual cycle documentation
- Roles undefined
- Tooling fragmented
- Metrics gaps
- Annual cycle ad-hoc
Greece Law 4624/2019 sectoral application. BANKING + FINANCIAL SERVICES: Bank of Greece supervisory authority + HDPA joint enforcement; specific guidance on AML + KYC + credit-reporting + collections + customer data; DORA transposition 2025; PSD2 + Open Banking + Greek payment services; Stricter penalties for financial-sector breaches. TELECOMMUNICATIONS: EETT (Hellenic Telecommunications + Post Commission) sectoral authority + HDPA cooperation; ePrivacy Law 3471/2006 implementation including cookies + caller ID + emergency services + lawful interception + traffic + location data + direct marketing. HEALTHCARE: Ministry of Health + EOPYY (National Healthcare Organization) + HDPA + medical confidentiality (medical privilege) + Greek Medical Code + e-prescription system + electronic health records + HIE coordination + biobanks + research processing + clinical trial regulation. INSURANCE: B
- Sectoral compliance program per industry
- Sectoral regulator engagement
- Article-specific compliance evidence
- Sectoral compliance fragmented
- Regulator coordination weak
- Article-specific gaps
Greece Law 4624/2019 status + HDPA enforcement + adequacy + 2025+ European governance. HDPA ENFORCEMENT 2023-2025: numerous GDPR fines including major bank fines + telecom + retailer + healthcare + public sector enforcement; rising enforcement intensity + EDPB cooperation + cross-border one-stop-shop participation; significant cases on AI + cookies + employee monitoring + biometric data + retention + transparency. RECENT NOTABLE HDPA ACTIONS: (a) banking-sector fines for credit-data + customer profiling violations; (b) telecom fines for marketing without consent + data retention; (c) healthcare-sector fines for biometric + health-data breaches; (d) public-sector data leaks + HDPA enforcement against public bodies; (e) airline + tourism sector fines for cross-border transfers + customer data. EDPB COORDINATION: HDPA actively participates in EDPB plenaries + Working Groups + cross-border e
- Enforcement-history monitoring
- EDPB engagement evidence
- Cross-border transfer mechanisms + TIAs
- Regulatory pipeline tracking
- Enforcement monitoring absent
- EDPB engagement weak
- Cross-border TIAs missing
- Regulatory pipeline not tracked
Greece Law 4624/2019: Chapter A - General Provisions, Scope, Greek-Specific Lawful Bases
Greece Law 4624/2019 Chapter A - General Provisions (Articles 1-4). SCOPE: applies to processing of personal data by public + private bodies in Greece + extra-territorial application per GDPR Article 3 + supplements GDPR + transposes LEDP. DEFINITIONS: aligns with GDPR Article 4 definitions + adds Greek-specific terms (e.g. Hellenic Data Protection Authority + Greek tax identification number AFM + social security identification AMKA). LAWFUL BASIS: (a) per GDPR Art. 6(1) - consent + contract + legal obligation + vital interests + public task + legitimate interest; (b) GREEK-SPECIFIC LAWFUL BASES under Article 6(1)(e) (public interest + official authority) include processing by public authorities for specific Greek statutory functions; (c) processing in employment context with employee consent rebuttable + employee personal data processing restrictions under Article 27. UNIQUE IDENTIFICAT
- Lawful basis assessment + documentation
- AFM/AMKA processing necessity + proportionality
- Special category data lawful basis + DPIA
- Lawful basis unclear
- AFM/AMKA processing without basis
- Special category data DPIA gaps
Greece Law 4624/2019: Chapter B - Hellenic Data Protection Authority (HDPA) Structure, Powers and Procedures
Greece Law 4624/2019 Chapter B - Hellenic Data Protection Authority (HDPA) governance. HDPA (Arhi Prostasias Dedomenon Prosopikou Charaktira) - independent Greek supervisory authority + constitutional body established by Law 2472/1997 + continued under Law 4624/2019 + Article 9A of the Greek Constitution. STRUCTURE: 9-member Board (President + Vice-President + 7 members) appointed by Greek Parliament with 4-year terms + independence guarantees + budget independence. POWERS: (a) investigative + audit + on-site inspection + document production + statement-taking; (b) corrective + warning + reprimand + order to comply + processing limitation + suspension + erasure + ban; (c) authorisation + accreditation of codes of conduct + certification bodies; (d) advisory + consultation + opinion + guidance + public awareness; (e) collaborative + EDPB + EDPS + GPEN + ICO + CNIL + other DPAs; (f) sancti
- HDPA cooperation evidence
- Complaint handling procedure
- Documented investigation responses
- HDPA cooperation absent
- Complaint procedure missing
- Investigation responses inadequate
Greece Law 4624/2019: Chapter C - GDPR Implementation Provisions (Sensitive Data, Employee, Children Age 15, Special Processing)
Greece Law 4624/2019 Chapter C - GDPR implementation specifics. CHILDREN AGE OF CONSENT (Article 21): age of consent for information society services set at 15 YEARS OLD (lower than GDPR default 16; using GDPR Art. 8(1) derogation); below 15 requires parental/guardian consent + verification mechanisms. EMPLOYEE PERSONAL DATA PROCESSING (Article 27): specific rules for employment context including (a) consent rebuttable + presumption against consent as lawful basis due to employer-employee power imbalance; (b) limited monitoring + transparency + necessity + proportionality; (c) biometric + genetic + health data restrictions; (d) background check + criminal record processing rules; (e) employee monitoring + electronic-communication surveillance restrictions; (f) data minimisation in employment lifecycle. PROCESSING FOR ARCHIVING + SCIENTIFIC RESEARCH + STATISTICAL PURPOSES (Article 30): sp
- Child-consent verification
- Employee processing notice + restrictions
- Research-archive DPIA
- Journalistic balancing-test
- DPO appointment + notification to HDPA
- Child-consent verification weak
- Employee monitoring without basis
- Research DPIA absent
- DPO not appointed
Greece Law 4624/2019 operational provisions covering Data Subject Rights + Breach + DPIA + Transfers + Children. DATA SUBJECT RIGHTS (per GDPR Art. 12-22 + Greek Articles 28-35): access + rectification + erasure + restriction + portability + objection + ADM/profiling; 30-day SLA + 60-day extension for complex requests; identity verification; Greek-language + accessible response format; HDPA escalation if denied. BREACH NOTIFICATION (Art. 33 GDPR + Greek Article 33): 72-hour notification to HDPA from awareness; risk-assessment + remediation + affected-data-subject notification if high risk; breach register + records + lessons-learned. DPIA (Art. 35 GDPR + Greek Article 33): mandatory for high-risk processing including (a) systematic + extensive evaluation (profiling); (b) special category large-scale; (c) public-area systematic monitoring; (d) new technologies; (e) HDPA prior consultation
- DSR procedure + Greek-language templates
- Breach response procedure + register
- DPIA library + HDPA consultations
- Transfer mechanism evidence + TIAs
- DSR turnaround poor
- Breach 72-hour SLA missed
- DPIA library missing
- Transfer mechanisms inadequate
Greece Law 4624/2019: Chapter D - LEDP Implementation (Directive (EU) 2016/680 for Law Enforcement)
Greece Law 4624/2019 Chapter D - implementation of EU LEDP Directive 2016/680 (Law Enforcement Data Protection Directive) into Greek law for processing by competent authorities for purposes of preventing + investigating + prosecuting criminal offences + executing criminal penalties + safeguarding against public security threats. COMPETENT AUTHORITIES: Hellenic Police + Hellenic Coast Guard + Greek Prosecutors + Courts + Greek National Intelligence Service (EYP) + Hellenic Anti-Corruption Authority + AADE Tax Authority (in specific criminal-investigation contexts) + Customs + Greek Financial Crimes Investigation. KEY LEDP PROVISIONS: (a) lawful basis restricted to criminal-law-enforcement-purposes + statutory + necessary + proportionate; (b) data subject rights similar to GDPR but with criminal-investigation restrictions + delayed/restricted notifications when prejudicial to ongoing inves
- LEDP-specific compliance documentation
- Restricted DSR procedures
- Europol + INTERPOL cooperation evidence
- LEDP scope unclear
- DSR restrictions over-applied
- Cross-border transfers without basis
Greece Law 4624/2019: Chapter E - Administrative Sanctions, Criminal Offences, Civil Liability
Greece Law 4624/2019 Chapter E - sanctions + final provisions. ADMINISTRATIVE FINES (Article 68): HDPA may impose fines up to GDPR maximums of EUR 20 MILLION or 4 PERCENT global annual turnover (whichever higher) for serious violations + GDPR Art. 83(5) violations; for lesser violations + GDPR Art. 83(4) maximum EUR 10 MILLION or 2 PERCENT global annual turnover. Public bodies subject to administrative fines too (with limits). PROPORTIONALITY + MITIGATION + AGGRAVATION factors per GDPR Art. 83(2) applied. CRIMINAL OFFENCES (Article 38): criminal sanctions for (a) unauthorised access to personal data; (b) unauthorised processing of sensitive categories; (c) breach of confidentiality + secrecy obligations; (d) destruction/alteration of personal data with intent to damage; (e) misuse for unauthorised purposes; (f) failure to comply with HDPA orders; penalties include imprisonment up to 5 ye
- Sanctions risk assessment + insurance
- Criminal-offence compliance program
- Civil-action defense + DPIA evidence
- Sanctions risk underestimated
- Criminal-offence compliance gaps
- Civil-action defense unprepared
Greece Law 4624/2019: Coordination with Greek Constitution Art. 9A, ePrivacy Law 3471/2006, NIS2, Whistleblower Law 4990/2022
Greece Law 4624/2019 coordination with adjacent Greek + EU statutes. GREEK CONSTITUTION ARTICLE 9A (2001 amendment): right to protection of personal data; constitutional foundation for Greek DP regime + HDPA independence. GREEK CONSTITUTION ARTICLES 9 (right to privacy + private life + correspondence) + 19 (secrecy of letters + free communications + provider obligations). ePRIVACY LAW 3471/2006: transposes EU Directive 2002/58/EC (ePrivacy Directive) on processing of personal data + protection of privacy in electronic communications sector; covers cookies + direct marketing + electronic communications + location data + caller ID + emergency services. GREEK WHISTLEBLOWER LAW 4990/2022 (transposing EU Directive 2019/1937): protections for reporting persons + obligation on public + private legal persons to establish reporting channels + retaliation prohibition + Whistleblower Officer + reme
- Multi-statute compliance program
- Sectoral compliance evidence
- NIS2 + DORA readiness
- Whistleblower channel + DP coordination
- Multi-statute coordination gaps
- Sectoral compliance fragmented
- NIS2 + DORA readiness gap
Greece Law 4624/2019 crosswalk to adjacent EU + Member State frameworks. EU GDPR + LEDP: Law 4624/2019 transposes/implements both directly; Greek-specific provisions supplement + do not override GDPR core. EU MEMBER STATE GDPR IMPLEMENTATIONS: Germany BDSG-neu + France Loi Informatique et Libertés + UK GDPR + Spain LOPDGDD + Italy DLgs 196/2003 (modified) + Netherlands UAVG + Belgium Cadre Loi + Sweden Dataskyddslagen + Denmark Databeskyttelsesloven + Austria DSG + Poland UODO + Finland Tietosuojalaki (separately verified in this corpus) + Estonia EPDPA + Latvia DPL + Lithuania DPA + Czech ZZOOU + Slovak ZOOU + Slovenia ZVOP + Croatia ZPP + Hungary Info Act + Romania Legea 190 + Bulgaria ZBPD + Cyprus DP Law + Malta DPA + Luxembourg DPA + Portugal LRGPD + Ireland DPA 2018 - parallel Member State national supplements + each with adequate level + national variations in child consent (13-16
- Multi-jurisdictional compliance program
- EU + Member State crosswalk documentation
- Schrems II + adequacy compliance
- Multi-jurisdictional gaps
- Member-state crosswalk missing
- Schrems II readiness gap
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.