This section sets out the legislation governing the protection of personal data at national and European level, artificial intelligence, and other areas in which the Authority has supervisory responsibilities, such as the single market for digital services and the transparency and targeting of political advertising.
Legislation on the protection of personal data includes the General Data Protection Regulation (EU) 2016/679 (GDPR), Law 4624/2019 (Law 4624/2019 in Greek with all amendments incorporated), Law 2472/1997 and Law 3471/2006 in the field of electronic communications.
In particular, the GDPR entered into force on 25 May 2018, in accordance with Article 99(2) thereof. According to Article 288 of the Treaty on the Functioning of the European Union (TFEU), the GDPR is directly applicable in all Member States, which are obliged to take the necessary measures to adapt their national legislation.
Law 4624/2019 (Government Gazette, Series I, No 137) lays down implementing measures for the GDPR and transposes Directive (EU) 2016/680 into national law. Law 2472/1997 was repealed, except for the provisions expressly referred to in Article 84 of Law 4624/2019.
Law 3471/2006, which transposes Directive 2002/58/EC (e-Privacy Directive), as amended by Directive 2009/136/EC, complements and specifies the institutional framework for the protection of personal data in the electronic communications sector.
European legislation on the protection of personal data includes Article F of the Treaty on European Union, Article 8 of the Charter of Fundamental Rights of the European Union, Article 8 of the European Convention on Human Rights, Council of Europe Convention 108 and its update.
This section also lists the Authority’s regulatory acts and guidance.
Additionally, with Law 5321/2026 (‘Measures implementing Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 (Regulation on Artificial Intelligence) – Amendment to Law 4961/2022 (Government Gazette, Series I, Νο 146) and other provisions’) the Authority assumes a central role acting, inter alia:
-
as the competent market surveillance authority for AI systems falling under the prohibited practices of the Regulation, high-risk AI systems listed in Annex III, and AI systems subject to the transparency obligations set out in Article 50 of the Regulation;
-
as the single point of contact for Greece with the European Commission and the respective national authorities;
-
as the competent authority for receiving and handling complaints concerning infringements of the Regulation;
-
as a notified body for the conformity assessment of certain high-risk AI systems, and
-
together with the Hellenic Telecommunications and Post Commission (EETT), as the competent authority for the operation of the national Artificial Intelligence regulatory sandbox (AI Sandbox).
At European level, the legal framework is complemented by Regulation (EU) 2026/1744, which amends and simplifies certain provisions of Regulation (EU) 2024/1689 (AI Act), including provisions concerning the application and supervision of the rules on Artificial Intelligence.
Furthermore, Article 5 of Law 5099/2024, which lays down measures for the implementation of Regulation (EU) 2022/2065 of the European Parliament and of the Council of 19 October 2022 on a Single Market for Digital Services (Digital Services Act), designates the Data Protection Authority as the competent authority for the supervision of providers of intermediary services and for the enforcement of Article 26(1)(d) and (3) (concerning information provided to users on the display and targeting of advertisements) and Article 28 (concerning the protection of minors) of that Regulation.
Pursuant to Article 23(5) of Law 5099/2024, Joint Decision No. 1/2024 (Government Gazette, Series II, No. 4593/07.08.2024) of the Hellenic Telecommunications and Post Commission (EETT), as Digital Services Coordinator pursuant to Article 4 of Law 5099/2024, the Data Protection Authority and the National Council for Radio and Television (ESR), both as competent authorities pursuant to Article 5 of Law 5099/2024, was adopted, regulating matters relating to their cooperation for the effective implementation of the Digital Services Act, in particular with regard to the coordination of data and information collection and exchange, the use of information systems at national level, and the procedure for receiving and transmitting complaints.

