{"id":146994,"date":"2026-08-11T09:53:12","date_gmt":"2026-08-11T09:53:12","guid":{"rendered":"https:\/\/my.legal500.com\/guides\/?post_type=comparative_guide&#038;p=146994"},"modified":"2026-08-11T09:53:12","modified_gmt":"2026-08-11T09:53:12","slug":"greece-tmt","status":"publish","type":"comparative_guide","link":"https:\/\/my.legal500.com\/guides\/chapter\/greece-tmt\/","title":{"rendered":"Greece: TMT"},"content":{"rendered":"","protected":false},"template":"","class_list":["post-146994","comparative_guide","type-comparative_guide","status-publish","hentry","guides-tmt","jurisdictions-greece"],"acf":[],"appp":{"post_list":{"below_title":"<div class=\"guide-author-details\"><span class=\"guide-author\">Nikolinakos &amp; Partners Law Firm<\/span><span class=\"guide-author-logo\"><img src=\"https:\/\/my.legal500.com\/guides\/wp-content\/uploads\/sites\/1\/2020\/07\/Logo-Nikolinakos-Partners-Law-Firm.jpg\"\/><\/span><\/div>"},"post_detail":{"above_title":"<div class=\"guide-author-details\"><span class=\"guide-author\">Nikolinakos &amp; Partners Law Firm<\/span><span class=\"guide-author-logo\"><img src=\"https:\/\/my.legal500.com\/guides\/wp-content\/uploads\/sites\/1\/2020\/07\/Logo-Nikolinakos-Partners-Law-Firm.jpg\"\/><\/span><\/div>","below_title":"<span class=\"guide-intro\">This country specific Q&amp;A provides an overview of TMT laws and regulations applicable in Greece<\/span><div class=\"guide-content\"><div class=\"filter\">\r\n\r\n\t\t\t\t<input type=\"text\" placeholder=\"Search questions and answers...\" class=\"filter-container__search-field\">\r\n\t\t\t<\/div>\r\n\r\n\t\t\t\r\n\r\n\r\n\t\t\t<ol class=\"custom-counter\">\r\n\r\n\t\t\t\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software \u2013 How are proprietary rights in software and associated materials protected?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Software in Greece is considered literary work and protected under the provisions of intellectual property law, according to par. 3 of art. 2 of Law 2121\/1993. A basic prerequisite for granting the protection of the intellectual property law to a software is that it is original, in the sense that it is the result of the personal intellectual work of its creator. In a few exceptional cases software can be protected by the industrial property law as a patent (Law 1733\/1987), if it qualifies as a patent, i.e. if it is a new invention, involving an inventive step and demonstrative of industrial application.<\/p>\n<p>Supplementary protection is provided by the law of unfair competition and specifically articles 16-18 of Law 146\/1914 concerning the protection of commercial and industrial secrecy, as long as this software constitutes a commercial secret or a business secret, and as long as legal and technical measures have been taken to prevent any third party\u2019s access to the program. Furthermore, in case of outright copy or imitation of software by a competitor, the general clause of article 1 of Law 146\/1914, prohibiting unfair behaviours, may apply.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software \u2013 In the event that software is developed by a software developer, consultant or other party for a customer, who will own the resulting proprietary rights in the newly created software in the absence of any agreed contractual position?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The creator of a computer software shall obtain the intellectual property rights over the software, provided that the software is original, meaning that it is the result of the creator\u2019s own intellectual effort, unless otherwise agreed by contract. The customer acquires only those rights of use necessary for the intended exploitation of the software, as determined by the nature and purpose of the software and the relevant contractual arrangements.<\/p>\n<p>However, under the intellectual property law, the economic right over a computer program that is created by an employee in the execution of their employment contract or following the instructions given by the employer, shall be ipso jure transferred to the latter, unless otherwise provided by contract (article 40 of Law 2121\/1993).<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software \u2013 Are there any specific laws that govern the harm \/ liability caused by Software \/ computer systems?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>There is no specific Greek statute governing liability for harm caused exclusively by software or computer systems. Instead, liability is assessed under the general legal framework applicable to the particular circumstances of each case.<\/p>\n<p>Depending on the facts, claims may arise under the provisions of the Greek Civil Code relating to contractual liability or tort, where damage results from a breach of contractual obligations or from unlawful and culpable conduct.<\/p>\n<p>In addition, article 6 of the Greek consumer protection law (Law 2251\/1994) establishes a strict liability regime for damage caused by defective products. However, the current statutory definition of a \u2018product\u2019 does not expressly include stand-alone software.<\/p>\n<p>This position is expected to change, as Greece is required to transpose Directive (EU) 2024\/2853 on liability for defective products by 9 December 2026. Once implemented, the revised regime will expressly extend the product liability framework to software and other digital products, including certain AI-enabled products.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software \u2013 To the extent not covered by (3) above, are there any specific laws that govern the use (or misuse) of software \/ computer systems?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>To the extent not covered by the rules on civil liability, there is no single Greek statute specifically governing the use or misuse of software or computer systems. Instead, the relevant legal framework is primarily set out in copyright legislation and criminal law.<\/p>\n<p>Software is protected under the copyright law (Law 2121\/1993), which grants copyright holders the right to seek the recognition of their rights, the cessation and omission of any infringement, as well as compensation for pecuniary damage and satisfaction for non-pecuniary damage. The law also provides for administrative sanctions in cases involving the unauthorised reproduction, distribution or commercial exploitation of computer programs.<\/p>\n<p>The Greek Criminal Code criminalises a number of offences relating to the misuse of software and computer systems, including unlawful access to information systems, the unlawful copying or use of computer programs, offences involving confidential data or computer programs, computer fraud, and the manufacture, possession, distribution or use of software or devices intended to facilitate the commission of cyber offences, including the unlawful interception of communications.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software Transactions (Licence and SaaS) \u2013 Other than as identified elsewhere in this overview, are there any technology-specific laws that govern the provision of software between a software vendor and customer, including any laws that govern the use of cloud technology?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Several legal instruments may apply to software transactions and cloud computing services in Greece.<\/p>\n<ul>\n<li>The general law of contracts under the Greek Civil Code is the primary legal framework.<\/li>\n<li>Law 2121\/1993 on Copyright is also of fundamental importance, as it governs the protection and licensing of computer programs and other software-related intellectual property rights.<\/li>\n<li>Where software or cloud services involve the processing of personal data, Regulation (EU) 2016\/679 (GDPR) and Law 4624\/2019 apply.<\/li>\n<li>For consumer transactions, Law 2251\/1994 on Consumer Protection applies, while Law 4967\/2022, which implemented Directive (EU) 2019\/770, establishes specific rules governing contracts for the supply of digital content and digital services to consumers.<\/li>\n<li>Presidential Decree 131\/2003, implementing the E-Commerce Directive, applies to information society services generally.<\/li>\n<li>Law 4727\/2020 governs digital governance and public sector digitalization and applies where cloud services are supplied to public sector bodies.<\/li>\n<li>Software vendors and cloud service providers should consider the impact of directly applicable EU legislation, including the Data Act, the NIS2 Directive (implemented through Law 5160\/2024) and the Digital Operational Resilience Act (DORA).<\/li>\n<\/ul>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software Transactions (License and SaaS) \u2013 Is it typical for a software vendor to cap its maximum financial liability to a customer in a software transaction? If \u2018yes\u2019, what would be considered a market standard level of cap?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>In Greek commercial practice, it is standard for software vendors to limit their contractual liability through negotiated limitation-of-liability clauses. However, while Greek law recognises the parties&#8217; freedom to allocate contractual risk, Article 332 of the Greek Civil Code provides that any prior agreement excluding or limiting liability for wilful misconduct or gross negligence is null and void.<\/p>\n<p>There is no market standard level of cap, but it is common for service providers to limit their financial liability to the fees paid by the customer over a specific period (e.g. one year).<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software Transactions (License and SaaS) \u2013 Please comment on whether any of the following areas of liability would typically be excluded from any financial cap on the software vendor\u2019s liability to the customer or subject to a separate enhanced cap in a negotiated software transaction (i.e. unlimited liability): (a) confidentiality breaches; (b) data protection breaches; (c) data security breaches (including loss of data); (d) IPR infringement claims; (e) breaches of applicable law; (f) regulatory fines; (g) wilful or deliberate breaches; (h) claims arising out of or in relation to artificial intelligence.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>In negotiated B2B software transactions, it is common market practice for areas of liability such as confidentiality, data protection and security and IPR infringement to be made subject to a higher cap, depending on the parties&#8217; bargaining power. This is not frequently the case with breaches of applicable law and regulatory fines, while pursuant to Article 332 of the Greek Civil Code, liability for wilful misconduct and gross negligence cannot be excluded or limited in advance.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software Transactions (License and SaaS) \u2013 Is it normal practice for software source codes to be held in escrow for the benefit of the software licensee? If so, who are the typical escrow providers used? Is an equivalent service offered for cloud-based software?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Software source code escrow is not standard practice in Greece.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">IT Outsourcing \u2013 Other than as identified elsewhere in this questionnaire, are there any specific technology laws that govern IT outsourcing transactions?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Greece has no dedicated body of legislation governing IT outsourcing transactions as such. Rather, these arrangements are governed by various laws and regulations that cover contract law, data protection, intellectual property, employment regulation, and tax law &#8211; each supplying relevant rules depending on the specifics of the transaction. Among the most significant instruments are: Executive Board Act no. 178\/5\/2.10.2020 issued by the Bank of Greece, which incorporates the European Banking Authority&#8217;s guidelines on outsourcing and extends to arrangements with cloud service providers; this Act builds a uniform framework covering all entities supervised by the Bank of Greece, supplying precise definitions of &#8220;outsourcing&#8221; and &#8220;critical or important functions,&#8221; and laying down internal governance standards together with obligations owed at both the pre-contractual and contractual stages, all intended to ensure institutions properly manage the risks that outsourcing arrangements can create. A further key instrument is Regulation (EU) 2022\/2554, the Digital Operational Resilience Act (DORA), which took effect on 17 January 2025 and applies to the outsourcing of critical ICT functions, imposing requirements on financial entities&#8217; contractual dealings with ICT providers with the aim of strengthening digital operational resilience across the financial sector. Finally, outsourcing agreements must also conform to the personal data protection regime, comprising the GDPR together with its domestic implementing legislation, Law 4624\/2019, which sets demanding standards for the processing and safeguarding of personal data.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">IT Outsourcing \u2013 Please summarise the principal laws (present or impending), if any, that protect individual staff in the event that the service they perform is transferred to a third party IT outsource provider, including a brief explanation of the general purpose of those laws.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Under Greek law, IT outsourcing is generally governed by the contractual terms agreed between the parties, pursuant to the principle of freedom of contract under Article 361 of the Greek Civil Code. However, the principal legislation protecting employees where IT services are transferred to an outsourcing provider is the transfer-of-undertakings framework set out in Council Directive 2001\/23\/EC, as implemented in Greece by Presidential Decree 178\/2002 and now codified in Articles 358\u2013367 of the current Labour Code, Presidential Decree 62\/2025.<\/p>\n<p>The purpose of these provisions is to safeguard employees&#8217; rights and ensure continuity of employment where an undertaking, business, or part of an undertaking or business is transferred to another employer. The transfer does not, in itself, constitute grounds for dismissal, although dismissals may still be made for economic, technical or organisational reasons, subject to the applicable legal requirements.<\/p>\n<p>An IT outsourcing arrangement will fall within this framework only where it involves the transfer of an economic entity &#8211; namely, an organised grouping of resources that retains its identity after the transfer. Whether this test is met depends on the circumstances rather than the contractual description. In accordance with the case law of the Court of Justice of the European Union (including S\u00fczen), the mere outsourcing of services or a change of service provider does not, by itself, constitute a transfer of an undertaking unless it is accompanied by the transfer of significant tangible or intangible assets or the taking over by the new provider of a major part of the workforce assigned to the relevant activity.<\/p>\n<p>Where an outsourcing arrangement constitutes a transfer of an undertaking or part of an undertaking, the transferor&#8217;s rights and obligations arising from the employment contracts or employment relationships connected with the transferred economic entity automatically pass to the transferee by operation of law. Conversely, where the outsourcing involves only the transfer of the activity and not of the underlying economic entity, employees do not automatically transfer to the outsourcing provider.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Telecommunications \u2013 Please summarise the principal laws (present or impending), if any, that govern telecommunications networks and\/or services, including a brief explanation of the general purpose of those laws.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The principal law governing telecommunications networks and\/or services in Greece is Law 4727\/2020, on Digital Governance and Electronic Communications. The second part of this law transposes into Greek legislation EU Directive 2018\/1972 for the establishment of the European Electronic Communications Code. The law establishes a harmonized framework for the regulation of electronic communications networks, electronic communications services, associated facilities and associated services, and certain aspects of terminal equipment. It also lays down national principles for the use of the radio spectrum and satellite orbits. Before the issuance of law 4727\/2020, the principal law governing the telecoms sector in Greece was Law 4070\/2012 on electronic communications. Although law 4727\/2020 replaced most of Law 4070\/2012, some provisions remain in force.<\/p>\n<p>Law 5160\/2024, which is the national transposition of the NIS2 Directive includes providers of public electronic communications networks or of publicly available electronic communications services among the entities that fall within its scope of obligations. These obligations include registration obligations on the National Cybersecurity Authority, implementation of cybersecurity measures, incident reporting obligations and appointment of an Information and Communication Systems Security Officer (ICSSO).<\/p>\n<p>Following the aforementioned laws, a wide range of secondary legislation has been issued by the Hellenic Telecommunications &amp; Post Commission (EETT). Special reference should be made to the following:<\/p>\n<ul>\n<li>EETT\u2019s Regulation on General Authorisations (EETT\u2019s Decision No. 1183\/2\/2026): which regulates the procedure and conditions for the provision of electronic communications networks and\/or services under the General Authorization Regime.<\/li>\n<li>ADAE\u2019s Decision No. 304\/2025, which is a Regulation ADAE published Decision No. 304\/2025 ensuring the privacy of electronic communications, along with Law 5002\/2022 regarding the procedure for the lifting of communications secrecy, cybersecurity and data protection.<\/li>\n<li>EETT\u2019s Regulation on the Management and Allocation of the Numbering Resources of the National Numbering Plan (EETT\u2019s Decision 966\/02\/2020), defining clear framework for the exercise of the rights and obligations of providers of electronic service networks or electronic communications services, as well as users, which guarantees objective, transparent, and impartial access to the numbering resources of the national numbering plan.<\/li>\n<li>EETT\u2019s Regulation on the Use and Granting of Rights of Use of Radio Frequencies under the General Authorization Regime for the Provision of Electronic Communications Networks and\/or Services (Decision 1075\/02\/2023), which defines the procedures, conditions, and any relevant details for the licensing of radio spectrum usage and the granting of individual radio spectrum usage rights under a General License regime. public consultation on the draft Regulation on Spectrum Fees has now concluded. The draft Regulation is expected to codify the existing regulatory framework by consolidating the original EETT Regulation on Spectrum Usage and Radio Frequency Assignment Fees together with all subsequent amendments into a single text.<\/li>\n<\/ul>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Telecommunications \u2013 Please summarise any licensing or authorisation requirements applicable to the provision or receipt of telecommunications services in your country. Please include a brief overview of the relevant licensing or authorisation regime in your response.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>In order to provide any kind of electronic communications networks and\/or services within the territory of Greece (except for number-independent interpersonal communications services), operators shall acquire a General Authorisation, in the form of a Registration Declaration to EETT, in accordance with EETT\u2019s Regulation on general authorisations (EETT\u2019s Decision No. 1183\/2\/2026, as it has been amended and in force). No general authorisation is required for the resale of electronic communications services to users. In contrast, a general authorisation is required for the provision of electronic communications services by third parties who, although they do not have their own electronic communications infrastructure, provide electronic communications services under a different brand and business organisation, relying on the infrastructure of other persons providing electronic communications networks and\/or services with whom they have concluded a contract. The first step for the acquisition of a general authorisation is that the interested party is registered on the EETT\u2019s Registry of Companies and Licenses (e-Registry) web app. After the registration in the Registry of Companies and Licenses is completed, the person interested in acquiring a general authorisation must apply for registration in the Registry of Electronic Communications Network and Service Providers, by submitting a registration declaration. The declaration shall be approved provided that it is fully and correctly completed. The registration declaration constitutes the general authorisation. The person filing the declaration may carry out the activity for which the registration declaration is submitted, directly by submitting a full declaration.<\/p>\n<p>Where the electronic communications activity is subject to the granting of rights to use radio frequencies, the person concerned must also obtain the required rights to use radio frequencies. The process for granting individual rights of use for specific radio frequencies or frequency bands for the provision of electronic communications networks and\/or services is defined in EETT\u2019s Decision 1075\/02\/12-6-2023 \u201cRegulation on the Use and Granting of Rights of Use of Radio Frequencies under the General Authorization Regime for the Provision of Electronic Communications Networks and\/or Services\u201d. Rights to use frequencies are granted by the EETT upon a relevant request. Such requests are submitted through the EETT\u2019s Spectrum Management System. Where no granting of individual rights to use radio frequencies is required, operators must meet the conditions set in the relevant regulation issued by EETT.<\/p>\n<p>Where the electronic communications activity is subject to the granting of rights to use numbers, the person concerned must also follow the procedure for number allocation, as described in EETT\u2019s Regulation on the Management and Allocation of the Numbering Resources of the National Numbering Plan (Decision 966\/2\/2020).<\/p>\n<p>Finally, where applicable, operators shall obtain the appropriate licences for every antenna they use. The relevant framework consists of law 4635\/2019 (articles 20\u201338) and EETT\u2019s Regulation 919\/26\/2019 on the licensing of antennas and base stations. Applications for issuance of antenna construction licences are submitted through the EETT\u2019s System for the Electronic Submission of Applications (SILYA). The planning approval is issued following the EETT\u2019s antenna construction permit, through the e-Licensing electronic system used for building. Low electromagnetic environmental nuisance antenna facilities are exempt from the licensing process. As a result, for a significant number of antennas, mainly within urban centres, a simple registration procedure is followed, which is also implemented through SILYA.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Telecommunications \u2013 Please summarise the principal laws (present or impending) that govern access to communications data by law enforcement agencies, government bodies, and related organisations. In your response, please outline the scope of these laws, including the types of data that can typically be requested, how these laws are applied in practice (e.g., whether requests are confidential, subject to challenge, etc.), and any legal or procedural safeguards that apply.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The confidentiality of communication is an individual right protected by the Constitution. According to Article 19 of the Constitution, the confidentiality of letters and freedom of correspondence or communication by any other means is absolutely inviolable. The same provision states that a law may provide guarantees under which judicial authorities are not bound by this confidentiality for the purpose of national security protection or for the purpose of investigating serious crimes. Based on the above, it follows that the lifting of confidentiality is permitted only as an exception, only if there is an order from a competent judicial authority, and only if the institutional and procedural requirements provided by law are met. The procedures for the lifting of the confidentiality of communications are primarily governed by Law 5002\/2022, while Presidential Decree 47\/2005, as in force, supplements this framework by setting out the relevant technical and organisational arrangements and specifying the categories of communications data that may be subject to interception.<\/p>\n<p>Article 19 also provides for the establishment of an independent authority with the aim of protecting communication confidentiality. The duties of the Hellenic Authority for Communication Security and Privacy (ADAE) include overseeing the compliance with the terms and procedures for the lifting of confidentiality.<\/p>\n<p>The lifting of confidentiality does not concern face-to-face communication but any kind of communication conducted via a communication network or service provider used by the subscriber or user against whom the lifting measure is taken. The specific communication details that may be included in an order for the lifting of confidentiality depend on the type of communication and are mentioned in detail in Article 4 of Presidential Decree 47\/2005. In short, the following information fall under the scope of the relevant provisions:<\/p>\n<ul>\n<li>The content of communication (content of telephone calls, SMS, emails, and generally any voice, image, or data communication).<\/li>\n<li>The identity of the caller\/sender and the recipient.<\/li>\n<li>The location data of the terminal device (geolocation).<\/li>\n<\/ul>\n<p>The law that specifies the conditions and procedures for lifting the confidentiality of communications is Law 5002\/2022. As indicated by the Constitution, this law provides two reasons for lifting the confidentiality of communications: for national security reasons and for the investigation of crimes, as defined in detail in the law.<\/p>\n<p>Requests for the lifting of communication confidentiality must be authorized by a judicial authority. According to this law, the lifting of communication confidentiality for national security reasons can be requested from the competent judicial officer only by the National Intelligence Service or the Special Violent Crime Squad of the Hellenic Police, either on their own initiative or following a relevant notification from a judicial or other public authority (political, military, or police) responsible for the national security issue requiring the lifting. If the prosecutor approves the request, the approval order shall be submitted without delay for approval to a Deputy Prosecutor of the Supreme Court or a Prosecutor of the Court of Appeals, appointed by decision of the Prosecutor of the Supreme Court (dual approval). The lifting of communication confidentiality for crime investigation purposes is ordered by the competent judicial council following a proposal by the prosecutor. In exceptional and urgent circumstances, the lifting can be ordered by the prosecutor or the investigating officer.<\/p>\n<p>The law defines in detail the minimum content of the relevant requests and court orders, ensuring that the legal standards of necessity and proportionality are met. The duration of the lifting of confidentiality cannot exceed two months. Two-month extensions may be ordered, provided that the reasons for the lifting still apply, but the total duration cannot exceed ten months. Exceeding this limit is only allowed under specific conditions in cases of lifting confidentiality for national security reasons. After the expiration of the defined period, the lifting of confidentiality automatically ceases. In any case, by order of the authority that imposed the lifting of confidentiality, the cessation of the measure can be ordered before the specified duration has expired, if the purpose has been fulfilled or the reasons for the imposition of the measure have ceased to exist.<\/p>\n<p>The procedure is strictly confidential. Three years after the validity period of the order for lifting the confidentiality for national security reasons has lapsed, the imposition of the measure is notified to the affected party, provided that the purpose for which it was ordered is not compromised. A relevant request for this notification is submitted to the Hellenic Authority for Communication Security and Privacy (ADAE), which is then forwarded to the National Intelligence Service and the Special Violent Crime Squad. The lifting of confidentiality is notified after a decision by a three-member body. If the decision is made to inform the affected party, they are notified about the imposition of the restrictive measure and its duration. The ADAE, after the expiration of the lifting of confidentiality measure for the investigation of crimes and following a relevant request by the affected party, shall notify them of the imposition of this measure within a period of sixty days, with the consent of the Prosecutor of the Supreme Court and provided that the purpose for which it was ordered is not compromised.<\/p>\n<p>A recent judicial development further clarified the scope of constitutional protection. In Decision No. 1\/2026, the Plenary of the Supreme Court (Criminal Division) held that the constitutional protection of the confidentiality of communications extends not only to the content of communications but also to traffic (external) communications data and stored communications. The Court further confirmed that the procedural safeguards and temporal limitations laid down in Law 5002\/2022 apply equally where the lifting of confidentiality concerns stored communications.<\/p>\n<p>Finally, the Greek Code of Criminal Procedure recognises the lifting of the confidentiality of communications as a special investigative measure in the context of criminal investigations. Articles 254 and 255 provide that, for specified categories of serious offences, the competent judicial authorities may order the lifting of the confidentiality of the content of communications, as well as location and traffic data, subject to the conditions, procedures and safeguards laid down in Law 5002\/2022. The Code further requires that such measures be authorised by a reasoned judicial decision, be limited to what is strictly necessary and proportionate for the purposes of the investigation, and be used only under the conditions prescribed by law.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Telecommunications \u2013 Please summarise the principal laws (present or impending) that impose cyber security and\/or operational resiliency obligations applicable to the operation of telecommunications infrastructure and\/or provision of telecommunications services.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The horizontal cornerstone of the Greek cybersecurity framework is Law 5160\/2024, which transposes Directive (EU) 2022\/2555 (NIS2) and establishes enhanced risk-management and incident-notification obligations for &#8220;essential&#8221; and &#8220;important&#8221; entities operating in sectors such as energy, transport, health and critically for present purposes digital infrastructure, a category that expressly includes providers of electronic communications networks and services. Pursuant to that law, Ministerial Decision 1381\/2025 and Ministerial Decision 1645\/2025 have already been issued (establishing a digital platform for the registration of entities under Article 4 of Law 5160\/2024), together with the more substantive Ministerial Decision 1689\/2025, which lays down the National Cybersecurity Requirements Framework for essential and important entities. Institutionally, supervision is now exercised by the National Cybersecurity Authority, established as an independent legal entity governed by public law under Law 5086\/2024.<\/p>\n<p>Alongside this horizontal NIS2 framework, the broader legislative landscape on digital governance and electronic communications remains relevant: Law 4727\/2020 (transposing Directive (EU) 2018\/1972, the European Electronic Communications Code, and providing definitions that are also used supplementarily in ADAE&#8217;s new Regulation), Law 4070\/2012 on the operation of electronic communications networks and the provision of electronic communications services, Law 4961\/2022 on emerging ICT technologies and the strengthening of digital governance, and Law 5002\/2022 on the lifting of the secrecy of communications, cybersecurity matters and the protection of citizens&#8217; personal data.<\/p>\n<p>At the sector-specific level, ADAE established under Law 3115\/2003 holds dedicated regulatory competence over the confidentiality of communications pursuant to Law 3674\/2008. Within that mandate, ADAE had previously issued Regulation 205\/2013 on the Security and Integrity of Networks and Electronic Communications Services, which was repealed and replaced by Regulation 28\/2024; the latter, together with the earlier Regulation 165\/2011 on the confidentiality of communications, has now been expressly repealed by the new ADAE Decision 304\/2025 (Government Gazette B&#8217; 4268\/07.08.2025). Decision 304\/2025 consolidates, in a single instrument, the requirements for a Networks and Services Security Policy covering security governance and risk management, personnel and contractor security, physical and logical access control, network security, security incident management, and internal as well as regulatory audits and now constitutes the principal sector-specific implementing tool for telecommunications providers, complementing the horizontal NIS2 regime.<\/p>\n<p>From a critical standpoint, telecommunications providers currently sit at the intersection of at least three parallel supervisory regimes NIS2\/the National Cybersecurity Authority, ADAE (Regulation 304\/2025), and EETT (General Authorisation Regulation) with overlapping but not fully harmonised obligations regarding incident notification, risk management and audits. Regulation 304\/2025&#8217;s reliance on general references to &#8220;applicable legislation,&#8221; without an explicit coordination mechanism vis-\u00e0-vis the NIS2 framework, remains a point worth monitoring. Moreover, the compliance deadlines set out in Article 12 of Regulation 304\/2025 have now expired: providers -\u201call persons providing public electronic communications networks or publicly available electronic communications services&#8221;- falling under Article 1.1, were required to draft and implement their Networks and Services Security Policy within nine months of publication (i.e., by 7 May 2026), while providers within the scope of Law 3674\/2008 (fixed and mobile interpersonal communications services, S001\/S002) were required to submit their Policy to ADAE for prior approval within three months of publication (i.e., by 7 November 2025). Providers that have not yet complied are, per Article 12.4 of the Regulation, exposed to the sanctions regime of Law 3115\/2003 and, where applicable, Law 3674\/2008. As matters currently stand, it would be worth verifying including directly with ADAE or through its published enforcement notices the extent to which providers have in fact complied within these now-elapsed deadlines, and whether ADAE has initiated any regulatory or ex officio audits (Article 10.1) on that basis, since this is precisely the phase in which enforcement activity and any first wave of sanctions or compliance findings would be expected to emerge.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Mobile communications and connected technologies \u2013 What are the principle standard setting organisations (SSOs) governing the development of technical standards in relation to mobile communications and newer connected technologies such as digital health or connected and autonomous vehicles?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>In Greece, the development of technical standards for mobile communications and connected technologies is governed by the Hellenic Organization for Standardization (ELOT) and the Hellenic Telecommunications and Post Commission (EETT). The Hellenic Organization for Standardization (ELOT)\u00a0 is the national standards body of Greece and has been founded by the Greek Law 372\/1976. ELOT&#8217;s mission is the promotion and application of standardization in Greece. ELOT&#8217;s main activities are: preparing and publishing standards, awarding marks of conformity and granting certificates of conformity, certifying quality systems for businesses and conducting laboratory tests. The Hellenic Telecommunications and Post Commission (EETT) is an independent authority with administrative and financial autonomy. It acts as the National Regulatory Authority (NRA) for electronic communications and postal services, complementing this framework by allocating spectrum, setting interoperability and licensing conditions under the General Authorisation Regulation, and thereby giving regulatory effect to the technical standards adopted at EU\/international level, a function of particular importance for 5G\/6G roll-out.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Mobile communications and connected technologies \u2013 How do technical standards facilitating interoperability between connected devices impact the development of connected technologies?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Technical standards that promote interoperability between connected devices significantly influence the development of connected technologies in the following ways:<\/p>\n<ol>\n<li>Interoperability standards enable diverse IoT devices (such as sensors, actuators, and smart appliances) to work together harmoniously.<\/li>\n<li>When devices follow common protocols and interfaces, they can seamlessly exchange data, commands, and status information. This seamless integration simplifies the development process and speeds up the time-to-market for new technologies.<\/li>\n<li>When manufacturers comply with recognized standards, consumers and businesses gain confidence in the technology. They are assured that devices from different vendors will work together reliably, driving adoption and investment.<\/li>\n<li>By leveraging existing standards, companies save resources. Additionally, interoperability reduces maintenance costs and ensures smoother upgrades.<\/li>\n<li>Standards provide a foundation upon, which innovators can build. As a result, developers can focus on creating novel applications and services instead of reinventing basic communication mechanisms.<\/li>\n<\/ol>\n<p>6.Standards help ensure compliance, leading to safer and more reliable products.<\/p>\n<p>In Greece, as in other EU countries, the legal framework concerning these standards is influenced by both national and EU laws and especially in the field of Intellectual Property (IP), Competition Law and Data Protection. Most recently, Regulation (EU) 2023\/2854 (the \u0395U Data Act), fully applicable as of 12 September 2025, has introduced specific interoperability and data-portability obligations for connected devices and related services, reinforcing the role of technical standards as a compliance mechanism rather than a purely voluntary market tool.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Data Protection \u2013 Please summarise the principal laws (present or impending), if any, that govern data protection, including a brief explanation of the general purpose of those laws.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Greece&#8217;s primary data protection law is Law 4624\/2019, which implements the General Data Protection Regulation (GDPR) and incorporates Directive (EU) 2016\/680. This legislation replaced the previous Law 2472\/1997, which implemented Directive 95\/46\/EC. In the area of electronic communications, Law 3471\/2006\u2014aligned with Directive 2002\/58\/EC (the ePrivacy Directive) and amended by Directive 2006\/13\/EC\u2014serves as a complementary framework specifically focused on protecting personal data. Other key laws that contribute to Greece&#8217;s broader data protection and cybersecurity landscape are the following:<\/p>\n<ul>\n<li>Law 5160\/2024, transposing Directive (EU) 2022\/2555 (NIS2 Directive), establishes the core horizontal national cybersecurity framework, introducing strict network and information security, incident reporting, and data security obligations for essential and important entities across critical sectors.<\/li>\n<li>Law 5002\/2022 outlines procedures for lifting the confidentiality of communications and sets provisions for cybersecurity and personal data protection of citizens.<\/li>\n<li>Law 4990\/2022 addresses the protection of whistleblowers reporting violations of EU law, incorporating Directive (EU) 2019\/1937.<\/li>\n<li>Law 4961\/2022 focuses on emerging information and communication technologies, aims to strengthen digital governance, and includes additional provisions.<\/li>\n<li>Law 4579\/2018 places obligations on air carriers regarding the collection and handling of passenger information.<\/li>\n<li>Law 3917\/2011 governs the retention of data generated or processed through publicly available electronic communication services or networks, as well as the use of audio and video surveillance in public areas.<\/li>\n<li>Law 3783\/2009 establishes rules for collecting and storing identifying data of mobile service subscribers for national security and the investigation of particularly serious crimes.<\/li>\n<li>Article 8 of Law 3144\/2003 sets out conditions for processing workers\u2019 medical data.<\/li>\n<li>Law 5321\/2026, establishing the national framework for the implementation of Regulation (EU) 2024\/1689 (the AI Act). Although not a data protection statute, it is particularly relevant where AI systems process personal data and therefore operates alongside the GDPR and Law 4624\/2019.<\/li>\n<\/ul>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Data Protection \u2013 What is the maximum sanction that can be imposed by a regulator in the event of a breach of any applicable data protection laws?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The Hellenic Data Protection Authority (HDPA) may impose administrative fines in accordance with Article 83 GDPR. Depending on the nature of the infringement, fines may reach up to \u20ac10 million or 2% of the total worldwide annual turnover of the preceding financial year, whichever is higher, or, for more serious infringements, up to \u20ac20 million or 4% of the total worldwide annual turnover, whichever is higher.<\/p>\n<p>Under Law 4624\/2019, where the controller or processor is a public authority or public body, the maximum administrative fine that may be imposed by the HDPA is \u20ac10 million.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Data Protection \u2013 What data protection rules are relevant to technology contracts in your country?  Do they typically refer to external data protection regimes, e.g. EU GDPR or CCPA, even where the contract has no clear international element?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Technology contracts in Greece that involve the processing of personal data typically refer to Regulation (EU) 2016\/679 (GDPR) and Law 4624\/2019, which supplements the GDPR and provides for its application in Greece. Where relevant, contracts may also refer to Law 3471\/2006 on privacy in electronic communications.<\/p>\n<p>Accordingly, technology agreements commonly include provisions addressing the parties&#8217; respective roles as controllers and\/or processors, the processing of personal data, security measures, international data transfers, confidentiality, data breach notification, audit rights and the conclusion of data processing agreements where required under Article 28 GDPR.<\/p>\n<p>Where a technology contract concerns the development, deployment or use of AI systems involving the processing of personal data, the parties must also take into account Regulation (EU) 2024\/1689 (the AI Act), Law 5321\/2026 establishing the national framework for its implementation, and the interaction of those instruments with the GDPR. As Greece is an EU Member State, technology contracts typically refer to the GDPR, even where there is no obvious international element.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Cybersecurity \u2013 Please summarise the principal laws (present or impending), if any, that govern cybersecurity (to the extent they differ from those governing data protection), including a brief explanation of the general purpose of those laws.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The principal laws regarding cybersecurity are the following:<\/p>\n<p>&#8211; Law No. 5160\/2024 constitutes the transposition of Directive (EU) 2022\/2555 (NIS 2) into Greek law, establishing a strengthened cybersecurity framework for essential and important entities operating in sectors such as energy, transport, health, and digital services.By virtue of Law 5160\/2024, the following ministerial decisions have also been issued:<\/p>\n<ol>\n<li>Ministerial Decision 1381\/2025 (Creation of a digital platform for the registration of entities under Article 4 of Law 5160\/2024.),<\/li>\n<\/ol>\n<ol start=\"2\">\n<li>Ministerial Decision 1645\/2025 (Amendment of Joint Ministerial Decision 2025 &#8211; Creation of a digital platform for the registration of entities under Article 4 of Law 5160\/2024.),<\/li>\n<\/ol>\n<ol start=\"3\">\n<li>Ministerial Decision 1689\/2025 (National Cybersecurity Requirements Framework for Essential and Important Entities.)<\/li>\n<li>Ministerial Decision 1899\/2025 (Determination of the qualifications, duties, incompatibilities and obligations of Information and Communication Systems Security Officers)<\/li>\n<\/ol>\n<p>&#8211; Law 5086\/2024 relates to the establishment of the National Cybersecurity Authority, as an independent legal entity governed by public law.<\/p>\n<p>&#8211; Law 4961\/2022 on the \u201cEmerging Information and Communication Technologies, Strengthening of Digital Governance and other provisions\u201d.<\/p>\n<p>&#8211; Law 5002\/2022 on the \u201clifting of the secrecy of communications process, cybersecurity issues and protection of citizens; personal data issues\u201d.<\/p>\n<p>&#8211; Law 4727\/2020 regarding \u201cDigital Governance (Transposition into Greek Legislation of Directive (EU) 2016\/2102 and Directive (EU) 2019\/1024) &#8211; Electronic Communications (Transposition into Greek Legislation of Directive (EU) 2018\/1972) and other provisions\u201d.<\/p>\n<p>&#8211; RegulationADAE Regulation 304\/2025\u00a0 by the Hellenic Authority for Communication Security and Privacy (ADAE)<\/p>\n<p>&#8211; Art. 386A of the Greek Penal Code, regarding fraud committed via a computer.<\/p>\n<p>Non-legislative but relevant: the NCSA&#8217;s National Cybersecurity Strategy 2026\u20132030 , and its Cybersecurity Handbook and self-assessment tool for organisations.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Cybersecurity \u2013 What is the maximum sanction that can be imposed by a regulator in the event of a breach of any applicable cybersecurity laws?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>According to Law 5160\/2024, essential entities may be subject to a fine of up to ten million (10,000,000) euros or up to 2% of the total worldwide annual turnover of the undertaking to which the essential entity belongs, for the preceding financial year, whichever is higher. Important entities may be subject to a fine of up to seven million (7,000,000) euros or up to 1.4% of the total worldwide annual turnover of the undertaking to which the important entity belongs, for the preceding financial year, whichever is higher.<\/p>\n<p>Art. 24 of Law 5160\/2024 also allows the NCSA, as an ultima ratio measure and only after prior binding instructions have gone unheeded, to temporarily suspend the exercise of managerial duties by any natural person acting as CEO or legal representative of an essential entity, until the entity remedies the relevant deficiencies.<\/p>\n<p>In addition, providers of public electronic communications networks or publicly available electronic communications services are subject to the regime set out in Art. 29 of Law 5160\/2024 and ADAE Regulation No. 304\/2025. This regime empowers the ADAE to require enhanced cybersecurity measures, mandate the adoption and approval of detailed Security Policies, and require immediate reporting of significant incidents to both the ADAE and the National Cybersecurity Authority (NCSA).<\/p>\n<p>Furthermore, the ADAE is entitled to address a recommendation for compliance with a certain provision of the law (being complemented by a warning for the imposition of sanctions in the case of a recurrence of the violation of the law governing the confidentiality of communication or the prerequisites and the procedure related to its declassification being substantiated), while it may also impose an administrative fine ranging from \u20ac15,000 to \u20ac1.5 million (Art. 11 of Law 3115\/2003).<\/p>\n<p>Art. 42 of Law 4961\/2022 provides that if an essential service operator or digital service provider, or any municipality, fails to comply with the obligations laid down in Arts 35 and 36, Art. 37 par. 2, Art. 38 par. 1 and Art. 40 of Law 4961\/2022, the competent body of the Ministry of Digital Governance, following a reasoned recommendation of the HCA, may impose the following sanctions, in this order of priority: (a) a recommendation to the entity; (b) a reprimand, if the operator has not complied despite the prior recommendation; (c) a fine of up to \u20ac15,000 for non-compliance with the reprimand; and (d) in the event of a repeat offence, a fine of up to \u20ac100,000.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Cybersecurity \u2013 Are there any cybersecurity regulatory frameworks in your jurisdiction which require registration for certain sectors or services?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Entities falling within the scope of Law 5160\/2024 as essential or important entities are required to submit prescribed information to the National Cybersecurity Authority through its electronic registration platform. The information is used by the Authority to identify the entities concerned and to compile and maintain the national list of essential and important entities. The information to be submitted includes the entity\u2019s corporate name, address and current contact details, email addresses and telephone numbers, IP address ranges, domain names used by the entity, the relevant sector, subsector and entity type and, where applicable, the other EU Member States in which the entity provides services covered by the legislation. Changes to this information must generally be notified without delay and, in any event, within two weeks.<\/p>\n<p>In addition, Article 19 of Law 5160\/2024 establishes a specific registration obligation for certain categories of digital service providers, namely DNS service providers, top-level domain name registries, domain-name registration service providers, cloud computing service providers, data centre service providers, content delivery network providers, managed service providers, managed security service providers, providers of online marketplaces, providers of online search engines and providers of social networking services platforms. These entities must submit details concerning their identity, relevant sector and entity type, principal establishment and other establishments in the EU, contact details, the Member States in which they provide services and their IP address ranges. Changes to the information submitted under Article 19 must be notified without delay and, in any event, within three months. Most of this information is subsequently transmitted by the National Cybersecurity Authority to ENISA.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Cybersecurity \u2013 Please summarise the regulatory framework for the reporting of cybersecurity incidents.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The principal cybersecurity incident-reporting framework in Greece is set out in Law 5160\/2024. Essential and important entities must notify the CSIRT of the National Cybersecurity Authority of any incident having a significant impact on the provision of their services. An incident is significant where it has caused, or may cause, severe operational disruption, substantial financial loss, or significant material or non-material damage to other persons.<\/p>\n<p>The reporting process is phased:<\/p>\n<ul>\n<li>an early warning within 24 hours of becoming aware of the incident;<\/li>\n<li>an incident notification within 72 hours, including an initial assessment of its severity, impact and any indicators of compromise;<\/li>\n<li>an intermediate report, if requested by the Authority; and<\/li>\n<li>a final report within one month, describing the incident, its root cause, impact, mitigation measures and any cross-border effects.<\/li>\n<\/ul>\n<p>If the incident remains ongoing, a progress report must be submitted, followed by a final report within one month of its resolution. Trust service providers are subject to a stricter 24-hour notification deadline.<\/p>\n<p>Affected entities may also be required to inform customers or other service recipients where the incident or a significant cyber threat may adversely affect them, including any protective or remedial measures they should take.<\/p>\n<p>Additional sector-specific duties apply. Public electronic communications providers must notify both the Hellenic Authority for Communication Security and Privacy and the National Cybersecurity Authority. A single incident may also trigger separate notification obligations under the GDPR, including notification to the Hellenic Data Protection Authority within 72 hours, and under DORA for financial entities.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Artificial Intelligence \u2013 Which body(ies), if any, is\/are responsible for the regulation of artificial intelligence?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>In Greece, the regulation and oversight of artificial intelligence (AI) are primarily governed by Regulation (EU) 2024\/1689 (the AI Act) and Law 5321\/2026, which establishes the national framework for its implementation. In parallel, Law 4961\/2022 continues to contain provisions relevant to Greece&#8217;s national AI strategy and digital governance, to the extent that these remain in force.<\/p>\n<p>Under Law 5321\/2026, the Hellenic Data Protection Authority (HDPA) has been designated as the market surveillance authority for AI systems falling within its competence under the AI Act, including prohibited AI practices, certain high-risk AI systems listed in Annex III and AI systems subject to the transparency obligations under Article 50 of the AI Act. The HDPA also serves as Greece&#8217;s single point of contact for the purposes of the AI Act and is responsible for coordinating cooperation among the competent national authorities and with the European Commission.<\/p>\n<p>The Hellenic Telecommunications and Post Commission (EETT) has been designated as the national notifying authority, responsible for the assessment, designation and monitoring of conformity assessment bodies under the AI Act. Law 5321\/2026 further establishes, within EETT, an AI Coordination and Expertise Centre, which provides technical and scientific support to the competent authorities, promotes the consistent application of the AI Act and contributes to the development of national expertise in artificial intelligence.<\/p>\n<p>In addition, the Special Secretariat for Artificial Intelligence and Data Governance, operating within the Ministry of Digital Governance, is responsible for the design, coordination and implementation of national policies relating to artificial intelligence and data governance.<\/p>\n<p>Furthermore, the AI Observatory, operating within the Special Secretariat for Artificial Intelligence and Data Governance, supports the implementation of the National Strategy on Artificial Intelligence by monitoring AI developments, collecting and analysing relevant data and contributing to the evaluation and development of AI policies.<\/p>\n<p>Separate from the national competent authorities responsible for market surveillance and conformity assessment, Greece has designated the following authorities and bodies pursuant to Article 77 of the AI Act, having regard to their responsibilities for the protection of fundamental rights in relation to the use of high-risk AI systems:<\/p>\n<ul>\n<li>the Hellenic Data Protection Authority (HDPA);<\/li>\n<li>the Greek Ombudsman;<\/li>\n<li>the Hellenic Authority for Communication Security and Privacy (ADAE); and<\/li>\n<li>the Greek National Commission for Human Rights.<\/li>\n<\/ul>\n<p>From 2 August 2026, these authorities are entitled, within the scope of their respective statutory mandates, to request and access the documentation and information required under the AI Act where necessary for the effective exercise of their supervisory functions concerning the protection of fundamental rights. Their designation under Article 77 does not confer general market surveillance or enforcement powers under the AI Act.<\/p>\n<p>Finally, Law 5321\/2026 provides for the establishment and operation of AI regulatory sandboxes, enabling the development, testing and validation of innovative AI systems in a controlled regulatory environment under the supervision of the competent authorities, in accordance with the AI Act.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Artificial Intelligence \u2013 Please summarise the principal laws (present or impending), if any, that govern the deployment and use of artificial intelligence, including a brief explanation of the general purpose of those laws.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The principal legal framework governing the deployment and use of artificial intelligence (AI) in Greece is Regulation (EU) 2024\/1689 (the AI Act), which entered into force on 1 August 2024 and is directly applicable in all EU Member States, including Greece. The AI Act establishes the first comprehensive legal framework for AI within the European Union, adopting a risk-based approach that classifies AI systems according to the level of risk they pose and lays down harmonised rules governing their development, placing on the market, putting into service and use. It also establishes obligations for providers, deployers, importers, distributors and other operators throughout the AI lifecycle, while introducing specific requirements for high-risk AI systems and general-purpose AI (GPAI) models.<\/p>\n<p>At national level, Law 5321\/2026 establishes the legal framework for the implementation and enforcement of the AI Act in Greece. The Law designates the competent national authorities, establishes the institutional and supervisory framework required by the AI Act, provides for the operation of AI regulatory sandboxes and lays down the national procedural, investigative and administrative enforcement provisions necessary for the effective application of the Regulation.<br \/>\nPrior to the adoption of Law 5321\/2026, Law 4961\/2022 introduced Greece&#8217;s first horizontal legislative framework on emerging information and communication technologies, including provisions relating to artificial intelligence, digital governance and the use of AI systems, particularly within the public sector. Following the entry into force of Law 5321\/2026, a number of the AI-related provisions of Law 4961\/2022 were amended or repealed in order to align the national framework with the AI Act. Accordingly, Law 4961\/2022 remains relevant only insofar as its provisions continue to be in force, while Law 5321\/2026 now constitutes the principal national framework governing the implementation and enforcement of the AI Act.<\/p>\n<p>Where AI systems involve the processing of personal data, Regulation (EU) 2016\/679 (the General Data Protection Regulation \u2013 GDPR) and Law 4624\/2019, which supplements the GDPR in Greece, apply in parallel with the AI Act. Depending on the specific AI application, additional legislation may also be relevant, including the national framework implementing Directive (EU) 2022\/2555 (NIS2) on cybersecurity, as well as legislation governing consumer protection, product safety and product liability.<\/p>\n<p>At the time of writing, no further legislative proposals introducing a separate horizontal legal framework governing the deployment and use of AI in Greece are pending. Future regulatory developments are expected to focus primarily on the implementation of the AI Act through secondary legislation, guidance and regulatory practice at both EU and national level.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Artificial Intelligence \u2013 Are there any specific legal provisions (present or impending) in respect of the deployment and use of Large Language Models and\/or generative AI (including agentic AI)?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The principal legal framework governing Large Language Models (LLMs), generative AI and other general-purpose AI models (GPAI models) in Greece is Regulation (EU) 2024\/1689 (the AI Act), which entered into force on 1 August 2024 and is directly applicable in all EU Member States, including Greece. At national level, Law 5321\/2026 establishes the institutional framework for the implementation and enforcement of the AI Act.<\/p>\n<p>The AI Act adopts a risk-based approach and introduces a dedicated regime for general-purpose AI models, including Large Language Models and generative AI systems, with additional obligations applying to general-purpose AI models with systemic risk. Providers of such models are subject to transparency and copyright-related obligations, while providers of GPAI models with systemic risk must also assess and mitigate systemic risks, conduct model evaluations and implement appropriate cybersecurity measures. These provisions have applied since 2 August 2025.<\/p>\n<p>In addition, the European Commission has published the General-Purpose AI Code of Practice and Guidelines on general-purpose AI models, which are intended to facilitate and promote the consistent application of the relevant provisions of the AI Act across the European Union. Although the Code is voluntary and the Guidelines are not legally binding, both are expected to play an important role in demonstrating and assessing compliance with the AI Act.<\/p>\n<p>Greek law does not currently contain any specific provisions governing Large Language Models, generative AI or agentic AI beyond those laid down in the AI Act. Accordingly, such systems are primarily regulated under the AI Act and, where they involve the processing of personal data, the General Data Protection Regulation (GDPR) and the applicable national data protection framework.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Artificial Intelligence \u2013 Do technology contracts in your jurisdiction typically contain either mandatory (e.g. mandated by statute) or recommended provisions dealing with AI risk? If so, what issues or risks need to be addressed or considered in such provisions?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>In Greece, apart from the general provisions of the Civil Code and commercial legislation, there are currently no mandatory statutory provisions specifically regulating AI-related contractual clauses in technology agreements. However, the increasing use of AI systems and the entry into force of Regulation (EU) 2024\/1689 (the AI Act) have significantly increased the importance of contractual provisions dealing with AI-related risks. In practice, technology agreements increasingly address issues such as liability allocation, regulatory compliance, transparency, data protection, intellectual property, confidentiality, cybersecurity and the allocation of responsibilities between the parties.<\/p>\n<p>At national level, Law 5321\/2026 establishes the institutional framework for the implementation of the AI Act in Greece, while certain provisions of Law 4961\/2022 concerning the use of AI systems, particularly in the public sector, remain applicable.<\/p>\n<p>According to this national legal framework, every public contract involving the design or development of an AI system must include:<\/p>\n<ul>\n<li>transparency guarantees, ensuring that the contracting public authority receives the information necessary for the transparent operation of the AI system;<\/li>\n<li>provisions allowing the contracting authority to study the functionality of the AI system and its decision-making parameters and, where appropriate, make improvements; and<\/li>\n<li>contractual commitments ensuring compliance with the applicable legal framework, including the protection of fundamental rights, personal data and the principle of non-discrimination.<\/li>\n<\/ul>\n<p>Although technology agreements usually take the form of software licences, some are considerably more complex and include multiple products or services. This should be taken into account when drafting technology agreements, in order to clearly allocate responsibilities, define the contractual scope, address regulatory compliance obligations and allocate risks appropriately.<\/p>\n<p>It is common for software and technology agreements to include limitations of liability. Following the adoption of the AI Act, contractual provisions increasingly seek to allocate responsibilities between the parties having regard to their respective roles under the AI regulatory framework (e.g. provider, deployer or importer, where applicable), while also addressing compliance, cooperation and information-sharing obligations.<\/p>\n<p>From a judicial perspective, clauses that extensively limit the liability of a professional towards a consumer in B2C agreements, particularly where they have not been individually negotiated, are likely to be regarded as unfair and therefore unenforceable. By contrast, in B2B agreements, the parties generally enjoy greater contractual freedom, subject to the mandatory limitations of Greek civil law, including the prohibition on excluding liability for wilful misconduct or, in principle, gross negligence.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Artificial Intelligence \u2013 Do software or technology contracts in your jurisdiction typically contain provisions regarding the application or treatment of copyright or other intellectual property rights, or the ownership of outputs in the context of the use of AI systems?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Under Greek law, the protection of copyright and ownership of outputs in the context of AI is primarily governed by Law 2121\/1993 on Copyright and Related Rights, as supplemented by other statutory provisions. According to Article 2(1) of Law 2121\/1993, a work is defined as any original intellectual creation expressed in any form, provided that it reflects human intellectual effort. Consequently, copyright protection presupposes a sufficient degree of human creative contribution. Works generated autonomously and exclusively by AI systems, without substantive human contribution, are generally considered not to qualify for copyright protection under Greek law. Conversely, where AI serves as an auxiliary tool and the human user exercises creative control, copyright may vest in the human creator, although the required degree of human contribution must be assessed on a case-by-case basis.<\/p>\n<p>Software, computer programs and databases enjoy protection under Law 2121\/1993, while databases may also benefit from the sui generis database right. Technology agreements in Greece therefore typically incorporate explicit clauses addressing intellectual property rights, not only to ensure compliance with the applicable legal framework but also to allocate risk contractually. Such agreements commonly regulate the ownership or licensing of AI-generated outputs, subject to applicable law and any third-party rights, and include intellectual property warranties and indemnity provisions to mitigate the risk of infringement claims. This practice remains particularly important in cloud computing and AI-driven environments, where the risk of third-party intellectual property claims may be increased.<\/p>\n<p>It is also relevant to note that Law 5321\/2026, which establishes the national framework for the implementation of the AI Act in Greece and amends Law 4961\/2022, does not introduce specific rules on copyright ownership of AI-generated outputs. Accordingly, issues concerning the ownership and exploitation of AI-generated outputs continue to be governed primarily by the applicable intellectual property framework and the contractual arrangements agreed between the parties.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Blockchain \u2013 What are the principal laws (present or impending), if any, that govern (i) blockchain specifically (if any) and (ii) digital assets, including a brief explanation of the general purpose of those laws?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>In Greece, the legal framework governing blockchain and digital assets is still evolving but has been significantly shaped by recent national and EU legislation.<\/p>\n<p>At the national level, Law 4961\/2022 on Emerging Information and Communication Technologies introduced definitions and general principles relating to blockchain and distributed ledger technology (DLT), aiming to facilitate the development and use of these technologies while ensuring compliance with the applicable legal and regulatory framework. Although Law 4961\/2022 constitutes the first legislative recognition of blockchain technology in Greece, it does not establish a comprehensive regulatory regime specifically governing blockchain applications.<br \/>\nWith respect to digital assets, Law 5193\/2025 supplements Regulation (EU) 2023\/1114 on Markets in Crypto-assets (MiCA) by introducing the national measures necessary for its implementation in Greece. In particular, it designates the competent supervisory authorities (specifically the Hellenic Capital Market Commission and the Bank of Greece), specifies their powers, provides for administrative measures and sanctions and establishes the national supervisory framework for entities falling within the scope of MiCA.<\/p>\n<p>Law 4557\/2018 on the prevention and suppression of money laundering and terrorist financing, as amended, also remains applicable. It defines virtual assets and virtual asset service providers (VASPs) and imposes registration, customer due diligence and other anti-money laundering compliance obligations in line with the applicable EU anti-money laundering framework.<\/p>\n<p>At the EU level, Regulation (EU) 2023\/1114 on Markets in Crypto-assets (MiCA) establishes a harmonised framework for the issuance of crypto-assets and the provision of crypto-asset services throughout the European Union. As a directly applicable Regulation, MiCA introduces authorisation, governance, prudential, conduct of business and disclosure requirements for issuers of crypto-assets and crypto-asset service providers (CASPs), and is supplemented in Greece by Law 5193\/2025.<br \/>\nIn addition, crypto-assets that qualify as financial instruments fall outside the scope of MiCA and remain subject to Law 4514\/2018, which transposed Directive 2014\/65\/EU (MiFID II) into Greek law.<\/p>\n<p>From a data protection perspective, blockchain technologies may also raise important compliance issues under the GDPR. In this regard, the European Data Protection Board (EDPB) adopted Guidelines 02\/2025 on the processing of personal data through blockchain technologies. These Guidelines provide important guidance on issues such as the identification of controllers and processors in decentralised environments, data minimisation, storage limitation and the exercise of data subject rights in blockchain-based systems.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Search Engines and Marketplaces \u2013 Please summarise the principal laws (present or impending), if any, that govern search engines and marketplaces, including a brief explanation of the general purpose of those laws.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Under Greek Law 5160\/2024, which implements the NIS2 Directive, both search engine providers and online marketplace providers fall within the category of &#8220;digital providers&#8221; set out in Annex II of the legislation. Accordingly, they are subject to the obligations laid down therein, including registration with the National Cybersecurity Authority, the implementation of cybersecurity risk-management measures, incident reporting obligations and the appointment of an Information and Communication Systems Security Officer (ICSSO).<\/p>\n<p>Regulation (EU) 2019\/1150 applies to online intermediation services and online search engines provided, or offered to be provided, to business users and corporate website users, respectively, that have their place of establishment or residence in the Union and that, through those services, offer goods or services to consumers located in the Union. Its purpose is to ensure transparency, fairness and effective redress for business users and corporate website users. Accordingly, the obligations laid down in Regulation (EU) 2019\/1150 apply to online marketplaces and online search engines falling within its scope.<\/p>\n<p>Online marketplaces and search engines are also subject to the Digital Services Act (DSA) and, where applicable, the Digital Markets Act (DMA), which establish the core EU regulatory framework for digital intermediary services and gatekeepers.<\/p>\n<p>In addition, online marketplaces are subject to the Greek Consumer Protection Law (Law 2251\/1994, as amended), which has been amended to implement, inter alia, the Omnibus Directive (EU) 2019\/2161. The law imposes specific transparency obligations on online marketplaces, including the obligation to inform consumers whether the third-party supplier is acting as a trader, whether consumer protection rules apply to the contract concluded with the third-party supplier, the main parameters determining the ranking of goods, services or digital content presented to consumers, and, where applicable, how contractual obligations are shared between the online marketplace provider and the third-party supplier.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Social Media \u2013 Please summarise the principal laws (present or impending), if any, that govern social media and online platforms, including a brief explanation of the general purpose of those laws?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The regulatory framework applicable to social media and online platforms in Greece comprises both EU instruments and national implementing laws, with the objective of ensuring transparency, safety, cybersecurity, and fair market conduct in digital services. The principle laws that govern social media and online platforms are the following:<\/p>\n<ol>\n<li><strong> Digital Services Act (DSA) \u2013 Regulation (EU) 2022\/2065 and Greek Law 5099\/2024: <\/strong>The DSA, fully applicable since 17 February 2024, establishes harmonized rules for digital intermediary services targeting users in the EU, regardless of the provider\u2019s country of establishment. It introduces layered obligations for online platforms, including:<\/li>\n<\/ol>\n<p>&#8211;\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Notice-and-action mechanisms for illegal content,<\/p>\n<p>&#8211;\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Transparency in terms of service and recommender systems,<\/p>\n<p>&#8211;\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Special risk assessment and mitigation duties for Very Large Online Platforms (VLOPs)<\/p>\n<p>In Greece, the DSA is complemented by Law 5099\/2024, which<\/p>\n<p>&#8211;\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Establishes national supervisory bodies for DSA enforcement,<\/p>\n<p>&#8211;\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Defines procedural rules and sanctions for non-compliance, and<\/p>\n<p>&#8211;\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Designates competent authorities for oversight in the domestic market.<\/p>\n<ol start=\"2\">\n<li><strong> Audiovisual Content and User-Generated Media (Law 4779\/2021): <\/strong>This law transposes the Audiovisual Media Services Directive (2018\/1808\/EU) and brings video-sharing platforms and social media services under Greek jurisdiction with respect to their audiovisual content, provided such content (user-generated or otherwise) is a principal function of the service and serves an informational, educational or entertainment purpose, absent editorial control. Obligations include:<\/li>\n<\/ol>\n<p>&#8211;\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Protection of minors,<\/p>\n<p>&#8211;\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Restrictions on hate speech and incitement to violence,<\/p>\n<p>&#8211;\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Requirements for audiovisual commercial communications.<\/p>\n<ol start=\"3\">\n<li><strong> Presidential Decree 131\/2003 (Platform Liability): <\/strong>Social media platforms are also regulated under PD 131\/2003, which transposed the E-Commerce Directive (2000\/31\/EC). The decree offers liability exemptions for intermediary services (hosting, caching, mere conduit) as long as providers remain neutral and act expeditiously upon acquiring knowledge of illegal content.<\/li>\n<li><strong> NIS2 Directive and Greek Law 5160\/2024 (cybersecurity obligations): <\/strong>Law 5160\/2024 transposes the NIS2 Directive, expanding the scope of cybersecurity obligations to include providers of social networking services as \u201cimportant entities\u201d. These providers are now subject to:<\/li>\n<\/ol>\n<p>&#8211;\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Risk management and incident reporting obligations,<\/p>\n<p>&#8211;\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Governance and compliance measures,<\/p>\n<p>&#8211;\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Oversight by competent national cybersecurity authorities.<\/p>\n<ol start=\"5\">\n<li><strong> GDPR and Law 4624\/2019 (Data Protection and Privacy): <\/strong>Social media platforms are subject to the General Data Protection Regulation (GDPR), implemented through Law 4624\/2019, and to Law 3471\/2006 (E-Privacy Directive), governing electronic communications and data processing.<\/li>\n<\/ol>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Social Media \u2013 What is the maximum sanction that can be imposed by a regulator in the event of a breach of any applicable online safety laws?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The most severe sanctions under the applicable online safety laws derive from directly applicable EU regulations and their national implementation:<\/p>\n<ul>\n<li>Under the Digital Services Act (DSA), regulators may impose administrative fines of up to 6% of the provider\u2019s total annual worldwide turnover for violations of the DSA. In Greece, enforcement is governed by Law 5099\/2024.<\/li>\n<li>\u00a0Under the General Data Protection Regulation (GDPR), breaches involving personal data can trigger fines of up to \u20ac20 million or 4% of global turnover, whichever is higher.<\/li>\n<li>For violations of audiovisual content rules under Law 4779\/2021, the National Council for Radio and Television may impose fines up to \u20ac500,000 per infringement and, in exceptional cases, suspend access to content or services.<\/li>\n<li>Under the NIS2 Directive, transposed into Greek law via Law 5160\/2024, social media platforms deemed \u201cimportant entities\u201d may face fines up to \u20ac7 million or 1.4% of annual turnover for failure to implement cybersecurity and incident response obligations.<\/li>\n<\/ul>\n<p>In addition to financial penalties, criminal sanctions may apply in cases involving illegal content (e.g. child sexual abuse or hate speech).<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Spatial Computing \u2013 Please summarise the principal laws (present or impending), if any, that govern spatial computing, including a brief explanation of the general purpose of those laws?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Greece has not adopted a dedicated legal framework governing spatial computing technologies, including augmented reality (AR), virtual reality (VR), extended reality (XR) and the metaverse. Instead, these technologies are regulated through existing EU and Greek legislation on data protection, cybersecurity, product safety, intellectual property and digital governance.<\/p>\n<p>The GDPR applies in full to the processing of personal data in immersive digital environments, particularly for biometric data where processed, and imposes obligations relating to lawful processing, transparency and accountability. Its application may raise particular challenges in allocating controller and processor responsibilities and determining jurisdiction in complex, multi-layered virtual environments.<\/p>\n<p>Cybersecurity obligations derive principally from Directive (EU) 2022\/2555 (NIS 2), as implemented in Greece by Law 5160\/2024, while additional requirements will be introduced by the forthcoming EU Cyber Resilience Act (CRA). Greek Laws 5002\/2022 and 4961\/2022 also strengthen the national framework on cybersecurity and digital governance. Hardware used in immersive environments, such as VR and AR headsets, is further subject to the General Product Safety Regulation (EU) 2023\/988, including its requirements relating to product safety and, where relevant, cybersecurity risks.<\/p>\n<p>Existing intellectual property legislation applies equally to virtual environments. Copyright is governed by Law 2121\/1993 and trademarks by Law 4679\/2020, covering issues such as the unauthorised use of trademarks in virtual spaces, digital assets and AI-generated content. However, the decentralised nature of many virtual environments may present practical challenges for the enforcement of intellectual property rights.<\/p>\n<p>Greece has also addressed certain legal issues relating to smart contracts, which are closely associated with blockchain technologies that may underpin virtual environments. Law 4961\/2022 recognises the legal validity and evidentiary value of smart contracts while providing that the general rules governing contractual validity continue to apply. It also enables courts to grant appropriate remedies where blockchain-based transactions are found to be invalid.<\/p>\n<p>Although Greece has not enacted legislation specifically regulating spatial computing or the metaverse, the combined application of EU and national rules on data protection, cybersecurity, product safety, intellectual property and blockchain technologies provides the principal legal framework governing these technologies, with further EU regulatory developments expected.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Quantum Computing \u2013 Please summarise the principal laws (present or impending), if any, that govern quantum computing and\/or issues around quantum cryptography, including a brief explanation of the general purpose of those laws?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>There are currently no specific laws in force or proposed that directly govern quantum computing or quantum cryptography. Existing general frameworks on cybersecurity and data protection may become relevant as the technology evolves.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Datacentres \u2013 Does your jurisdiction have any specific regulations that apply to data centres?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Yes, Greece has adopted a number of legislations that apply to data centres. Key pieces of legislation<br \/>\ninclude:<\/p>\n<ul>\n<li>Law 5069\/2023, which sets out building terms, construction requirements, and permissible land uses for data centres, amending Law 4442\/2016.<\/li>\n<li>Law 4933\/2022, which transposes Directive (EU) 2019\/2161 and includes provisions on consumer protection and transparency.<\/li>\n<li>Law 5160\/2024, which transposes the NIS 2 Directive, establishing enhanced cybersecurity obligations for essential and important entities.<\/li>\n<li>\u00a0Law 4014\/2011, which governs the environmental permitting procedures.<\/li>\n<li>Law 4759\/2020, which relates to the modernization of spatial and urban planning.<\/li>\n<li>Law 4864\/2021, which introduces strategic investment incentives.<\/li>\n<\/ul>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">General \u2013 What are your top 3 predictions for significant developments in technology law in the next 3 years?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Changes and innovations in technology law are and are expected to be rapid in the next few years. In particular, only some of the sectors where significant growth is expected are the following:<\/p>\n<p><strong>1.AI Governance and Liability<\/strong><\/p>\n<p>The relationship between artificial intelligence systems and legal accountability is expected to remain a key area of regulatory, legislative and judicial focus. As the obligations introduced by the EU AI Act come into effect progressively, Greek and EU legislators, regulators and courts will increasingly be required to address complex issues relating to algorithmic transparency, human oversight, AI governance frameworks, and the allocation of liability across the AI value chain.<\/p>\n<p>Furthermore, product liability litigation involving software, AI-enabled systems and other emerging technologies is expected to increase in Greece. This trend is likely to be reinforced by the recast Product Liability Directive (EU) 2024\/2853, which expands the scope of the EU product liability regime to cover software and AI systems. Member States are required to transpose the Directive into national law by December 2026, following which its provisions will progressively shape the liability landscape for businesses operating across the AI ecosystem and increase the need for careful assessment of compliance obligations and potential exposure to liability risks arising from the development, deployment and use of AI technologies.<\/p>\n<p><strong>2. Strengthening of cybersecurity and digital resilience requirements:<\/strong><\/p>\n<p>Following the implementation of the NIS 2 Directive and the continued development of the EU cybersecurity framework, organisations operating critical infrastructure and digital services will face enhanced cybersecurity, incident reporting and risk management obligations. Regulatory scrutiny and enforcement in relation to cyber resilience are expected to increase.<\/p>\n<p><strong>3. Emerging Technologies Legislation<\/strong>:<\/p>\n<p>Greece has already adopted new legislation on emerging information and communication technologies. This trend is expected to continue, with new legislation being introduced to strengthen digital governance and address the challenges posed by novel technologies, including IoT and robotics.<br \/>\nGeneral \u2013 Do technology contracts in your country commonly include provisions to address sustainability \/ net-zero obligations or similar environmental commitment?<\/p>\n<p>That is not usually the case.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\r\n<div class=\"word-count-hidden\" style=\"display:none;\">Estimated word count: <span class=\"word-count\">11476<\/span><\/div>\r\n\r\n\t\t\t<\/ol>\r\n\r\n<script type=\"text\/javascript\" src=\"\/wp-content\/themes\/twentyseventeen\/src\/jquery\/components\/filter-guides.js\" async><\/script><\/div>"}},"_links":{"self":[{"href":"https:\/\/my.legal500.com\/guides\/wp-json\/wp\/v2\/comparative_guide\/146994","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/my.legal500.com\/guides\/wp-json\/wp\/v2\/comparative_guide"}],"about":[{"href":"https:\/\/my.legal500.com\/guides\/wp-json\/wp\/v2\/types\/comparative_guide"}],"wp:attachment":[{"href":"https:\/\/my.legal500.com\/guides\/wp-json\/wp\/v2\/media?parent=146994"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}