Skip to content
EUMEDIUM coverage1 enforcement action

Cyprus — GDPR + EU AI Act + Cyprus Digitalization Strategy + CPDBP: AI Compliance Requirements

Cyprus's Commissioner for Personal Data Protection (CPDBP) supervises GDPR compliance. Cyprus has positioned itself as a regional tech and financial services hub (serving Middle East and Eastern Mediterranean markets). The Cyprus Deputy Ministry of Research, Innovation and Digital Policy coordinates EU AI Act implementation. Cyprus is developing AI in legal services, shipping, and financial technology.

Summary of publicly-available regulatory text as of 2026-08-22. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

May 25, 2018

Enforcement Begins

August 2, 2026

Maximum Penalty

€20,000,000 or 4% of global turnover (GDPR); EU AI Act: €35M or 7% global turnover

What Your Business Must Do

2 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

GDPR AI Compliance — CPDBP Supervision

Critical

Cyprus CPDBP enforces GDPR for AI systems processing Cypriot residents' data. Cyprus hosts numerous international businesses serving Middle East and North African markets — these operations often process cross-border personal data through AI systems requiring SCCs or adequacy decisions. DPIA required for: AI in financial services, legal AI (very active sector in Cyprus), AI-driven AML/KYC.

GDPR Art. 22 (automated decisions); Art. 35 (DPIA)

EU AI Act — AI in Financial Services & Shipping

High Priority

Cyprus is a major maritime and financial services jurisdiction. AI used in ship management (crew scheduling, route optimization, predictive maintenance) and financial services (fund management, forex, payments) may trigger EU AI Act high-risk classification. Cypriot-registered financial entities should assess AI systems against Annex III and coordinate with CySEC (securities regulator). NOTE: the "Digital Omnibus" amendment (Regulation (EU) 2026/1744, in force 2026-07-27) deferred stand-alone high-risk (Annex III) conformity obligations from 2026-08-02 to 2027-12-02.

Deadline: December 2, 2027

EU AI Act Art. 6, Annex III (high-risk classification); Art. 16 (provider obligations); Art. 43 (conformity assessment); Art. 26 (deployer obligations)

Who Does This Apply To?

Applies to: any organisation established in Cyprus, and any organisation outside Cyprus processing the personal data of Cypriot residents through AI systems — GDPR applies with extraterritorial reach (Art. 3), obligations attaching to the processing activity rather than company size, with no general small-business exemption. Because Cyprus hosts international businesses serving Middle East and North African markets, AI operations often involve cross-border transfers requiring Standard Contractual Clauses or an adequacy basis, and must comply with both Cypriot GDPR and the destination country's data law. As an EU member state, Cyprus is fully subject to the EU AI Act: AI in financial services (fund management, forex, payments) and ship management (crew scheduling, route optimisation, predictive maintenance) may trigger Annex III high-risk classification, coordinated with CySEC for regulated entities. The Commissioner for Personal Data Protection (CPDBP) requires a DPIA for AI in financial, legal and AML/KYC services and Article 22 human review allowing compliance officers to override AI risk scores before restricting customer accounts. Penalties reach €20M / 4% of global turnover under GDPR and €35M / 7% under the EU AI Act.

Recent Enforcement Actions

2024-Q4Source verified· as of 2026-08-22

Against:

Recent Regulatory Guidance

guidance2025-06

CPDBP AI and GDPR — Cross-Border Data Flows for AI in Cyprus

Cyprus CPDBP guidance for financial and legal AI services: (1) AI processing Middle East or North Africa client data through Cyprus must comply with both Cypriot GDPR and the destination country's data law; (2) CySEC-regulated entities using AI for investment recommendations must disclose AI involvement to clients; (3) shipping AI processing crew personal data requires a DPIA and documented processing agreements. Separately, the Central Bank of Cyprus's AML/CFT Directive (R.A.A. 120/2025, in force 2025-06-02) explicitly addresses use of analytics, machine learning, and automated transaction monitoring for AML/fraud-prevention purposes.

Frequently Asked Questions

Does Cyprus — GDPR + EU AI Act + Cyprus Digitalization Strategy + CPDBP apply to my business?

Cyprus's Commissioner for Personal Data Protection (CPDBP) supervises GDPR compliance. Cyprus has positioned itself as a regional tech and financial services hub (serving Middle East and Eastern Mediterranean markets). The Cyprus Deputy Ministry of… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under Cyprus — GDPR + EU AI Act + Cyprus Digitalization Strategy + CPDBP is: €20,000,000 or 4% of global turnover (GDPR); EU AI Act: €35M or 7% global turnover. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with Cyprus — GDPR + EU AI Act + Cyprus Digitalization Strategy + CPDBP?

The 2 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://www.dataprotection.gov.cy/dataprotection/dataprotection.nsf/home_en/home_en?opendocument

Last updated: 2026-08-22 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan