Skip to content
Questa e una traduzione di cortesia. La versione inglese e la versione ufficiale e giuridicamente vincolante. Visualizza versione inglese
GRMEDIUM coverage1 enforcement action

Greece — HDPA + EU AI Act + Hellenic AI Strategy: AI Compliance Requirements

Greece's Hellenic Data Protection Authority (HDPA / Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα — APDPX) enforces GDPR and has issued AI-specific guidance, particularly for public sector AI in healthcare and e-government. Greece published its "National Strategy for Artificial Intelligence 2025" through the Ministry of Digital Governance. Greece hosts the Archimedes AI research centre and is developing a national AI governance framework aligned with EU standards.

Summary of publicly-available regulatory text as of 2026-08-22. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

January 1, 2021

Enforcement Begins

August 2, 2026

Maximum Penalty

GDPR (HDPA): up to €20M or 4% global turnover. EU AI Act: €35M or 7% global turnover.

What Your Business Must Do

3 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

EU AI Act Compliance (Mandatory)

Critical

Greece is subject to the EU AI Act. AI systems used in Greece or processing Greek residents' data must comply. The Ministry of Digital Governance coordinates national implementation. High-risk AI in Greek public administration, banking (Bank of Greece oversight), and healthcare requires conformity assessment and registration. NOTE: the EU AI Act high-risk (Annex III) conformity-assessment deadline was deferred EU-wide from 2026-08-02 to 2027-12-02 by the "Digital Omnibus" amendment, Regulation (EU) 2026/1744 (in force 2026-07-27) -- Article 50 transparency obligations still apply from 2026-08-02, but conformity assessment/technical documentation/registration for stand-alone high-risk systems is not due until 2027-12-02 (2028-08-02 for Annex I product-embedded high-risk systems).

Deadline: December 2, 2027

EU AI Act Art. 6, Annex III (high-risk classification); Art. 16 (provider obligations); Art. 43 (conformity assessment); Art. 26 (deployer obligations)

HDPA AI and GDPR Enforcement

High Priority

HDPA requires DPIA for all AI profiling of Greek residents, explicit consent documentation for sensitive AI processing, and individual rights fulfilment within GDPR timelines. HDPA has conducted investigations into facial recognition AI in Greek public spaces and issued guidance on AI in employment decisions.

GDPR Art. 9 (special-category biometric data — no legitimate-interest basis available); Art. 22 (automated decisions); Art. 35 (DPIA)

Greek National AI Strategy 2025

Medium Priority

Greece's National AI Strategy establishes trustworthy AI principles for public and private sector. Organizations offering AI to Greek public authorities must comply with Ministry of Digital Governance AI procurement standards, including algorithmic transparency requirements and bias auditing.

Who Does This Apply To?

Applies to: any organisation established in Greece, and any organisation outside Greece processing the personal data of Greek residents through AI systems — GDPR applies with extraterritorial reach (Art. 3), obligations attaching to the processing activity rather than company size, with no general small-business exemption. As an EU member state, Greece is fully subject to the EU AI Act, with national implementation coordinated by the Ministry of Digital Governance: AI used in Greece or processing Greek residents' data must be risk-classified, and high-risk AI in public administration, banking (Bank of Greece oversight) and healthcare requires conformity assessment and registration. The Hellenic Data Protection Authority (HDPA) requires a DPIA for all AI profiling of Greek residents, explicit consent for sensitive-data AI processing, and — for public-sector AI decisions with significant effects (e-government, automated tax assessment, social-benefit AI) — Article 22 human review and citizen-facing explanations. Penalties reach €20M / 4% of global turnover under GDPR and €35M / 7% under the EU AI Act.

Recent Enforcement Actions

2022-07-13Source verified· as of 2026-08-22

Against:

Recent Regulatory Guidance

guidance2024

HDPA AI and GDPR — Guidelines for AI in Greek Public Administration

HDPA guidelines for AI in the Greek public sector (e-government, tax AI, social-benefit AI): (1) all public-sector AI decisions with significant effects require GDPR Art. 22 human review; (2) automated tax-assessment AI must provide citizen-facing explanations; (3) the Ministry of Digital Governance must publish an AI systems register for public accountability.

Frequently Asked Questions

Does Greece — HDPA + EU AI Act + Hellenic AI Strategy apply to my business?

Greece's Hellenic Data Protection Authority (HDPA / Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα — APDPX) enforces GDPR and has issued AI-specific guidance, particularly for public sector AI in healthcare and e-government. Greece published its… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under Greece — HDPA + EU AI Act + Hellenic AI Strategy is: GDPR (HDPA): up to €20M or 4% global turnover. EU AI Act: €35M or 7% global turnover.. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with Greece — HDPA + EU AI Act + Hellenic AI Strategy?

The 3 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://www.dpa.gr/en/artificial-intelligence

Last updated: 2026-08-22 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan