On 27.04.2016, the European Union adopted Regulation EU 2016/679 on the protection of natural persons with regard to the processing of their personal data and on the free movement of such data. The Regulation, which bears the name “General Data Protection Regulation” (GDPR), came into force on 25.05.2018, automatically repealing Directive 95/46/EC.
The entry into force of the GDPR is direct and does not require the enactment of any national law for its incorporation into Greek legislation. Nevertheless, member states are permitted to adopt national measures on specific matters (“escape clauses”).
As mentioned above, the General Regulation came into force on 25.05.2018, requiring all public and private sector entities of EU member states to align and comply with the new provisions and the level of protection afforded to personal data.
A number of businesses — some to a lesser and others to a greater extent — have already begun their efforts to comply with the provisions of the Regulation. However, due to the complexity of the newly introduced provisions and the changes brought about by the Regulation, particularly in respect of the obligations of the parties involved in processing, full alignment is not expected to occur immediately.
The existing national legal framework
The protection of personal data has always constituted a fundamental issue and a societal need that had to be addressed.
In Greece, personal data have, until now, been protected by Law 2472/1997 (On the Protection of Individuals from the Processing of Personal Data), which transposed the (now repealed) Directive 95/46/EC (On the protection of individuals with regard to the processing of personal data and on the free movement of such data).
The protection of personal data following the GDPR
Following the entry into force of Regulation 679/2016, the framework for the protection of personal data
becomes more stringent, as, among other things, the following are provided for:
• Accountability of the Data Controller and the Data Processor,
• collection of data strictly for specific purposes,
• privacy-by-design requirements for information systems,
• written policies for collection, management, and security protection,
• expansion of the rights of data subjects and transparent policies for satisfying the new rights of data subjects,
• carrying out a Data Protection Impact Assessment for the potential risks and consequences that processing may entail,
• stricter criminal and administrative sanctions, with increased fines based on the business’s turnover,
• the existence of a Data Protection Officer as an internal body that will act independently and ensure compliance with the provisions of the Regulation within each business/company,
• procedures for notifying the Competent Authority (within 72 hours) and the affected individuals (where required) of any personal data breach.
In summary, it could be said that the new Regulation creates new obligations for every business. Most of these obligations existed previously, but were very often not taken seriously into account. From now on, however, the need to avoid the unpleasant consequences arising from the ignorance and negligence of the parties involved has rendered adaptation to the provisions and requirements of the new Regulation unavoidable.
FREQUENTLY ASKED QUESTIONS ON GDPR – PERSONAL DATA PROTECTION
1. What do I face if my personal data have been leaked?
When a business, bank, hospital or public authority unlawfully processes your data or suffers a breach, the protective framework of the General Regulation 2016/679 (GDPR) and Law 4624/2019 is activated. Your rights include information, access to data, rectification, erasure (“right to be forgotten”), restriction of processing and objection. In parallel, the data controller is obliged to notify you of the breach incident where there is a high risk to your rights. The breach gives rise to a claim for damages, both for material and moral damages, irrespective of any administrative sanctions that may be imposed on the responsible entity.
2. What can I do when my data are breached?
Initially, a written request is submitted to the data controller (company, authority, website) with specific content, e.g. erasure, rectification or information about the processing. If they do not respond within one month or reject the request, a complaint is submitted to the Hellenic Data Protection Authority (HDPA). In parallel, a lawsuit is filed before the Multi-Member Court of First Instance for the award of damages. In serious cases, such as unlawful surveillance, interception or use of data for extortion, a criminal complaint is also filed with the Public Prosecutor’s Office of First Instance, which is then forwarded to the Cybercrime Prosecution Directorate. The correct sequence of actions and the gathering of evidence from the outset significantly strengthen the case.
3. Within what timeframe must I take legal action?
The complaint to the Hellenic Data Protection Authority is, as a rule, submitted within one year from the time you became aware of the breach. The claim for damages from a tort is subject to a five-year limitation period from the time of knowledge of the damage and of the liable party, and in any event after twenty years from the breach. For criminal offenses related to personal data, the general limitation periods of the Penal Code (PK) apply. In any case, immediate reaction is critical because digital evidence (logs, messages, log files) is retained by providers for a limited period.
4. What documents and evidence do I need?
All correspondence (email, sms, letters) with the data controller is gathered, as well as screenshots from websites or platforms where your data appeared, copies of contracts or terms of use you signed, and any breach notification you received. Useful items include medical certificates if psychological distress was caused, evidence of financial loss (withdrawals, charges) and certifications from banks or providers. In cases of database leaks, the official announcement by the company or news reports documenting the incident are crucial. All material is preserved in original files without any modification.
5. What damages can I realistically claim?
The amount of damages depends on the nature of the data (ordinary or sensitive, such as health, political beliefs, sexual orientation), the extent of the leak, the number of third parties who became aware and the consequences for your life and reputation. Case law awards substantial sums for moral damages where psychological suffering, stigmatization or professional repercussions are demonstrated. In parallel, if material loss was caused (e.g. fraud following a leak of banking data), this is also claimed. The Hellenic Data Protection Authority may impose administrative fines on the responsible entity of up to EUR 20 million or 4% of global annual turnover, a factor that strengthens the victim’s negotiating position for an out-of-court settlement.
6. What is the role of the lawyer in such cases?
The lawyer assesses whether there is a breach of the provisions of the GDPR, drafts the initial extra-judicial notice to the data controller with precise legal grounds, submits the complaint to the Hellenic Data Protection Authority and represents the client in the hearing before it. Subsequently, the lawyer files a lawsuit for damages and, where required, submits a criminal complaint to the Public Prosecutor’s Office of First Instance for criminal offenses such as unauthorized access to an information system or unlawful processing of data. The experience of Ziamparas D. & Associates Law Firm in cybercrime and data breach matters ensures the proper technical handling of digital evidence and coordination with specialist IT expert witnesses where needed.


