Greece — HDPA + EU AI Act + Hellenic AI Strategy: AI Compliance Requirements
Greece's Hellenic Data Protection Authority (HDPA / Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα — APDPX) enforces GDPR and has issued AI-specific guidance, particularly for public sector AI in healthcare and e-government. Greece published its "National Strategy for Artificial Intelligence 2025" through the Ministry of Digital Governance. Greece hosts the Archimedes AI research centre and is developing a national AI governance framework aligned with EU standards.
Key Facts
January 1, 2021
August 2, 2026
GDPR (HDPA): up to €20M or 4% global turnover. EU AI Act: €35M or 7% global turnover.
What Your Business Must Do
3 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.
EU AI Act Compliance (Mandatory)
CriticalGreece is subject to the EU AI Act. AI systems used in Greece or processing Greek residents' data must comply. The Ministry of Digital Governance coordinates national implementation. High-risk AI in Greek public administration, banking (Bank of Greece oversight), and healthcare requires conformity assessment and registration.
Deadline: August 2, 2026
HDPA AI and GDPR Enforcement
High PriorityHDPA requires DPIA for all AI profiling of Greek residents, explicit consent documentation for sensitive AI processing, and individual rights fulfilment within GDPR timelines. HDPA has conducted investigations into facial recognition AI in Greek public spaces and issued guidance on AI in employment decisions.
Greek National AI Strategy 2025
Medium PriorityGreece's National AI Strategy establishes trustworthy AI principles for public and private sector. Organizations offering AI to Greek public authorities must comply with Ministry of Digital Governance AI procurement standards, including algorithmic transparency requirements and bias auditing.
Frequently Asked Questions
Does Greece — HDPA + EU AI Act + Hellenic AI Strategy apply to my business?
Greece's Hellenic Data Protection Authority (HDPA / Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα — APDPX) enforces GDPR and has issued AI-specific guidance, particularly for public sector AI in healthcare and e-government. Greece published its "Nat. Use ComplianceIQ's free scanner to get a personalized assessment in under 5 minutes.
What is the penalty for non-compliance?
The maximum penalty under Greece — HDPA + EU AI Act + Hellenic AI Strategy is: GDPR (HDPA): up to €20M or 4% global turnover. EU AI Act: €35M or 7% global turnover.. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.
How do I comply with Greece — HDPA + EU AI Act + Hellenic AI Strategy?
The 3 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. ComplianceIQ generates all required documents automatically.
Official Source
https://www.dpa.gr/en/artificial-intelligenceLast updated: 2026-04-14 — verify at source before relying on this information.
Don't leave compliance to chance
ComplianceIQ scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.
Start your free compliance scan