GREnforcement: August 2, 2026

Greece — HDPA + EU AI Act + Hellenic AI Strategy: AI Compliance Requirements

Greece's Hellenic Data Protection Authority (HDPA / Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα — APDPX) enforces GDPR and has issued AI-specific guidance, particularly for public sector AI in healthcare and e-government. Greece published its "National Strategy for Artificial Intelligence 2025" through the Ministry of Digital Governance. Greece hosts the Archimedes AI research centre and is developing a national AI governance framework aligned with EU standards.

Key Facts

Effective Date

January 1, 2021

Enforcement Begins

August 2, 2026

Maximum Penalty

GDPR (HDPA): up to €20M or 4% global turnover. EU AI Act: €35M or 7% global turnover.

What Your Business Must Do

3 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

EU AI Act Compliance (Mandatory)

Critical

Greece is subject to the EU AI Act. AI systems used in Greece or processing Greek residents' data must comply. The Ministry of Digital Governance coordinates national implementation. High-risk AI in Greek public administration, banking (Bank of Greece oversight), and healthcare requires conformity assessment and registration.

Deadline: August 2, 2026

HDPA AI and GDPR Enforcement

High Priority

HDPA requires DPIA for all AI profiling of Greek residents, explicit consent documentation for sensitive AI processing, and individual rights fulfilment within GDPR timelines. HDPA has conducted investigations into facial recognition AI in Greek public spaces and issued guidance on AI in employment decisions.

Greek National AI Strategy 2025

Medium Priority

Greece's National AI Strategy establishes trustworthy AI principles for public and private sector. Organizations offering AI to Greek public authorities must comply with Ministry of Digital Governance AI procurement standards, including algorithmic transparency requirements and bias auditing.

Frequently Asked Questions

Does Greece — HDPA + EU AI Act + Hellenic AI Strategy apply to my business?

Greece's Hellenic Data Protection Authority (HDPA / Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα — APDPX) enforces GDPR and has issued AI-specific guidance, particularly for public sector AI in healthcare and e-government. Greece published its "Nat. Use ComplianceIQ's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under Greece — HDPA + EU AI Act + Hellenic AI Strategy is: GDPR (HDPA): up to €20M or 4% global turnover. EU AI Act: €35M or 7% global turnover.. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with Greece — HDPA + EU AI Act + Hellenic AI Strategy?

The 3 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. ComplianceIQ generates all required documents automatically.

Official Source

https://www.dpa.gr/en/artificial-intelligence

Last updated: 2026-04-14 — verify at source before relying on this information.

Don't leave compliance to chance

ComplianceIQ scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan