Greece - Digital Governance Framework (4961/2022)

Law 4961/2022: Emerging information and communication technologies, strengthening digital governance and other provisions

Νόμος 4961/2022: Αναδυόμενες πληροφοριακές και επικοινωνιακές τεχνολογίες, ενίσχυση της ψηφιακής διακυβέρνησης και άλλες διατάξεις

Greece

RAI-GR-NA-4EICTXX-2022
Effective: July 27, 2022
In Force(In Force)
ActGovernance and OversightConformity Assessment and Registration
Export PDF

Law 4961/2022 (published in FEK A' 146 on 27 July 2022) establishes a horizontal national framework in Greece for emerging information and communication technologies (AI, IoT, DLT/blockchain, 3D printing, UAV postal uses, smart contracts), strengthens digital governance and public‑sector digital processes, and adds sectoral obligations for cybersecurity, transparency, documentation and liability. It creates institutional bodies and registries, requires impact assessments and documentation, and sets enforcement and surveillance powers for national authorities.

Summary

Law 4961/2022, published in the Greek Government Gazette (FEK A' 146) on 27 July 2022, creates a comprehensive national framework to regulate and support the adoption and safe use of emerging information and communication technologies across the public and private sectors in Greece. The Act covers a wide scope of technologies — notably artificial intelligence (AI) systems, Internet of Things (IoT) devices, distributed ledger technologies (DLT / blockchain), 3D printing processes and files, unmanned aerial systems (UAS) employed for postal/logistics services, and smart contracts — and sets mandatory governance, documentation, risk‑assessment and cybersecurity measures.

Key structural elements: the law establishes institutional arrangements to coordinate national AI policy and digital governance, including a Coordinating/Steering Committee for AI, provisions for an Observatory on Hybrid Threats (as an advisory body to the National Cybersecurity Authority), and duties for the Ministry of Digital Governance and the General Directorate of Cybersecurity. For public bodies the law tightens controls on the use of algorithmic systems: public authorities (except defence and internal security where the law provides carve‑outs) may only deploy AI systems where authorisation is provided by law and adequate safeguards are in place. Entities deploying AI in certain sensitive uses must undertake an algorithmic impact assessment (AIA) in addition to any GDPR/data protection impact assessment, and keep registries describing model technical characteristics, affected population sizes, and data sources.

Cybersecurity and resilience: the Act designates the General Directorate of Cybersecurity within the Ministry of Digital Governance as responsible for national cybersecurity coordination and as the national authority to support conformity assessment and market surveillance for ICT products and services. Central government bodies must appoint a Responsible Officer for Information and Communications Systems Security (ΥΑΣΠΕ) and maintain risk‑analysis and security policies; critical public infrastructure must appoint security coordinators.

Product and supply‑chain obligations: Law 4961/2022 imposes specific duties on manufacturers, importers, distributors and operators of IoT devices and related software — aligning with EU policy objectives to raise baseline security standards. For DLT and smart contracts the law recognises legal validity for certain transactions, sets rules for records and ledgers, and identifies civil liability pathways. For 3D printing the law clarifies copyright protection for CAD files and digital designs (including remuneration mechanisms) and assigns liability regimes for defective digital files and printed outputs.

Transparency, accountability and enforcement: the law requires entities (public and certain private entities of medium/large size) to maintain internal registries for AI systems used for consumer profiling or personnel evaluation, to document operating parameters and governance controls, and to provide transparency to affected persons. The Act empowers national authorities to conduct market surveillance, conformity assessment and to require information, and sets administrative sanctions and liability frameworks for breaches. The law also anticipates alignment with EU-level regulatory instruments and establishes mechanisms to monitor and adapt to international rules.

Impact and reach: Law 4961/2022 functions as a horizontal national statute with sectoral cross‑cutting effects: it affects public administration digital transformation, banking and finance (digital signatures and interoperability), health and social services (digital KEPAs and disability registries), logistics (UAS postal uses), manufacturing (3D printing) and technology providers. The law is integrated into the national legislative map and has already been referenced in subsequent amendments and related laws implementing EU cybersecurity and digital resilience directives and regulations.

Full article

Read full text ↗

Overview

Law 4961/2022 (FEK A' 146, 27 July 2022) is Greece's horizontal statute addressing adoption, governance and regulation of emerging information and communication technologies. It sets out obligations for public authorities and private actors, creates institutional coordination mechanisms and assigns roles for national cybersecurity and market surveillance. Key pillars include (i) governance and institutional structures for AI and digital governance, (ii) mandatory risk assessments and registries for certain AI uses, (iii) baseline security and supply‑chain duties for IoT and connected devices, (iv) legal recognition and rules for DLT/blockchain and smart contracts, and (v) IP and liability rules for 3D printing files and products. The full enacted text is published in the Government Gazette; the official FEK entry and downloadable PDF are referenced in the Sources below (FEK entry for Law 4961/2022 and Official FEK PDF (Law 4961/2022)).

Definitions

The Act defines a set of core technology terms to avoid ambiguity in application: "AI system" (broad definition covering models, algorithms and data pipelines), "Internet of Things (IoT)" (connected devices performing automated processing and data exchange), "distributed ledger technology (DLT)" and "blockchain" (shared, synchronized ledgers using consensus mechanisms), "3D printing" (additive manufacturing using CAD files), "smart contract" (codified contractual logic executed on DLT), and "UAS / UAV" (systems for unmanned aerial operations). These definitions are used to delineate obligations by actor (manufacturer, importer, distributor, operator) and by use case (profiling, personnel evaluation, critical infrastructure management).

Governance and Institutional Framework

Law 4961 establishes or assigns responsibilities to multiple public bodies to ensure coherent national governance. The Ministry of Digital Governance (General Directorate for Digital Policy / General Directorate of Cybersecurity) is the central coordinator for implementing digital governance and cybersecurity measures. A national Coordinating Committee for Artificial Intelligence is created to steer implementation of the National AI Strategy and advise on legal safeguards. The law designates the General Directorate of Cybersecurity as the national certification/co‑ordination point for EU cybersecurity certification schemes and mandates the creation of an Observatory for Hybrid Threats to provide expert analysis and strategic guidance (National Cybersecurity Authority note on national law). In addition, the law requires each central government entity to appoint a Responsible Officer for Information and Communications Systems Security (ΥΑΣΠΕ) and sets duties for critical infrastructure coordinators.

Key Focus Areas

The Act focuses on specific dimensions: (1) algorithmic governance — requiring algorithmic impact assessments alongside GDPR DPIAs for public sector AI deployments and for private uses affecting consumers/employees; (2) documentation and registries — mandatory registries for AI systems used in profiling and personnel evaluation where entities above a size threshold must maintain descriptive records of operating parameters, affected population estimates and risk mitigation measures; (3) cybersecurity and supply‑chain security — obligations for IoT device makers, importers and operators to ensure baseline security and to cooperate with national conformity assessment and market surveillance; (4) DLT and smart contracts — legal recognition and evidentiary rules for records maintained on distributed ledgers and rules facilitating certain transactions and dispute resolution; (5) 3D printing, IP and product liability — protection and remuneration mechanisms for CAD files and liability for defective digital models and printed goods; and (6) UAS postal/logistics services — technical and safety rules for UAV operations used in postal distribution. These focus areas are developed into sectoral obligations and enforcement mechanisms across the law (EY summary of Law 4961/2022).

Implementation Framework

Implementation relies on a mix of primary statutory obligations and delegated instruments. The law provides for ministerial and joint ministerial decisions to specify detailed technical and procedural requirements (e.g., templates for algorithmic impact assessments, registries, IoT security standards, and DLT record‑keeping rules). The General Directorate of Cybersecurity is empowered to define conformity assessment procedures, to designate assessment bodies, and to carry out market surveillance (including requests for information and inspections). Public authorities are required to integrate data classification and security planning into procurement processes (strengthened requirements for government cloud hosting and system design). The law further mandates coordination with the Hellenic Data Protection Authority on overlapping data protection matters and creates a registry of public sector data protection officers to facilitate information exchange.

Monitoring and Evaluation

Monitoring mechanisms include periodic reporting by public entities on AI use and by designated registrants on AI system operation; the law authorises audits and inspections by the National Cybersecurity Authority and other competent bodies. The Coordinating Committee for AI and the Observatory on Hybrid Threats are tasked with producing periodic assessments of technology risks, adoption trends and cross‑sector impacts, enabling policy updates. Market surveillance measures provide for corrective measures and public advisories where systemic risks or product deficiencies are identified.

Penalties, Liability, and Appeals

The statute establishes administrative sanctioning powers for non‑compliance (penalties, suspension of operations, orders to correct deficiencies) and describes civil liability rules for damage caused by defective digital products (including defective CAD files and AI‑driven decisions). The law preserves criminal liability where other criminal law provisions apply. It also sets internal appeal routes and administrative judicial review for decisions by supervisory authorities. Fines and other administrative measures are imposed according to the seriousness of violations, in accordance with the enabling provisions for enforcement (details of monetary scales and procedural rules are provided in delegated acts and are subject to subsequent amendments).

Relationship to Other Instruments

Law 4961/2022 expressly interacts with EU and national frameworks: it preserves the applicability of the GDPR (Regulation (EU) 2016/679) and aligns national cybersecurity roles with EU certification/regulatory initiatives. The law includes transposition/interaction clauses with existing national digital governance statutes (e.g., Law 4727/2020) and anticipates alignment with subsequent EU measures such as the AI Act and NIS2 (where applicable). The statute also amends numerous domestic provisions (e.g., administrative procedure registers, KEPAs, public procurement and signature rules) to harmonise digital transformation and administrative processes.

International Alignment

From the drafting stage, the law was designed to be compatible with European policy objectives on AI, cybersecurity and digital operational resilience. It creates national authorities and processes that can implement EU regulatory instruments (for example, implementing EU cybersecurity certification frameworks and cooperating with EU supervisory mechanisms). The law also enables Greece to incorporate future EU rules (including delegated acts and sectoral regulations) through ministerial and delegated decisions, thereby maintaining operational alignment with EU directives/regulations.

Implementation Timeline

MilestoneDate
Publication in FEK (official gazette)2022-07-27
General commencement of the law (majority of provisions)2022-07-27
Designated transitional or specific entry dates for certain provisions (e.g., provisions cited as taking effect on 15 September 2022 and 1 November 2022 in the official text)2022-09-15; 2022-11-01
Delegated acts and ministerial decisions to be issued (ongoing)Varies — follow Ministry releases

Sources and References

SourceType
Νόμος 4961/2022 (ΦΕΚ Α 146/27.07.2022) - Αναδυόμενες τεχνολογίες πληροφορικής και επικοινωνιών, ενίσχυση της ψηφιακής διακυβέρνησης και άλλες διατάξειςOfficial Gazette
Law n. 4961/2022 Emerging information and communication technologies and societies, enhancing digital governance and other provisions - OECD.AIInternational Organization
Law 4961/2022 (Official Government Gazette A' 146/27.07.2022) - European Restructuring Monitor - EurofoundInternational Organization

Requirements for a company

What an organisation has to do under Greece - Digital Governance Framework (4961/2022), at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Must do

13
  • Perform algorithmic impact assessments for AI deployments.Public sector entities and private entities using AI affecting consumers/employees.
  • Maintain a registry entry for AI systems used in profiling or personnel evaluation.Entities above a size threshold using AI for profiling or personnel evaluation.
  • Document operating parameters, affected population estimates, and risk mitigation measures for registered AI systems.Entities above a size threshold using AI for profiling or personnel evaluation.
  • Implement risk mitigation measures for AI systems used in profiling or personnel evaluation.Entities above a size threshold using AI for profiling or personnel evaluation.
  • Ensure baseline security for IoT devices.IoT device makers, importers, and operators.
  • Comply with conformity assessment rules for IoT devices.Manufacturers and importers of IoT devices.
  • +7 more in the table below

Must not do

0

Nothing in this category.

Should do

0

Nothing in this category.

Should not do

0

Nothing in this category.

Who must do what

The obligations under Greece - Digital Governance Framework (4961/2022), most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Public sector entities and private entities using AI affecting consumers/employees.Perform algorithmic impact assessments for AI deployments.
requiring algorithmic impact assessments alongside GDPR DPIAs for public sector AI deployments and for private uses affecting consumers/employees
Before deploying AI systemsCritical
2Entities above a size threshold using AI for profiling or personnel evaluation.Maintain a registry entry for AI systems used in profiling or personnel evaluation.
mandatory registries for AI systems used in profiling and personnel evaluation where entities above a size threshold must maintain descriptive records
Critical
3Entities above a size threshold using AI for profiling or personnel evaluation.Document operating parameters, affected population estimates, and risk mitigation measures for registered AI systems.
must maintain descriptive records of operating parameters, affected population estimates and risk mitigation measures
Critical
4Entities above a size threshold using AI for profiling or personnel evaluation.Implement risk mitigation measures for AI systems used in profiling or personnel evaluation.
must maintain descriptive records of operating parameters, affected population estimates and risk mitigation measures
Critical
5IoT device makers, importers, and operators.Ensure baseline security for IoT devices.
obligations for IoT device makers, importers and operators to ensure baseline security
Before placing on market or operatingCritical
6Manufacturers and importers of IoT devices.Comply with conformity assessment rules for IoT devices.Before placing on marketCritical
7Entities above a size threshold using AI for profiling or personnel evaluation.Ensure transparency to data subjects regarding AI systems used for profiling or personnel evaluation.Critical
8Central government entities.Appoint a Responsible Officer for Information and Communications Systems Security (ΥΑΣΠΕ).
each central government entity to appoint a Responsible Officer for Information and Communications Systems Security (ΥΑΣΠΕ)
Important
9IoT device makers, importers, and operators.Cooperate with national conformity assessment and market surveillance authorities.
cooperate with national conformity assessment and market surveillance
Important
10Public authorities.Integrate data classification and security planning into procurement processes.
Public authorities are required to integrate data classification and security planning into procurement processes
Important
11Manufacturers and importers of IoT devices.Maintain technical documentation for IoT devices.Important
12Public sector entities with DPOs.Register public sector data protection officers.
creates a registry of public sector data protection officers to facilitate information exchange.
Important
13Public entities using AI and designated registrants of AI systems.Submit periodic reports on AI system use and operation.
periodic reporting by public entities on AI use and by designated registrants on AI system operation
Important

© Regulations.AI · updated on 13-Jun-2026