Greece - Data Governance Implementation (5188/2025)
Law 5188/2025: Measures for the implementation of the Data Governance Act and the National Strategy for public sector data
Νόμος 5188/2025: Μέτρα για την εφαρμογή του Κανονισμού Διακυβέρνησης Δεδομένων και της Εθνικής Στρατηγικής για τα δεδομένα του δημόσιου τομέα
Greece
RAI-GR-NA-5MIDGXX-2025Law 5188/2025 (FEK A' 49/28-03-2025) transposes measures of Regulation (EU) 2022/868 (the Data Governance Act) into Greek law, designating the Ministry of Digital Governance as the competent authority for data intermediation services and data altruism organisations and creating a national framework and strategy for the reuse of protected public sector data. The law establishes institutional roles (including Data Use Officers), enforcement powers and fines, and a five-year National Strategy for public sector information.
Summary
Law 5188/2025 (published in FEK A' 49 on 28 March 2025) establishes national implementing measures to bring into effect Regulation (EU) 2022/868 (the Data Governance Act) within the Greek legal order and to coordinate related interoperability obligations under Regulation (EU) 2024/903. The Act covers three main pillars: (1) a framework for the re-use of certain categories of protected public sector information (including personal data and data protected by intellectual property rights) through a single information point and defined procedures; (2) a regime for the notification, recognition and supervision of data intermediation service providers and voluntary registration of data altruism organisations; and (3) the adoption and operation of a binding National Strategy for public sector data with coordinating structures at the Ministry of Digital Governance.
Key institutional features introduced by the law include designation of the Ministry of Digital Governance as the single information point and competent supervisory authority for the matters covered; the mandatory appointment of a Data Use Officer (DUO) at each central government body (explicitly distinct from the Data Protection Officer and the Information and Communication Systems Security Officer); and the establishment of a Coordinating Committee for public sector information within the Ministry to draft, adopt and supervise the National Strategy.
On the re-use of protected public sector information, the law promotes the principle of 'open access by design and by default' and requires public sector bodies to catalogue and make data available in formats that facilitate anonymisation and machine-readability where feasible. Requests for access to protected public sector data are processed via the single information point, and administrative decisions may be subject to judicial review before the territorially competent Administrative Court of Appeal.
For market actors, Law 5188/2025 creates a supervisory framework for data intermediation service providers — entities that facilitate data exchange between holders and data subjects — including notification/recognition procedures, minimum organisational requirements and limited administrative sanctions for non-compliance. It also provides for a voluntary national register of recognised data altruism organisations and the procedures for their entry and removal.
Enforcement powers granted by the law include administrative fines (reported legislative text sets a range of €10,000 to €100,000 for breaches of the national implementing measures), injunctive measures, and procedural safeguards such as the requirement for a prior hearing and the availability of judicial appeals. The law explicitly confirms application subject to the primacy of EU data protection rules (GDPR) and cross-references related sectoral and Union law.
Law 5188/2025 also introduces an implementation architecture — including timelines for strategy adoption and requirements for periodic monitoring and reporting — to align national public sector data governance with EU mechanisms such as the European Data Innovation Board and existing GDPR supervisory frameworks. The law is an enabling measure intended to facilitate responsible data sharing across the public and private sectors while protecting individual rights and ensuring accountability and transparency in the reuse and exchange of public sector data.
Full article
Read full text ↗Overview
Law 5188/2025 (FEK A' 49/28-03-2025) adopts national measures to implement Regulation (EU) 2022/868 (the Data Governance Act) and to define the National Strategy and institutional framework for public sector data in Greece. The law focuses on enabling the re-use of protected public sector information, establishing a supervisory framework for data intermediation service providers and a register for data altruism organisations, and creating governance structures within the Ministry of Digital Governance to implement a five-year National Strategy for public sector information. The published Government Gazette entry and official administrative procedure records define the law's articles and administrative attachments; the full published act is accessible through the national FEK record (see Government Gazette (FEK) A' 49/28-03-2025) and administrative guidance is published on the Ministry of Digital Governance registries and procedure portals (e.g., Ministry procedural registry).
Definitions
The law imports several core definitions from the Data Governance Act and clarifies them in Greek law: 'data' (digital representation of acts, facts or information), 'protected public sector data' (data held by public sector bodies that are legally protected by personal data rules, IP or confidentiality), 'data intermediation services' (services that facilitate the exchange of data between data subjects/holders and third parties), 'data altruism organisation' (legal persons which make data available for altruistic objectives and seek voluntary registration), 'single information point' (the platform and administrative function to coordinate access requests), and 'Data Use Officer (DUO)' (an appointed official in each central government body responsible for managing requests and compliance under the law). These definitions are used throughout the instrument to determine application, duties and rights.
Governance and Institutional Framework
Article-level provisions designate the Ministry of Digital Governance as the single information point and as the competent supervisory authority for the notification/recognition and oversight of data intermediation services and the registration of data altruism organisations. The law establishes a Coordinating Committee for public sector information within the Ministry, charged with drafting the National Strategy and coordinating cross-sectoral working groups. Each central government body is required to appoint a Data Use Officer (DUO) who will manage requests for reuse of protected data, liaise with the Ministry, and implement the National Strategy at the entity level. The DUO must be a person distinct from the Data Protection Officer and the Information and Communication Systems Security Officer to maintain separation of operational responsibilities. Administrative guidance and procedural forms for registrations, notices and submissions are issued and maintained on governmental portals (see the Ministry registry and procedural pages like procedural entry).
Key Focus Areas
Law 5188/2025 concentrates on several interlocking policy goals: (1) enabling lawful re-use of protected public sector data while ensuring compliance with data protection and confidentiality obligations; (2) fostering trustworthy data exchange markets through registration and oversight of data intermediation service providers; (3) supporting civic and research-driven data sharing via a voluntary register of recognised data altruism organisations; (4) promoting interoperability, machine-readability and anonymisation 'by design' within public sector data publishing practices; and (5) creating a national strategic framework that sets principles, targets and responsibilities for public sector data management for a five-year period. The law explicitly reaffirms the primacy of Union data protection rules (GDPR / Regulation (EU) 2016/679) and coordinates with sectoral EU instruments (including the Data Governance Act itself and the Interoperable Europe Regulation). Practically, the law requires public bodies to catalog protected datasets, to provide access decisions through the single information point, and to maintain procedures for timely processing, reasoned refusals and judicial review opportunities. It also prescribes conditions for data intermediation service providers to notify and operate and for data altruism organisations to register, publish charters and ensure governance safeguards.
Implementation Framework
The Ministry of Digital Governance is responsible for drafting the National Strategy (five-year duration) which becomes binding on public sector bodies. The Coordinating Committee may establish working groups, including external experts, to develop sectoral implementation roadmaps. Public sector bodies must appoint DUOs and update internal procedures, metadata inventories and anonymisation processes. The law requires development and maintenance of the single information point (a digital portal) that centralises applications and decisions; administrative workflows and time limits are stipulated in the implementing provisions. The notification and registry procedures for data intermediation services and data altruism organisations follow specified templates; decisions on recognition or refusal include due process safeguards and are subject to appeal. The implementation architecture anticipates cooperation with data protection authorities and other sectoral regulators to ensure complementary oversight and to avoid regulatory gaps or overlaps.
Monitoring and Evaluation
The law mandates periodic reporting and monitoring mechanisms: the Ministry must publish annual status reports on implementation, including statistics on requests processed through the single information point, entries and removals from the data altruism register, notifications of data intermediation providers and enforcement actions taken. The Coordinating Committee compiles recommendations, sets KPIs for dataset publication and anonymisation rates, and proposes regulatory adjustments. Independent oversight is supported through judicial review of administrative decisions. The law also requests alignment with EU-level monitoring instruments (such as reporting to the European Data Innovation Board) to ensure interoperability and comparability across Member States.
Penalties, Liability, and Appeals
Enforcement provisions grant the Ministry administrative powers to impose corrective measures and sanctions following a prior hearing. The primary monetary penalty range set out in the national implementing text is between €10,000 and €100,000 for relevant breaches, subject to proportionality and due process. The law allows for additional measures including warnings, temporary suspension or removal from national registers, and injunctive remedies to halt non-compliant activity. Decisions imposing sanctions are subject to appeals on the merits before the competent Administrative Court of Appeal. The law also clarifies that liability under sectoral Union rules (including data protection law) is unaffected and that remedies under GDPR and national liability regimes remain available to injured parties.
Relationship to Other Instruments
Law 5188/2025 explicitly implements and meshes with EU-level instruments. It transposes obligations arising from Regulation (EU) 2022/868 (Data Governance Act) and references Regulation (EU) 2016/679 (GDPR) as the prevailing rule for personal data protection. The law coordinates with the Interoperable Europe Regulation (Regulation (EU) 2024/903) concerning technical and organisational interoperability for public services. In the national context, the law interacts with administrative transparency legislation, sector-specific data regimes, and future laws on sectoral data spaces; it is designed to be complementary and without prejudice to pre-existing national confidentiality or public security exceptions.
International Alignment
The law aligns Greece with EU-level goals to create a single market for data by implementing the Data Governance Act and contributing to EU-wide governance through the European Data Innovation Board. The national framework supports cross-border data intermediation and recognition of data altruism organisations under EU labels where applicable, while preserving GDPR constraints on transfers and processing. Greece's implementing measures are designed to be interoperable with Union registers and recognition frameworks and to facilitate participation of Greek organisations in EU data-sharing initiatives and research collaborations.
Implementation Timeline
| Date | Event |
|---|---|
| 2025-03-28 | Publication in FEK (A' 49) — Law 5188/2025 enters into force. |
| 2025 Q2–Q4 | Ministry issues implementing administrative guidance, establishes Coordinating Committee and begins DUO appointments across central government bodies. |
| 2025–2026 | Deployment of the single information point portal and opening of registrations/notifications for data altruism organisations and data intermediation services. |
| Every year | Annual report by the Ministry on implementation metrics and enforcement actions. |
Sources and References
| Source | Type |
|---|---|
| Government Gazette (FEK) A' 49/28-03-2025: Law 5188/2025 | Primary Source |
| Regulation (EU) 2022/868 (Data Governance Act) — EUR-Lex | Primary Source |
| Ministry of Digital Governance procedural registry for data altruism organisations | Primary Source (administrative) |
Requirements for a company
What an organisation has to do under Greece - Data Governance Implementation (5188/2025), at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Must do
10- Appoint a Data Use Officer (DUO) distinct from the DPO and security officer.Central government bodies
- Provide access decisions for protected data through the single information point.Public sector bodies
- Notify the Ministry of Digital Governance to operate as a data intermediation service provider.Data intermediation service providers
- Register with the Ministry of Digital Governance as a data altruism organisation.Data altruism organisations
- Comply with specified administrative procedures and templates for notifications and registrations.Data intermediation service providers and data altruism organisations
- Catalog protected datasets, including metadata inventories and anonymisation plans.Public sector bodies
- +4 more in the table below
Must not do
0Nothing in this category.
Should do
1- Promote interoperability, machine-readability, and anonymisation 'by design' in data publishing practices.Public sector bodies
Should not do
0Nothing in this category.
Who must do what
The obligations under Greece - Data Governance Implementation (5188/2025), most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | Central government bodies | Appoint a Data Use Officer (DUO) distinct from the DPO and security officer. “Each central government body is required to appoint a Data Use Officer (DUO) who will manage requests for reuse of protected data” | By end of 2025 | Governance and Institutional Framework | Critical |
| 2 | Public sector bodies | Provide access decisions for protected data through the single information point. “the law requires public bodies to... provide access decisions through the single information point” | After 2026-01-01 | Key Focus Areas | Critical |
| 3 | Data intermediation service providers | Notify the Ministry of Digital Governance to operate as a data intermediation service provider. “the law also prescribes conditions for data intermediation service providers to notify and operate” | After 2026-01-01 | Key Focus Areas | Critical |
| 4 | Data altruism organisations | Register with the Ministry of Digital Governance as a data altruism organisation. “for data altruism organisations to register, publish charters and ensure governance safeguards.” | After 2026-01-01 | Key Focus Areas | Critical |
| 5 | Data intermediation service providers and data altruism organisations | Comply with specified administrative procedures and templates for notifications and registrations. “The notification and registry procedures for data intermediation services and data altruism organisations follow specified templates” | After 2026-01-01 | Implementation Framework | Critical |
| 6 | Public sector bodies | Catalog protected datasets, including metadata inventories and anonymisation plans. “the law requires public bodies to catalog protected datasets” | — | Key Focus Areas | Important |
| 7 | Public sector bodies | Maintain internal procedures for timely processing of data reuse requests. “to maintain procedures for timely processing, reasoned refusals and judicial review opportunities.” | — | Key Focus Areas | Important |
| 8 | Data altruism organisations | Publish charters and ensure governance safeguards as a data altruism organisation. “for data altruism organisations to register, publish charters and ensure governance safeguards.” | Upon registration | Key Focus Areas | Important |
| 9 | Public sector bodies | Update internal procedures, metadata inventories, and anonymisation processes. “Public sector bodies must... update internal procedures, metadata inventories and anonymisation processes.” | — | Implementation Framework | Important |
| 10 | Ministry of Digital Governance | Publish annual status reports on implementation, including statistics and enforcement actions. “the Ministry must publish annual status reports on implementation, including statistics on requests processed” | Every year | Monitoring and Evaluation | Important |
| 11 | Public sector bodies | Promote interoperability, machine-readability, and anonymisation 'by design' in data publishing practices. “promoting interoperability, machine-readability and anonymisation 'by design' within public sector data publishing practices” | — | Key Focus Areas | Recommended |
Related Regulations
Law 4727/2020: Code on Digital Governance (Digital Governance Law)
Greece89% similar
Digital Transformation Bible 2020-2025 (National digital strategy / National Data Strategy elements)
Greece89% similar
Draft Act on Data Management (Projekt ustawy o zarządzaniu danymi)
Poland88% similar
Law 4961/2022: Emerging information and communication technologies, strengthening digital governance and other provisions
Greece88% similar
Greece AI Regulation Overview
Greece87% similar
© Regulations.AI · updated on 13-Jun-2026