Greece - Data Governance Implementation (5188/2025)

Law 5188/2025: Measures for the implementation of the Data Governance Act and the National Strategy for public sector data

Νόμος 5188/2025: Μέτρα για την εφαρμογή του Κανονισμού Διακυβέρνησης Δεδομένων και της Εθνικής Στρατηγικής για τα δεδομένα του δημόσιου τομέα

Greece

RAI-GR-NA-5MIDGXX-2025
Effective: March 28, 2025
In Force(In Force)
ActGovernance and OversightConformity Assessment and Registration
Export PDF

Law 5188/2025 (FEK A' 49/28-03-2025) transposes measures of Regulation (EU) 2022/868 (the Data Governance Act) into Greek law, designating the Ministry of Digital Governance as the competent authority for data intermediation services and data altruism organisations and creating a national framework and strategy for the reuse of protected public sector data. The law establishes institutional roles (including Data Use Officers), enforcement powers and fines, and a five-year National Strategy for public sector information.

Summary

Law 5188/2025 (published in FEK A' 49 on 28 March 2025) establishes national implementing measures to bring into effect Regulation (EU) 2022/868 (the Data Governance Act) within the Greek legal order and to coordinate related interoperability obligations under Regulation (EU) 2024/903. The Act covers three main pillars: (1) a framework for the re-use of certain categories of protected public sector information (including personal data and data protected by intellectual property rights) through a single information point and defined procedures; (2) a regime for the notification, recognition and supervision of data intermediation service providers and voluntary registration of data altruism organisations; and (3) the adoption and operation of a binding National Strategy for public sector data with coordinating structures at the Ministry of Digital Governance.

Key institutional features introduced by the law include designation of the Ministry of Digital Governance as the single information point and competent supervisory authority for the matters covered; the mandatory appointment of a Data Use Officer (DUO) at each central government body (explicitly distinct from the Data Protection Officer and the Information and Communication Systems Security Officer); and the establishment of a Coordinating Committee for public sector information within the Ministry to draft, adopt and supervise the National Strategy.

On the re-use of protected public sector information, the law promotes the principle of 'open access by design and by default' and requires public sector bodies to catalogue and make data available in formats that facilitate anonymisation and machine-readability where feasible. Requests for access to protected public sector data are processed via the single information point, and administrative decisions may be subject to judicial review before the territorially competent Administrative Court of Appeal.

For market actors, Law 5188/2025 creates a supervisory framework for data intermediation service providers — entities that facilitate data exchange between holders and data subjects — including notification/recognition procedures, minimum organisational requirements and limited administrative sanctions for non-compliance. It also provides for a voluntary national register of recognised data altruism organisations and the procedures for their entry and removal.

Enforcement powers granted by the law include administrative fines (reported legislative text sets a range of €10,000 to €100,000 for breaches of the national implementing measures), injunctive measures, and procedural safeguards such as the requirement for a prior hearing and the availability of judicial appeals. The law explicitly confirms application subject to the primacy of EU data protection rules (GDPR) and cross-references related sectoral and Union law.

Law 5188/2025 also introduces an implementation architecture — including timelines for strategy adoption and requirements for periodic monitoring and reporting — to align national public sector data governance with EU mechanisms such as the European Data Innovation Board and existing GDPR supervisory frameworks. The law is an enabling measure intended to facilitate responsible data sharing across the public and private sectors while protecting individual rights and ensuring accountability and transparency in the reuse and exchange of public sector data.

Full article

Read full text ↗

Overview

Law 5188/2025 (FEK A' 49/28-03-2025) adopts national measures to implement Regulation (EU) 2022/868 (the Data Governance Act) and to define the National Strategy and institutional framework for public sector data in Greece. The law focuses on enabling the re-use of protected public sector information, establishing a supervisory framework for data intermediation service providers and a register for data altruism organisations, and creating governance structures within the Ministry of Digital Governance to implement a five-year National Strategy for public sector information. The published Government Gazette entry and official administrative procedure records define the law's articles and administrative attachments; the full published act is accessible through the national FEK record (see Government Gazette (FEK) A' 49/28-03-2025) and administrative guidance is published on the Ministry of Digital Governance registries and procedure portals (e.g., Ministry procedural registry).

Definitions

The law imports several core definitions from the Data Governance Act and clarifies them in Greek law: 'data' (digital representation of acts, facts or information), 'protected public sector data' (data held by public sector bodies that are legally protected by personal data rules, IP or confidentiality), 'data intermediation services' (services that facilitate the exchange of data between data subjects/holders and third parties), 'data altruism organisation' (legal persons which make data available for altruistic objectives and seek voluntary registration), 'single information point' (the platform and administrative function to coordinate access requests), and 'Data Use Officer (DUO)' (an appointed official in each central government body responsible for managing requests and compliance under the law). These definitions are used throughout the instrument to determine application, duties and rights.

Governance and Institutional Framework

Article-level provisions designate the Ministry of Digital Governance as the single information point and as the competent supervisory authority for the notification/recognition and oversight of data intermediation services and the registration of data altruism organisations. The law establishes a Coordinating Committee for public sector information within the Ministry, charged with drafting the National Strategy and coordinating cross-sectoral working groups. Each central government body is required to appoint a Data Use Officer (DUO) who will manage requests for reuse of protected data, liaise with the Ministry, and implement the National Strategy at the entity level. The DUO must be a person distinct from the Data Protection Officer and the Information and Communication Systems Security Officer to maintain separation of operational responsibilities. Administrative guidance and procedural forms for registrations, notices and submissions are issued and maintained on governmental portals (see the Ministry registry and procedural pages like procedural entry).

Key Focus Areas

Law 5188/2025 concentrates on several interlocking policy goals: (1) enabling lawful re-use of protected public sector data while ensuring compliance with data protection and confidentiality obligations; (2) fostering trustworthy data exchange markets through registration and oversight of data intermediation service providers; (3) supporting civic and research-driven data sharing via a voluntary register of recognised data altruism organisations; (4) promoting interoperability, machine-readability and anonymisation 'by design' within public sector data publishing practices; and (5) creating a national strategic framework that sets principles, targets and responsibilities for public sector data management for a five-year period. The law explicitly reaffirms the primacy of Union data protection rules (GDPR / Regulation (EU) 2016/679) and coordinates with sectoral EU instruments (including the Data Governance Act itself and the Interoperable Europe Regulation). Practically, the law requires public bodies to catalog protected datasets, to provide access decisions through the single information point, and to maintain procedures for timely processing, reasoned refusals and judicial review opportunities. It also prescribes conditions for data intermediation service providers to notify and operate and for data altruism organisations to register, publish charters and ensure governance safeguards.

Implementation Framework

The Ministry of Digital Governance is responsible for drafting the National Strategy (five-year duration) which becomes binding on public sector bodies. The Coordinating Committee may establish working groups, including external experts, to develop sectoral implementation roadmaps. Public sector bodies must appoint DUOs and update internal procedures, metadata inventories and anonymisation processes. The law requires development and maintenance of the single information point (a digital portal) that centralises applications and decisions; administrative workflows and time limits are stipulated in the implementing provisions. The notification and registry procedures for data intermediation services and data altruism organisations follow specified templates; decisions on recognition or refusal include due process safeguards and are subject to appeal. The implementation architecture anticipates cooperation with data protection authorities and other sectoral regulators to ensure complementary oversight and to avoid regulatory gaps or overlaps.

Monitoring and Evaluation

The law mandates periodic reporting and monitoring mechanisms: the Ministry must publish annual status reports on implementation, including statistics on requests processed through the single information point, entries and removals from the data altruism register, notifications of data intermediation providers and enforcement actions taken. The Coordinating Committee compiles recommendations, sets KPIs for dataset publication and anonymisation rates, and proposes regulatory adjustments. Independent oversight is supported through judicial review of administrative decisions. The law also requests alignment with EU-level monitoring instruments (such as reporting to the European Data Innovation Board) to ensure interoperability and comparability across Member States.

Penalties, Liability, and Appeals

Enforcement provisions grant the Ministry administrative powers to impose corrective measures and sanctions following a prior hearing. The primary monetary penalty range set out in the national implementing text is between €10,000 and €100,000 for relevant breaches, subject to proportionality and due process. The law allows for additional measures including warnings, temporary suspension or removal from national registers, and injunctive remedies to halt non-compliant activity. Decisions imposing sanctions are subject to appeals on the merits before the competent Administrative Court of Appeal. The law also clarifies that liability under sectoral Union rules (including data protection law) is unaffected and that remedies under GDPR and national liability regimes remain available to injured parties.

Relationship to Other Instruments

Law 5188/2025 explicitly implements and meshes with EU-level instruments. It transposes obligations arising from Regulation (EU) 2022/868 (Data Governance Act) and references Regulation (EU) 2016/679 (GDPR) as the prevailing rule for personal data protection. The law coordinates with the Interoperable Europe Regulation (Regulation (EU) 2024/903) concerning technical and organisational interoperability for public services. In the national context, the law interacts with administrative transparency legislation, sector-specific data regimes, and future laws on sectoral data spaces; it is designed to be complementary and without prejudice to pre-existing national confidentiality or public security exceptions.

International Alignment

The law aligns Greece with EU-level goals to create a single market for data by implementing the Data Governance Act and contributing to EU-wide governance through the European Data Innovation Board. The national framework supports cross-border data intermediation and recognition of data altruism organisations under EU labels where applicable, while preserving GDPR constraints on transfers and processing. Greece's implementing measures are designed to be interoperable with Union registers and recognition frameworks and to facilitate participation of Greek organisations in EU data-sharing initiatives and research collaborations.

Implementation Timeline

DateEvent
2025-03-28Publication in FEK (A' 49) — Law 5188/2025 enters into force.
2025 Q2–Q4Ministry issues implementing administrative guidance, establishes Coordinating Committee and begins DUO appointments across central government bodies.
2025–2026Deployment of the single information point portal and opening of registrations/notifications for data altruism organisations and data intermediation services.
Every yearAnnual report by the Ministry on implementation metrics and enforcement actions.

Sources and References

SourceType
Government Gazette (FEK) A' 49/28-03-2025: Law 5188/2025Primary Source
Regulation (EU) 2022/868 (Data Governance Act) — EUR-LexPrimary Source
Ministry of Digital Governance procedural registry for data altruism organisationsPrimary Source (administrative)

Requirements for a company

What an organisation has to do under Greece - Data Governance Implementation (5188/2025), at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Must do

10
  • Appoint a Data Use Officer (DUO) distinct from the DPO and security officer.Central government bodies
  • Provide access decisions for protected data through the single information point.Public sector bodies
  • Notify the Ministry of Digital Governance to operate as a data intermediation service provider.Data intermediation service providers
  • Register with the Ministry of Digital Governance as a data altruism organisation.Data altruism organisations
  • Comply with specified administrative procedures and templates for notifications and registrations.Data intermediation service providers and data altruism organisations
  • Catalog protected datasets, including metadata inventories and anonymisation plans.Public sector bodies
  • +4 more in the table below

Must not do

0

Nothing in this category.

Should do

1
  • Promote interoperability, machine-readability, and anonymisation 'by design' in data publishing practices.Public sector bodies

Should not do

0

Nothing in this category.

Who must do what

The obligations under Greece - Data Governance Implementation (5188/2025), most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Central government bodiesAppoint a Data Use Officer (DUO) distinct from the DPO and security officer.
Each central government body is required to appoint a Data Use Officer (DUO) who will manage requests for reuse of protected data
By end of 2025Governance and Institutional FrameworkCritical
2Public sector bodiesProvide access decisions for protected data through the single information point.
the law requires public bodies to... provide access decisions through the single information point
After 2026-01-01Key Focus AreasCritical
3Data intermediation service providersNotify the Ministry of Digital Governance to operate as a data intermediation service provider.
the law also prescribes conditions for data intermediation service providers to notify and operate
After 2026-01-01Key Focus AreasCritical
4Data altruism organisationsRegister with the Ministry of Digital Governance as a data altruism organisation.
for data altruism organisations to register, publish charters and ensure governance safeguards.
After 2026-01-01Key Focus AreasCritical
5Data intermediation service providers and data altruism organisationsComply with specified administrative procedures and templates for notifications and registrations.
The notification and registry procedures for data intermediation services and data altruism organisations follow specified templates
After 2026-01-01Implementation FrameworkCritical
6Public sector bodiesCatalog protected datasets, including metadata inventories and anonymisation plans.
the law requires public bodies to catalog protected datasets
Key Focus AreasImportant
7Public sector bodiesMaintain internal procedures for timely processing of data reuse requests.
to maintain procedures for timely processing, reasoned refusals and judicial review opportunities.
Key Focus AreasImportant
8Data altruism organisationsPublish charters and ensure governance safeguards as a data altruism organisation.
for data altruism organisations to register, publish charters and ensure governance safeguards.
Upon registrationKey Focus AreasImportant
9Public sector bodiesUpdate internal procedures, metadata inventories, and anonymisation processes.
Public sector bodies must... update internal procedures, metadata inventories and anonymisation processes.
Implementation FrameworkImportant
10Ministry of Digital GovernancePublish annual status reports on implementation, including statistics and enforcement actions.
the Ministry must publish annual status reports on implementation, including statistics on requests processed
Every yearMonitoring and EvaluationImportant
11Public sector bodiesPromote interoperability, machine-readability, and anonymisation 'by design' in data publishing practices.
promoting interoperability, machine-readability and anonymisation 'by design' within public sector data publishing practices
Key Focus AreasRecommended

© Regulations.AI · updated on 13-Jun-2026