Greece - AI Fundamental Rights Supervisors
Publication of national authorities/bodies designated to supervise/enforce fundamental-rights obligations under the EU Artificial Intelligence Act (national designation under Art.77)
Δημοσίευση εθνικών αρχών/φορέων που έχουν οριστεί για την εποπτεία/επιβολή υποχρεώσεων θεμελιωδών δικαιωμάτων σύμφωνα με τον Κανονισμό για την Τεχνητή Νοημοσύνη της ΕΕ (εθνικός καθορισμός σύμφωνα με το Άρθρο 77)
Greece
RAI-GR-NA-PNADSXX-2024On 12 November 2024 the Hellenic Ministry of Digital Governance published Greece’s official list of national authorities and bodies designated under Article 77 of the EU Artificial Intelligence Act to supervise and enforce fundamental-rights obligations in relation to high‑risk AI systems. The list names four national bodies and notes that the additional powers conferred by the AI Act will become applicable from 2 August 2026; the list has been notified to the European Commission and will be updated as required.
Summary
Background and legal basis: The EU Artificial Intelligence Act (Regulation (EU) 2024/1689) requires Member States to identify and publish the national public authorities or bodies that will supervise and enforce obligations to protect fundamental rights in the context of high‑risk AI systems (Article 77). Greece fulfilled this publication requirement on 12 November 2024 via the Hellenic Ministry of Digital Governance. The publication lists four existing national authorities that shall exercise the Article 77 functions within the limits of their jurisdiction and in coordination with other national competent authorities under the AI Act.
Designated authorities (Greece): The Ministry’s announcement explicitly names the following bodies: (1) the Hellenic Data Protection Authority (HDPA / Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα); (2) the Greek Ombudsman (Συνήγορος του Πολίτη); (3) the Hellenic Authority for Ensuring Communications Secrecy (Αρχή Διασφάλισης του Απορρήτου των Επικοινωνιών, ADAE); and (4) the Greek National Commission for Human Rights (GNCHR / Εθνική Επιτροπή Δικαιωμάτων του Ανθρώπου). The Ministry’s press release reiterates that these are existing independent public bodies with mandates touching on privacy, equality, communications secrecy and human‑rights protection and that they will receive the AI‑Act‑related additional powers only to the extent necessary for fulfilling their mandates.
Scope and powers: Under Article 77 the listed authorities acquire the power to request and access documentation created or maintained by providers, deployers or other operators to demonstrate compliance with AI Act obligations when such documentation is necessary for the effective fulfilment of their public‑law mission and within the limits of their existing jurisdiction. The Greek announcement also notes the procedural interplay with the market surveillance and notifying authorities: Article 77 authorities may request further testing or investigation but the AI Act assigns investigative and sanctioning powers (including ordering corrective measures and imposing fines) primarily to market surveillance authorities; Article 77 authorities must inform the market surveillance authority of any requests and may make reasoned requests for testing where documentation is insufficient.
Timing and implementation: The Ministry’s publication states the additional Article 77 competences will apply from 2 August 2026, reflecting the phased entry into application for various AI Act obligations. The Ministry also confirmed that the list was notified to the European Commission and that it will be updated when needed.
Implications for regulated entities: Organisations deploying high‑risk AI systems in Greece should expect increased access requests and cooperation requests from the four authorities named. Entities should prepare documentation under the AI Act (technical documentation, risk assessments, fundamental‑rights impact assessments where applicable) and ensure secure, auditable recordkeeping so that lawful requests from Article 77 authorities can be handled promptly. They should also be aware that while Article 77 authorities can request access, enforcement measures (including fines) will generally be exercised by the market surveillance authority designated under the AI Act; coordination mechanisms at the national level will therefore be important.
Sources and transparency: The primary source for Greece’s designation is the official Hellenic Ministry of Digital Governance press release of 12 November 2024. Secondary corroboration and analysis are available from civil society organizations, legal commentators and European digital‑policy trackers that compiled Member State implementation steps. The Ministry’s announcement provides the authoritative list and the formal notification status to the Commission.
Full article
Read full text ↗Overview
On 12 November 2024 the Hellenic Ministry of Digital Governance published the national list of authorities and public bodies designated under Article 77 of the EU Artificial Intelligence Act to supervise and enforce obligations protecting fundamental rights in the use of high‑risk AI systems. The publication names four existing independent public authorities and confirms that they will obtain AI‑Act related powers where necessary and within their statutory jurisdiction. The Ministry announced the list was notified to the European Commission and indicated that the additional competences will take effect from 2 August 2026. The official announcement is available from the Ministry’s communications page: Ministry of Digital Governance – press release (12 Nov 2024).
Definitions
This publication should be read in the context of the AI Act definitions: "authorities protecting fundamental rights" (Article 77) are national public authorities or bodies responsible for enforcing respect for fundamental rights (e.g., data protection, equality, freedom from discrimination, communications secrecy, and human‑rights protections) in relation to high‑risk AI systems listed in Annex III of the AI Act. "Documentation" refers to the technical and organisational documentation, fundamental‑rights impact assessments, risk assessments, and records that providers, deployers and other actors must create or maintain under the AI Act. "High‑risk AI systems" are those systems covered by Annex III and subject to mandatory requirements under the AI Act. The Greek announcement refers to the four national authorities designated to exercise these functions within the limits of their jurisdiction.
Governance and Institutional Framework
Greece’s approach relies on existing independent bodies rather than creating a new sui generis authority. The four bodies named — the Hellenic Data Protection Authority, the Greek Ombudsman (Synigoros), the Hellenic Authority for Ensuring Communications Secrecy (ADAE), and the Greek National Commission for Human Rights (GNCHR) — reflect a cross‑sectoral cluster combining data‑protection, administrative‑complaints and human‑rights expertise. The Greek Ministry of Digital Governance will continue to coordinate national implementation steps and to publish updates. The Article 77 authorities will operate in coordination with the national market surveillance authority and notifying authority designated under other AI Act provisions; the market surveillance authority retains principal investigative and sanctioning powers under the AI Act, while Article 77 bodies have targeted access and request powers to protect fundamental rights.
Key Focus Areas
The Ministry’s publication and the architecture of Article 77 create several practical focal points for national enforcement: (1) Access to documentation for rights‑protection reviews — Article 77 authorities will be entitled to request and access documentation kept by providers/deployers for compliance verification; (2) Discrimination and equality — bodies with mandates on nondiscrimination (e.g., GNCHR, Ombudsman) will review AI systems’ impact on equal treatment; (3) Privacy and data protection — the HDPA will focus on data‑processing risks and rights under the GDPR and the AI Act; (4) Communications secrecy — ADAE will have a role where AI affects confidentiality of communications; (5) Coordination and referrals — Article 77 requests that reveal potential breaches will be referred to the market surveillance authority for testing or enforcement, and Article 77 bodies may request testing where documentation is insufficient. The coexistence of these functions emphasizes a cross‑disciplinary, evidence‑based enforcement model that seeks to protect fundamental rights while respecting the AI Act’s separation of investigative and sanctioning competences.
Implementation Framework
Implementation is staged. The Ministry’s notice confirms the published list (12 Nov 2024) and states that the additional Article 77 competences will apply from 2 Aug 2026 — consistent with the AI Act’s phased timelines for different obligations. National implementation requires: (a) internal administrative arrangements within each designated authority (resourcing, training, procedures for receiving and processing documentation requests); (b) coordination arrangements with the designated market surveillance and notifying authorities (including single point of contact where applicable); (c) secure channels for receiving sensitive documentation; and (d) guidance for private‑sector actors on how to respond to Article 77 requests. The Ministry indicated the list will be updated to reflect future needs and circumstances (Ministry press release).
Monitoring and Evaluation
Monitoring will combine national reporting, inter‑authority coordination and Commission oversight. The AI Act foresees Commission dissemination of designated national authorities and a role for the AI Board and the European Artificial Intelligence Office in supporting exchange of experience. National authorities will need to develop metrics and case logs to track Article 77 access requests, referrals to market surveillance authorities, outcomes of documentation reviews and any corrective or remedial actions. Periodic reviews should evaluate whether the composition of the list remains appropriate, whether mandates and resourcing are sufficient, and whether information exchange procedures with market surveillance authorities are working effectively.
Penalties, Liability, and Appeals
The Ministry’s publication is a designation notice; it does not itself create new sanctions. Under the AI Act, primary sanctioning powers (warnings, orders to bring systems into compliance, restrictions, fines) are principally vested in market surveillance authorities and other competent enforcement bodies designated under Articles 70–76. Article 77 authorities may request access and request market surveillance authorities to conduct tests but do not in principle exercise the main sanctioning powers under the AI Act. Individuals and organisations affected by administrative measures retain legal remedies under national administrative law and under the AI Act where applicable. Practically, entities should expect that findings by Article 77 bodies may lead to referrals that trigger sanctions by market surveillance authorities; appeal routes will be those provided by Greek administrative and judicial procedures and by EU remedies where applicable.
Relationship to Other Instruments
Article 77 designations are complementary to existing national and EU instruments. Where fundamental‑rights issues intersect with personal data processing, the GDPR and national data‑protection law (enforced by the HDPA) remain central. Equality and anti‑discrimination law continue to apply where AI affects protected characteristics. Communications secrecy rules remain relevant where AI systems process or infer communications content or metadata. The Ministry’s designation emphasizes that Article 77 powers are exercised within the authorities’ existing mandates and in coordination with the notifying and market surveillance authorities designated under the AI Act (Ministry announcement).
International Alignment
Greece’s designation mirrors the approach adopted by many EU Member States of using existing sectoral human‑rights, data‑protection and oversight bodies to fulfil Article 77 obligations. The Ministry’s public notice aligns with EU expectations that Member States publish designated authorities and notify the Commission. Greece’s list contributes to the Commission’s consolidated register of Member State designations and facilitates cross‑border cooperation, referrals and exchanges through the AI Board and Commission channels. Internationally, using established independent bodies helps ensure alignment with data‑protection standards (GDPR) and human‑rights norms promoted by Council of Europe and UN instruments.
Implementation Timeline
| Event | Date |
|---|---|
| AI Act entered into force (EU) | 2024-08-02 |
| Greece publishes Article 77 list (Ministry press release) | 2024-11-12 |
| Notification of list to European Commission (as stated by Ministry) | 2024-11 (notification) |
| Additional Article 77 competences apply (phased application for many AI Act obligations) | 2026-08-02 |
Sources and References
| Source | Type |
|---|---|
| Ministry of Digital Governance (Greece) – 'Οι Αρχές προστασίας των θεμελιωδών δικαιωμάτων σε σχέση με τη χρήση Τεχνητής Νοημοσύνης στην Ελλάδα' (12 Nov 2024) | Primary Source |
| Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα) | Primary Source (authority site) |
| Greek Ombudsman (Συνήγορος του Πολίτη) | Primary Source (authority site) |
| Hellenic Authority for Ensuring Communications Secrecy (Α.Δ.Α.Ε.) | Primary Source (authority site) |
| Greek National Commission for Human Rights (GNCHR / ΕΕΔΑ) | Primary Source (authority site) |
Requirements for a company
What an organisation has to do under Greece - AI Fundamental Rights Supervisors, at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Not yet in force (Awaiting Entry). These requirements apply once the instrument takes effect and may change before then.
Must do
3- Maintain complete AI Act documentation.Providers and deployers of high-risk AI systems.
- Establish secure channels for authority requests.Providers and deployers of high-risk AI systems.
- Understand that Article 77 reviews may trigger enforcement actions.Providers and deployers of high-risk AI systems.
Must not do
0Nothing in this category.
Should do
2- Identify national market surveillance and Article 77 authorities.Providers and deployers of high-risk AI systems.
- Train compliance teams on responding to authority requests.Providers and deployers of high-risk AI systems.
Should not do
0Nothing in this category.
Who must do what
The obligations under Greece - AI Fundamental Rights Supervisors, most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | Providers and deployers of high-risk AI systems. | Maintain complete AI Act documentation. “Maintain complete AI Act documentation” | Aug 2, 2026 | — | Critical |
| 2 | Providers and deployers of high-risk AI systems. | Establish secure channels for authority requests. “Establish secure channels for authority requests” | Aug 2, 2026 | — | Important |
| 3 | Providers and deployers of high-risk AI systems. | Understand that Article 77 reviews may trigger enforcement actions. “Plan for referrals and potential enforcement” | Aug 2, 2026 | — | Important |
| 4 | Providers and deployers of high-risk AI systems. | Identify national market surveillance and Article 77 authorities. “Identify national contacts” | Aug 2, 2026 | — | Recommended |
| 5 | Providers and deployers of high-risk AI systems. | Train compliance teams on responding to authority requests. “Train compliance teams” | Aug 2, 2026 | — | Recommended |
Related Regulations
A Blueprint for Greece's AI Transformation (High-Level Advisory Committee on AI report / foundational national AI strategy blueprint)
Greece91% similar
Greece AI Regulation Overview
Greece90% similar
Governance Framework for the Implementation of Regulation (EU) 2024/1689 on Artificial Intelligence in Cyprus
Cyprus89% similar
Final Advice on the Organisation of AI Supervision (Eindadvies inrichting AI-toezicht) — AP & RDI
Netherlands88% similar
Royal Decree 729/2023 approving the Statute of the Spanish Agency for AI Supervision (Agencia Española de Supervisión de la Inteligencia Artificial - AESIA)
Spain88% similar
© Regulations.AI · updated on 13-Jun-2026