Greece - AI Regulation Overview (Law 5188/2025)

Greece AI Regulation Overview

Επισκόπηση Κανονισμού Τεχνητής Νοημοσύνης στην Ελλάδα

Greece

RAI-GR-NA-SUMMARY-2026
Governance and OversightData Protection and PrivacyFundamental Rights
Export PDF

Greece combines early horizontal AI legislation (Law 4961/2022) with strict EU AI Act alignment, focusing on public sector transparency, fundamental rights oversight, and a robust national data governance strategy.

Overview

Greece’s approach to artificial intelligence (AI) regulation is characterized by a proactive, "digital-first" philosophy that seeks to balance rapid technological adoption with robust legal safeguards. Historically, Greece was among the first European Union member states to enact a horizontal statute specifically addressing emerging technologies, including AI, through Law 4961/2022. This early legislative move signaled a shift from fragmented sectoral rules to a unified national framework. The Greek regulatory philosophy is deeply rooted in the "Digital Transformation Bible 2020-2025," which envisioned a modern, interoperable state. By 2026, this vision has matured into a sophisticated ecosystem where national laws such as Law 5188/2025 (implementing the Data Governance Act) work in tandem with the EU AI Act to ensure that AI systems deployed within the Hellenic Republic are transparent, accountable, and human-centric. The institutional center of gravity for AI in Greece is the Ministry of Digital Governance, which serves as the primary coordinator for national digital policy. The government’s strategy has evolved from basic digitalization to a value-driven "AI Transformation Blueprint," published in late 2024. This blueprint emphasizes the protection of human dignity, pluralism, and transparency as non-negotiable pillars of the Greek AI economy. Greece has also demonstrated a commitment to institutional innovation by designating a cluster of independent authorities—including the Data Protection Authority and the Greek Ombudsman—to supervise fundamental rights in the context of high-risk AI. This multi-layered governance model aims to position Greece not just as a consumer of AI, but as a regional leader in ethical AI governance and secure data sharing, particularly through its "open access by design" principle for public sector data.

Regulatory Approach

Greece employs a hybrid regulatory approach that combines horizontal statutory obligations with targeted sectoral requirements, all framed within the mandatory architecture of European Union law. The foundational horizontal instrument, Law 4961/2022, sets broad requirements for AI systems, Internet of Things (IoT) devices, and distributed ledger technologies. This law introduced the concept of mandatory Algorithmic Impact Assessments (AIAs) for public sector AI deployments long before such measures were standardized across the EU. This risk-based approach is now being harmonized with the EU AI Act (Regulation (EU) 2024/1689), which classifies AI systems based on their potential to cause harm. Greece’s national implementation focuses heavily on the "public-law mission" of state bodies, ensuring that any algorithmic decision-making affecting citizens is subject to strict transparency and registry requirements. In addition to binding legislation, Greece utilizes "soft law" and strategic policy documents to guide the private sector and research community. The "Blueprint for Greece’s AI Transformation" serves as a foundational policy proposal that informs subsequent legislative and budgetary actions. This approach is characterized by a "staged implementation" model, where governance bodies and flagship pilots are established first, followed by mature regulatory machinery and enforcement. A unique feature of the Greek approach is the mandatory appointment of Data Use Officers (DUOs) within central government bodies under Law 5188/2025. These officers are distinct from Data Protection Officers (DPOs) and are specifically tasked with managing the reuse of protected public sector data, reflecting a prescriptive yet enabling regulatory stance designed to unlock the economic value of data while maintaining strict compliance with the GDPR.

Key AI Legislation

The legislative landscape is anchored by several key instruments that ensure a comprehensive coverage of the AI lifecycle. Law 5188/2025 is the most recent addition, focusing on the implementation of the Data Governance Act and the National Strategy for public sector data. This act establishes the framework for re-using protected public sector information and creates the role of the Data Use Officer (DUO). Law 4961/2022 remains the primary horizontal statute on emerging technologies. It mandates Algorithmic Impact Assessments for the public sector and requires registries for AI systems used in profiling or personnel evaluation in the private sector. Law 4727/2020, known as the Code on Digital Governance, provides the overarching legal framework for Greece's digital transition, transposing EU directives on open data and web accessibility, and providing the legal basis for interoperability across the Greek state. Law 5039/2023 is an omnibus act that amended Law 4961/2022 to clarify cybersecurity oversight and the governance of the Galileo Public Regulated Service (PRS) under the National Cybersecurity Authority. Finally, the EU AI Act (Regulation (EU) 2024/1689) is directly applicable in Greece, providing the tiered risk-based classification system and the primary compliance obligations for providers and deployers of AI systems. Together, these laws create a comprehensive net that covers data acquisition, system development, deployment, and post-market monitoring, ensuring that the Hellenic Republic remains at the forefront of European digital sovereignty.

Governance & Enforcement Bodies

The governance of AI in Greece is a distributed but coordinated effort led by the Ministry of Digital Governance. The Ministry acts as the "single information point" and the competent supervisory authority for data intermediation services and the National Strategy for public sector data. Within the Ministry, the General Directorate of Cybersecurity and the General Secretariat for Information Systems of Public Administration (ΓΓΠΣΔΔ) handle the technical and security aspects of AI deployment. A key institutional feature is the Coordinating Committee for Artificial Intelligence, which steers the implementation of the national strategy and advises the government on legal safeguards and ethical considerations. This committee ensures that AI policy is integrated across various ministries, from Health to Infrastructure and Transport. For the enforcement of fundamental rights, Greece has designated four existing independent authorities under Article 77 of the EU AI Act. These are the Hellenic Data Protection Authority (HDPA), the Greek Ombudsman, the Hellenic Authority for Ensuring Communications Secrecy (ADAE), and the Greek National Commission for Human Rights (GNCHR). These bodies have the power to request documentation and investigate the impact of high-risk AI systems within their respective jurisdictions. While the Ministry of Digital Governance coordinates the overall market surveillance, these independent bodies provide a critical check on the use of AI in sensitive areas such as law enforcement, migration, and employment. This cluster-based governance model ensures that expertise in privacy, equality, and human rights is directly applied to AI oversight, preventing the concentration of power in a single administrative entity.

Penalties & Enforcement

Enforcement of AI regulations in Greece involves a combination of administrative fines, injunctive measures, and procedural sanctions. Under Law 5188/2025, breaches of the national data governance measures can result in administrative fines ranging from €10,000 to €100,000. These penalties are designed to be proportionate yet deterrent, particularly for violations related to the unauthorized reuse of protected public sector information or failures in the notification process for data intermediation service providers. The law also provides for the removal of organizations from the national register of data altruism organizations in cases of non-compliance with transparency or governance standards. All administrative decisions are subject to judicial review before the competent Administrative Court of Appeal, ensuring a robust appeals process for regulated entities. The enforcement landscape is further significantly expanded by the EU AI Act, which Greece implements through its designated market surveillance authorities. The AI Act prescribes massive tiered fines: up to €35 million or 7% of total worldwide annual turnover for prohibited AI practices; up to €15 million or 3% for non-compliance with requirements for high-risk AI systems; and up to €7.5 million or 1.5% for providing incorrect or misleading information to authorities. In Greece, the market surveillance authority works in coordination with the Article 77 fundamental rights bodies. While the fundamental rights bodies can request documentation and investigations, the primary power to impose these heavy fines and order corrective measures (such as the withdrawal of a system from the market) rests with the market surveillance authority, creating a clear separation between rights-based review and market-based enforcement.

Data Protection Framework

The data protection framework in Greece is built upon the General Data Protection Regulation (GDPR) and its national implementing act, Law 4624/2019. This framework is central to AI regulation, as most AI systems rely on the processing of personal data. The Hellenic Data Protection Authority (HDPA) is the primary regulator, ensuring that AI developers and deployers adhere to principles of data minimization, purpose limitation, and transparency. Law 4961/2022 explicitly requires that any Algorithmic Impact Assessment (AIA) must be conducted in coordination with the Data Protection Impact Assessment (DPIA) required under the GDPR. This ensures that the risks to individual privacy are evaluated alongside the broader societal and technical risks posed by the AI system. Greece has also introduced specific data governance rules through Law 5188/2025 to facilitate the reuse of "protected" public sector data—data that is subject to IP rights, statistical confidentiality, or personal data protections. This law promotes the principle of "open access by design and by default" but mandates that such data must be anonymized or processed in secure environments to prevent the re-identification of individuals. The appointment of Data Use Officers (DUOs) across the public sector is a strategic move to ensure that data sharing for AI training and research is done legally and securely. Greece does not have general data localization requirements, but it emphasizes the use of the "G-Cloud" (Government Cloud) for sensitive public sector data, ensuring that high-security standards are maintained within the national digital infrastructure. This focus on secure, sovereign data environments is a cornerstone of the Greek strategy to build a trustworthy AI ecosystem.

Sector-Specific Rules

In the public sector, AI regulation is particularly stringent. Law 4961/2022 mandates that public authorities may only deploy AI systems when authorized by law and after conducting a thorough AIA. These systems must be recorded in a central registry that describes their technical characteristics, the data sources used, and the population affected. This is particularly relevant in sectors like Health and Social Security, where AI is used for disability registries (digital KEPAs) and diagnostic support. In these contexts, the law emphasizes human-in-the-loop requirements to prevent automated decisions from negatively impacting citizens' access to essential services. The "Digital Transformation Bible" further outlines specific AI pilot projects in justice, where AI is being tested for case-law analysis and administrative efficiency, subject to strict judicial independence safeguards. Beyond public administration, Greece is focusing on AI applications in strategic sectors such as Maritime/Shipping and Tourism. For maritime logistics, the regulatory focus is on the use of AI for autonomous vessel navigation and port management, aligning with international maritime standards and EU cybersecurity rules. In the tourism sector, AI is being deployed for personalized visitor experiences and resource management. Law 5039/2023 introduced specific provisions for the use of the Galileo satellite system (PRS) in transport and critical infrastructure, which is vital for autonomous vehicles and logistics drones. Furthermore, Law 4961/2022 sets specific rules for Unmanned Aerial Systems (UAS) used in postal and logistics services, combining technical safety requirements with data privacy protections for the operation of delivery drones in urban environments.

International Alignment

Greece’s AI regulatory framework is characterized by deep alignment with European Union standards and international best practices. As an EU member state, Greece is a direct participant in the implementation of the EU AI Act, the Data Act, and the Data Governance Act. The Ministry of Digital Governance actively coordinates with the European Commission and the European Data Innovation Board to ensure that Greek national registries and supervisory bodies are interoperable with EU-level systems. Greece has also committed to the OECD Principles on Artificial Intelligence, which emphasize trustworthy AI, transparency, and accountability. This international alignment is not merely passive; Greece has sought to lead in areas like "cultural heritage and AI," proposing flagship programs that use AI to preserve and promote Hellenic culture while respecting intellectual property rights. The "Blueprint for Greece’s AI Transformation" explicitly references the need for Greece to participate in international AI research networks and to align its national standards with global cybersecurity frameworks. Greece is also a participant in the "Interoperable Europe" initiative (Regulation (EU) 2024/903), which aims to create seamless cross-border digital public services. By adopting the "AI Politeia" concept—an advisory research lab—Greece seeks to create a bridge between domestic policy and international academic excellence. This alignment extends to bilateral and multilateral agreements on cybersecurity and data sharing, ensuring that Greece remains a secure and attractive destination for international AI investment while maintaining the high standards of fundamental rights protection expected within the European Digital Single Market.

Future Developments

The future of AI regulation in Greece will be defined by the full operationalization of the EU AI Act and the maturation of the 2025-2030 National Strategy for public sector data. By late 2026, the additional competences granted to the Article 77 fundamental rights authorities (HDPA, Ombudsman, ADAE, GNCHR) will be fully in effect, leading to a more rigorous oversight of high-risk AI systems in the wild. We expect a wave of secondary legislation, including ministerial decisions that will define the specific technical templates for Algorithmic Impact Assessments and the detailed operational rules for the "single information point" for data reuse. The government is also expected to launch the "AI Observatory," a digital dashboard that will monitor AI adoption rates, compliance metrics, and incident reporting across both the public and private sectors. Another significant area of development is the expansion of the "Data Altruism" framework. Under Law 5188/2025, the Ministry of Digital Governance will begin the voluntary registration of data altruism organizations, which is expected to unlock large datasets for medical research and environmental monitoring. Furthermore, as the "Blueprint for Greece’s AI Transformation" moves from a policy proposal to a series of enacted laws, we anticipate new regulations specifically targeting AI in education and the reskilling of the workforce. These measures will likely include incentives for "ethics-by-design" development and the establishment of national AI testbeds (sandboxes) where startups can test their models in a controlled regulatory environment. The ongoing update of the "Digital Transformation Bible" will continue to integrate these emerging needs into the unified government policy program, ensuring that Greece remains a resilient and innovative digital state.

Key Regulations

TitleTypeStatusYear
Law 5188/2025: Measures for the implementation of the Data Governance ActActIn Force2025
Designation of fundamental-rights authorities under the EU AI Act (Art. 77)PolicyAwaiting Entry2024
A Blueprint for Greece's AI TransformationPolicyDraft2024
Law 5039/2023: Omnibus measures (Cybersecurity amendments)ActIn Force2023
Law 4961/2022: Emerging ICT and Digital GovernanceActIn Force2022
Digital Transformation Bible 2020-2025PolicyIn Force2021
Law 4727/2020: Code on Digital GovernanceActIn Force2020

Enforcement Bodies

AgencyMandateKey PowersWebsite
Ministry of Digital GovernanceCentral coordination of digital policy and data governance.Supervisory authority for data intermediation; drafting national AI strategy.mindigital.gr
Hellenic Data Protection Authority (HDPA)Supervision of personal data protection and fundamental rights.Investigative powers; administrative fines for GDPR/AI Act breaches.dpa.gr
The Greek OmbudsmanProtection of citizens' rights in interactions with the state.Access to documentation for high-risk AI systems; mediation and reporting.synigoros.gr
ADAE (Authority for Communication Secrecy)Ensuring the secrecy of communications.Oversight of AI affecting communication privacy and security.adae.gr
National Cybersecurity AuthorityNational cybersecurity coordination and certification.Market surveillance for ICT products; conformity assessments.cybersecurity.gov.gr

Real enforcement actions

4 actions recorded · ~€20.2M in fines

Public enforcement actions where regulators cited Greece - AI Regulation Overview (Law 5188/2025). Helps you see how the law is actually applied in practice.

  1. OtherDec 31, 2025

    HDPA vs Hellenic Police / Ministry of Citizen Protection

    Sector: Public administration / Law enforcement

    The HDPA issued Decision 45/2025, ruling that the activation of the 'Smart Policing' system, which includes AI technologies like facial recognition and fingerprint identification, would constitute unlawful processing of personal data. The Authority explicitly warned the Hellenic Police not to operationalize this AI-enabled system.

    Source ↗
  2. May 29, 2025

    HDPA vs Hangzhou DeepSeek Artificial Intelligence Co., Ltd.

    Sector: Technology

    The HDPA closed its investigation into the DeepSeek Artificial Intelligence application after Hangzhou DeepSeek Artificial Intelligence Co., Ltd. appointed an EU representative.

    Source ↗
  3. FineApr 3, 2024

    Hellenic Data Protection Authority (HDPA) vs Ministry of Migration and Asylum

    €175K
    Fine

    The HDPA fined the Ministry EUR 175,000 with a compliance order over the 'Centaur' (AI behavioural-analytics cameras, drones, CCTV) and 'Hyperion' (RFID + fingerprint biometric entry-exit) surveillance systems at reception centres on five Aegean islands, finding the DPIAs substantially incomplete.

    Source ↗
  4. FineJul 13, 2022

    Hellenic Data Protection Authority (HDPA) vs Clearview AI Inc.

    Sector: Technology

    €20.0M
    Fine

    HDPA imposed a €20 million fine on Clearview AI for violating GDPR by unlawfully collecting and processing facial images (biometric data) from public websites for facial recognition, and ordered the deletion of data on Greek data subjects and prohibition of further processing.

    Source ↗

© Regulations.AI — created on 06-Jan-2026 using Gemini 3 Flash Preview