act · Effective Jan 1, 2025
GR regulates AI through Law 5188/2025: Measures for the implementation of the Data Governance Act.
Law 5188/2025: Measures for the implementation of the Data Governance Act · effective 2025
Updated 60 days ago · 2 sources · confidence: medium
Overview
Greece’s approach to artificial intelligence (AI) regulation is characterized by a proactive, "digital-first" philosophy that seeks to balance rapid technological adoption with robust legal safeguards. Historically, Greece was among the first European Union member states to enact a horizontal statute specifically addressing emerging technologies, including AI, through Law 4961/2022. This early legislative move signaled a shift from fragmented sectoral rules to a unified national framework. The Greek regulatory philosophy is deeply rooted in the "Digital Transformation Bible 2020-2025," which envisioned a modern, interoperable state. By 2026, this vision has matured into a sophisticated ecosystem where national laws such as Law 5188/2025 (implementing the Data Governance Act) work in tandem with the EU AI Act to ensure that AI systems deployed within the Hellenic Republic are transparent, accountable, and human-centric. The institutional center of gravity for AI in Greece is the Ministry of Digital Governance, which serves as the primary coordinator for national digital policy. The government’s strategy has evolved from basic digitalization to a value-driven "AI Transformation Blueprint," published in late 2024. This blueprint emphasizes the protection of human dignity, pluralism, and transparency as non-negotiable pillars of the Greek AI economy. Greece has also demonstrated a commitment to institutional innovation by designating a cluster of independent authorities—including the Data Protection Authority and the Greek Ombudsman—to supervise fundamental rights in the context of high-risk AI. This multi-layered governance model aims to position Greece not just as a consumer of AI, but as a regional leader in ethical AI governance and secure data sharing, particularly through its "open access by design" principle for public sector data.
Regulatory approach
Greece employs a hybrid regulatory approach that combines horizontal statutory obligations with targeted sectoral requirements, all framed within the mandatory architecture of European Union law. The foundational horizontal instrument, Law 4961/2022, sets broad requirements for AI systems, Internet of Things (IoT) devices, and distributed ledger technologies. This law introduced the concept of mandatory Algorithmic Impact Assessments (AIAs) for public sector AI deployments long before such measures were standardized across the EU. This risk-based approach is now being harmonized with the EU AI Act (Regulation (EU) 2024/1689), which classifies AI systems based on their potential to cause harm. Greece’s national implementation focuses heavily on the "public-law mission" of state bodies, ensuring that any algorithmic decision-making affecting citizens is subject to strict transparency and registry requirements. In addition to binding legislation, Greece utilizes "soft law" and strategic policy documents to guide the private sector and research community. The "Blueprint for Greece’s AI Transformation" serves as a foundational policy proposal that informs subsequent legislative and budgetary actions. This approach is characterized by a "staged implementation" model, where governance bodies and flagship pilots are established first, followed by mature regulatory machinery and enforcement. A unique feature of the Greek approach is the mandatory appointment of Data Use Officers (DUOs) within central government bodies under Law 5188/2025. These officers are distinct from Data Protection Officers (DPOs) and are specifically tasked with managing the reuse of protected public sector data, reflecting a prescriptive yet enabling regulatory stance designed to unlock the economic value of data while maintaining strict compliance with the GDPR. The governance of AI in Greece is a distributed but coordinated effort led by the Ministry of Digital Governance. The Ministry acts as the "single information point" and the competent supervisory authority for data intermediation services and the National Strategy for public sector data. Within the Ministry, the General Directorate of Cybersecurity and the General Secretariat for Information Systems of Public Administration (ΓΓΠΣΔΔ) handle the technical and security aspects of AI deployment. A key institutional feature is the Coordinating Committee for Artificial Intelligence, which steers the implementation of the national strategy and advises the government on legal safeguards and ethical considerations. This committee ensures that AI policy is integrated across various ministries, from Health to Infrastructure and Transport. For the enforcement of fundamental rights, Greece has designated four existing independent authorities under Article 77 of the EU AI Act. These are the Hellenic Data Protection Authority (HDPA), the Greek Ombudsman, the Hellenic Authority for Ensuring Communications Secrecy (ADAE), and the Greek National Commission for Human Rights (GNCHR). These bodies have the power to request documentation and investigate the impact of high-risk AI systems within their respective jurisdictions. While the Ministry of Digital Governance coordinates the overall market surveillance, these independent bodies provide a critical check on the use of AI in sensitive areas such as law enforcement, migration, and employment. This cluster-based governance model ensures that expertise in privacy, equality, and human rights is directly applied to AI oversight, preventing the concentration of power in a single administrative entity.
Enforcement & penalties
Enforcement of AI regulations in Greece involves a combination of administrative fines, injunctive measures, and procedural sanctions. Under Law 5188/2025, breaches of the national data governance measures can result in administrative fines ranging from €10,000 to €100,000. These penalties are designed to be proportionate yet deterrent, particularly for violations related to the unauthorized reuse of protected public sector information or failures in the notification process for data intermediation service providers. The law also provides for the removal of organizations from the national register of data altruism organizations in cases of non-compliance with transparency or governance standards. All administrative decisions are subject to judicial review before the competent Administrative Court of Appeal, ensuring a robust appeals process for regulated entities. The enforcement landscape is further significantly expanded by the EU AI Act, which Greece implements through its designated market surveillance authorities. The AI Act prescribes massive tiered fines: up to €35 million or 7% of total worldwide annual turnover for prohibited AI practices; up to €15 million or 3% for non-compliance with requirements for high-risk AI systems; and up to €7.5 million or 1.5% for providing incorrect or misleading information to authorities. In Greece, the market surveillance authority works in coordination with the Article 77 fundamental rights bodies. While the fundamental rights bodies can request documentation and investigations, the primary power to impose these heavy fines and order corrective measures (such as the withdrawal of a system from the market) rests with the market surveillance authority, creating a clear separation between rights-based review and market-based enforcement.
Data protection
The data protection framework in Greece is built upon the General Data Protection Regulation (GDPR) and its national implementing act, Law 4624/2019. This framework is central to AI regulation, as most AI systems rely on the processing of personal data. The Hellenic Data Protection Authority (HDPA) is the primary regulator, ensuring that AI developers and deployers adhere to principles of data minimization, purpose limitation, and transparency. Law 4961/2022 explicitly requires that any Algorithmic Impact Assessment (AIA) must be conducted in coordination with the Data Protection Impact Assessment (DPIA) required under the GDPR. This ensures that the risks to individual privacy are evaluated alongside the broader societal and technical risks posed by the AI system. Greece has also introduced specific data governance rules through Law 5188/2025 to facilitate the reuse of "protected" public sector data—data that is subject to IP rights, statistical confidentiality, or personal data protections. This law promotes the principle of "open access by design and by default" but mandates that such data must be anonymized or processed in secure environments to prevent the re-identification of individuals. The appointment of Data Use Officers (DUOs) across the public sector is a strategic move to ensure that data sharing for AI training and research is done legally and securely. Greece does not have general data localization requirements, but it emphasizes the use of the "G-Cloud" (Government Cloud) for sensitive public sector data, ensuring that high-security standards are maintained within the national digital infrastructure. This focus on secure, sovereign data environments is a cornerstone of the Greek strategy to build a trustworthy AI ecosystem.
Sector-specific rules
In the public sector, AI regulation is particularly stringent. Law 4961/2022 mandates that public authorities may only deploy AI systems when authorized by law and after conducting a thorough AIA. These systems must be recorded in a central registry that describes their technical characteristics, the data sources used, and the population affected. This is particularly relevant in sectors like Health and Social Security, where AI is used for disability registries (digital KEPAs) and diagnostic support. In these contexts, the law emphasizes human-in-the-loop requirements to prevent automated decisions from negatively impacting citizens' access to essential services. The "Digital Transformation Bible" further outlines specific AI pilot projects in justice, where AI is being tested for case-law analysis and administrative efficiency, subject to strict judicial independence safeguards. Beyond public administration, Greece is focusing on AI applications in strategic sectors such as Maritime/Shipping and Tourism. For maritime logistics, the regulatory focus is on the use of AI for autonomous vessel navigation and port management, aligning with international maritime standards and EU cybersecurity rules. In the tourism sector, AI is being deployed for personalized visitor experiences and resource management. Law 5039/2023 introduced specific provisions for the use of the Galileo satellite system (PRS) in transport and critical infrastructure, which is vital for autonomous vehicles and logistics drones. Furthermore, Law 4961/2022 sets specific rules for Unmanned Aerial Systems (UAS) used in postal and logistics services, combining technical safety requirements with data privacy protections for the operation of delivery drones in urban environments.
International alignment
Greece’s AI regulatory framework is characterized by deep alignment with European Union standards and international best practices. As an EU member state, Greece is a direct participant in the implementation of the EU AI Act, the Data Act, and the Data Governance Act. The Ministry of Digital Governance actively coordinates with the European Commission and the European Data Innovation Board to ensure that Greek national registries and supervisory bodies are interoperable with EU-level systems. Greece has also committed to the OECD Principles on Artificial Intelligence, which emphasize trustworthy AI, transparency, and accountability. This international alignment is not merely passive; Greece has sought to lead in areas like "cultural heritage and AI," proposing flagship programs that use AI to preserve and promote Hellenic culture while respecting intellectual property rights. The "Blueprint for Greece’s AI Transformation" explicitly references the need for Greece to participate in international AI research networks and to align its national standards with global cybersecurity frameworks. Greece is also a participant in the "Interoperable Europe" initiative (Regulation (EU) 2024/903), which aims to create seamless cross-border digital public services. By adopting the "AI Politeia" concept—an advisory research lab—Greece seeks to create a bridge between domestic policy and international academic excellence. This alignment extends to bilateral and multilateral agreements on cybersecurity and data sharing, ensuring that Greece remains a secure and attractive destination for international AI investment while maintaining the high standards of fundamental rights protection expected within the European Digital Single Market.
What's next
The future of AI regulation in Greece will be defined by the full operationalization of the EU AI Act and the maturation of the 2025-2030 National Strategy for public sector data. By late 2026, the additional competences granted to the Article 77 fundamental rights authorities (HDPA, Ombudsman, ADAE, GNCHR) will be fully in effect, leading to a more rigorous oversight of high-risk AI systems in the wild. We expect a wave of secondary legislation, including ministerial decisions that will define the specific technical templates for Algorithmic Impact Assessments and the detailed operational rules for the "single information point" for data reuse. The government is also expected to launch the "AI Observatory," a digital dashboard that will monitor AI adoption rates, compliance metrics, and incident reporting across both the public and private sectors. Another significant area of development is the expansion of the "Data Altruism" framework. Under Law 5188/2025, the Ministry of Digital Governance will begin the voluntary registration of data altruism organizations, which is expected to unlock large datasets for medical research and environmental monitoring. Furthermore, as the "Blueprint for Greece’s AI Transformation" moves from a policy proposal to a series of enacted laws, we anticipate new regulations specifically targeting AI in education and the reskilling of the workforce. These measures will likely include incentives for "ethics-by-design" development and the establishment of national AI testbeds (sandboxes) where startups can test their models in a controlled regulatory environment. The ongoing update of the "Digital Transformation Bible" will continue to integrate these emerging needs into the unified government policy program, ensuring that Greece remains a resilient and innovative digital state.
act · Effective Jan 1, 2025
policy · Effective Nov 11, 2024
policy · Effective Jan 1, 2024
act · Effective Jan 1, 2023
act · Effective Jan 1, 2022
policy · Effective Jan 1, 2021
act · Effective Jan 1, 2020
central_coordinator
Central coordination of digital policy and data governance.
data_protection
Supervision of personal data protection and fundamental rights.
sectoral
Protection of citizens' rights in interactions with the state.
data_protection
Ensuring the secrecy of communications.
enforcement
National cybersecurity coordination and certification.
Jun 29, 2025 · news
Greek Ministry of Digital Governance renamed to include AI
Open source →May 28, 2025 · enforcement_action
HDPA closes investigation into DeepSeek
Open source →Nov 27, 2024 · news
Greece releases national AI blueprint
Open source →Nov 11, 2024 · law_amended
Authorities appointed to oversee EU AI Act in Greece
Open source →