Data & Privacy ยท Cyprus
Data protection & GDPR compliance in Cyprus (2026)
Cyprus shaded by its data & privacy status
Data protection in Cyprus: comprehensive law.
FrameworkGDPR (Regulation 2016/679) directly applicable; national supplementing legislation: Law 125(I)/2018 (Protection of Physical Persons Against the Processing of Personal Data and Free Movement of Such Data); Law 44(I)/2019 for law-enforcement processing (Directive 2016/680). Supervisory authority: Office of the Commissioner for Personal Data Protection (Nicosia).
As an EU member state, Cyprus applies the GDPR directly and has enacted Law 125(I)/2018 to exercise permitted national derogations and specify the powers of its independent supervisory authority, the Commissioner for Personal Data Protection. The Commissioner enforces GDPR rights and obligations, including transparency, data-subject rights, DPO appointment, DPIA requirements, and 72-hour breach notification, and has issued over โฌ1 million in cumulative fines since 2018. A new Commissioner, Maria Christofidou, was appointed by the Council of Ministers in September 2025.
GDPR & data protection in Cyprus
In Cyprus, data protection is governed by the EU General Data Protection Regulation (GDPR), which applies directly and is enforced by the Office of the Commissioner for Personal Data Protection.
- Framework
- the GDPR (Regulation (EU) 2016/679) plus the national data-protection act
- Supervisory authority
- the Office of the Commissioner for Personal Data Protection
- Applies to
- any organisation processing the personal data of people in Cyprus, wherever the organisation is based
- Maximum fine
- โฌ20 million or 4% of global annual turnover, whichever is higher
- Breach notification
- within 72 hours of becoming aware, to the supervisory authority
- DPO
- required for large-scale monitoring or large-scale special-category processing
The GDPR is bloc-wide; Cyprus supplements it with a national data-protection act and its own supervisory authority.
GDPR in Cyprus: FAQ
Yes. As an EU/EEA member, Cyprus applies the GDPR (Regulation (EU) 2016/679) directly, enforced by the Office of the Commissioner for Personal Data Protection.
The Office of the Commissioner for Personal Data Protection.
Up to โฌ20 million or 4% of global annual turnover, whichever is higher.
A DPO is required where you carry out large-scale monitoring or process special-category data at scale.
Personal-data breaches must be notified to the supervisory authority within 72 hours of becoming aware.
Key points
GDPR (Regulation 2016/679) is directly applicable. Law 125(I)/2018, in force since 31 July 2018, supplements the GDPR by exercising national margins of appreciation and establishing the supervisory authority. It repealed the previous Law 138(I)/2001.
The Commissioner for Personal Data Protection is the independent national DPA. Maria Christofidou was appointed Commissioner by the Council of Ministers in September 2025, succeeding Irene Loizidou Nicolaidou (who served simultaneously as EDPB Vice-President). The Commissioner has powers to investigate, issue corrective measures, and impose administrative fines.
Cyprus set the age of digital consent for information-society services at 14 years (below which parental consent is required). Law 125(I)/2018 also prohibits the processing of genetic and biometric data for life and health insurance purposes, a stricter position than the GDPR baseline.
Controllers must observe GDPR principles (lawfulness, purpose limitation, data minimisation), conduct DPIAs for high-risk processing, appoint a DPO where mandated, and notify the Commissioner of personal data breaches within 72 hours. DPO contact details must be registered via the Commissioner's online portal.
Individuals hold the full suite of GDPR rights: access, rectification, erasure ('right to be forgotten'), restriction of processing, data portability, and the right to object. These may be restricted by national law only where necessary to safeguard specified public-interest objectives.
The Cyprus DPC has issued over โฌ1 million in cumulative administrative fines since GDPR took effect. A notable 2025 action saw two fines totalling โฌ58,400 imposed on Aylo Freesites Ltd (formerly Mindgeek) for GDPR breaches (decision dated 28 March 2025). Enforcement has focused on tourism, financial services, telecoms, marketing, and employment contexts.
Timeline - major decisions & events
Parliament enacted the NIS2 transposition law, extending mandatory cybersecurity obligations to a broader set of 'essential' and 'important' entities, imposing 6-hour initial incident-notification deadlines, and making top management personally accountable for cybersecurity governance. The Digital Security Authority gained enhanced fine-setting powers, creating a tighter regulatory perimeter around organisations that process personal data at scale.
Harneys (law firm briefing on NIS2 Amendment Law 2025) โThe Commissioner fined adult-content platform operator Aylo Freesites Ltd โฌ58,400 for violating the GDPR principles of accountability, transparency, lawfulness, data minimisation, storage limitation and data security, as well as illegal cookie deployment without valid consent. The case was one of the largest fines imposed by Cyprus against a digital content provider and reinforced the Commissioner's enforcement focus on online tracking.
DataGuidance โ Cyprus jurisdiction overview (citing Commissioner decision Q4 2024) โThe Office of the Commissioner published findings from an administrative audit of 28 public-sector bodies (ministries, departments, independent offices), revealing 60% initially lacked a GDPR-compliant privacy policy or DPO contact details and 40% had policies with material gaps. All 28 entities achieved full compliance by August 2024 after acting on the Commissioner's recommendations, marking the first systematic government-wide transparency audit.
DataGuidance (citing Cyprus Commissioner for Personal Data Protection, 2 Sept 2024) โThe Commissioner's Office published a structured compliance guide addressing frequent gaps found in complaints and investigations, covering lawful bases, data subject rights, data breach notification procedures, and DPO appointment requirements. The guidance served as a key soft-law reference for Cypriot organisations navigating Law 125(I)/2018.
DataGuidance (citing Cyprus Commissioner for Personal Data Protection, 19 Feb 2024) โThe Commissioner fined Bank of Cyprus โฌ17,000 after a personal data breach revealed deficiencies in the bank's technical security measures. The sanction signalled that major financial institutions are not exempt from data-protection accountability and complemented parallel supervisory oversight by the Central Bank of Cyprus.
DataGuidance (citing Cyprus Commissioner for Personal Data Protection, 15 Nov 2022) โLarnaca criminal court imposed โฌ76,000 in criminal fines on WS WiSpear Systems Ltd under the criminal provisions of Law 125(I)/2018 for the unlawful collection and processing of personal data via its mobile surveillance rig. Combined with the 2021 administrative fine of โฌ925,000, total sanctions exceeded โฌ1 million โ the largest data-protection enforcement action in Cyprus's history.
Cyprus Mail (22 Feb 2022) โThe Commissioner imposed a โฌ925,000 administrative fine on surveillance firm WS WiSpear Systems Ltd for covertly harvesting MAC addresses and IMSI identifiers from thousands of mobile devices near Larnaca airport using a purpose-built van, breaching GDPR principles of lawfulness, fairness and transparency. The 'spy van' case became a landmark test of whether Cyprus would enforce privacy rights against advanced commercial surveillance.
DataGuidance (citing Cyprus Commissioner for Personal Data Protection, Nov 2021) โCyprus enacted the Protection of Natural Persons with regard to the Processing of Personal Data Law 125(I)/2018, supplementing the directly applicable GDPR, exercising key Member-State derogations (age of consent for children's data set at 16; employment data rules; research exemptions), and repealing the prior Law 138(I)/2001. The law formally re-established and empowered the Commissioner for Personal Data Protection as Cyprus's independent supervisory authority under GDPR Article 51.
Cyprus Commissioner for Personal Data Protection โ official text of Law 125(I)/2018 โPart 14 of the Regulation of Electronic Communications and Postal Services Law 112(I)/2004 (as amended) entered into force, implementing the EU ePrivacy Directive (2002/58/EC as amended by 2009/136/EC). The provisions required opt-in consent for cookies and unsolicited electronic marketing, with the Commissioner for Personal Data Protection designated as the competent enforcement authority alongside OCECPR (the telecoms regulator).
Linklaters โ Data Protected: Cyprus โCyprus enacted the Processing of Personal Data (Protection of Individuals) Law 138(I)/2001, implementing EU Directive 95/46/EC ahead of EU accession (which came in 2004). The law established the Office of the Commissioner for Personal Data Protection as an independent supervisory authority, set out data-subject rights, controller obligations, and registration requirements, and formed the bedrock of Cyprus's privacy framework for nearly two decades until replaced by Law 125(I)/2018.
ILO NATLEX โ Law 138(I)/2001 record โCyprus - other topics
Data & Privacy in other countries
Last verified 5/24/2026 ยท Orientation, not legal advice - verify against the primary sources linked above. Methodology & how to cite ยท State of Technology Regulation 2026 ยท Explore the full world map โ