Skip to content
World Watch/Cyprus/Data & Privacy

Data & Privacy ยท Cyprus

Data protection & GDPR compliance in Cyprus (2026)

Comprehensive lawCountry index 96 ยท A+

Cyprus shaded by its data & privacy status

Data protection in Cyprus: comprehensive law.

FrameworkGDPR (Regulation 2016/679) directly applicable; national supplementing legislation: Law 125(I)/2018 (Protection of Physical Persons Against the Processing of Personal Data and Free Movement of Such Data); Law 44(I)/2019 for law-enforcement processing (Directive 2016/680). Supervisory authority: Office of the Commissioner for Personal Data Protection (Nicosia).

As an EU member state, Cyprus applies the GDPR directly and has enacted Law 125(I)/2018 to exercise permitted national derogations and specify the powers of its independent supervisory authority, the Commissioner for Personal Data Protection. The Commissioner enforces GDPR rights and obligations, including transparency, data-subject rights, DPO appointment, DPIA requirements, and 72-hour breach notification, and has issued over โ‚ฌ1 million in cumulative fines since 2018. A new Commissioner, Maria Christofidou, was appointed by the Council of Ministers in September 2025.

GDPR & data protection in Cyprus

In Cyprus, data protection is governed by the EU General Data Protection Regulation (GDPR), which applies directly and is enforced by the Office of the Commissioner for Personal Data Protection.

Framework
the GDPR (Regulation (EU) 2016/679) plus the national data-protection act
Supervisory authority
the Office of the Commissioner for Personal Data Protection
Applies to
any organisation processing the personal data of people in Cyprus, wherever the organisation is based
Maximum fine
โ‚ฌ20 million or 4% of global annual turnover, whichever is higher
Breach notification
within 72 hours of becoming aware, to the supervisory authority
DPO
required for large-scale monitoring or large-scale special-category processing

The GDPR is bloc-wide; Cyprus supplements it with a national data-protection act and its own supervisory authority.

GDPR in Cyprus: FAQ

Does the GDPR apply in Cyprus?

Yes. As an EU/EEA member, Cyprus applies the GDPR (Regulation (EU) 2016/679) directly, enforced by the Office of the Commissioner for Personal Data Protection.

Who enforces data protection law in Cyprus?

The Office of the Commissioner for Personal Data Protection.

What are the GDPR fines in Cyprus?

Up to โ‚ฌ20 million or 4% of global annual turnover, whichever is higher.

Do you need a Data Protection Officer in Cyprus?

A DPO is required where you carry out large-scale monitoring or process special-category data at scale.

How quickly must a data breach be reported in Cyprus?

Personal-data breaches must be notified to the supervisory authority within 72 hours of becoming aware.

Key points

Primary legal framework

GDPR (Regulation 2016/679) is directly applicable. Law 125(I)/2018, in force since 31 July 2018, supplements the GDPR by exercising national margins of appreciation and establishing the supervisory authority. It repealed the previous Law 138(I)/2001.

Supervisory authority

The Commissioner for Personal Data Protection is the independent national DPA. Maria Christofidou was appointed Commissioner by the Council of Ministers in September 2025, succeeding Irene Loizidou Nicolaidou (who served simultaneously as EDPB Vice-President). The Commissioner has powers to investigate, issue corrective measures, and impose administrative fines.

National derogations under Law 125(I)/2018

Cyprus set the age of digital consent for information-society services at 14 years (below which parental consent is required). Law 125(I)/2018 also prohibits the processing of genetic and biometric data for life and health insurance purposes, a stricter position than the GDPR baseline.

Key controller/processor obligations

Controllers must observe GDPR principles (lawfulness, purpose limitation, data minimisation), conduct DPIAs for high-risk processing, appoint a DPO where mandated, and notify the Commissioner of personal data breaches within 72 hours. DPO contact details must be registered via the Commissioner's online portal.

Data subject rights

Individuals hold the full suite of GDPR rights: access, rectification, erasure ('right to be forgotten'), restriction of processing, data portability, and the right to object. These may be restricted by national law only where necessary to safeguard specified public-interest objectives.

Enforcement record

The Cyprus DPC has issued over โ‚ฌ1 million in cumulative administrative fines since GDPR took effect. A notable 2025 action saw two fines totalling โ‚ฌ58,400 imposed on Aylo Freesites Ltd (formerly Mindgeek) for GDPR breaches (decision dated 28 March 2025). Enforcement has focused on tourism, financial services, telecoms, marketing, and employment contexts.

Timeline - major decisions & events

Apr 25, 2025law
Cyprus transposes NIS2 Directive โ€” Network and Information Systems Security (Amendment) Law 2025

Parliament enacted the NIS2 transposition law, extending mandatory cybersecurity obligations to a broader set of 'essential' and 'important' entities, imposing 6-hour initial incident-notification deadlines, and making top management personally accountable for cybersecurity governance. The Digital Security Authority gained enhanced fine-setting powers, creating a tighter regulatory perimeter around organisations that process personal data at scale.

Harneys (law firm briefing on NIS2 Amendment Law 2025) โ†—
Oct 1, 2024enforcement
Aylo Freesites Ltd fined โ‚ฌ58,400 for cookie abuse and core GDPR breaches

The Commissioner fined adult-content platform operator Aylo Freesites Ltd โ‚ฌ58,400 for violating the GDPR principles of accountability, transparency, lawfulness, data minimisation, storage limitation and data security, as well as illegal cookie deployment without valid consent. The case was one of the largest fines imposed by Cyprus against a digital content provider and reinforced the Commissioner's enforcement focus on online tracking.

DataGuidance โ€” Cyprus jurisdiction overview (citing Commissioner decision Q4 2024) โ†—
Sep 2, 2024decision
Commissioner publishes public-sector website audit: 60% initially non-compliant

The Office of the Commissioner published findings from an administrative audit of 28 public-sector bodies (ministries, departments, independent offices), revealing 60% initially lacked a GDPR-compliant privacy policy or DPO contact details and 40% had policies with material gaps. All 28 entities achieved full compliance by August 2024 after acting on the Commissioner's recommendations, marking the first systematic government-wide transparency audit.

DataGuidance (citing Cyprus Commissioner for Personal Data Protection, 2 Sept 2024) โ†—
Feb 19, 2024guidance
Commissioner issues practical GDPR compliance guidance for controllers and processors

The Commissioner's Office published a structured compliance guide addressing frequent gaps found in complaints and investigations, covering lawful bases, data subject rights, data breach notification procedures, and DPO appointment requirements. The guidance served as a key soft-law reference for Cypriot organisations navigating Law 125(I)/2018.

DataGuidance (citing Cyprus Commissioner for Personal Data Protection, 19 Feb 2024) โ†—
Nov 15, 2022enforcement
Bank of Cyprus fined โ‚ฌ17,000 for personal data security failures

The Commissioner fined Bank of Cyprus โ‚ฌ17,000 after a personal data breach revealed deficiencies in the bank's technical security measures. The sanction signalled that major financial institutions are not exempt from data-protection accountability and complemented parallel supervisory oversight by the Central Bank of Cyprus.

DataGuidance (citing Cyprus Commissioner for Personal Data Protection, 15 Nov 2022) โ†—
Feb 22, 2022enforcement
WiSpear 'spy van' criminal conviction โ€” โ‚ฌ76,000 in court-imposed fines

Larnaca criminal court imposed โ‚ฌ76,000 in criminal fines on WS WiSpear Systems Ltd under the criminal provisions of Law 125(I)/2018 for the unlawful collection and processing of personal data via its mobile surveillance rig. Combined with the 2021 administrative fine of โ‚ฌ925,000, total sanctions exceeded โ‚ฌ1 million โ€” the largest data-protection enforcement action in Cyprus's history.

Cyprus Mail (22 Feb 2022) โ†—
Nov 1, 2021enforcement
WiSpear fined โ‚ฌ925,000 โ€” Cyprus's largest-ever GDPR administrative penalty

The Commissioner imposed a โ‚ฌ925,000 administrative fine on surveillance firm WS WiSpear Systems Ltd for covertly harvesting MAC addresses and IMSI identifiers from thousands of mobile devices near Larnaca airport using a purpose-built van, breaching GDPR principles of lawfulness, fairness and transparency. The 'spy van' case became a landmark test of whether Cyprus would enforce privacy rights against advanced commercial surveillance.

DataGuidance (citing Cyprus Commissioner for Personal Data Protection, Nov 2021) โ†—
Jul 31, 2018lawofficial
Law 125(I)/2018 enacted โ€” national GDPR implementation law replaces 2001 statute

Cyprus enacted the Protection of Natural Persons with regard to the Processing of Personal Data Law 125(I)/2018, supplementing the directly applicable GDPR, exercising key Member-State derogations (age of consent for children's data set at 16; employment data rules; research exemptions), and repealing the prior Law 138(I)/2001. The law formally re-established and empowered the Commissioner for Personal Data Protection as Cyprus's independent supervisory authority under GDPR Article 51.

Cyprus Commissioner for Personal Data Protection โ€” official text of Law 125(I)/2018 โ†—
May 18, 2012law
ePrivacy provisions take force โ€” cookie and electronic marketing consent rules

Part 14 of the Regulation of Electronic Communications and Postal Services Law 112(I)/2004 (as amended) entered into force, implementing the EU ePrivacy Directive (2002/58/EC as amended by 2009/136/EC). The provisions required opt-in consent for cookies and unsolicited electronic marketing, with the Commissioner for Personal Data Protection designated as the competent enforcement authority alongside OCECPR (the telecoms regulator).

Linklaters โ€” Data Protected: Cyprus โ†—
Jan 1, 2001lawofficial
Law 138(I)/2001 โ€” Cyprus enacts first comprehensive data protection statute

Cyprus enacted the Processing of Personal Data (Protection of Individuals) Law 138(I)/2001, implementing EU Directive 95/46/EC ahead of EU accession (which came in 2004). The law established the Office of the Commissioner for Personal Data Protection as an independent supervisory authority, set out data-subject rights, controller obligations, and registration requirements, and formed the bedrock of Cyprus's privacy framework for nearly two decades until replaced by Law 125(I)/2018.

ILO NATLEX โ€” Law 138(I)/2001 record โ†—

Cyprus - other topics

Data & Privacy in other countries

Last verified 5/24/2026 ยท Orientation, not legal advice - verify against the primary sources linked above. Methodology & how to cite ยท State of Technology Regulation 2026 ยท Explore the full world map โ†’