GREECE ADOPTS LEGISLATION IMPLEMENTING THE AI ACT: A PIVOTAL ROLE FOR THE DATA PROTECTION AUTHORITY WITHIN THE NEW REGULATORY FRAMEWORK
In July 2026, Greece adopted Law 5321/2026 (“the Law”) which introduced measures implementing Regulation (EU) 2024/1689 (“AI Act”). In line with the AI Act, the Law aims to establish an appropriate framework for achieving the effective supervision of Artificial Intelligence Systems, to ensure a high level of protection of health, safety and fundamental rights in the use of such systems, and support innovation. In particular, the Law designates, for the purposes of the AI Act, the market surveillance authorities, the single point of contact and the notifying authorities, and regulates issues relating to cooperation and coordination between the competent authorities. Moreover, the Law governs issues pertaining to AI regulatory sandboxes and testing of AI systems in real world conditions. With regards to infringements of the AI Act and the Law, effective, proportionate and dissuasive penalties are determined, while provisions relating to judicial protection and the exercise of the right to appeal against decisions issued pursuant to the AI Act and the Law are also included. In the above regulatory framework, the Hellenic Data Protection Authority is assigned a particularly important and multifaceted role.
28 September 2026
HELLENIC DATA PROTECTION AUTHORITY AS MARKET SURVEILLANCE AUTHORITY AND SINGLE POINT OF CONTACT
The Hellenic Data Protection Authority is designated, according to the Law, as the competent market surveillance authority regarding AI systems involving practices classified as prohibited, pursuant to Article 5 of the AI Act, high-risk AI systems outlined in Annex III of the AI Act, and AI systems for which transparency obligations are applicable, pursuant to Article 50 of the AI Act.
Further, the Law stipulates that the Authority shall be the single point of contact, in accordance with Article 70 para 2 of the AI Act; it is also provided that is shall be in direct contact with the AI Office of the Commission established pursuant to Article 64 of the AI Act, as well as in information exchange with it, and that it will be reporting under the AI Act.
The above roles and responsibilities of the Data Protection Authority are without prejudice to authorities which, under the Greek legislation transposing Directives or implementing Regulations of the EU, as listed in Section A of Annex I to the AI Act, are appointed as market surveillance authorities concerning high-risk AI systems related to the products covered by that EU harmonisation legislation.
ADMINISTRATIVE SANCTIONS AND JUDICIAL PROTECTION
In its capacity as market surveillance authority, the Data Protection Authority is vested by the Law with specific powers that supplement the relevant powers and measures provided under the AI Act.
Specifically, the Data Protection Authority has the power to issue warnings to operators of AI systems considered for being placed on the market or put into service, when it is likely that such systems can infringe the AI Act or the Law, or reprimands in cases that infringements can be established. Pursuant to the Law, the Authority can also order operators to comply with its provisions or with the AI Act and in a specified and prompt manner.
Importantly, the Data Protection Authority is responsible for imposing the administrative fines outlined in Article 99 of the AI Act and has the power to threaten or impose periodic penalty payments where operators fail to comply with its orders; according to the Law, such periodic penalty payments shall not exceed two per cent (2%) of the average daily total worldwide turnover or income in the preceding financial year and their imposition shall cease when the operators concerned demonstrate full compliance with the relevant orders and their requirements.
Similar powers are awarded by the Law to the market surveillance authorities appointed by virtue of special legislation. These authorities, as well as the Data Protection Authority, must impose in each individual case administrative sanctions that are effective, proportionate and dissuasive. Decisions imposing sanctions may be challenged by an application for annulment before the Supreme Administrative Court (Council of State).
AI REGULATORY SANDBOXES, REAL WORLD TESTING, AND THE DUAL ROLE OF THE HELLENIC DATA PROTECTION COMMISSION
With regards to the AI regulatory sandbox which, as per Article 57 of the AI Act, must be established, the Law provides its creation within the Hellenic Telecommunications and Post Commission, while the Data Protection Authority is appointed, together with the Hellenic Telecommunications and Post Commission, as the competent authority concerning its operation.
Further, the responsibility of monitoring the testing of high-risk AI systems in real world conditions outside AI regulatory sandboxes, is in principle assigned to the Data Protection Authority. Importantly, with regards to the approval of the testing required under Article 60 para 4 (b) of the AI Act, such approval must be granted explicitly, under the Law, it being explicitly provided that the expiry of the thirty (30) days for granting of such approval is not deemed as tacit approval.
HELLENIC TELECOMMUNICATIONS AND POST COMMISSION AS NOTIFYING AUTHORITY AND OTHER PROVISIONS
According to the Law and pursuant to Article 28 of the AI Act, the Hellenic Telecommunications and Post Commission will serve as the authority responsible for setting up and carrying out the necessary procedures for the assessment, designation and notification of conformity assessment bodies and for their monitoring.
The Law also provides for the establishment, within the Special Secretariat for Artificial Intelligence and Data Governance of the Ministry of Digital Governance, of a central register of AI systems used by public sector bodies, the reinforcement of the operations of the AI Observatory for monitoring the National AI Strategy, and the facilitation of recruitment of personnel by the Hellenic Data Protection Authority in its capacity as market surveillance authority.
CONCLUDING REMARKS
The rise of the use of Artificial Intelligence and the unprecedented changes it entails, enables people to work more efficiently and improves decision-making, while also transforms businesses and drives economic growth.
The Greek regulatory framework represents a significant step in fostering compliance with the requirements of the AI Act. Within it, the role of the Data Protection Authority is crucial and highlights the paramount importance attributed by the national legislator in the protection of personal data in the use of AI.
Importantly, the framework introduced by the Law is an important piece of the broader regulatory landscape created by the AI Act and requires businesses operating in Greece to adopt appropriate and effective compliance measures.
Article provided by INPLP member: Georgios Tsouloufas (Papadonikolaki-Lianos-Tsouloufas Law Firm, Greece)

By Georgios Tsouloufas — Papadonikolaki-Lianos-Tsouloufas Law Firm, Greece