Data protection in Cyprus

Cyprus answers the questions Europe leaves to each country in its own law: a lower age of consent, closed categories, criminal liability. We will apply those answers to your product.

 

Own consent from

Согласие с

14 years old

14 лет

Fines in 2024

Штрафы за 2024

EUR 133,900

133 900 евро

Criminal ceiling

Уголовный потолок

3 years

3 года

Complaints in 2024

Жалоб за 2024

531

531

When you need data protection advice in Cyprus

A complaint reached the Commissioner

Five hundred complaints a year reach the Commissioner, a fifth of them about unwanted marketing. The first letter arrives with questions rather than a penalty.

Teenagers can sign up to your service

The local age at which a person agrees for themselves is lower than the European default, and a sign-up form built for the default collects consent that does not count here.

You run an insurance or health product

Some processing is closed here outright rather than merely conditioned, and an insurance product is the likeliest place to walk into that wall.

You would rather stay quiet

Staying silent towards the people affected is possible, but only through a written assessment and a prior consultation. It is a procedure, not a decision you make alone.

What you get

  • Your duties under the national law as well as the European ones
  • Consent flows built for the local age
  • A breach route that matches the local form
  • A record of processing that survives an inspection
  • The criminal exposure named, with what removes it

What the Cypriot law adds on top of Europe

The European regulation applies here directly, and it deliberately leaves a set of questions to each member state. Cyprus answered them in law 125(I)/2018, amended in 2022, and those answers are what makes compliance here different from compliance anywhere else in the union.

Supervision belongs to the Commissioner for Personal Data Protection, whose office sits in Nicosia; responsibility for the law as a whole rests with the Minister of Justice and Public Order.

The four local answers

A child agrees for themselves at fourteen

Where an online service relies on the child's own consent, fourteen is the line. Below it, consent is given or approved by whoever holds parental responsibility.

Insurance may not use genetic or biometric data

Processing genetic and biometric data for health and life insurance purposes is prohibited outright. Where consent is the ground for such data, reusing it for anything further needs separate consent.

Silence towards the affected person is a procedure

A controller may be released, wholly or partly, from telling people about a breach — but only after an impact assessment and a prior consultation with the Commissioner, who may attach conditions.

Some failures are criminal as well as expensive

Not keeping the record of processing activities, or giving the Commissioner false or misleading information about it, is a criminal offence for the controller and for the processor alike.

What the local penalties actually look like

The criminal track carries up to three years in prison or thirty thousand euro, or both; where the offence damages the interests of the Republic, the ceiling rises to five years. Administrative fines follow the European scale, with one national cap: a public authority acting non-commercially cannot be fined more than two hundred thousand euro.

The practice is more modest than the scale suggests. In 2024 the Commissioner issued 88 decisions, imposed fines in 21 of them, and the whole year's fines added up to 133,900 euro across 531 complaints and 94 reported breaches.

How a breach is reported here

Notification goes to the Commissioner through the government portal's own service, and for a cross-border breach to the lead authority instead. Providers of publicly available electronic communications services carry a parallel duty under the 2004 communications law, which is easy to miss when only the European text has been read.

The Commissioner may also publish the operations for which a data protection officer is compulsory beyond the European list, and maintains a public register of controllers who have appointed one and asked to be listed. Everything else we handle on the island is gathered on the Cyprus page.

Sources: the age of fourteen, the insurance prohibition, the breach-notification release, the 200,000 cap and the criminal penalties — law 125(I)/2018 as amended by 26(I)/2022; the 2024 figures — the Commissioner's annual report; the notification route — the government service page.

Stages of work

Reading the national law against your product — 3–5 working days

The local answers get checked one by one: the age of consent, the closed categories, the officer, the record. Each either touches your product or is written off in a line.

Rebuilding the consent flow for fourteen

Where the service may be used by teenagers, the form has to establish age and route the under-fourteens to a parent. We will write the wording and the evidence you keep.

Writing the record of processing activities

Here this is not paperwork for its own sake: the record is the document the Commissioner asks for first, and its absence is an offence rather than an oversight.

Setting the breach route and the local form

We will write who decides, what goes to the Commissioner through the portal service and when the parallel communications duty applies, so nobody has to improvise.

Preparing the consultation, if silence is the plan

If you want release from telling the affected people, that release comes through an assessment and a prior consultation. We will prepare both and deal with the conditions attached.

Answering the Commissioner's first letter

Most files here start with questions rather than a fine. We will draft the answer, gather the evidence behind it and keep the correspondence in one place.

This page is part of what we do under Licensing & Compliance.

Our case studies

No items found.

Leaders of the Area

Alexandra Kurdiumova

Alexandra

Kurdiumova

arrow_outward

FAQ

From what age can a user agree by themselves?
add
remove
How large are the fines in practice?
add
remove
Can a data protection failure be a crime here?
add
remove
Must we always tell customers about a breach?
add
remove
Is a European compliance file enough for Cyprus?
add
remove

Discuss
the Task

Speak to our team

Speak to our team. Tell us about your task –

we’ll help you with it in any jurisdiction.

Tell us about your task –
we’ll help you with it in any jurisdiction.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

We use cookies to improve your experience.