Data protection in Cyprus
Cyprus answers the questions Europe leaves to each country in its own law: a lower age of consent, closed categories, criminal liability. We will apply those answers to your product.
Own consent from
Согласие с
14 years old
14 лет
Fines in 2024
Штрафы за 2024
EUR 133,900
133 900 евро
Criminal ceiling
Уголовный потолок
3 years
3 года
Complaints in 2024
Жалоб за 2024
531
531
When you need data protection advice in Cyprus

A complaint reached the Commissioner
Five hundred complaints a year reach the Commissioner, a fifth of them about unwanted marketing. The first letter arrives with questions rather than a penalty.
Teenagers can sign up to your service
The local age at which a person agrees for themselves is lower than the European default, and a sign-up form built for the default collects consent that does not count here.
You run an insurance or health product
Some processing is closed here outright rather than merely conditioned, and an insurance product is the likeliest place to walk into that wall.
You would rather stay quiet
Staying silent towards the people affected is possible, but only through a written assessment and a prior consultation. It is a procedure, not a decision you make alone.
What you get
- Your duties under the national law as well as the European ones
- Consent flows built for the local age
- A breach route that matches the local form
- A record of processing that survives an inspection
- The criminal exposure named, with what removes it
What the Cypriot law adds on top of Europe

The European regulation applies here directly, and it deliberately leaves a set of questions to each member state. Cyprus answered them in law 125(I)/2018, amended in 2022, and those answers are what makes compliance here different from compliance anywhere else in the union.
Supervision belongs to the Commissioner for Personal Data Protection, whose office sits in Nicosia; responsibility for the law as a whole rests with the Minister of Justice and Public Order.
The four local answers
A child agrees for themselves at fourteen
Where an online service relies on the child's own consent, fourteen is the line. Below it, consent is given or approved by whoever holds parental responsibility.
Insurance may not use genetic or biometric data
Processing genetic and biometric data for health and life insurance purposes is prohibited outright. Where consent is the ground for such data, reusing it for anything further needs separate consent.
Silence towards the affected person is a procedure
A controller may be released, wholly or partly, from telling people about a breach — but only after an impact assessment and a prior consultation with the Commissioner, who may attach conditions.
Some failures are criminal as well as expensive
Not keeping the record of processing activities, or giving the Commissioner false or misleading information about it, is a criminal offence for the controller and for the processor alike.
What the local penalties actually look like
The criminal track carries up to three years in prison or thirty thousand euro, or both; where the offence damages the interests of the Republic, the ceiling rises to five years. Administrative fines follow the European scale, with one national cap: a public authority acting non-commercially cannot be fined more than two hundred thousand euro.
The practice is more modest than the scale suggests. In 2024 the Commissioner issued 88 decisions, imposed fines in 21 of them, and the whole year's fines added up to 133,900 euro across 531 complaints and 94 reported breaches.
How a breach is reported here
Notification goes to the Commissioner through the government portal's own service, and for a cross-border breach to the lead authority instead. Providers of publicly available electronic communications services carry a parallel duty under the 2004 communications law, which is easy to miss when only the European text has been read.
The Commissioner may also publish the operations for which a data protection officer is compulsory beyond the European list, and maintains a public register of controllers who have appointed one and asked to be listed. Everything else we handle on the island is gathered on the Cyprus page.
Sources: the age of fourteen, the insurance prohibition, the breach-notification release, the 200,000 cap and the criminal penalties — law 125(I)/2018 as amended by 26(I)/2022; the 2024 figures — the Commissioner's annual report; the notification route — the government service page.
Stages of work
Reading the national law against your product — 3–5 working days
The local answers get checked one by one: the age of consent, the closed categories, the officer, the record. Each either touches your product or is written off in a line.
Rebuilding the consent flow for fourteen
Where the service may be used by teenagers, the form has to establish age and route the under-fourteens to a parent. We will write the wording and the evidence you keep.
Writing the record of processing activities
Here this is not paperwork for its own sake: the record is the document the Commissioner asks for first, and its absence is an offence rather than an oversight.
Setting the breach route and the local form
We will write who decides, what goes to the Commissioner through the portal service and when the parallel communications duty applies, so nobody has to improvise.
Preparing the consultation, if silence is the plan
If you want release from telling the affected people, that release comes through an assessment and a prior consultation. We will prepare both and deal with the conditions attached.
Answering the Commissioner's first letter
Most files here start with questions rather than a fine. We will draft the answer, gather the evidence behind it and keep the correspondence in one place.
This page is part of what we do under Licensing & Compliance.
Our case studies
FAQ
Fourteen. Where an online service is offered directly to a child and relies on the child's own consent, processing is lawful from that age; below it, consent has to be given or approved by the holder of parental responsibility. The European default is higher, so a registration flow copied from a European product collects consent that does not work here. In practice this means an age question in the form and a record of the answer.
Smaller than the European ceiling suggests. Across 2024 the Commissioner issued 88 decisions, imposed a fine in 21 of them, and the total for the year came to 133,900 euro. Individual penalties in that year ran in the low thousands. The scale that matters for a company here is therefore the criminal one and the cost of the investigation, rather than the headline percentage of worldwide turnover.
Yes, and that is the sharpest local difference. Failing to keep the record of processing activities, refusing to hand it to the Commissioner, or giving false, inaccurate or misleading information about it are offences carrying up to three years in prison or a fine of thirty thousand euro, or both. Where the interests of the Republic are damaged, the ceiling is five years. The record is therefore the first document worth getting right.
Not always, but the exemption is earned rather than assumed. A controller may be released wholly or partly from communicating a breach to the people affected, and the release runs through an impact assessment and a prior consultation with the Commissioner, who can attach conditions to it. Deciding internally to stay quiet, without that assessment and that consultation, is the version that goes wrong.
It is the larger half, and it is not the whole. A European file will not carry the age of fourteen, the prohibition on genetic and biometric data in insurance, the consultation needed before staying silent, or the fact that a missing record of processing is an offence. We keep what the European file already does well and add the national layer on top, then check the two do not contradict each other.
Discuss
the Task
Speak to our team
Speak to our team. Tell us about your task –
we’ll help you with it in any jurisdiction.
