<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	
	xmlns:georss="http://www.georss.org/georss"
	xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#"
	>

<channel>
	<title>Data Protection Archives | Rokas Law Firm</title>
	<atom:link href="https://rokas.com/category/data-protection/feed/" rel="self" type="application/rss+xml" />
	<link>https://rokas.com/category/data-protection/</link>
	<description></description>
	<lastBuildDate>Wed, 26 Aug 2026 10:39:00 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://rokas.com/wp-content/uploads/2021/02/cropped-favicon-32x32.png</url>
	<title>Data Protection Archives | Rokas Law Firm</title>
	<link>https://rokas.com/category/data-protection/</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">241114223</site>	<item>
		<title>Is Your Business Ready for Greece&#8217;s Cybersecurity Law? Law 5160/2024 in Practice, and Where Greece Stands in the EU</title>
		<link>https://rokas.com/is-your-business-ready-for-greeces-cybersecurity-law-law-5160-2024-in-practice-and-where-greece-stands-in-the-eu/</link>
		
		<dc:creator><![CDATA[Rokas admin]]></dc:creator>
		<pubDate>Wed, 26 Aug 2026 10:38:16 +0000</pubDate>
				<category><![CDATA[Data Protection]]></category>
		<guid isPermaLink="false">https://rokas.com/?p=14803</guid>

					<description><![CDATA[<p>The article was drafted by Alexandros Sarris &#38; Magdalini Mavromichali, Senior Associates for Lexology on 26 August 2026. The compliance deadline businesses already missed Most companies still think of Greece&#8217;s cybersecurity law, Law 5160/2024, as a future obligation. It isn&#8217;t. The law transposing the EU&#8217;s NIS2 Directive has been in force since 27 November 2024, [&#8230;]</p>
<p>The post <a href="https://rokas.com/is-your-business-ready-for-greeces-cybersecurity-law-law-5160-2024-in-practice-and-where-greece-stands-in-the-eu/">Is Your Business Ready for Greece&#8217;s Cybersecurity Law? Law 5160/2024 in Practice, and Where Greece Stands in the EU</a> appeared first on <a href="https://rokas.com">Rokas Law Firm</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><strong><em>The article was drafted by Alexandros Sarris &amp; Magdalini Mavromichali, Senior Associates for Lexology on 26 August 2026.</em></strong></p>
<div id="lex-article-body" class="article-body clippable-element text-clippable image-clippable" data-integrity-check="1E97BB12844435FEE3BA98F44EC8D26B" data-content-slug="d5d147bb-8c17-468e-bb50-25339a81d842" data-friendly-name="Is Your Business Ready for Greece's Cybersecurity Law? Law 5160/2024 in Practice, and Where Greece Stands in the EU" data-firm-ref="1865" data-content-type="Article" data-workareas="21" data-jurisdictions="57,68">
<ol>
<li><b>The compliance deadline businesses already missed</b></li>
</ol>
<p>Most companies still think of Greece&#8217;s <strong class="highlight" data-markjs="true">cybersecurity</strong> law, Law 5160/2024, as a future obligation. It isn&#8217;t. The law transposing the EU&#8217;s NIS2 Directive has been in force since 27 November 2024, registration with the National <strong class="highlight" data-markjs="true">Cybersecurity</strong> Authority closed earlier in 2025, and the regulator is now actively supervising the market. For essential entities, the exposure for getting this wrong runs to €10,000,000 or 2% of worldwide turnover, whichever is higher, and board members can be held personally liable for governance failures, including through suspension from their management functions.</p>
<p>This article sets out what the law actually requires, how it interacts with two regimes many affected entities already know well, DORA and the GDPR, and how Greece&#8217;s position compares with the rest of the EU, including the Netherlands, where equivalent legislation has just been confirmed to take effect on 15 August 2026.</p>
<ol start="2">
<li><b>Background: from NIS to NIS2</b></li>
</ol>
<p>NIS2 replaced the original 2016 NIS Directive following a wave of attacks on hospitals, energy grids, and supply chains across the Union. Compared with its predecessor, it widens the sectors in scope, tightens supervision, strengthens cross-border cooperation between Member States, expands the list of expected risk-management measures, and introduces a more structured incident-notification regime with defined deadlines. Law 5160/2024 mirrors the three pillars of the Directive itself: obligations placed directly on in-scope entities, a strengthened role for the national regulator, and a formal cooperation mechanism at EU level.</p>
<p>A defining feature of the regime is where accountability lands. The law requires a named Information Systems Security Officer for every in-scope entity. That officer must be a person distinct from the entity&#8217;s Data Protection Officer under Article 37 GDPR, must act autonomously in decision-making, and serves as the entity&#8217;s direct point of contact with the regulator. Administrative bodies bear personal responsibility for adopting and maintaining the required risk-management measures, placing accountability with the board and senior management rather than solely with IT functions.</p>
<ol start="3">
<li><b>Affected entities/persons</b></li>
</ol>
<p>The law casts a wide net, dividing covered activity into two tiers of sector. Sectors of high criticality include energy, digital infrastructure, transport, space, health, public administration, drinking water, banking, financial market infrastructure, and ICT service management. A broader tier of other critical sectors covers chemicals manufacturing and distribution, general manufacturing, research, postal and courier services, waste management, food production and distribution, and digital providers.</p>
<p>Within these sectors, entities are classified as either essential or important, based on criteria set out in Articles 3 and 4 of the law, generally tracking size and the criticality of the sector concerned. Essential entities are subject to materially tighter supervision, more intrusive enforcement powers, and higher potential fines than important entities. Certain categories, including cloud computing, DNS, and top-level domain registry providers, are treated as a distinct group under Article 19, reflecting the systemic role they play in the wider digital ecosystem, and were subject to an earlier registration deadline on that basis.</p>
<p>In our experience, the businesses most exposed right now are not the obvious critical-infrastructure operators who saw this coming years ago. They are mid-market companies in manufacturing, logistics, food production, and digital services who assumed this law was aimed at someone else, and are only now discovering they meet the size and sector thresholds.</p>
<ol start="4">
<li><b>What compliance actually requires</b></li>
</ol>
<p>Three obligations follow once an entity falls within scope.</p>
<ol>
<li><u>Registration</u>: essential and important entities were required to submit the information specified in Article 4(3) to the National <strong class="highlight" data-markjs="true">Cybersecurity</strong> Authority, with cloud, DNS, and TLD providers submitting their Article 19(1) information on an earlier timeline. Both windows have closed, and any entity that has not yet registered should treat the obligation as overdue.</li>
<li><u>Risk management</u>: administrative bodies must adopt <strong class="highlight" data-markjs="true">cybersecurity</strong> measures that are technical, organizational, and business-related, proportionate to the entity&#8217;s risk exposure, size, and the likely severity of incidents. Article 15(2) sets these out in detail, including policies for risk analysis and information-system security, incident management, business continuity, basic cyber hygiene and staff training, the use of cryptography and encryption where appropriate, multi-factor or continuous authentication, and secured voice, video, text, and emergency communications.</li>
<li><u>Incident reporting</u>: significant incidents, meaning those compromising the availability, authenticity, integrity, or confidentiality of data or services and causing or risking severe operational disruption, financial loss, or harm, must be reported to the Greek CSIRT in three stages. An early warning is due within 24 hours of the entity becoming aware of the incident, indicating whether it appears to result from unlawful or malicious activity and whether it may have cross-border effects. An incident notification follows within 72 hours, updating the early warning with an initial assessment of severity, impact, and any available indicators of compromise. A final report is due no later than one month after the notification, describing the incident, the type of threat, and the mitigation measures applied.</li>
</ol>
<p>On paper, this reads like a checklist. In practice, a considerable amount of businesses are missing at least one of the three pillars entirely, most commonly a tested incident-reporting process that would actually work at 2am on a Saturday.</p>
<p>You can read the full article here: <a href="https://www.lexology.com/library/detail.aspx?g=d5d147bb-8c17-468e-bb50-25339a81d842">Is Your Business Ready for Greece&#8217;s Cybersecurity Law? Law 5160/2024 in Practice, and Where Greece Stands in the EU </a></p>
</div>
<p>&nbsp;</p>
<div id="lex-article-body" class="article-body clippable-element text-clippable image-clippable" data-integrity-check="1E97BB12844435FEE3BA98F44EC8D26B" data-content-slug="d5d147bb-8c17-468e-bb50-25339a81d842" data-friendly-name="Is Your Business Ready for Greece's Cybersecurity Law? Law 5160/2024 in Practice, and Where Greece Stands in the EU" data-firm-ref="1865" data-content-type="Article" data-workareas="21" data-jurisdictions="57,68">
<p>&nbsp;</p>
<p>&nbsp;</p>
</div>
<p>The post <a href="https://rokas.com/is-your-business-ready-for-greeces-cybersecurity-law-law-5160-2024-in-practice-and-where-greece-stands-in-the-eu/">Is Your Business Ready for Greece&#8217;s Cybersecurity Law? Law 5160/2024 in Practice, and Where Greece Stands in the EU</a> appeared first on <a href="https://rokas.com">Rokas Law Firm</a>.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">14803</post-id>	</item>
		<item>
		<title>Greece’s Under-15 Social Media Ban: Balancing Child Protection and Privacy Rights</title>
		<link>https://rokas.com/greeces-under-15-social-media-ban-balancing-child-protection-and-privacy-rights/</link>
		
		<dc:creator><![CDATA[Rokas admin]]></dc:creator>
		<pubDate>Fri, 08 May 2026 09:02:48 +0000</pubDate>
				<category><![CDATA[Data Protection]]></category>
		<guid isPermaLink="false">https://rokas.com/?p=14708</guid>

					<description><![CDATA[<p>Greece has announced a legislative initiative to prohibit access to social media platforms for children under the age of 15, with entry into force on 1 January 2027. The measure, announced in April 2026, forms part of a broader social policy framework aimed at addressing issues of addiction and psychological strain among minors, while at [&#8230;]</p>
<p>The post <a href="https://rokas.com/greeces-under-15-social-media-ban-balancing-child-protection-and-privacy-rights/">Greece’s Under-15 Social Media Ban: Balancing Child Protection and Privacy Rights</a> appeared first on <a href="https://rokas.com">Rokas Law Firm</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Greece has announced a legislative initiative to prohibit access to social media platforms for children under the age of 15, with entry into force on 1 January 2027. The measure, announced in April 2026, forms part of a broader social policy framework aimed at addressing issues of addiction and psychological strain among minors, while at the same time assigning responsibility for age verification and user identification to service providers.</p>
<p>This development constitutes a significant intervention in the way the national legal order seeks to regulate the presence of minors in the digital environment, in alignment with EU law and relevant European Union guidelines. It is not merely a protective measure against online risks, but one that is intrinsically linked to the broader framework of personal data protection.</p>
<p>A key challenge arises in relation to the practical implementation of the measure, as the imposition of an age restriction necessarily entails the development of reliable age verification mechanisms. Such mechanisms involve the processing of identity and age-related data, thereby making it essential that data protection principles be embedded from the design stage. In particular, age verification must comply with the principle of data minimization, through technical solutions that limit data collection strictly to what is necessary for confirming the relevant age threshold.</p>
<p>Particular importance is also attached to the choice of the age limit at 15 years. According to Article 8 of the GDPR, a minor’s consent to the processing of personal data in the context of information society services is, in principle, valid from the age of 16, while allowing Member States to set a lower threshold. The Greek legislator, through the national implementing law (Law 4624/2019), set this threshold at 15 y.o., recognizing that from this age onwards minors possess a sufficient level of digital maturity to provide valid consent independently. In this light, the adoption of the same age threshold within the emerging regulatory framework governing access to social media does not appear arbitrary but rather reflects a coherent and consistent legislative approach aligned with the national legal understanding of minors’ digital maturity.</p>
<p>The real challenge, therefore, lies not in the age threshold itself, but in its implementation. The objective is to design age verification mechanisms that effectively protect minors without resulting in excessive collection or processing of personal data, and without undermining in practice the level of privacy protection that data protection law seeks to guarantee.</p>
<p>The post <a href="https://rokas.com/greeces-under-15-social-media-ban-balancing-child-protection-and-privacy-rights/">Greece’s Under-15 Social Media Ban: Balancing Child Protection and Privacy Rights</a> appeared first on <a href="https://rokas.com">Rokas Law Firm</a>.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">14708</post-id>	</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/

Page Caching using Disk: Enhanced 

Served from: rokas.com @ 2026-09-05 20:26:54 by W3 Total Cache
-->