GDPR in Cyprus: A 2025 Compliance Overview

A graphic for SONEVERSE on GDPR in Cyprus: A 2025 Compliance Overview.

As an EU member, Cyprus enforces the General Data Protection Regulation (GDPR) through local law 125(I)/2018. This guide explains how Cyprus aligns with GDPR, what organizations must do, and how businesses can comply effectively.


GDPR Framework in Cyprus

Cyprus adopted the GDPR via national legislation—Law 125(I)/2018—effective July 31, 2018. This law follows all GDPR provisions, including rights for data subjects, obligations for controllers/processors, and rules for transferring data abroad.

The Office of the Commissioner for Personal Data Protection in Nicosia oversees enforcement. It acts independently and represents Cyprus on the European Data Protection Board (EDPB).


Key Concepts and Principles

Cyprus mirrors GDPR’s definitions and core principles:

  • Personal Data includes names, IDs, IP addresses, biometric and health data.
  • Lawful processing must be based on consent, contract, legal obligation, public interest, vital interests, or legitimate interests.
  • Privacy by design and data minimisation are required, meaning systems must limit data collection to what is necessary and protect it from the outset.

Obligations for Businesses

Organizations in Cyprus must:

  1. Maintain records of processing activities if they employ 250+ employees, process sensitive data, or engage in systematic monitoring.
  2. Implement security measures such as pseudonymization and encryption.
  3. Report breaches within 72 hours to the Commissioner.
  4. Appoint a Data Protection Officer (DPO) if they regularly monitor individuals or process special categories of data on a large scale.
  5. Ensure lawful transfers of data internationally, using adequacy decisions, standard contract clauses, or specific derogations .

Enforcement and Penalties

The Cyprus Commissioner holds the power to audit organizations and impose sanctions. Fines can reach up to €20 million or 4% of global revenue—whichever is higher.

Although only about 1.3% of investigations result in fines, regulatory scrutiny continues to rise.

Data subjects may seek compensation through civil courts for GDPR violations, and the Commissioner has fined public bodies (e.g., a Ministry fined €8,000).


Local Guidance and Support

Cyprus’s data protection authority provides guidance and best practices for controllers and processors. It also issued instructions on notification requirements for transfers of sensitive data to countries outside the EU.

Specific sectors—like healthcare, finance, and telecommunications—face stricter rules, especially around patient health data and customer payment information.


Steps to Achieve GDPR Compliance

To comply under Cypriot law, businesses should:

  1. Map data flows and maintain records of processing.
  2. Review legal bases for each type of data processing.
  3. Update privacy notices to include rights, contact info, and data retention schedules.
  4. Implement technical and organizational safeguards, including preventing unauthorized access.
  5. Train staff regularly and conduct awareness campaigns.
  6. Establish breach response plans with timely reporting procedures.
  7. Consult the Commissioner’s guidance and document adherence for audit readiness.

Liability and Impact

Non-compliance can result in heavy fines and legal claims from affected individuals. Conversely, strong GDPR compliance strengthens reputation, builds trust with customers, and ensures smoother operations across the EU.


For more practical insights on data compliance, privacy, and business law in Cyprus, visit Soneverse and explore our detailed Guide Page. You’ll find tools, templates, and expert advice to support your GDPR journey.

Stay Informed

On everything business-related

more insights