In Cyprus the GDPR applies directly, and the Protection of Natural Persons with regard to the Processing of Personal Data and the Free Movement of such Data Law 125(I)/2018 fills in the national details. Fines are imposed by the Commissioner for Personal Data Protection and can in theory reach €20 million or 4% of worldwide annual turnover. In practice Cypriot fines have been far smaller, usually in the thousands or tens of thousands of euros, but the Cyprus law adds something the GDPR itself does not: criminal offences carrying up to three years in prison.
Who enforces it
The Commissioner for Personal Data Protection is an independent authority based in Nicosia. It takes complaints from individuals, receives breach notifications from organisations, and can open investigations on its own initiative. Its powers come from Article 58 of the GDPR: it can demand information, carry out audits, order an organisation to bring its processing into line, impose a temporary or permanent ban on processing, and fine.
Filing a complaint costs nothing. A customer, employee or tenant who thinks their data has been mishandled can write to the Commissioner directly, and a good share of published Cypriot decisions start that way, often with an ignored subject access request.
How big the fines can be
The ceilings are set by Article 83 of the GDPR, not by Cyprus law:
| Type of breach | Maximum fine |
|---|---|
| Record-keeping, security, breach notification, DPO duties (lower tier) | €10 million or 2% of worldwide annual turnover, whichever is higher |
| Lawful basis, consent, data subject rights, international transfers, ignoring the Commissioner's orders (upper tier) | €20 million or 4% of worldwide annual turnover, whichever is higher |
| Public authorities and bodies (Law 125(I)/2018) | €200,000 |
The public-sector cap is a Cypriot choice. The GDPR left each member state to decide whether, and how far, its own public bodies could be fined, and Cyprus opted for a limit of €200,000.
Those upper figures are rarely approached here. Published decisions give a better sense of scale. The State Health Services Organisation was fined €46,500 after 13 personal data breaches involving lost medical records and registration forms. A bank was fined €15,000 for several GDPR failings. The Mediterranean Hospital of Cyprus paid €10,000 for failing to cooperate with the Commissioner, and a state hospital was fined €5,000 after a patient's request for their own medical file went unanswered.
The last two are instructive. Neither involved a hack or a leak. One was about not answering the regulator and the other about not answering the patient, which is where many small Cypriot businesses are most exposed.
What the Commissioner weighs when setting a fine
Article 83(2) lists the factors, and Cypriot decisions work through them expressly. The ones that most often move the figure:
- how serious the breach was and how long it lasted, and how many people were affected
- whether it was deliberate or negligent
- what the organisation did to limit the damage once it knew
- any previous breaches
- how well it cooperated with the investigation
- the categories of data involved, with health, biometric and criminal-record data treated most seriously
- whether the organisation reported the breach itself or the Commissioner found out another way
The Commissioner can also stop short of a fine and issue a reprimand or an order to fix the problem by a deadline. Ignoring that order is itself an upper-tier infringement.
The 72-hour breach notification rule
When personal data is lost, stolen, wrongly disclosed or made unavailable, the controller has 72 hours from becoming aware of it to notify the Commissioner under Article 33 of the GDPR, unless the breach is unlikely to put anyone's rights at risk. If notification comes later, the reasons for the delay have to accompany it. Where the risk to individuals is high, Article 34 requires telling the people affected as well, without undue delay.
Every breach has to be logged internally, including the ones that did not need reporting. A misdirected email with a client's passport attached, a stolen laptop, a ransomware attack on a clinic's booking system: all of these start the 72-hour clock. Organisations that wait to find out how bad things are before reporting often end up in breach of Article 33 on top of whatever caused the incident.
What Cyprus adds to the GDPR
Law 125(I)/2018 uses the room the GDPR leaves to member states. The provisions that matter most day to day:
- Children's consent. For online services offered directly to children, a child of 14 or over can give valid consent. Below 14, a parent or guardian has to authorise it. The GDPR default is 16.
- Genetic and biometric data. Using genetic or biometric data for life or health insurance is prohibited outright.
- Journalism. Processing for journalistic purposes is lawful where it is proportionate and respects the rights protected by the EU Charter, the European Convention on Human Rights and the Cyprus Constitution.
- Restricting data subject rights. A controller can restrict certain rights only in limited cases, after a data protection impact assessment and consultation with the Commissioner.
Employers carry much of the compliance risk. CCTV in the workplace, monitoring of work emails, and holding copies of staff ID and health records all need a lawful basis and a stated purpose, and employees can use a subject access request as a lever in a wider dispute. If you are drafting staff documents, our guide to Cyprus employment contract rules covers the written terms that have to be issued in any case.
The criminal offences
This is where Cyprus goes further than many member states. Law 125(I)/2018 lists 14 criminal offences, separate from the Commissioner's administrative fines. One of them, for example, covers the unlawful interconnection of public-sector filing systems. Twelve of them carry up to three years' imprisonment and/or a fine of up to €30,000, and the other two up to one year and/or €10,000. Where certain offences harm the interests of the state or threaten national security, the maximum rises to five years and/or €50,000.
The Commissioner's published decisions are almost all administrative fines and reprimands. The criminal route matters because it is aimed at people rather than organisations, so a director or employee who misuses personal data can face it personally.
Challenging a fine, and claiming compensation
A fine is an administrative act, so it is challenged by a recourse to the Administrative Court under Article 146 of the Constitution, filed within 75 days of the decision being published or notified. The court reviews whether the decision was lawful and properly reasoned rather than rehearing the whole matter, so the ground has to be prepared during the investigation, when the organisation can still put its account on record.
Individuals have a separate route. Article 82 of the GDPR lets anyone who has suffered material or non-material damage from a breach sue the controller or processor for compensation in the ordinary courts. A Commissioner's finding against the organisation does not decide the damages claim, but it makes it considerably easier to bring.
Practical steps for a Cyprus business
For most small and medium firms, the published decisions point to the same short list:
- 1Keep a record of what personal data you hold, why, and for how long.
- 2Answer subject access requests within one month (extendable by two months for complex requests, with an explanation).
- 3Have a written breach procedure that names who decides whether to notify within 72 hours.
- 4Reply to the Commissioner promptly and in full. Non-cooperation has cost Cypriot organisations money in its own right.
- 5Check whether you need a data protection officer under Article 37, which applies to public bodies and to organisations whose core activities involve large-scale monitoring or special-category data.
Data protection sits alongside a company's other statutory duties, many of which are set out in our guide to Cyprus company annual obligations. If you are setting up a new business, it is easier to build these records in from the start, as explained in setting up a company in Cyprus.
Facing a Commissioner investigation or a data breach? Browse corporate and company lawyers in our directory, including firms in Nicosia, where the Commissioner and the Administrative Court sit. Figures and rules here reflect the position in September 2026; confirm the current position with a qualified Cyprus advocate before relying on them.