Business Law · Regulatory

Sub-Practice Regulatory &
Compliance.

GDPR, EU AI Act, NIS2 and DSA compliance, sector licensing and corporate governance obligations — built into an ongoing programme, not a one-off certificate. Backed by in-house regulatory experience across eight countries.

GDPR to DSAFull Coverage
8Jurisdictions (GC Background)
3Languages
Publications and international speaking
The firm's lawyers contribute to leading international legal publications and are regularly invited to speak at international symposia.
In-house regulatory experience, 8 jurisdictions
As general counsel to a Fortune 50 technology group, Dionysios Pantazis handles regulatory compliance across Greece, Cyprus, Bulgaria, Romania, Serbia, Croatia, Slovenia and Albania — real exposure to how regulators actually enforce, not just the text of the regulation.
Dual-qualified for cross-border regulatory work
Our Managing Partner is dual-qualified in England & Wales and Greece, so English-law questions are advised on directly in-house. Court appearances remain before the Greek courts and international arbitral tribunals; English proceedings are conducted through instructed English correspondent counsel.
Compliance built to run the business, not stall it
Regulatory advice calibrated to what the business can actually operationalise — proportionate, prioritised and workable, not a binder of policies nobody follows.
Not sure where you stand?
Tell us what the business does and what data or platforms are involved. We'll map the regulatory exposure and prioritise what actually needs fixing first.
Request Consultation
Overview Scope of Service Process Why Us FAQs

Regulatory & Compliance

EU regulation now reaches deep
into how Greek businesses actually operate.

The compliance landscape for Greek and EU businesses has expanded sharply in the last few years, and it keeps expanding. The Hellenic Data Protection Authority (HDPA/ΑΠΔΠΧ) has moved from occasional guidance to active enforcement, issuing substantial fines against companies that treated GDPR as a policy document rather than an operating discipline. The EU AI Act's phased obligations are now starting to bite for businesses that deploy or provide AI systems, with prohibited-practice rules already in force and higher-risk obligations following on a fixed timetable. NIS2 has significantly widened which companies count as "essential" or "important" entities with binding cybersecurity obligations — well beyond the utilities and telecoms operators the old NIS Directive targeted. And the Digital Services Act now imposes real, enforceable obligations on online platforms and marketplaces, not just the largest ones. A regulatory compliance lawyer in Greece maps obligations to activities, since most regimes bite on what you do rather than where you are.

The businesses that get caught out are rarely the ones that ignored compliance entirely. More often, they treated it as a one-off exercise — a policy pack purchased once, a data protection notice drafted three years ago and never revisited, a cookie banner installed and forgotten. Regulation of this kind does not stay still: the AI Act's obligations phase in over time, NIS2 supervisory guidance is still being refined by national authorities, and the DSA's transparency and risk-assessment duties are interpreted and enforced progressively. Compliance that was correct in 2023 can be materially incomplete by 2026.

"The fines are not theoretical anymore. The HDPA and its counterpart authorities across the EU are actively enforcing — and 'we didn't know the rules had changed' has never been a defence." A regulatory compliance lawyer in Greece should tell you which regimes do not apply, which narrows the work considerably.

Sector matters too. Financial services, healthcare, telecoms, energy and other regulated industries operating in Greece carry licensing and sector-specific compliance obligations layered on top of the horizontal regulation above — and those sector regimes are themselves being updated to align with NIS2 and the AI Act. We advise across this full stack: general EU regulation, sector licensing, and the corporate governance structures — policies, training, reporting lines, documented decision-making — that make compliance defensible if a regulator ever asks to see it. Describe the business and we will identify what actually applies.

Who this affects
Who needs this
Any business processing personal data, deploying AI systems, operating digital infrastructure, or running an online platform or marketplace in the EU is now in scope of at least one of GDPR, the AI Act, NIS2 or the DSA — often more than one.
Enforcement reality
Fines are not theoretical
The HDPA and sister authorities across the EU are issuing real fines against real businesses, including SMEs. Regulatory risk is no longer a remote contingency to footnote in a board pack.
Programme, not project
Compliance is not one-off
A policy drafted once and filed away does not stay compliant as obligations phase in and enforcement guidance develops. We build compliance as a maintained programme, not a closed project.
Multi-jurisdiction exposure
Cross-border regulatory complexity
Businesses operating across several EU member states face overlapping supervisory authorities and national transposition differences. Dual qualification and in-house experience across 8 jurisdictions inform how we navigate this.

Scope of Service

From GDPR fundamentals
to AI Act, NIS2 and DSA.

GDPR & Data Protection Compliance
Data mapping, lawful basis analysis, privacy notices, data processing agreements, DPO assessment and breach-response protocols — advice built for your operations, not a template pack.
GDPRDPOBreach Response
Core service →
01
EU AI Act Compliance
Classifying AI systems by risk category, assessing prohibited-practice exposure, and building the documentation and governance the AI Act requires as obligations phase in on schedule.
Risk ClassificationGovernanceDocumentation
Core service →
02
NIS2 Cybersecurity & Critical Infrastructure
Assessing whether your business now falls within NIS2's widened "essential" or "important" entity categories, and building the risk-management and incident-reporting obligations that follow.
Scope AssessmentIncident ReportingRisk Management
Core service →
03
DSA & Digital Platform Compliance
Transparency, content-moderation and trader-traceability obligations under the Digital Services Act for online platforms, marketplaces and intermediary services operating in the EU.
PlatformsMarketplacesTransparency
Core service →
04
Sector Licensing & Regulatory Approvals
Licensing and authorisation requirements for regulated sectors operating in Greece — financial services, healthcare, telecoms and energy — including ongoing regulatory reporting obligations.
LicensingApprovalsReporting
Core service →
05
Corporate Governance & Compliance Programmes
Building the governance backbone that makes compliance defensible — policies, training, reporting lines and documented decision-making, maintained as an ongoing programme.
PoliciesTrainingGovernance
Core service →
06

How We Work

A compliance process built to keep working after day one.

STEP 01
Regulatory Gap Assessment
We map which regulation actually applies — GDPR, AI Act, NIS2, DSA and any sector licensing regime — and assess current practice against it to identify the real gaps, prioritised by risk.
STEP 02
Compliance Programme Design
Designing a compliance programme calibrated to the business — policies, data flows, governance structures and reporting lines that are proportionate and genuinely workable, not generic.
STEP 03
Implementation & Documentation
Drafting and rolling out the policies, notices, agreements and internal documentation the programme requires, and training the people who need to apply it day to day.
STEP 04
Ongoing Monitoring & Regulatory Updates
Compliance is maintained, not filed away — tracking regulatory and enforcement developments and updating the programme as AI Act obligations phase in and guidance evolves.

Why Pantazis & Associates

Regulatory advice grounded
in a real qualification, not a crash course.

Publications · Speaking
Publications and international speaking
The firm's lawyers contribute to leading international legal publications and are regularly invited to speak at international symposia.
In-House · Fortune 50
Fortune 50 GC experience
Managing Partner Dionysios Pantazis has served for eleven years as General Counsel to a Fortune 50 technology group, with responsibility across seven business lines and eight countries.
Emerging Regulation · EU-Wide
AI Act, NIS2 and DSA expertise — kept current, not static
These regimes are new and still developing. We track phased AI Act obligations, evolving NIS2 supervisory guidance and DSA enforcement practice as they unfold, rather than advising from a snapshot taken when the regulation was first published.
Dual Qualification · International
England & Wales + Greece — cross-border regulatory work covered
Group-wide compliance programmes, cross-border NIS2 obligations and regulation with a UK or international dimension are handled directly under a single instruction, without a referral to a second firm.
Regulatory · NIS
NIS Directive obligations mapped for a corporate group
Advised a group of companies on the scope of its obligations under the NIS Directive, identifying which entities fell within scope and what security and incident-reporting duties followed.

Frequently Asked Questions

Questions about regulatory compliance.

Does my business need a Data Protection Officer under GDPR?+

It depends on what your business does, not its size. A DPO is mandatory where core activities involve large-scale, regular and systematic monitoring of individuals, or large-scale processing of special categories of data such as health or biometric information — public authorities also require one regardless of scale. Many businesses that fall short of the mandatory threshold still benefit from appointing one, or from an external, part-time equivalent, because it gives the Hellenic Data Protection Authority a documented contact point and signals a functioning compliance programme. We assess the requirement against your actual data processing activities rather than a generic checklist.

Does the EU AI Act apply to my business, and from when?+

The AI Act applies broadly to anyone who develops, deploys or distributes AI systems used in the EU, with obligations that scale with the system's risk classification. Prohibited practices are already banned. Obligations for high-risk AI systems and for general-purpose AI models are phasing in on a fixed timetable running through 2026 and beyond. Many businesses are surprised to learn a tool they use for recruitment screening, credit scoring or biometric identification qualifies as high-risk. We classify your specific use cases against the Act's categories rather than assuming a blanket answer.

What changes under NIS2 compared to the old NIS Directive — is my company now in scope?+

NIS2 significantly widens the net. The original NIS Directive mainly targeted core infrastructure — energy, transport, banking and similar operators. NIS2 extends mandatory cybersecurity risk-management and incident-reporting obligations to a much broader list of sectors, including digital providers, manufacturing, postal services, waste management and public administration, categorised as "essential" or "important" entities depending on sector and size. A company that was comfortably outside scope under the old regime may now be squarely inside it. We run the sector-and-size assessment against the current thresholds rather than relying on how the business was classified before.

Do the DSA's obligations apply to my platform or marketplace?+

The Digital Services Act applies tiered obligations to intermediary services, hosting services, online platforms and online marketplaces operating in the EU — the specific duties that apply depend on which category your service falls into and its user base, not only whether you are a "Very Large" platform. Marketplaces carry additional trader-traceability and product-safety-related duties. If your business operates any kind of online platform, marketplace or hosting service reaching EU users, it is worth confirming exactly which DSA obligations apply rather than assuming the rules are only for the largest tech companies.

Can regulatory compliance be handled as part of an Outsourced General Counsel retainer, or does it need a separate engagement?+

For most clients, it sits naturally within the Outsourced General Counsel retainer. Because our technology law expertise already covers EU AI Act, NIS2, DSA and emerging regulation, regulatory compliance advice is integrated into the ongoing retainer rather than treated as a separate engagement — the same way commercial contracts or employment questions are handled as they arise. Larger, standalone projects — a full GDPR compliance programme build-out, or a NIS2 gap assessment across multiple entities — are usually scoped and quoted separately given the volume of work involved, but the ongoing maintenance of that programme then folds back into the retainer.

Not sure if you're compliant?
Let's find out before a regulator does.

A confidential conversation about your data, your platform, and your actual regulatory exposure.