Technology Law · Privacy & Security

Data Privacy & Cybersecurity.

GDPR compliance programmes, DPIAs, DPO advisory, data processing agreements, cross-border transfer mechanisms (SCCs), NIS2 compliance, breach notification and representation in HDPA proceedings.

8Jurisdictions Covered
4Languages
Fortune 50 GC experience
Our Managing Partner has served for eleven years as General Counsel to a Fortune 50 technology group, with responsibility across seven business lines and eight countries.
Publications and international speaking
The firm's lawyers contribute to leading international legal publications and are regularly invited to speak at international symposia.
Dual-qualified: Greece & England/Wales
Our Managing Partner is dual-qualified in England & Wales and Greece, so English-law questions are advised on directly in-house. Court appearances remain before the Greek courts and international arbitral tribunals; English proceedings are conducted through instructed English correspondent counsel.
Trusted by foreign embassies
A number of embassies in Greece — among them the United Kingdom, United States, Australia, France and Poland — refer their nationals to the firm.
Worried about your data protection exposure?
Tell us what data you hold, where it moves, and what triggered the question. We'll flag the real gaps before a regulator or a breach does.
Request Consultation
Overview Scope of Service Process Why Us FAQs

Data Privacy & Cybersecurity

Compliance is a programme
not a document you file away.

The Hellenic Data Protection Authority (HDPA / ΑΠΔΠΧ) is one of the more active data protection regulators in Europe, and Greek businesses increasingly discover their GDPR exposure only after a complaint, an audit or a breach has already put them in front of it. Enforcement is not theoretical: fines, corrective orders and public decisions are a routine feature of the HDPA's docket, and the gap between what a business assumes it has in place and what it can actually produce on request is usually where the exposure sits. A GDPR lawyer in Greece will document the lawful basis before anything else, because that is what a regulator asks for first.

A privacy policy is not a compliance programme. A published policy is the visible tip of what the GDPR actually requires — records of processing activities, a documented lawful basis for each processing purpose, Data Protection Impact Assessments (DPIAs) for higher-risk processing, and a Data Protection Officer where one is required. NIS2 has significantly widened who counts as regulated. The directive's "essential" and "important" entity categories now reach well beyond traditional critical infrastructure into digital services, manufacturing, and mid-sized companies that never previously considered themselves subject to cybersecurity regulation — each with mandatory risk-management measures and incident reporting duties attached.

Having a privacy policy on the website and having a functioning GDPR compliance programme are two different things, and the difference is exactly what a regulator, an auditor or a breach will test. Where processing crosses borders, a GDPR lawyer in Greece checks the transfer mechanism and the assessment behind it.

Cross-border data transfers add a further layer that businesses routinely get wrong. Since the Schrems II judgment, transferring personal data outside the EEA — to a US cloud provider, an offshore support team, a group company — requires a valid legal transfer mechanism, typically Standard Contractual Clauses (SCCs) accompanied by a documented transfer impact assessment, not simply a clause buried in a vendor's terms. And when a breach does happen, the GDPR's 72-hour notification clock to the HDPA starts running immediately, whether or not the organisation is ready. Having designed and implemented a pan-European GDPR compliance programme in-house, for a multinational technology operator across 8 jurisdictions, is what makes it possible to build programmes that hold up under real regulatory scrutiny rather than ones that only look complete on paper. Send your processing record and we will tell you what is missing.

Not a filing exercise
GDPR compliance is a programme, not a document
Records of processing, lawful basis documentation and DPIAs are what a regulator actually asks to see — a published privacy policy alone will not hold up.
Expanded scope
NIS2 has widened who is in scope
"Essential" and "important" entity categories now reach digital services, manufacturing and mid-sized companies that were never previously regulated on cybersecurity.
Post-Schrems II
Cross-border transfers need a legal mechanism
Moving personal data outside the EEA requires Standard Contractual Clauses and a documented transfer impact assessment, not a clause buried in vendor terms.
No grace period
Breach notification has a 72-hour clock
The GDPR's notification deadline to the HDPA starts the moment a breach is discovered, regardless of whether the organisation is ready to respond.

Scope of Service

From data mapping
to a defensible compliance programme.

GDPR Compliance Programmes
Designing and implementing full GDPR compliance programmes — records of processing, lawful basis documentation, data retention policies and internal governance, built to hold up under regulatory scrutiny.
GDPRGovernanceRecords of Processing
Core service →
01
Data Protection Impact Assessments (DPIAs)
Conducting and documenting DPIAs for higher-risk processing activities — new systems, profiling, large-scale monitoring — as the GDPR requires before processing begins.
DPIARisk AssessmentAudit
Core service →
02
DPO Advisory Services
Acting as, or advising, the Data Protection Officer — the independent oversight function the GDPR requires for many organisations, with the independence that role requires.
DPOAdvisory
Core service →
03
Data Processing Agreements & Cross-Border Transfers (SCCs)
Drafting and negotiating Data Processing Agreements, and structuring cross-border transfer mechanisms — Standard Contractual Clauses and transfer impact assessments post-Schrems II.
DPASCCsCross-Border
Core service →
04
NIS2 Cybersecurity Compliance
Assessing whether your organisation falls within NIS2's expanded "essential" or "important" entity categories, and implementing the risk-management and reporting measures that follow.
NIS2CybersecurityIncident Reporting
Core service →
05
Data Breach Response & HDPA Representation
Managing the 72-hour breach notification timeline and representing your organisation before the Hellenic Data Protection Authority in investigations and proceedings.
Breach ResponseHDPARepresentation
Core service →
06

How We Work

A compliance process built to survive an audit.

STEP 01
Data Mapping & Gap Assessment
Mapping what personal data you hold, where it flows, and where the current position falls short of GDPR and NIS2 obligations.
STEP 02
Compliance Programme Design
Designing the programme — lawful basis documentation, DPIA framework, transfer mechanisms and DPO structure — calibrated to your actual risk profile.
STEP 03
Implementation & Documentation
Drafting the records of processing, DPAs, SCCs and internal policies, and putting them into practice across the organisation, not just on file.
STEP 04
Ongoing Monitoring & Breach Readiness
Keeping the programme current as processing activities change, and maintaining a tested breach response plan ready for the 72-hour clock.

Why Pantazis & Associates

Privacy advice from someone
who has built the programme before.

In-House · Fortune 50
Fortune 50 GC experience
Managing Partner Dionysios Pantazis has served for eleven years as General Counsel to a Fortune 50 technology group, with responsibility across seven business lines and eight countries.
Publications · Speaking
Publications and international speaking
The firm's lawyers contribute to leading international legal publications and are regularly invited to speak at international symposia.
Dual Qualification · International
Greece & England/Wales — cross-border transfers covered directly
SCC drafting and transfer impact assessments for data moving between EU and non-EU jurisdictions handled under a single instruction, without a referral to a second firm.
Recognised · Independent
Trusted by foreign embassies
A number of embassies in Greece — among them the United Kingdom, United States, Australia, France and Poland — refer their nationals to the firm.
Data Protection · Enforcement
Defence before the Data Protection Authority
Represented a multinational company before the Data Protection Authority in proceedings concerning alleged infringements of the GDPR.

Frequently Asked Questions

Questions about data privacy & cybersecurity.

Do I need a Data Protection Officer (DPO)?+

A DPO is mandatory under the GDPR for public authorities, and for any organisation whose core activities involve large-scale, regular and systematic monitoring of individuals, or large-scale processing of special category data. Many businesses that fall outside the strict legal requirement still appoint one — or retain external DPO advisory support — because the function forces the documentation and oversight a compliance programme needs anyway. We assess whether the requirement applies to you, and can act as, or advise, your DPO under a -accredited mandate either way.

What is a DPIA and when is one legally required?+

A Data Protection Impact Assessment (DPIA) is a structured process for identifying and mitigating data protection risk before a processing activity begins. It is legally required whenever processing is likely to result in a high risk to individuals' rights — large-scale profiling, systematic monitoring, processing of special category data at scale, or deploying new technology with uncertain privacy implications are typical triggers. Skipping a required DPIA is itself a compliance failure, independent of whether anything subsequently goes wrong with the processing itself. We run the assessment and document it to a standard that holds up if the HDPA asks to see it.

What are our obligations if we suffer a data breach?+

Where a breach is likely to result in a risk to individuals, the GDPR requires notification to the HDPA within 72 hours of the organisation becoming aware of it, describing the nature of the breach, the likely consequences and the measures taken or proposed. Where the risk to individuals is high, they must also be notified directly, without undue delay. The 72-hour clock does not pause for internal investigation, and organisations without a tested breach response plan routinely miss it or file an incomplete notification. We help build the plan in advance and manage the notification and any follow-on HDPA correspondence when a breach actually occurs.

Does NIS2 apply to my company even if we're not in a traditionally "critical" sector?+

Very likely yes, if you meet the applicable size thresholds. NIS2 significantly expanded the scope of EU cybersecurity regulation beyond traditional critical infrastructure — its "essential" and "important" entity categories now capture digital infrastructure and service providers, manufacturing, postal and courier services, waste management, food production and a range of mid-sized companies that never previously considered themselves regulated on cybersecurity. We assess whether your organisation and sector fall within scope, and if so, implement the risk-management measures and incident reporting duties NIS2 requires.

Can you represent us in an HDPA (ΑΠΔΠΧ) investigation?+

Yes — representation before the Hellenic Data Protection Authority in complaints, audits and formal investigations is a core part of the practice, drawing on direct experience liaising with the HDPA while designing and running a pan-European GDPR compliance programme in-house. That includes preparing the organisation's submissions and evidence, managing correspondence and deadlines, and, where a decision or corrective order results, advising on next steps. Early engagement — before a position is locked in on paper — generally produces a materially better outcome than responding after the fact.

Does NIS2 apply to my company even if we're not in a traditionally critical sector?+

Very likely yes, if you meet the applicable size thresholds. NIS2 significantly expanded the scope of EU cybersecurity regulation beyond traditional critical infrastructure, now capturing digital infrastructure providers, manufacturing, postal services, waste management and many mid-sized companies. We assess whether your organisation and sector fall within scope and implement the measures NIS2 requires.

Can you represent us in an HDPA investigation?+

Yes, representation before the Hellenic Data Protection Authority in complaints, audits and formal investigations is a core part of the practice, drawing on direct experience liaising with the HDPA while designing and running a pan-European GDPR compliance programme in-house. Early engagement generally produces a materially better outcome than responding after the fact.

Worried about your data protection exposure?
Let's find out before the HDPA does.

A confidential conversation about your data, your systems, and the compliance gaps that actually carry risk.