Cyprus
Tier 2 Comprehensive law EuropePrincipal framework: GDPR + Law 125(I)/2018 (2018). Regulator: Commissioner for Personal Data Protection. Combines GDPR and Law Enforcement Directive implementation; journalism balancing test.
At a glance
- Criminal offences
- Yes — a dedicated offence carrying custody exists
- Public-sector fines
- Capped
- Principal law
- Ο περί της Προστασίας των Φυσικών Προσώπων Έναντι της Επεξεργασίας Δεδομένων Προσωπικού Χαρακτήρα Νόμος 125(I)/2018 [Law 125(I)/2018 on the Protection of Natural Persons with regard to the Processing of Personal Data]
- Regulator
- Cypriot Data Protection Authority
- Breach notification
- 72 hours to the supervisory authority (Art 33); undue-delay notice to individuals at high risk
- Maximum penalty
- Up to €20m or 4% of global annual turnover
- DPO required
- Public authorities; large-scale regular monitoring or special-category processing (Art 37)
- Digital consent age
- 14
- Extraterritorial reach
- Yes — targeting or monitoring people in the EU (Art 3(2))
- National implementing act
- Law 125(I)/2018
Structure
- Structural pattern
- Not assessed
- Sub-jurisdictions
- None — no sub-national axis
- ISO code
- CY
A Pattern 4 jurisdiction has no sub-national layer to model. Devolution elsewhere in the legal system does not imply it here — check each Act rather than reasoning from the country.
Transfers and adequacy
- EU member
- Yes
- EEA member
- Yes
- Holds EU adequacy
- Yes
EU/EEA member — intra-EEA transfers need no adequacy decision.
Instruments
No instrument profiled yet.
Also applies here
Directly applicable as EU law, without national transposition. The national act supplements it rather than replacing it.
Sources
- Regulator Cypriot Data Protection Authority
- Regulator Cypriot Data Protection Authority
- Primary Regulation (EU) 2016/679 (GDPR) EUR-Lex
Never independently verified — seeded from the prototype.