GDPR for Greek websites: what you must have in 2026
Cookie consent, lawful basis, data subject rights, retention policy — the guide to surviving a Hellenic DPA audit.
The Hellenic DPA is auditing
Since 2024 the Greek Data Protection Authority runs active audits, especially on e-shops and sites with email lists.
Core checklist
- Cookie banner with granular consent (not just "Accept all")
- Privacy policy per GDPR articles 13-14
- Clear lawful basis per data type
- Data subject request workflow (access, rectification, erasure)
- Retention schedule per data category
- Data Processing Agreement with every third party (Google Analytics, Stripe, Mailchimp)
- 72-hour breach notification protocol
Practical fixes
In most cases, a properly configured consent banner + an updated privacy policy cover 80% of the risk. The rest is architecture (logs, backups, retention).