What Is Protection of Natural Persons with Regard to the Processing of Personal Data and the Free Movement of Such Data Law 125(I)/2018?
Cyprus is an EU member state, so the GDPR applies directly alongside Law 125(I)/2018, the national Protection of Natural Persons with Regard to the Processing of Personal Data and the Free Movement of Such Data Law. The current consolidated record shows the original statute and amendment 26(I)/2022, with no additional amendments remaining outside the consolidated text. The Cyprus law adds targeted national rules rather than replacing the GDPR. Section 11 can restrict Articles 12, 18, 19, and 20 only for GDPR Article 23 purposes and with its safeguards; Section 29(2) limits Articles 14 and 15 for specified journalism and expression purposes, while Section 31 provides an express safeguard for research, archival, and statistical processing rather than a broad rights exemption. The Commissioner provides complaint forms for rights complaints, other breaches, and unsolicited electronic communications. A written progress or outcome notice is due within 30 days where possible depending on the nature and type of the matter, but no separate statutory deadline located for a final merits decision.
At a glance
- Full name
- Protection of Natural Persons with Regard to the Processing of Personal Data and the Free Movement of Such Data Law 125(I)/2018
- Short code
- Law 125(I)/2018
- Jurisdiction
- Cyprus
- Enacted
- 2018
- Last major update
- Amendment 26(I)/2022 published 11 March 2022; the current CyLaw consolidated record shows no additional amendments outside the consolidated text
- Regulator
- Commissioner for Personal Data Protection
- Private right of action
- Limited
Scope, who Law 125(I)/2018 covers
Protected data
Data subject rights
Right to transparent information under Article 12, subject to the targeted Section 11 restrictions
Right to information under Articles 13 and 14, with Section 29(2) limitations for specified journalism and expression processing
Right of access under Article 15, with the Section 29(2) journalism and journalistic-secrecy limitation
Right to rectification under Article 16; no specific derogation located
Right to erasure under Article 17; no general derogation located
Right to restriction of processing under Article 18, subject to Section 11 restrictions for GDPR Article 23 purposes
Right to data portability under Article 20, subject to Section 11 restrictions
Right to object under Article 21; it is not listed in Section 11, and Section 31 does not name or disapply it
Protection against legally or similarly significant automated decisions under Article 22
Right to complain to the Commissioner using Form A for rights complaints, Form B for other breaches, or Form C for unsolicited electronic communications
Right to appeal a Commissioner decision to the Administrative Court within 75 days from the decision date under the Commissioner’s procedure
Notable features
Section 11 is not a blanket exemption: it targets only Articles 12, 18, 19, and 20 within GDPR Article 23 purposes and safeguards. Other distinctive rules include a 14-year information-society child-consent age, separate criminal penalties, transfer safeguards for certain special-category data, and Section 3(2)’s extension to the UK Sovereign Base Areas in Cyprus.
Enforcement & penalties
Regulator: Commissioner for Personal Data Protection
Penalties: GDPR Article 83 administrative-fine structure applies under Section 32(1). Section 32(3) adds a narrow ceiling of €200,000 for a fine on a public authority or body concerning non-profit activities only; it is not a general public-sector cap or general fine schedule. Separate Section 33 criminal penalties include up to 3 years’ imprisonment and a €30,000 fine for specified offenses, up to 1 year and €10,000 for another category, and up to 5 years and €50,000 for national-security or government-function-affecting offenses.
Private right of action: A right to appeal a Commissioner decision to the Administrative Court, generally within 75 days under the Commissioner’s procedure, is the identified mechanism. A general private damages action was not located in the report.
Relevance to data brokers
Not located. No Cyprus-specific data-broker, people-search, or public-record route was located in the reviewed materials. The generic Commissioner-FAQ write-to-controller route is the only mechanism found, alongside the general GDPR access, rectification, erasure, restriction, portability, objection, and complaint mechanisms.
Generate requests in under 60 seconds
Generate removal requests for 1,034 US/global profiles, $9
FAQ
Does Cyprus have a separate privacy law alongside the GDPR?+
Yes. Cyprus is an EU member state, so the GDPR applies directly. Law 125(I)/2018 adds Cyprus-specific rules, and Section 3(1) expressly applies the law in accordance with GDPR Articles 2 and 3.
How long does the Cyprus Commissioner have to resolve a complaint?+
The Commissioner’s procedure provides for a written progress or outcome notice within 30 days where possible, depending on the nature and type of the matter. No separate statutory deadline located for a final merits decision.
Does Cyprus have a dedicated data-broker removal route?+
Not located. No Cyprus-specific data-broker, people-search, or public-record route was located in the reviewed materials. The identified mechanisms are the general GDPR rights and the Commissioner’s complaint process.
Official sources & citations
Other international privacy regimes
Law 125(I)/2018 sits in a global ecosystem of data-protection laws. Compare with other jurisdictions that shape cross-border data flows:
