In Cyprus, failing to report a data breach is a criminal offence, not only a regulatory one. Law 125(I)/2018 attaches imprisonment of up to three years, a fine of up to €30,000, or both, to a controller who does not notify the Commissioner.
Businesses treat the General Data Protection Regulation as a fine risk. In Cyprus that is an incomplete picture, and the missing half is the one that reaches individuals rather than balance sheets.
The Regulation is directly applicable and sets the substantive rules. What sits on top of it here is the Protection of Natural Persons with Regard to the Processing of Personal Data Law, Law 125(I)/2018, and that law does things the Regulation does not: it fixes a different age of consent, prohibits a category of processing outright, and turns a list of failures into criminal offences.
The part nobody plans for
Section 33(1) creates criminal offences. Among them, a controller commits an offence who does not notify the Commissioner of a personal data breach under Article 33(1) of the Regulation, and a processor commits an offence who does not inform the controller without delay under Article 33(2). A controller who does not communicate the breach to the data subject under Article 34 commits an offence as well.
The list does not stop at breaches. It reaches a controller or processor who does not keep or update the record of processing activities required by Article 30, refuses to produce it to the Commissioner on request, or gives the Commissioner false, inaccurate, incomplete or misleading information about it. It reaches failure to cooperate with the Commissioner under Article 31. It reaches a controller who does not carry out a data protection impact assessment where Article 35(1) requires one. And it reaches a controller or processor who obstructs the data protection officer in performing their duties, particularly their cooperation with the Commissioner.
On conviction the penalty is imprisonment not exceeding three years, a fine not exceeding €30,000, or both.
The practical consequence is a change in who has to care. A fine is a company problem. A criminal offence is a problem for the people who decide whether to report, and it is decided in the first hours after a breach is discovered.
Seventy two hours, and the excuse that does not work
The deadline is in the Regulation, not the Cyprus law: notification to the supervisory authority under Article 33(1) without undue delay and, where feasible, not later than seventy two hours after becoming aware of the breach. Communication to the data subject under Article 34 is required without undue delay where the breach is likely to result in a high risk to their rights and freedoms.
Cyprus law then closes the route most often reached for. A controller may be relieved, wholly or partly, of the duty to communicate the breach to the data subject, but section 12(1) allows that only for a purpose in Article 23(1) of the Regulation, and section 12(2) makes the relief conditional on carrying out an impact assessment and consulting the Commissioner in advance. Section 12(4) lets the Commissioner attach terms and conditions to it.
In other words the decision not to tell the people affected is not a decision the business makes on its own. It is one it applies for, and applying for it takes time the seventy two hours do not contain.
Four Cyprus rules that differ from the assumption
The age of consent is fourteen. Where information society services are offered directly to a child on the basis of the child's consent, section 8(1) makes the processing lawful if the child is at least fourteen. Below fourteen, section 8(2) requires consent given or authorised by the holder of parental responsibility. Businesses working to thirteen or to sixteen because that is what another Member State does are working to the wrong number here.
Biometric and genetic data cannot be used for insurance. Section 9(1) prohibits the processing of genetic and biometric data for health and life insurance purposes. It is a flat prohibition, not a balancing exercise.
Consent to genetic or biometric processing does not carry forward. Where such processing is based on consent, section 9(2) requires separate consent for further processing of that data.
The list of who needs a data protection officer can grow. Section 14(1) appoints the officer subject to Article 37 of the Regulation, but section 14(2) allows the Commissioner to draw up and publish a list of processing operations and cases where an officer must be appointed in addition to those in Article 37(1). Reading Article 37 alone is therefore not enough to conclude that no officer is needed.
Fines, and the one that is capped
Section 32(1) provides that the Commissioner imposes administrative fines subject to Article 83 of the Regulation, and section 32(2) makes an unpaid fine recoverable as a civil debt due to the Republic.
One category is capped. Under section 32(3), an administrative fine imposed on a public authority or public body in respect of activities of a non-profit nature may not exceed €200,000.
What to do in the first hours
Establish when the organisation became aware, because the seventy two hours run from awareness and the answer is a question of fact that gets harder to reconstruct with every day that passes. Write down what is known and what is not. Do not decide against notifying the data subjects on the footing that the relief in section 12 is available, because it is available only after an impact assessment and prior consultation.
Then check the record of processing activities. If it does not exist or is out of date, the exposure under section 33(1)(a) is separate from the breach itself and does not go away because the breach is handled well.
What to send us
The timeline of what happened and when it was noticed, the categories of data and the approximate number of people affected, the record of processing activities if there is one, and any communication already sent to anybody. The first question we answer is whether the clock has started and when.
Questions we are asked
Is failing to report a data breach a crime in Cyprus?
Yes. Under section 33(1) of Law 125(I)/2018 a controller who does not notify the Commissioner under Article 33(1) of the Regulation commits a criminal offence, as does a controller who does not communicate the breach to the data subject under Article 34. The penalty is imprisonment of up to three years, a fine of up to €30,000, or both.
How long do I have to report a breach?
Article 33(1) of the Regulation requires notification without undue delay and, where feasible, not later than seventy two hours after becoming aware of the breach. The time runs from awareness, which is a question of fact.
Can I avoid telling the people affected?
Only with permission. Section 12(1) allows relief from the duty to communicate for a purpose in Article 23(1) of the Regulation, but section 12(2) requires an impact assessment and prior consultation with the Commissioner, and section 12(4) allows the Commissioner to impose terms.
What age can a child consent at in Cyprus?
Fourteen. Section 8(1) makes processing lawful where information society services are offered directly to a child on the child’s consent and the child is at least fourteen. Below that, section 8(2) requires consent given or authorised by the holder of parental responsibility.
Can biometric data be used for insurance?
No. Section 9(1) prohibits the processing of genetic and biometric data for health and life insurance purposes.
Does Article 37 of the Regulation tell me whether I need a data protection officer?
Not by itself. Section 14(2) allows the Commissioner to publish a list of processing operations and cases requiring an officer in addition to those in Article 37(1) of the Regulation.
Related reading
This work sits within our technology and e-commerce practice. Where the processing is done by an AI system, the liability and contract questions are dealt with in when an AI system causes loss, and what a professional firm must settle before putting client material into such a tool is in AI tools and client confidentiality.
This article is for general information only and does not constitute legal advice. Laws and their application can change, and individual circumstances differ. For advice on your own matter, contact Klitos Platis at klitos@kleanthousplatis.com or telephone +357 22 680 330.

Klitos Platis
Advocate, Partner
Kleanthous & Platis LLC, Nicosia · Published 16 August 2026
Need advice on your own matter?
Send us the documents and a short description at office@kleanthousplatis.com and we will reply within one business day.
Or use the enquiry form, message us on WhatsApp, or call +357 22 680 330.