Skip to content

Jurisdictions / Cyprus

GDPR compliance in Cyprus — DPO and data protection services

GDPR in Cyprus means the EU regulation plus Law 125(I)/2018, supervised by the Commissioner for Personal Data Protection. We provide the data protection officer role, compliance audits, DSAR handling and Article 27 EU representation for organisations operating in or selling into Cyprus — from an EU establishment you can verify on a public register.

Acting for a client? We are appointed behind professional advisers and report to you. Your relationship with your client stays yours.

Why Cyprus operations attract data protection scrutiny

Cyprus concentrates fund administration, corporate and fiduciary services, shipping and international business — sectors that hold identity documents, due-diligence files and beneficial-ownership records for clients across many countries. That is precisely the processing a supervisory authority examines hardest, and it is where a properly appointed, genuinely independent DPO and clean DSAR evidence earn their keep.

  • Data protection officer services — the named, independent role under a service contract
  • GDPR compliance audits and gap analyses against GDPR and Law 125(I)/2018
  • DSAR handling — intake, identity verification, search, redaction and defensible evidence
  • EU representation (Article 27) for organisations outside the EU serving Cyprus
  • DPIAs, records of processing, policies and staff training
  • UK GDPR coverage alongside, for organisations serving both markets

One provider across the EU and UK

Privacy Core Services is established in the EU (Privacy Core Services Ltd, C 95774, Malta) and in the United Kingdom (Privacy Core UK Ltd, Companies House 17350509) — both on public registers you can check before you appoint us. For a Cypriot group with UK-facing clients, or a non-EU group serving Cyprus, that means one contract covering both regimes with no chain of subcontractors.

Questions, answered

What data protection law applies in Cyprus?

The EU GDPR, supplemented by Cyprus Law 125(I)/2018 on the protection of natural persons with regard to the processing of personal data. The supervisory authority is the Commissioner for Personal Data Protection. Organisations that also serve the UK market answer separately to the UK GDPR.

Does a Cypriot company need a Data Protection Officer?

The GDPR test applies: a DPO is mandatory for public authorities, for core activities involving regular and systematic monitoring of individuals on a large scale, and for large-scale processing of special-category or criminal-offence data. Fund administrators, corporate service providers and firms handling client due-diligence files at scale often meet the threshold or choose a voluntary appointment because a counterparty asked for one. Article 37(6) permits the role to be held under a service contract.

Can our DPO be outside Cyprus?

Yes. The GDPR requires the DPO to be easily accessible from each establishment, not locally resident. We hold the role from our EU establishment in Malta, work in English, and deal with the Commissioner for Personal Data Protection the way an in-country provider would.

We are outside the EU but serve Cypriot clients. What do we need?

If you have no establishment in the EU and you offer goods or services to people in Cyprus or monitor their behaviour, Article 27 GDPR requires an EU Representative. Ours is held from Malta — inside the EU, on a public register you can verify before you appoint us.

Start with a short conversation

Tell us what you process and for whom, and we will tell you plainly what the GDPR and Law 125(I)/2018 require of you. No automated signup; we reply within one business day.

Beyond data protection

Once the data protection engagement is in place, we can also support the corporate side — company formation in Cyprus, domiciliary services and bank account opening.