The regulatory framework for businesses in Greece and the European Union has widened considerably. The GDPR, the AI Act, NIS2 and the DSA each create different obligations, depending on the activity, the data, the systems and the services a business provides. The AI Act applies in stages, with certain prohibitions and obligations already in force and others following on set dates. NIS2 has widened the range of businesses subject to cybersecurity requirements and has now been transposed into Greek law. The DSA applies to a broad range of online intermediary services and platforms, with additional obligations for the largest platforms.
The challenge is not only knowing which rules exist. It is knowing which of them apply to your business and what has to change in practice. A compliance programme designed years ago may no longer match the business's activity, its systems or the framework now in force.
"The right question is not how many policies you have on file. It is whether the business actually operates in line with them."
Regulatory compliance differs considerably from sector to sector. Businesses in financial services, health, telecoms, energy and other regulated activities may be subject, beyond the horizontal European legislation, to specific licensing, supervisory and corporate governance requirements. We advise businesses on assessing the applicable framework, on designing and documenting compliance procedures, and on dealing with regulatory issues when they arise. The aim is a framework that can be applied in the day-to-day running of the business — with clear priorities, responsibilities and procedures. Compliance does not mean that every rule applies to everyone. The first step is to establish what actually applies. From the activity and the business model through to the data, the technology and the markets you operate in, we map the key regulatory requirements and rank the issues that need attention.
Who it affects
When regulatory support is needed
The need for regulatory compliance depends on the activity, the data the business processes, the technology it uses and the markets in which it operates. Depending on those factors, the GDPR, the AI Act, NIS2, the DSA or more than one framework may apply.
The Reality of Supervision
Fines are not theoretical
Supervisory authorities in Greece and the European Union impose fines and other administrative measures for breaches of the applicable rules. Assessing the regulatory exposure before an issue arises can therefore be an essential part of managing a business's legal position.
A Continuing Process
Compliance is not a one-off
Regulatory requirements, guidance and supervisory practice all develop. A compliance programme therefore has to be revisited whenever the activity, the technology or the applicable framework changes.
Cross-Border Activity
When the business operates in several countries
Operating in more than one state can create additional requirements because of differences in national implementation and supervisory practice. Experience in an international business environment and dual qualification in Greece and in England and Wales allow us to assess such questions from a cross-border perspective.