Greece Law 4624/2019 operational provisions covering Data Subject Rights + Breach + DPIA + Transfers + Children. DATA SUBJECT RIGHTS (per GDPR Art. 12-22 + Greek Articles 28-35): access + rectification + erasure + restriction + portability + objection + ADM/profiling; 30-day SLA + 60-day extension for complex requests; identity verification; Greek-language + accessible response format; HDPA escalation if denied. BREACH NOTIFICATION (Art. 33 GDPR + Greek Article 33): 72-hour notification to HDPA from awareness; risk-assessment + remediation + affected-data-subject notification if high risk; breach register + records + lessons-learned. DPIA (Art. 35 GDPR + Greek Article 33): mandatory for high-risk processing including (a) systematic + extensive evaluation (profiling); (b) special category large-scale; (c) public-area systematic monitoring; (d) new technologies; (e) HDPA prior consultation if residual high risk; templates + frameworks. INTERNATIONAL TRANSFERS (Art. 44-50 GDPR + Greek Article 32): adequacy decisions + SCCs (new SCCs since 2021) + BCRs + derogations; Schrems II compliance + Transfer Impact Assessment (TIA); CBPR/Global CBPR Forum potential mechanism. CHILDREN PROVISIONS (Greek Article 21): age of consent 15 for ISS; parental verification; child-specific transparency; profiling restrictions; coordination with Greek Law 5043/2023 children online safety. SPECIAL CATEGORY DATA: Greek implementation Article 25 specific lawful bases + necessary safeguards.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.