Greece Law 4624/2019 implementation roadmap. ORGANIZATIONAL ROLES: (a) DATA PROTECTION OFFICER (DPO) - mandatory for public authorities + bodies with large-scale processing of special category data + criminal data + systematic monitoring (Greek Article 6); independent + reports to top management + HDPA-notified + adequate qualifications + resources; many Greek companies appoint outsourced/shared DPO; (b) PRIVACY OFFICER + COMPLIANCE OFFICER - operational; (c) LEGAL - HDPA cooperation + statutory interpretation + breach response; (d) CISO + INFOSEC - GDPR Art. 32 security + NIS2 + DORA security; (e) HR - employee data + Article 27 compliance + workplace monitoring + employee rights; (f) MARKETING + COMMUNICATIONS - consent + transparency + opt-out + e-marketing rules per ePrivacy Law 3471/2006; (g) IT + ENGINEERING - privacy-by-design + privacy-by-default + DPIA + technical security; (h) PROCUREMENT + VENDOR MANAGEMENT - processor agreements + DPA + sub-processor; (i) AUDIT - internal audit + HDPA-readiness; (j) WHISTLEBLOWER OFFICER - per Law 4990/2022; (k) BOARD + EXECUTIVE - executive accountability + NIS2 + DORA. TOOLING: (a) Privacy management platforms (OneTrust + TrustArc + Securiti + Privya + Iubenda); (b) Consent management (OneTrust + Didomi + Usercentrics + Cookiebot); (c) DSAR management (OneTrust + Securiti + Transcend); (d) DPIA platforms (PrivacyEngine + Securiti + OneTrust); (e) Greek-language privacy notice templates + GDPR transparency; (f) Employee training (KnowBe4 + IAPP + Greek-language); (g) Sectoral compliance platforms; (h) Incident response (OneTrust + Resilience + various). METRICS: HDPA cooperation + investigation responses + complaints handled + DSR turnaround + DPIA completion + breach notifications (within 72 hours) + employee training completion + vendor due diligence + Article 24 unique-ID processing reviews + Article 27 employee processing audits + Article 30 special-processing journalism+research+archiving documentation. ANNUAL CYCLE: annual DPO report to management + HDPA risk assessment + DPIA review + DSR statistics + breach reports + training + audit.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.