Greece is a member of the European Union and applies the GDPR alongside the national Law 4624/2019, which adapts Greek law to the regulation. The national supervisory authority is the Hellenic Data Protection Authority (HDPA), known in Greek as the Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα. Greece has a rapidly evolving digital landscape, with platforms like Facebook, Instagram, LinkedIn, and the local marketplace Car.gr widely used across the country. Whether you want to verify an online date, investigate a suspicious seller, or protect your own photographs from impersonators, understanding Greek privacy law is essential before using any face search engine. For a comparison with another Southern European country, see our guide to face search in Italy.
Face Search in Greece Overview
Face search allows you to upload a photograph to a face search engine and receive a list of public web pages where the same face appears. In Greece, this technology is used for identity verification, dating safety, marketplace fraud prevention, and personal image protection. Greek law treats facial images processed for the purpose of uniquely identifying a person as biometric data, a special category of personal data under Article 9 of the GDPR. Processing biometric data is prohibited in principle unless a narrow exception applies — most commonly the explicit consent of the data subject or processing necessary for reasons of substantial public interest. The HDPA has emphasized that biometric systems must be proportionate, necessary, and transparent, and that less intrusive alternatives should always be considered first. To understand the underlying technology, read our complete guide to facial recognition.
The HDPA and Greek Enforcement
The HDPA is Greece's independent data protection authority. It enforces both the GDPR and Law 4624/2019, investigates complaints, issues guidance, and has the power to impose administrative fines of up to 20 million euros or 4% of global annual turnover, whichever is higher. The HDPA has been active in scrutinizing biometric processing, particularly in employment, education, and law enforcement contexts. The authority has issued guidance on the use of CCTV cameras with facial recognition capabilities, ruling that continuous biometric monitoring in workplaces is generally disproportionate. The HDPA has also addressed the use of facial recognition in public spaces, cautioning that mass surveillance through biometric technology without a clear legal basis violates fundamental rights. The authority has warned about the risks of commercial face search tools that build permanent biometric databases.
GDPR and Law 4624/2019
The GDPR applies directly in Greece and is supplemented by Law 4624/2019, which fills in areas where the GDPR allows member-state discretion. The core principles relevant to face search mirror those across the EU: lawfulness, fairness, and transparency; purpose limitation; data minimization; and storage limitation. Because facial data is a special category, controllers need both an Article 6 lawful basis and an Article 9 exception. For face search, this typically means explicit consent. The HDPA expects organizations to conduct a Data Protection Impact Assessment (DPIA) before processing biometric data at scale. Law 4624/2019 also includes provisions specific to the Greek context, such as rules on processing personal data for journalistic purposes, the processing of data by religious communities, and specific conditions for processing data in the context of employment.
Legal Use Cases in Greece
- Online dating safety — verifying that a match on Tinder, Bumble, or a Greek dating platform is using authentic photos
- Marketplace fraud prevention — checking whether a seller on Car.gr or OLX Greece is using stolen images
- Identity verification — confirming the identity of freelancers, contractors, or online business contacts
- Personal image protection — discovering whether your own photos are being misused by impersonators
- Journalistic and OSINT research — verifying subjects in stories of public interest
- Tourism sector vetting — verifying identities in Greece's large tourism and hospitality industry
How to Use Face Search Responsibly in Greece
Using reverse face search responsibly in Greece means choosing a tool that respects both the GDPR and the HDPA's guidance. A compliant service deletes uploaded photos immediately after processing, does not retain facial templates, and does not build a permanent biometric database. The GDPR's household exemption may cover an individual using face search for purely personal activities — such as verifying a dating match or checking whether their own photos are being misused — but the HDPA and the Court of Justice of the European Union interpret this exemption narrowly. If the activity extends beyond the purely personal sphere, full GDPR compliance is required, including a lawful basis and an Article 9 exception. Greek users should also be mindful of the country's constitutional protections for personal data under Article 9A of the Greek Constitution. Always use results ethically: do not stalk, harass, or discriminate. To find someone by photo today, try facesearching by visiting the facesearching home page.
Greek Privacy Rights and Redress
Greek residents enjoy the full suite of GDPR rights: access, rectification, erasure, restriction, data portability, and objection. Law 4624/2019 adds national specifics, including provisions on how public authorities handle personal data and how image rights interact with privacy obligations under the Greek Civil Code. The HDPA operates an accessible complaints mechanism, and individuals can file complaints online without legal representation. If a face search service processes your facial data in violation of the law, you have the right to seek redress through the HDPA and the Greek courts. For more on safeguarding your online presence, see our guide to protecting your digital identity.
Greece's HDPA has ruled that continuous facial recognition in workplaces violates the GDPR's proportionality principle — any face search engine serving Greek users must delete uploads and never retain biometric templates.