The Greek authority adopts an opinion on the regulatory framework for places of worship and the protection of personal data
The Hellenic Data Protection Authority has issued an opinion on a draft ministerial decision concerning the authorization framework for places of worship, identifying several points of non-compliance with the GDPR.
Requested by the Ministry of Education, Religions and Sports, the Authority analyzed the draft joint ministerial decision implementing Law No. 5224/2025. This law establishes a new authorization regime for the construction, establishment, and operation of places of worship for all confessions, except the Greek Orthodox Church. The authorization procedure involves the collection of personal data from applicants and religious officials, including data revealing their religious beliefs, which are considered special categories of data.
The Authority noted several major breaches of the GDPR. Firstly, the draft decision relies on consent as the legal basis for processing, which is not valid for processing carried out by public authorities in the exercise of their tasks. Secondly, it provides for the online publication of authorization decisions on the "Clarity Program," which would result in the disclosure of sensitive data, contrary to the law that exempts from publication acts containing such information. Finally, the draft does not define any retention period for the collected data. The Authority recommends revising the legal basis, publishing only anonymized summaries of decisions, setting strict retention periods, and ensuring transparent information to data subjects in accordance with Articles 12 to 14 of the GDPR.
Requested by the Ministry of Education, Religions and Sports, the Authority analyzed the draft joint ministerial decision implementing Law No. 5224/2025. This law establishes a new authorization regime for the construction, establishment, and operation of places of worship for all confessions, except the Greek Orthodox Church. The authorization procedure involves the collection of personal data from applicants and religious officials, including data revealing their religious beliefs, which are considered special categories of data.
The Authority noted several major breaches of the GDPR. Firstly, the draft decision relies on consent as the legal basis for processing, which is not valid for processing carried out by public authorities in the exercise of their tasks. Secondly, it provides for the online publication of authorization decisions on the "Clarity Program," which would result in the disclosure of sensitive data, contrary to the law that exempts from publication acts containing such information. Finally, the draft does not define any retention period for the collected data. The Authority recommends revising the legal basis, publishing only anonymized summaries of decisions, setting strict retention periods, and ensuring transparent information to data subjects in accordance with Articles 12 to 14 of the GDPR.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire