The Greek authority rejects a request for deletion from the register of undesirable foreigners for national security reasons

The Greek authority rejected a complaint seeking the erasure of data from a national register for national security reasons, finding the processing and refusal of erasure compliant with the legal framework.

Facts and context

The Hellenic Data Protection Authority published on 17 July 2026 a decision rejecting a complaint against the Ministry of Citizen Protection, concerning the legality of the registration of a person in the National Catalogue of Undesirable Foreigners.

The case originated from a complaint by an individual, designated by the letter A, requesting their removal from the National Catalogue of Undesirable Foreigners (E.K.A.N.A.).

Grounds for the decision

The authority examined the legality of the complainant's data processing and concluded no breach, based on the following elements:

  • Legality of the processing and its purpose: The authority considered that the complainant's registration in the register was lawful. It is based on national law 3386/2005, which authorizes the registration of persons whose presence constitutes a threat to national security. The authority noted that the successive decisions to maintain and renew the registration, notably those of 25 July 2020, 24 July 2023, and 30 January 2025, were motivated by such reasons. The procedure also provides for a triennial review of the necessity of the registration, which constitutes a safeguard against indefinite retention.
  • Limitation of the rights of the data subject: The authority judged that the refusal of erasure and the non-disclosure of certain information to the complainant were justified. It relied on national law 4624/19, which allows the controller to restrict the rights of data subjects for national security reasons. Consequently, the ministry's decision not to communicate the classified elements justifying the maintenance of the registration was considered compliant with the applicable legal framework.

Authority's decision

Consequently, the authority rejected the complaint filed by the data subject.

Lessons learned

This decision recalls that:

  • The right to erasure is not absolute and may be set aside when data processing is necessary for the safeguarding of national security, provided that such processing is based on a clear and precise national legal basis.
  • National legislations may legitimately provide for restrictions on the rights of data subjects, including the right of access and the right to information, if these limitations constitute a necessary and proportionate measure to protect national security.
  • Personal data processing based on national security imperatives must include appropriate safeguards, such as a defined retention period and periodic review of the necessity to maintain the data.
  • A public authority may legitimately refuse to disclose to a data subject the specific reasons for their registration in a file if the underlying information is classified for national security reasons.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire