Sources & references: Cyprus & EU employment-data law
About these sources
Every claim in this guide is backed by a primary source, and this page is where you check it. It lists the Cyprus and EU instruments each article cites in its footnotes: nothing secondary, nothing from a vendor. We restrict ourselves to primary law and official documents: the text of the GDPR, Cyprus statutes, a published opinion of the Cyprus Data Protection Commissioner, a judgment of the Administrative Court of Cyprus, official guidance from the EU’s data-protection regulators (the Article 29 Working Party and its successor the European Data Protection Board), Court of Justice judgments and a European Commission report. Each entry in the list below is linked to its source and tagged with the date and jurisdiction (CY for Cyprus, EU for European Union) so you can confirm any statement in the guide against the original, and so a Cyprus source is never confused with a Greek one. The full list is generated automatically from what the guide cites, which keeps it honest: a source appears here only because a page in the guide actually relies on it.
Cyprus sources
Seven Cyprus sources anchor the guide. The backbone is Opinion 2/2018 of the Office of the Commissioner for Personal Data Protection, which holds that using biometric systems to control employees’ arrival and departure is disproportionate, that employee consent does not cure this because it is not freely given in employment, and that biometrics may be justified only by exception for the physical security of genuinely high-risk premises. [1] That position has judicial backing: in Case No. 1930/2012 (19 May 2017) the Administrative Court of Cyprus dismissed a hospital’s recourse and upheld the Commissioner, confirming that collecting employees’ fingerprints solely to control working hours breaches proportionality and that consent does not cure it, though the judgment applied the earlier Law 138(I)/2001, since repealed, so it is cited as affirmation of the proportionality position rather than as a statement of the current statute. [2] The national data-protection statute now in force is Law 125(I)/2018, which gives effect to and complements the GDPR in Cyprus and establishes the Commissioner as the supervisory authority. [3] On hours, the Organisation of Working Time Law sets the 48-hour weekly average and ties a records duty to the opt-out from that cap: a targeted obligation, not a general daily-hours recording rule. [4] On the essential terms of employment, Law 25(I)/2023 (the Transparent and Predictable Working Conditions Law) transposes the EU’s transparent-working-conditions Directive and, in section 11, requires every employer to inform employees of those essential terms, with section 27 setting a fine not exceeding €5,500 for contravention. [5] Those terms are declared in the Cyprus «ΕΡΓΑΝΗ»/ERGANI information system, the Ministry of Labour and Social Insurance platform through which employers notify recruitment and termination and declare terms of employment, the Cyprus system, not the Greek one of the same name. [6] Decree K.D.P. 455/2024 gave that duty its first concrete deadline, requiring employers to register all existing employees’ essential terms (including the normal working-day/week schedule) in ERGANI during a one-off window that ran from 2 January to 28 February 2025. [7] Reading these together, note that the working-time position is also shaped by EU-level findings and rulings, covered in the EU sources below. [8]
EU sources
Eleven EU sources supply the wider legal frame. The GDPR itself does most of the work: Article 4(14) defines biometric data as data from specific technical processing that allows or confirms unique identification, such as fingerprints or facial images; [9] Article 9 prohibits, in principle, processing special categories of data, expressly including biometric data used to identify a person uniquely, unless an exception applies; [10] Article 35 requires a data protection impact assessment before processing that is likely to be high-risk, which is the gate any lawful biometric access-control deployment must pass; [11] Article 88 lets Member States set more specific employment-data rules and requires safeguards for workers’ dignity and fundamental rights, with particular regard to the transparency of processing and monitoring systems at the workplace; [12] and Recital 51 explains why such data merits specific protection and clarifies that a photograph is biometric data only when processed through specific technical means to identify a person uniquely. [13] At the EU guidance level, the Article 29 Working Party’s Opinion 2/2017 on data processing at work sets out that workplace consent is almost never freely given, that any monitoring must be strictly necessary and proportionate with the assessment made before deployment, and that prevention should be favoured over detection; [14] and the European Data Protection Board’s Guidelines 3/2019 on video devices set out that biometric processing carries heightened risks and must respect necessity, proportionality and data minimisation, and that private-sector biometric identification will in most cases require explicit consent. [15] On working time, the Court of Justice in Case C-55/18 (CCOO v Deutsche Bank) held that Member States must oblige employers to set up an objective, reliable and accessible system to measure each worker’s daily hours; [16] Case C-531/23 (19 December 2024) reaffirmed that obligation and refused to exempt the employers of domestic workers from it, evidence that the requirement is hardening; [17] and the European Commission’s 2023 implementation report on the Working Time Directive names Cyprus among five Member States without a clear obligation to record working time: the finding that gives the CCOO principle its practical bite in Cyprus. [8] On the separate question of the essential terms of employment, Directive (EU) 2019/1152 on transparent and predictable working conditions (the instrument Cyprus transposed in Law 25(I)/2023) requires in Article 4 that employers inform each worker of the essential aspects of the relationship, expressly including, for work with a predictable pattern, the length of the standard working day or week; it is the source of the contracted-hours schedule that Cyprus employers declare in ERGANI, and is distinct from the CCOO duty to measure hours actually worked. [18]
References
- Γνώμη 2/2018 για ΚΚΒΠ και βιομετρικά στο χώρο εργασίας (Opinion 2/2018 on CCTV and biometrics in the workplace) . Office of the Commissioner for Personal Data Protection (Cyprus), 2018-10-19 (CY)
- ΑΠΟΛΛΩΝΕΙΟ ΙΔΙΩΤΙΚΟ ΝΟΣΟΚΟΜΕΙΟ ΔΗΜΟΣΙΑ ΕΤΑΙΡΕΙΑ ΛΤΔ ν. Επιτρόπου Προστασίας Δεδομένων Προσωπικού Χαρακτήρα, Υπόθεση Αρ. 1930/2012 (ECLI:CY:DD:2017:189) . Administrative Court of Cyprus (via CyLaw), 2017-05-19 (CY)
- Ο περί της Προστασίας των Φυσικών Προσώπων Έναντι της Επεξεργασίας των Δεδομένων Προσωπικού Χαρακτήρα και της Ελεύθερης Κυκλοφορίας των Δεδομένων αυτών Νόμος του 2018 (125(I)/2018) . Republic of Cyprus (via CyLaw), 2018-07-31 (CY)
- Ο περί της Οργάνωσης του Χρόνου Εργασίας Νόμος του 2002 (63(I)/2002), άρθρο 7 — Μέγιστη εβδομαδιαία διάρκεια εργασίας . Republic of Cyprus (via CyLaw), 2002-01-01 (CY)
- Ο περί Διαφανών και Προβλέψιμων Όρων Εργασίας Νόμος του 2023 (25(I)/2023), άρθρα 11 και 27 . Republic of Cyprus (via CyLaw), 2023-04-13 (CY)
- Πληροφοριακό Σύστημα ΕΡΓΑΝΗ (ERGANI Information System) . Ministry of Labour and Social Insurance (Cyprus), 2021-09-13 (CY)
- Το περί Διαφανών και Προβλέψιμων Όρων Εργασίας (Ουσιώδεις Όροι Εργοδότησης για Καταχώριση σε Ηλεκτρονικό Σύστημα) Διάταγμα του 2024 (Κ.Δ.Π. 455/2024) . Republic of Cyprus, Minister of Labour and Social Insurance (Official Gazette, via CyLaw), 2024-12-20 (CY)
- Report on the implementation of Directive 2003/88/EC (COM(2023) 72 final) . European Commission, 2023-03-15 (EU)
- Regulation (EU) 2016/679 (GDPR), Article 4(14) — Definition of biometric data . European Union (Official Journal L 119), 2016-04-27 (EU)
- Regulation (EU) 2016/679 (GDPR), Article 9 — Processing of special categories of personal data . European Union (Official Journal L 119), 2016-04-27 (EU)
- Regulation (EU) 2016/679 (GDPR), Article 35 — Data protection impact assessment . European Union (Official Journal L 119), 2016-04-27 (EU)
- Regulation (EU) 2016/679 (GDPR), Article 88 — Processing in the context of employment . European Union (Official Journal L 119), 2016-04-27 (EU)
- Regulation (EU) 2016/679 (GDPR), Recital 51 . European Union (Official Journal L 119), 2016-04-27 (EU)
- Opinion 2/2017 on data processing at work (WP249) . Article 29 Data Protection Working Party, 2017-06-08 (EU)
- Guidelines 3/2019 on processing of personal data through video devices, Version 2.0 . European Data Protection Board, 2020-01-29 (EU)
- Judgment of the Court (Grand Chamber), Case C-55/18, Federación de Servicios de Comisiones Obreras (CCOO) v Deutsche Bank SAE (ECLI:EU:C:2019:402) . Court of Justice of the European Union, 2019-05-14 (EU)
- Judgment of the Court, Case C-531/23, HJ v US and MU (ECLI:EU:C:2024:1050) . Court of Justice of the European Union, 2024-12-19 (EU)
- Directive (EU) 2019/1152 on transparent and predictable working conditions in the European Union, Article 4 . European Union (Official Journal L 186), 2019-06-20 (EU)