Greece also has an unusually active national data protection authority when it comes to cookies and website tracking, which shapes what a Greek legal or IT reviewer will ask before signing off a new vendor. This page sets out the framework that applies here, what that review usually covers, and how lead.box is structured to answer it.
At a glance
- Framework
- GDPR + Law 4624/2019
- Supervision
- HDPA (Hellenic Data Protection Authority)
- Usual legal basis
- Legitimate interest, Art. 6(1)(f) GDPR, with a documented balancing test
- Processing location
- ISO-certified EU data centres
The legal framework in Greece
Regulation at a glance
- FrameworkGDPR + Law 4624/2019
- SupervisionHDPA (Hellenic Data Protection Authority)
- Usual legal basisLegitimate interest, Art. 6(1)(f) GDPR, with a documented balancing test
- Processing locationISO-certified EU data centres
The GDPR sets the substantive rules, and Greece's Law 4624/2019 implements it domestically, establishing the HDPA (Hellenic Data Protection Authority, Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα) as supervisory authority, defining national derogations such as processing for employment and public-interest purposes, and fixing the procedure for complaints and audits. For a B2B website this means a lawful basis you can articulate, an internal record of processing activities, and a signed processor agreement before any script starts running.
The HDPA is one of the more visibly active authorities in the EU on the specific subject of cookies and website tracking: it has issued detailed guidelines on consent banners, published decisions against companies for non-compliant cookie walls, and audited sites for undisclosed third-party trackers rather than treating a published policy as sufficient on its own. A tool that touches visitor data on a Greek site is therefore judged less by its documentation and more by what it is actually observed doing in the browser.
Cookie and electronic-communications rules sit in Law 3471/2006 on the protection of personal data in electronic communications, which transposes the ePrivacy Directive and governs storing or reading information on a visitor's device. Identification that resolves a visit to a company without placing advertising identifiers or persistent tracking cookies sits outside the consent trigger that law creates, though everything else running on the page remains the controller's own assessment.
What the Greek market expects
Given the HDPA's cookie-specific enforcement record, Greek reviewers tend to ask precise, technical questions about what a snippet drops on the browser rather than accepting a generic assurance: expect requests for a clear description of the mechanism, a data processing agreement under Art. 28 GDPR, and a named sub-processor list before a tool is approved.
Many Greek B2B buyers, especially in shipping and energy, run procurement through group-level compliance functions that also cover other EU jurisdictions, so documentation needs to stand on its own rather than rely on local relationships. A privacy policy and processor documentation available in Greek, alongside English, speeds up sign-off with smaller in-house teams that review contracts without outside counsel.
Claims that a vendor's tool removes the need for a legal review do not survive contact with an HDPA-literate reviewer, given how specifically the authority has ruled on cookie practice. What holds up is a precise, checkable account of what is resolved to a company, what is discarded, and where the customer's own responsibility as controller begins.
Start free
Install the snippet and see the first named companies on your own traffic.
What you actually see
Named companies in your dashboard, with industry, size and the pages they read.
Where identification pays off here
Greece's shipping and maritime logistics sector is a defining export industry, and its buyers research suppliers, class societies and technical service providers over long cycles, often from group offices outside Greece, well before any direct contact is made. Seeing the company behind that research early lets a sales team reach out while the shortlist is still forming.
Energy project developers and the country's growing tourism-technology sector show a similar pattern: technical and commercial teams evaluate platforms and equipment vendors quietly, and a single identified visit from a known account is worth an immediate, targeted follow-up rather than waiting for an inbound enquiry that may never come.
How lead.box works here
GDPR-compliant visitor identification: the 5 rules
1. Company level only
Identification resolves the organisation behind a visit through network and IP-to-company matching. Individual people are never identified, and a visit that cannot be matched to a company stays anonymous.
2. Legal basis: legitimate interest, Art. 6(1)(f) GDPR
Company-level identification is commonly based on legitimate interest under Art. 6(1)(f) GDPR, documented with a balancing test. Consent is not required where no personal identifiers are processed; the final assessment stays with you as the controller.
3. No personal identifiers
No names, personal e-mail addresses, device fingerprints or cross-site profiles are created. Raw network addresses are not available in the interface, exports or API — only the resolved company is stored.
4. EU data processing
Personal and visitor data concerning the EU is processed in ISO-certified data centres in the European Union. EU visitor data is not moved outside the EU for this purpose.
5. Transparency and opt-out
Disclose the identification in your privacy policy — a copy-ready paragraph is on this page. Every visitor can object at any time through the public opt-out page.
lead.box applies all five rules by design.
Questions from this market
Yes, it is workable under the GDPR and Law 4624/2019, provided the output stays at company level and no individual is identified. The usual legal basis is legitimate interest under Art. 6(1)(f) GDPR, documented through a written balancing test that weighs your commercial interest in knowing which accounts are researching you against the visitor's expectations, and disclosed plainly in your privacy policy. Greek reviewers, used to a demanding HDPA, tend to check that the balancing test actually exists on paper rather than accepting a verbal assurance. lead.box acts as your processor under a signed Art. 28 data processing agreement, but the final call on lawfulness for your own site sits with you as controller, so it is worth having your own counsel confirm the basis before launch, especially if your sector already runs group-wide compliance reviews.
The HDPA, formally the Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα, supervises GDPR compliance in Greece under Law 4624/2019 and is notably one of the more assertive EU authorities on cookie and website-tracking practice specifically, having issued detailed banner guidance and sanctioned companies over non-compliant consent walls. That enforcement record means a Greek legal or IT reviewer will typically ask what a script actually does in the browser rather than take a vendor's written claim at face value, so expect questions about storage mechanisms, retention windows and whether anything beyond company resolution is happening. Because the HDPA also handles complaints from individuals directly, having a clear, checkable answer ready before a contract is signed avoids delays later, and your own legal advisor should confirm how this applies to your specific site setup and any other trackers you already run.
Company-level identification through lead.box does not set advertising identifiers, device fingerprints or persistent tracking cookies, so on its own it sits outside the consent trigger created by Law 3471/2006, the Greek law transposing the ePrivacy Directive that governs reading or writing information on a visitor's device. That said, most Greek sites run several other tools, from analytics to advertising pixels, that do require consent, and the HDPA has specifically fined companies for cookie walls that force acceptance or hide a genuine reject option, so your existing banner setup for those tools should not be touched based on adding lead.box. Whether your particular implementation needs adjustment, and how you categorise the snippet in your cookie policy, remains your own assessment as controller, ideally confirmed with counsel familiar with current HDPA practice.
Data concerning EU visitors is processed in ISO-certified EU data centres, and it is not routed or stored outside the EU for this purpose, which matters for Greek buyers whose group compliance functions often flag any non-EU processing as a blocking issue regardless of legal mechanism used. Retention is limited to what is needed to resolve and deliver company-level matches, rather than being kept indefinitely, and the versioned sub-processor list is published so a reviewer can check exactly who touches the data before approval rather than requesting it separately mid-negotiation. A signed data processing agreement under Art. 28 GDPR is available before commitment, which tends to shorten the review cycle for Greek shipping and energy buyers whose procurement runs through a parent company's compliance desk covering several jurisdictions at once.
There is no strict GDPR requirement for a vendor to supply documentation in Greek, but in practice many Greek buyers, particularly smaller in-house legal or IT teams without outside counsel, treat the absence of a Greek-language privacy summary as a gap that slows down sign-off. Commercial contracts themselves are commonly executed in English between Greek companies and foreign B2B vendors, especially in shipping and energy where English is the working language, but the privacy policy and processor summary given to an internal reviewer are more often expected in Greek so nothing gets lost in translation during an internal escalation. lead.box structures its legal documentation and market pages to make that kind of local review straightforward, though your own team should confirm what your specific reviewer or auditor requires.
Greek companies are identified for VAT and invoicing purposes by their ΑΦΜ (tax registration number, Αριθμός Φορολογικού Μητρώου), and any subscription contract should reference that number alongside the registered company name held with the ΓΕΜΗ commercial registry, since Greek finance teams generally will not process a supplier invoice without a correctly matched ΑΦΜ. For intra-EU B2B services, VAT is typically handled under the reverse-charge mechanism rather than charged directly, but your own finance or tax advisor should confirm the applicable treatment for your entity and reporting obligations, since practice can vary depending on how your company is structured and registered. Getting the ΑΦΜ and legal entity name right at contracting stage avoids the invoice-matching delays that Greek accounting departments are known to flag during procurement.
Company-level identification resolves a visit to the organisation behind it, typically via IP-to-company matching combined with first-party signals on your own site, and it deliberately stops short of identifying, profiling or contacting the individual browsing, which is the distinction Greek reviewers focus on because HDPA scrutiny concentrates heavily on personal-level tracking rather than aggregate business intelligence. No name, email address or individual browsing history tied to a specific person is produced or stored as part of this process, and the output is an account name and firmographic context your sales team can use, not a personal profile. This is also why the legitimate interest basis under Art. 6(1)(f) GDPR is generally considered defensible here, though your own data protection officer or counsel should confirm this reading fits your specific implementation and any additional data you combine it with.
Timelines vary, but Greek B2B buyers in shipping, energy and tourism technology commonly route new vendor approvals through a compliance function that also covers sister entities elsewhere in the EU, so a tool with published documentation ready in advance tends to move faster than one requiring back-and-forth requests. Having the Art. 28 data processing agreement, sub-processor list, and a plain description of the mechanism available upfront removes several rounds of email exchange that otherwise stretch a review over multiple weeks. Because the HDPA's cookie enforcement record makes Greek reviewers particularly attentive to what happens in the browser rather than what a policy claims, being able to demonstrate exactly what is and is not collected, in writing, is usually the single factor that most shortens the process for teams evaluating lead.box against internal risk criteria.
See which companies are already researching you in Greece
Install a first-party snippet, watch the first companies appear, and hand your legal or procurement reviewer the documents in the same week.