What’s HDPA and how does it affect Magento cookie + privacy compliance?
HDPA (Hellenic Data Protection Authority, Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα) is Greece’s GDPR enforcer, with a track record of significant fines for ePrivacy + cookie violations (multiple six-figure fines against Greek media + e-commerce sites).
Concrete Magento implications:
- Cookie consent, HDPA aligns with EDPB guidelines: granular per-purpose opt-in, no pre-ticked checkboxes, “Reject all” as prominent as “Accept all”, no cookie wall.
- ePrivacy (Law 3471/2006), Greek transposition of ePrivacy, layered on top of GDPR. Stricter on direct marketing + cookies than some EU peers.
- DSAR routing, data-subject access requests must be answered within 1 month, in Greek by default (English on request).
- Data localisation, HDPA prefers EU-region hosting. Frankfurt / Athens / Greek hosting (Pointer.gr / Papaki / OVH Greece) all qualify.
- Breach notification, 72 hours to HDPA, plus affected users.
We ship Cookiebot / OneTrust / Iubenda wired into Magento’s cookie API, banner copy reviewed against HDPA guidance, plus a Greek-language privacy policy + DPA template.