If you run a Greek website with Google Analytics, a Meta pixel or embedded videos, then you need consent before any of them loads, and your banner must have a refuse button as easy to use as the accept button. That is not my interpretation, and it is not something I thought up one evening because I was short of a topic. It has been written in an official document of the Hellenic Data Protection Authority since 2020.

Let me tell you the most common mistake I see on Greek sites, and it is not the wording in the footer. It is the belief that cookies are governed by the GDPR. They are not, at least not by the GDPR alone, and that misunderstanding leads to the wrong conclusions. So let us start where the confusion starts.

It is not one law, it is two

Regulation (EU) 2016/679 governs the processing of personal data. Article 4(11) defines consent as a “freely given, specific, informed and unambiguous indication of the data subject’s wishes”, and Article 7 adds that the controller must be able to demonstrate it and that withdrawal must be as easy as giving it. Hold on to that “able to demonstrate”, we will come back to it.

Cookies, however, are governed by a different provision, and this is exactly where most people get lost: Article 5(3) of Directive 2002/58/EC, transposed in Greece by Article 4(5) of law 3471/2006. It states that storing information, or gaining access to information already stored, in the terminal equipment of a user is only allowed after consent, following clear and comprehensive information.

Picture it this way. The visitor’s device is their house. The GDPR deals with what you do with whatever you took out of it. Law 3471/2006 deals with the knock on the door itself, before we even discuss what you took.

That distinction has one important consequence. The rule applies regardless of whether the stored information is personal data. Again, this is not my opinion: the Court of Justice of the European Union confirmed it explicitly in C-673/17 Planet49 on 1 October 2019, where it also ruled that a pre ticked checkbox is not valid consent.

So the argument “I do not collect personal data, therefore I do not need a banner” is legally wrong at its root. I have heard it many times, always delivered with great confidence.

What passes without asking and what does not

Without consentWith prior consent
TestStrictly necessary for transmission or for the service the user requestedAnything else
ExamplesShopping cart, login session, security, load balancing, language choiceGoogle Analytics, Meta pixel, Google Ads, embedded YouTube, chat widgets, heatmaps
TimingImmediatelyOnly after an explicit affirmative action
If the user does not answerRuns normallyMay not be set
Legal basisExemption in Article 4(5) law 3471/2006Consent, never legitimate interest

The last row deserves attention, because that is where a trap hides, and plenty of people are paying for it. The EDPB Cookie Banner Taskforce report, adopted on 17 January 2023, records as the common position of European authorities that legitimate interest cannot be a legal basis for setting cookies under Article 5(3). And yet many off the shelf banners sold in the Greek market still offer that option in their settings. You have seen it, an innocent looking line in the settings panel that does not hold up.

The eight rules the Authority has already written down

The document anyone running a Greek site should read is called Recommendations 1/2020, issued on 25 February 2020. It uses the term “tracker” and covers not only cookies but also HTML5 local storage, device fingerprinting, and operating system and hardware identifiers.

The practical rules, as the Authority states them:

1. Pre ticked boxes, continued browsing and scrolling are not consent.

2. Browser default settings that accept cookies are not consent.

3. If the user expresses no choice, no non essential tracker may be used.

4. Acceptance and refusal must be possible with the same number of clicks and from the same layer.

5. Withdrawal must use the same means and be as easy as giving consent.

6. Refusal may not result in exclusion from the content.

7. The buttons must have the same size, the same emphasis and the same colour.

8. The banner must reappear after the same interval, whether the user accepted or refused.

Read them once more, then picture your own banner. How many of the eight does it actually keep?

And one point that surprises most people, which I have kept for last on purpose: Recommendation A.4 names Google Analytics explicitly and states that third party statistical analysis tools may only be used with the user’s consent. There is no “statistics exemption” in the Greek framework today.

How far the rule really reaches

If your reaction was “fine, I drop the cookies and I am done”, let us not rush. In October 2024 the European Data Protection Board issued Guidelines 2/2023 on the technical scope of Article 5(3). The conclusion is that the rule is not about cookies alone.

Explicitly covered: tracking pixels and tracked links, because even temporary storage in the browser cache counts as storage. Local storage. Unique identifiers. IP based tracking where the address originates from the user’s equipment. Even HTTP headers and ETags.

In practice that means a page which sets no cookie at all but loads a Meta pixel is squarely within scope. “I do not use cookies” is, sadly, not an answer.

What changes in 2026 and what has not changed yet

Two developments that have not reached the Greek market yet.

The ePrivacy Regulation proposal was withdrawn. COM(2017)10, which the market waited on for eight years, appears in the Commission’s list of withdrawn proposals published in the Official Journal on 6 October 2025. It is not coming. Eight years of waiting, and the answer arrived as one line in a list.

The Digital Omnibus took its place. On 19 November 2025 the Commission tabled proposal COM(2025) 837, which moves the cookie rule out of the ePrivacy Directive and into the GDPR itself, as a new Article 88a. The points that matter for a small business:

  • A new exemption from consent for audience measurement carried out by the provider of the service, exclusively for its own use. That is first party analytics with no banner, which is not permitted in Greece today.
  • Refusal must be possible “through a single click button or an equivalent means”.
  • After a refusal, re asking for the same purpose is prohibited for at least six months.
  • A new Article 88b: choices are to be expressed through machine readable browser signals which websites must honour.

Mind the wording, and here I want to be completely clear: this is a proposal, it has not been adopted. The EDPB and the EDPS published a joint opinion in February 2026 supporting the aim of tackling consent fatigue, with reservations on other points. Until it passes, everything described above still applies.

Let us be honest about enforcement in Greece

This calls for honesty, because numbers circulate that do not exist.

In May 2022 the Authority audited 30 news websites on its own initiative and found violations of Recommendations 1/2020, mainly the absence of an equally accessible refusal and visual emphasis on the “I agree” button. After notification all but one complied. No fine was imposed.

The only published fine citing Article 4(5) of law 3471/2006 is decision 50/2017, of 75,000 euro, and it concerned trackers inside marketing emails.

If someone is selling you compliance on the fear of a specific Greek banner fine, ask them for the decision number. Watch what comes back. The real risk is not the fine. It is the complaint, the audit, the time it eats, and the fact that a non compliant setup usually means the rest of your data handling is not in order either.

Half an hour with your site and eight questions

Open your site in a private window and check:

  1. Before you click anything, open Developer Tools and see whether requests have already gone out to google-analytics.com or facebook.net. If they have, your banner is decorative.
  2. Is there a refuse button on the first layer, not behind “Settings”?
  3. Do the two buttons have the same size and colour?
  4. Does closing the banner with the X activate trackers?
  5. Is there a way to change your mind later without hunting for it?
  6. Does the cookie policy state the purpose, duration and recipient per tracker, or is it generic text?
  7. Do you keep a record of consents, with timestamp and notice version?
  8. If someone refuses, does the banner reappear more often than for someone who accepted?

Point seven is the one that fails almost everywhere, and that is no accident. Article 7(1) GDPR requires you to demonstrate consent. A banner that looks correct but keeps no record does not cover you on the day you are asked. And that day, if it comes, does not send a warning first.

The hard part in all of the above is not the banner. It is the proof: Article 7(1) requires you to be able to show that the visitor consented, and most free banners keep nothing. Handsome on the surface, hollow inside.

That is the gap MS-Consent fills, the next tool in the MS-Logic ecosystem. It is in its final stage and will be announced shortly. What it does:

  • Shows and records consent in line with the GDPR, through a discreet banner at the bottom of the page.
  • Keeps trackers frozen until the visitor says yes. Google Analytics, the Facebook pixel and embedded videos do not load before acceptance.
  • Each visitor’s choice is stored as anonymous proof: what was accepted and when. No name, no email, no personal details.
  • A permanent privacy button at the bottom left, so the visitor can change their mind at any time. That is the requirement of Article 7(3) and of Recommendation C.5.
  • Greek and English, switching automatically on English URLs. On mobile and on desktop.
  • Two lines of code at the top of the page. It works on any website, WordPress, Wix or custom, not only the ones we host. We handle the configuration centrally.

And now two things I will not tell you, because they would not be true. First, no tool makes you “100% legally covered”. MS-Consent is a strong compliance tool, but final responsibility stays with the site owner, and I am not a legal adviser either. Second, freezing trackers on a site we do not control requires an extra per site setup. On our own sites it is close to automatic, elsewhere we verify it before telling you that you are in the clear.

Why this matters in the end

Cookie compliance is not a legal text in the footer. It is a technical setup: what loads when, what gets recorded, and what you can prove. The rules have been written down since 2020, they are specific, and most Greek sites fail them because nobody read them.

2026 will most likely bring some relief on audience measurement and more strictness on how refusal is handled. Until then, the eight point audit is half an hour of work and tells you exactly where you stand.

Which brings us back to the door we started with. A visitor lets you into their house for a few seconds. The least you owe them is to knock first.

If you want to see what your site actually loads before anyone clicks anything, get in touch.