In January 2019, Privacy Minders announced that Maria Raphael had been selected to contribute the Cyprus chapter to the International Association of Privacy Professionals’ EU Member State GDPR Derogation Implementation Tracker.

The resource had been developed to help privacy professionals understand an important feature of the General Data Protection Regulation:

although the GDPR created a directly applicable European framework, it also left a number of areas in which Member States were required or permitted to adopt national rules.

Those national choices are commonly described as GDPR derogations.

The IAPP Tracker brought those national implementation choices together in a comparative format, allowing privacy professionals to examine how individual Member States had approached the areas in which the GDPR permitted domestic variation.

Why GDPR derogations matter

The GDPR significantly harmonised European data-protection law, but it did not remove every area of national discretion.

A number of provisions permit or require Member States to adopt rules reflecting their domestic legal systems and policy choices.

Examples can include matters such as:

  • the age at which a child may consent to information-society services;
  • processing of particular categories of personal data;
  • freedom of expression and information;
  • employment-related processing;
  • public-sector processing;
  • restrictions on data-subject rights;
  • and other areas in which the Regulation permits national specification.

For organisations operating across several EU Member States, those differences can matter in practice.

A GDPR compliance programme may therefore require both:

  • an understanding of the Regulation itself; and
  • an understanding of the national legislation applying in the relevant Member State.

A comparative Member State resource

The IAPP launched the EU Member State GDPR Derogation Implementation Tracker as a comparative resource for its members.

The IAPP described the project as a community effort bringing together contributors from multiple EU jurisdictions.

The purpose was to enable users to compare how individual Member States had implemented the GDPR’s national options and derogations.

Rather than requiring privacy professionals to review each national implementation statute independently, the Tracker provided a structured point of comparison across jurisdictions.

The original IAPP launch announcement stated that the resource had been created with contributions from 21 professionals across 16 EU countries.

Contributing the Cyprus chapter

Maria Raphael was selected to contribute the Cyprus chapter to the Tracker.

The contribution required analysis of how Cyprus had implemented the GDPR in areas where the Regulation allowed national legislative choices.

That work involved mapping the relevant provisions of Cyprus law against the corresponding GDPR derogations and presenting the national position in a format capable of comparison with other Member States.

The contribution formed part of a wider collaborative exercise intended to make Member State implementation more accessible to privacy professionals working across the European Union.

European harmonisation still requires national-law awareness

The Tracker reflected a broader feature of European data-protection compliance that remains important.

The GDPR is a European Regulation, but organisations cannot always assume that the legal position is identical in every Member State.

National rules can remain relevant where the GDPR expressly allows domestic implementation choices.

For cross-border organisations, this means that a European privacy programme may need to account for:

  • common GDPR requirements;
  • national derogations;
  • domestic supervisory practice;
  • and sector-specific national legislation.

The Cyprus contribution to the IAPP project therefore formed part of a wider comparative-law exercise concerning how a harmonised European framework operates through different national legal systems.