Pandora AI · 5 AI employees · Free AI Profit Scan in 60 sec
LEADSBOT · COMPLIANCE

What you may lawfully do with Greek B2B data.

Greece's commercial registry publishes company email addresses through an open, openly-licensed government API. Greek law then makes it unlawful to send marketing to those addresses. Both things are true, and the gap between them is where most B2B prospecting advice goes wrong.

5 min readPandoraBot

Most English-language guidance on EU B2B prospecting says roughly this: company data is not personal data, GDPR barely applies, and cold email is defensible under legitimate interest. For Greece, that advice is wrong, and following it has produced fines.

The confusion is understandable. It comes from treating the GDPR as the only relevant law. It is not the one that bites here.

What GEMI actually holds

The Γενικό Εμπορικό Μητρώο (GEMI) is Greece's single national commercial register, established by Law 3419/2005 and now governed by Law 4919/2022. Supervision sits with the Ministry of Development; the IT systems are operated by the Union of Hellenic Chambers (ΚΕΕΕ), and the front-line registry offices are the local chambers of commerce.

The Union of Hellenic Chambers reported more than 930,000 active commercial businesses on the register in May 2024. Registration is compulsory for anyone carrying on commercial activity, and chamber membership follows automatically from it.

Public search is free at publicity.businessportal.gr. There is also an official open-data API, published on data.gov.gr as a High-Value Dataset under the EU Open Data Directive and licensed ODC-BY-1.0 — attribution required, no additional commercial restriction. It returns, per company:

  • GEMI number, ΑΦΜ (VAT number), Greek and English names and trading titles
  • Full registered address, municipality, prefecture, postcode
  • Company website and company email address
  • ΚΑΔ activity codes, legal form, corporate purpose, capital
  • Incorporation date, current status, last status change
  • Directors and shareholders, with roles, dates and shareholding percentages
  • Annual financial statements, filed within nine months of year-end

Two practical caveats before anyone plans a pipeline around it. The API requires an approved key — the documentation key returns Unauthorized — is rate-limited per IP, caps results at 200 per request, and offers no bulk export. And records carrying autoRegistered: false belong to companies that never completed self-registration; the specification itself warns that the returned data is incomplete.

GEMI holds no telephone numbers. Chamber directories are a separate source and often do carry them — the Athens Chamber's public directory is searchable by KAD and by category, including exporters and producers, a segmentation GEMI does not offer.

ΚΑΔ 2025 replaced ΚΑΔ 2008 this year

Activity codes are the practical segmentation key, and they changed recently enough that stored lists may be stale. ΚΑΔ 2025, set by AADE decision Α.1003/12.01.2026, took effect on 1 March 2026 and repealed the 2008 classification. It aligns to NACE Rev. 2.1.

The code is eight digits and hierarchical: two digits for division, three for group, four for class — the EU-harmonised NACE level — five and six for CPA categories, and eight for a Greek national extension. Parsing the official AADE publication gives roughly 9,600 unique codes, of which about half sit at the eight-digit national level.

That last level is unusually granular. Hairdressing, for instance, splits by the number of technicians employed — a size proxy sitting inside the activity code itself.

Then the law, which is the part that matters

GDPR Recital 14 does exclude legal persons: the name, form and contact details of a company are not personal data. That much of the conventional advice is correct.

But direct marketing by electronic means is governed by the ePrivacy Directive, which is lex specialis and applies independently. Article 13(5) let each member state decide how far to extend its protections to non-natural persons. Most member states created a B2B exemption. Greece did the opposite.

Article 11 of Law 3471/2006 permits unsolicited electronic marketing — naming email explicitly — only where the subscriber has given prior express consent. And it closes with the sentence that decides the question:

“Οι ανωτέρω ρυθμίσεις ισχύουν και για τους συνδρομητές που είναι νομικά πρόσωπα.”

The above provisions apply also to subscribers that are legal persons.

The case that settled it

In decision 52/2024 (18 December 2024), the Hellenic Data Protection Authority fined a digital marketing agency €10,000 for a single unsolicited email pitching web design services. The recipient had no prior relationship; the agency said the address came from “market research”.

The reasoning is what makes the decision important. The Authority found expressly that the address was a company's central contact inbox, did not correspond to a natural person, and was therefore not personal data at all. GDPR did not apply. It fined anyway, purely under Article 11.

That is precisely the scenario a GEMI-derived email list produces: a generic company inbox, lawfully obtained from a public register, emailed once. Ten thousand euro.

The Authority has also closed the standard workaround. Its published guidance states that sending an invitation email in order to obtain consent is itself prohibited. You may not email someone to ask whether you may email them.

Nor can the liability be outsourced. The Authority's position is that a controller remains accountable for marketing carried out through a third-party list vendor, and must be able to prove the list was lawfully built.

What remains lawful

This is the useful part, and it is more than people expect.

ChannelLawful without consent?Conditions
Postal mailYesThe Authority names GEMI explicitly as a legitimate source. Name, address and profession only; easy objection route; a GDPR Art. 14 notice identifying GEMI as the source.
Phone call, humanYesScreen against every provider's Article 11 opt-out register, current to within 30 days, plus your own objection list. Identify yourself, do not mask caller ID, keep call logs.
Email to existing customerYesContact details obtained during a sale, for similar products, with a free and easy opt-out in every message.
Cold email or SMSNoPrior express consent required. Applies to legal persons.
Email asking for consentNoExpressly prohibited by the Authority.
Automated calls, faxNoPrior express consent required.

Sources: Law 3471/2006 Art. 11; ePrivacy Directive 2002/58/EC Art. 13; Hellenic DPA published guidance on product promotion and decision 52/2024. This is a summary for orientation, not legal advice.

Read that table the right way round. It does not say a GEMI-derived list is useless. It says the list is for qualification and for the phone and the post, not for a bulk email sequence. Which, for a considered B2B sale, is arguably the better use anyway.

Two traps worth knowing

The AADE VAT lookup notifies the company you looked up. The tax authority's registry service returns basic details by ΑΦΜ, but its own documentation states that the VAT number being searched receives notification of who searched it. Whatever else that is, it is not quiet prospecting.

VIES does return Greek company names. Several vendor blogs claim Greece withholds name and address from the EU VAT validation system for privacy reasons. We tested it: Greece returns both. If you have built enrichment logic around that assumption, check it.

What this means if you are building a list

The compliant shape of a Greek B2B motion is: build the list from public registry data, segment it hard on KAD and region, qualify it, then reach out by telephone with opt-out screening or by post — reserving email for companies that have opted in or are already customers.

LeadsBot builds lists from public Greek business data with activity, region and size filtering, and carries opt-out handling and audit logging. Those controls exist because of everything above: the constraint is not on holding the data, it is on which channel you use to act on it.

Frequently asked

Is B2B cold email really illegal in Greece?

For unsolicited marketing email, yes. Article 11 of Law 3471/2006 requires prior express consent and states that the rule applies to subscribers that are legal persons. The Hellenic DPA fined a company €10,000 in decision 52/2024 for one such email to a generic company inbox. This is stricter than most EU member states.

Does legitimate interest under GDPR Article 6(1)(f) help?

Not for this. ePrivacy operates independently of the GDPR and imposes its own consent requirement. Decision 52/2024 makes the point cleanly: the Authority found the address was not personal data, so GDPR did not apply, and fined under ePrivacy anyway.

Can I buy a list from a vendor and rely on their compliance?

You remain accountable. The Authority's position is that a controller is answerable for marketing sent to a purchased list and must be able to demonstrate that the list was lawfully compiled. Contractual assurances do not transfer the liability.

Is GEMI data free?

Public search is free, and the open-data API is free but requires an approved key. Certificates and official copies cost €5, or €10 for a historic certificate. The annual GEMI fee is paid by registered companies, not by people reading the register.

Are transactional messages affected?

No. An appointment reminder or an order confirmation sent to an existing customer about their own booking is a service message, not direct marketing, and Article 11 does not apply to it. The restriction is on acquisition marketing.

What about LinkedIn or social outreach?

We could not establish a clear published position from the Greek DPA on social platform messaging, so we are not going to guess. Take advice if that channel is central to your plan.

This article is general information about Greek and EU law as at 20 August 2026, not legal advice, and does not create a lawyer-client relationship. Enforcement practice evolves and individual circumstances differ — take qualified Greek legal advice before designing an outreach programme. Statutory quotations are from published codified texts; where different official renderings of Article 11 disagree on paragraph numbering we have cited the Article rather than the paragraph. Last updated 20 August 2026.