
AthensGov platform, digital assistant and mobile application of the Municipality of Athens
Last updated: 14 August 2026
This Privacy Policy is provided in order to inform data subjects in accordance with Articles 12, 13 and 14 of the General Data Protection Regulation (EU) 2016/679 (the “GDPR”) and Greek Law 4624/2019. It supplements, and does not replace, the Personal Data Protection Policy (GDPR) of the Municipality of Athens, which is available on the Municipality’s official website.
The data controller is the Municipality of Athens, a first-tier local government authority and legal entity governed by public law, having its seat at 22 Liosion Street, Athens, as lawfully represented (Article 4(7) GDPR). The Municipality of Athens determines the purposes and means of the processing described in this Policy.
Municipality employees, under any form of employment relationship, who process personal data act as “persons acting under the authority of the controller” (Article 29 GDPR). Third-party natural or legal persons processing personal data on behalf of the Municipality act as “processors” (Article 4(8) GDPR), under a contract pursuant to Article 28 GDPR.
The Municipality of Athens has appointed a Data Protection Officer (Article 37 GDPR), Mr Nikolaos A. Karanikolas. Contact details: tel. +30 210 5277432, e-mail: dpo@athens.gr. You may contact the DPO on any matter relating to the processing of your personal data and the exercise of your rights.
This Policy covers digital service channels of the Municipality of Athens and, in particular:
Any reference in this Policy to the “Services” means the above channels collectively.
The Municipality of Athens collects and processes personal data exclusively in order to exercise its statutory competences and comply with its legal obligations, including the obligation of every public authority to maintain an e-government website (Law 3979/2011, Government Gazette A΄ 138). Specifically:
In line with the Municipality’s GDPR Policy, the Municipality of Athens does not rely on “legitimate interests” (final subparagraph of Article 6(1) GDPR) as a legal basis for processing.
For services requiring authentication, identification is carried out via TAXISnet credentials (Interoperability Centre / gov.gr). The Municipality receives only the identification data strictly necessary for access control.
Contact details and the content you submit when registering a request, complaint or issue report (e.g. description, incident location, photographs), as well as electronic appointment booking data.
The content of your questions and conversations with the digital assistant, as well as any ratings you submit regarding its answers.
IP address, browser type and version (user agent), device and operating system type, log files and security-related data.
When you leave a comment, the data shown in the comment form, your IP address and your user agent are collected in order to help detect spam. If you upload images, you should avoid files containing embedded location data (EXIF GPS), as such data may be extracted by visitors.
Aggregated and, to the extent possible, anonymised traffic and usage data, used to improve the Services.
No submission of personal data is required for the operation of the digital assistant. Please do not include personal information, or special categories of data (Article 9 GDPR), in the questions you address to the assistant.
The AthensGov platform hosts a digital assistant that uses Artificial Intelligence and Natural Language Processing technologies, trained on open data of the Municipality and on relevant public sources. The assistant is of a purely informative nature and its answers do not constitute the issuance of an administrative act, nor an official opinion of any competent body.
The identification data obtained when logging in via TAXISnet are used exclusively for access control, are not transmitted to the Artificial Intelligence system and are not stored in connection with the content of the conversation.
The digital assistant is hosted on the Public Sector Government Cloud (G-Cloud) infrastructure. No data is transferred outside the hosting infrastructure.
No automated decision-making within the meaning of Article 22 GDPR takes place, nor is any user profiling carried out.
The Municipality of Athens provides the official “AthensGov” mobile application, available for Android devices through the Google Play Store and for iOS devices through the Apple App Store. The application is an alternative access channel to the same digital services offered through the platform https://athensgov.cityofathens.gr/ and is governed by exactly the same Terms of Use and by this Privacy Policy, with no differentiation as to purposes, legal bases, retention periods or your rights. Authentication in the application is likewise carried out via TAXISnet and the data are held on the same Government Cloud (G-Cloud) infrastructure.
In addition, when using the mobile application you may be asked to grant permissions to access device features, such as the camera and media library (to attach photographs to a request), location (to identify the location of a request or display nearby services) and push notifications (to keep you informed of the progress of your requests). These permissions are optional and granted with your consent (Article 6(1)(a) GDPR), may be withdrawn at any time through your device settings, and withholding them does not prevent you from using the core functions of the application. Please note that Google LLC and Apple Inc., as operators of the respective app stores, act as independent data controllers in respect of the data they collect when the application is downloaded and updated (e.g. account details, device identifiers, store analytics), in accordance with their own privacy policies, for which the Municipality of Athens bears no responsibility.
We use cookies that are technically necessary for the operation and security of the Services, as well as optional cookies which are placed only with your consent. Indicatively:
You may withdraw your consent or manage cookies at any time through your browser settings or the consent tool available in the Services.
Certain pages may include embedded third-party content (e.g. videos, maps, posts). Such content behaves in exactly the same way as if you had visited the third-party website, which may collect data about you, use cookies and monitor your interaction with the embedded content, in accordance with its own privacy policy.
Access to your data is limited to authorised staff of the competent services of the Municipality of Athens, to the extent necessary to handle your request, and to processors engaged by the Municipality (e.g. providers of system development, hosting and technical support), who are bound by a contract under Article 28 GDPR and process data solely on the Municipality’s documented instructions. Data are disclosed to public authorities only where required by law.
Data are held on infrastructure located within the European Union and, in particular, on Public Sector Government Cloud (G-Cloud) infrastructure. Should a specific service require a transfer to a third country, such transfer will take place only on the basis of an adequacy decision of the European Commission or appropriate safeguards under Articles 46 et seq. GDPR, and you will be informed accordingly.
Data are retained for as long as necessary to fulfil the purposes for which they are collected and, thereafter, for as long as required by public sector records-management legislation.
In particular, conversations with the digital assistant are retained in the user’s account until the user chooses to delete them. After deletion by the user, the conversations are stored in pseudonymised form for a period of one (1) month, exclusively for the training and optimisation of the assistant.
Comments and their metadata may be retained for as long as the relevant content remains published, so that follow-up comments by the same user can be recognised and approved automatically.
The Municipality of Athens implements appropriate technical and organisational measures pursuant to Article 32 GDPR, taking into account the state of the art, the cost of implementation and the risks of processing, including: pseudonymisation and encryption; the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems; the ability to restore access to data in a timely manner in the event of an incident; and processes for regularly testing and evaluating the effectiveness of those measures.
Measures are also taken to ensure that any person acting under the authority of the Municipality who has access to personal data processes them only on the instructions of the controller.
In the event of a personal data breach, the Municipality notifies the Hellenic Data Protection Authority without undue delay and, where feasible, within seventy-two (72) hours of becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons (Article 33 GDPR). Where the breach is likely to result in a high risk to your rights and freedoms, you will also be informed without undue delay (Article 34 GDPR).
As a data subject you have the following rights:
To exercise your rights, please contact the Data Protection Officer of the Municipality of Athens (dpo@athens.gr). The Municipality will respond within one (1) month of receipt of the request. That period may be extended by a further two (2) months where necessary, taking into account the complexity and number of requests, and you will be informed of any such extension within the first month. Where you submit your request by electronic means, the information will likewise be provided by electronic means, unless you request otherwise.
If you consider that the processing of your personal data infringes the GDPR, you have the right to lodge a complaint with the Hellenic Data Protection Authority (1-3 Kifisias Avenue, 115 23 Athens, tel. +30 210 6475600, www.dpa.gr).
The Services are addressed to adults. Services requiring TAXISnet authentication are accessible only to persons holding the relevant credentials.
This Policy may be updated, in particular as a result of changes in legislation, in the services provided or in the technologies used. The version in force at any given time is published within the Services, indicating the date of the latest update.
This Policy supplements and does not replace the Personal Data Protection Policy (GDPR) of the Municipality of Athens and the General Terms of Use of the official website, which also apply to the Services to the extent compatible with their nature and operation. In the event of a conflict, this Policy prevails as the more specific one. This Policy is governed by Greek law.