Data Privacy in Monaco: the APDP and Law No. 1.565
Guide to data privacy in Monaco — Law No. 1.565 of 3 December 2024, the APDP supervisory authority that replaced the CCIN, data subject rights, business obligations, breach notification and penalties.

Overview
Monaco rewrote its data protection law from scratch in 2024. Law No. 1.565 of 3 December 2024 on the protection of personal data, published in the Journal de Monaco on 13 December 2024, replaced Law No. 1.165 of 23 December 1993 — the text that had governed "informations nominatives" in the Principality for three decades. Sovereign Ordinance No. 11.327 of 10 July 2025 sets out the implementing rules.
Two things changed that matter to anyone handling personal data in Monaco:
- The supervisory authority is now the APDP (Autorité de Protection des Données Personnelles), which took over from the CCIN with a broader mandate and real fining power.
- The old prior declaration and authorisation system has largely been dismantled in favour of an accountability model — you no longer file a form before processing, you document your own compliance and stand ready to justify it.
Monaco is neither an EU nor an EEA member state, so the GDPR does not apply of its own force in the Principality. Law No. 1.565 is nevertheless closely modelled on it, and Monaco is explicitly seeking an adequacy decision from the European Commission.
The APDP
The APDP is Monaco's independent data protection authority, composed of eight members with recognised expertise in the field. Its responsibilities include:
- Investigating complaints from individuals
- Conducting audits and on-site inspections of processing activities
- Receiving personal data breach notifications
- Issuing guidance, recommendations, formal notices and sanctions
- Advising the Government on data protection matters
Contact: Le Concorde, 11 rue du Gabian, 98000 Monaco — tel. +377 97 70 22 44 — apdp.mc, which publishes practical fact sheets (fiches pratiques) by theme.
Note that ccin.mc and older references to the CCIN are now historical. If a Monaco privacy policy or supplier contract still names the CCIN, it predates the reform and is due for review.
Law No. 1.565 — key principles
The law runs to 118 articles across 10 chapters and states principles that will be familiar to anyone who has worked with the GDPR:
Lawfulness and purpose limitation
Personal data must be processed lawfully, fairly and for specified, explicit and legitimate purposes. Data must not be further processed in a manner incompatible with those purposes.
Data minimisation
Only data that is adequate, relevant and limited to what is necessary for the purpose may be collected and processed.
Accuracy
Controllers must take reasonable steps to keep personal data accurate and up to date. Inaccurate data must be corrected or erased.
Storage limitation
Personal data must not be kept longer than necessary for the purposes for which it was collected. Sector-specific retention rules may apply — banking and employment records in particular.
Integrity and confidentiality
Controllers must implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss or destruction.
Accountability
This is the structural change. Rather than seeking the authority's approval in advance, controllers must be able to demonstrate compliance: records of processing activities, documented legal bases, retention schedules, data protection impact assessments for high-risk processing, and written agreements with processors.
Data subject rights
Individuals whose data is processed in Monaco have the right to:
- Be informed about the processing — purposes, legal basis, recipients, retention period and how to complain
- Access their personal data and obtain a copy
- Rectification of inaccurate or incomplete data
- Erasure of data in defined circumstances
- Restriction of processing while a dispute is resolved
- Data portability for data they provided, where processing rests on consent or a contract
- Object to processing, including to direct marketing
- Not be subject to a decision based solely on automated processing that produces legal effects
Rights are exercised with the controller directly. If the response is unsatisfactory or absent, the individual can complain to the APDP.
Business obligations
No more routine prior formalities
Under Law No. 1.165, almost every processing operation had to be declared to the CCIN before it began, with prior authorisation for sensitive categories. Law No. 1.565 removes most of that. What replaces it is internal documentation and, for genuinely high-risk processing, a data protection impact assessment carried out before processing starts — with prior consultation of the APDP if a high residual risk remains.
Transitional deadlines
Organisations processing data before the reform were given time to adapt: broadly one year to bring existing processing into line with the new lawfulness requirements, and up to three years for impact assessments and risk reassessment, including certain processing operations run by administrative and judicial authorities. Those windows are now largely closed or closing, so an unreviewed pre-2025 compliance file is a live exposure.
Data protection officer
Appointment of a délégué à la protection des données (DPO) is mandatory in defined cases — notably public authorities and organisations whose core activities involve large-scale regular monitoring or large-scale processing of sensitive data — and advisable well beyond them. The DPO's contact details are notified to the APDP.
Transfers outside Monaco
Personal data may be transferred abroad where the destination ensures an adequate level of protection, or under appropriate safeguards such as standard contractual clauses or binding corporate rules. Transfers to EU member states are routine in practice; transfers to jurisdictions with no adequacy finding require documented safeguards.
Breach notification
Controllers must notify the APDP of any personal data breach likely to result in a risk to individuals' rights and freedoms. The reference deadline is 72 hours from becoming aware of the breach; if you notify later, you must be able to demonstrate that you did so at the earliest opportunity. Where the breach poses a high risk, the individuals concerned must also be informed.
Penalties
The APDP can impose administrative fines of up to €10 million or 4% of worldwide annual turnover, whichever is higher — an order of magnitude beyond anything the CCIN could do. It can also issue formal notices, order processing to stop, and impose temporary or permanent processing bans.
Criminal penalties remain available under Monegasque law for serious violations, including unlawful processing and failure to comply with the authority's orders.
Relationship with the GDPR
Monaco is a Council of Europe member state but sits outside the EU and the EEA, so the GDPR does not apply directly. It can still catch a Monaco business through its extraterritorial scope — for instance where the business offers goods or services to people in the EU, or monitors their behaviour. In practice many Monaco firms with EU clients run a single compliance programme designed to satisfy both texts, which the alignment of Law No. 1.565 makes realistic.
The European Commission has not yet issued an adequacy decision for Monaco. Obtaining one is a stated objective of the 2024 reform; until then, EU-to-Monaco transfers may require safeguards under EU law.
Practical steps
- Replace every reference to the CCIN and Law No. 1.165 in your privacy notices, contracts and internal policies.
- Build and maintain a record of processing activities — it is the first thing an inspection will ask for.
- Document a legal basis for each processing purpose, and a retention period for each data category.
- Run a data protection impact assessment before launching high-risk processing, not after.
- Put a breach procedure in writing so the 72-hour clock is workable rather than theoretical.
- Consult the APDP's fiches pratiques at apdp.mc for sector guidance before commissioning outside advice.
Related guides
- Data protection compliance for businesses — obligations, legal bases and implementation in practice
- Extended Monaco and e-government — how the Principality's digital services handle your data
- Registering a business in Monaco — the wider compliance picture for new companies
The information provided is for general guidance only. For official procedures, always consult the official sources.
Related pages
See all guidesBusiness Disputes in Monaco: Litigation, Arbitration and Enforcement
Guide to resolving business disputes in Monaco — the Tribunal de Première Instance commercial division, arbitration at the Centre de Médiation, international enforcement, timelines and costs.
Consumer Rights in Monaco: Protections, Disputes and Remedies
Guide to consumer protection in Monaco — the Direction du Commerce et de l'Industrie, warranty obligations, return policies, dispute resolution and mediation options.
Employment Law in Monaco: Contracts, Protections and Labour Courts
Comprehensive guide to Monaco's employment law — the Code du Travail, CDI and CDD contracts, termination procedures, the Tribunal du Travail, employee protections, and collective agreements.
Inheritance Law in Monaco: Forced Heirship, Tax Rates and Succession Rules
Guide to Monaco's inheritance law — forced heirship (réserve héréditaire), 0% inheritance tax for direct heirs, testamentary freedom limits, notary role, and cross-border succession considerations.
