Data Protection Compliance for Businesses in Monaco
Data protection compliance in Monaco under Law No. 1.565 — legal bases, individual rights, DPIAs, breach notification, transfers and APDP penalties

Key facts
- Primary Regulation
- Law No. 1.565 of 3 December 2024 (Monegasque law, GDPR-aligned)
- Enforcement Authority
- APDP (Autorité de Protection des Données Personnelles), successor to the CCIN
- Applicability
- Controllers and processors established in Monaco; EU businesses may also fall under GDPR
- Penalties
- Up to €10 million or 4% of worldwide annual turnover (whichever higher)
Overview
Data protection in Monaco is governed by Law No. 1.565 of 3 December 2024, which replaced the 1993 law on "informations nominatives" and is enforced by the APDP (Autorité de Protection des Données Personnelles), successor to the CCIN. Sovereign Ordinance No. 11.327 of 10 July 2025 sets out the implementing rules.
The reform replaced the old prior-declaration regime with an accountability model: you no longer file paperwork before processing, you document your compliance and must be able to demonstrate it on request. This guide covers what that means in practice for a business.
For the legal framework itself — the APDP's remit, contact details, transitional deadlines and the relationship with EU law — see Data privacy in Monaco: the APDP and Law No. 1.565.
Legal Framework & Principles
Monaco law, GDPR alignment
What applies where:
- Monaco is not an EU or EEA member state, so the GDPR does not apply of its own force
- Controllers and processors established in Monaco are governed by Law No. 1.565
- The GDPR can apply in addition, through its extraterritorial reach, where a business offers goods or services to people in the EU or monitors their behaviour
- Most Monaco firms with EU clients therefore run one compliance programme designed to satisfy both
Why the two texts look alike:
- Law No. 1.565 was deliberately drafted along the lines of the EU data protection package
- Obligations, legal bases and individual rights follow a near-identical structure
- Monaco is seeking an adequacy decision from the European Commission; none has been issued to date
- Vocabulary differs in places: the Monegasque authority is the APDP, not a national DPA under the GDPR
Core Principles
Lawfulness, Fairness, Transparency:
- Data processing must be lawful (permitted basis exists)
- Fair means no deception or harmful manipulation
- Transparency requires clear privacy notices
Purpose Limitation:
- Data collected for specific purpose
- Cannot be used for unrelated purposes later (without new consent/basis)
- Repurposing requires impact assessment
Data Minimization:
- Only collect data actually needed
- Don't over-collect "just in case"
- Regular audit and deletion of excess data
Accuracy:
- Data must be accurate and current
- Individuals have right to correct inaccurate data
- Systems to keep data updated
Storage Limitation:
- Retain data only as long as needed
- Delete when purpose fulfilled
- Retention schedule documented
Integrity & Confidentiality:
- Security measures to prevent unauthorized access
- Encryption, access controls, monitoring
- Disaster recovery and business continuity
Accountability:
- Document compliance decisions
- Privacy impact assessments (for high-risk processing)
- Data Processing Agreements with processors
- Breach documentation and reporting
Legal Basis for Processing
Six Lawful Bases (Choose One):
1. Consent
Definition: Individual freely gives specific, informed permission
Requirements:
- Freely given (no coercion or pressure)
- Specific (for particular purpose)
- Informed (knows what they're consenting to)
- Unambiguous (clear affirmative action, not pre-ticked boxes)
- Documented (proof of consent)
Practical:
- Checkbox (must be opt-in, not pre-checked)
- Separate consent for each purpose (not bundled)
- Easy withdrawal mechanism
- Suitable for: Marketing, optional data collection, cookies
Drawback: Can be withdrawn anytime (less stable basis than others)
2. Contract
Definition: Processing necessary to perform/negotiate contract with individual
Examples:
- Shipping address for order fulfillment
- Payment information for transaction
- Contact info for service delivery
Requirement: Data must be necessary for contract (not excessive)
Advantage: Stable basis; individual can't easily withdraw
3. Legal Obligation
Definition: Processing required by law or regulation
Examples:
- Tax reporting (government requires data)
- AML/KYC (regulatory compliance)
- Accounting records (company law)
- Employment records (labor law)
Advantage: Clearly justified; no consent/negotiation needed
4. Vital Interests
Definition: Protect individual's life or health
Examples:
- Medical emergency processing (hospital)
- Missing person searches
- Health threat alerts
Restriction: Very limited use; usually no consent alternative available
5. Public Task
Definition: Processing necessary for public interest or official authority function
Examples:
- Government services (not typical for private business)
- Electoral processes
- Public health initiatives
Rarely used by private businesses
6. Legitimate Interests
Definition: Business has valid interest that outweighs individual's privacy interests
Examples:
- Fraud prevention (security interest)
- Direct marketing (business development interest)
- Analytics and optimization (business improvement interest)
- Vendor management (relationship interest)
Requirement: Legitimate Interest Assessment (LIA)
- Purpose (legitimate?)
- Necessity (necessary to achieve purpose?)
- Proportionality (outweigh individual privacy interests?)
Balancing Test: If individual interest outweighs, cannot use this basis
Suitability: Business operations, fraud prevention, analytics
Individual Rights
Right to Access (Data Subject Access Request)
Right: Individual can request copy of their personal data
Requirement:
- Organization must provide within 30 days
- Free of charge (normally)
- In commonly used format
- Includes: What data, source, recipients, retention period
Limitation:
- Can be denied if excessive/repeated requests
- Can refuse if disclosure harms others' privacy
- Business secrets not required to be disclosed (sometimes)
Practical:
- Have process to handle requests
- Document request and response
- Train staff to recognize requests
Right to Rectification
Right: Correct inaccurate data
Example:
- Name misspelled in system
- Outdated address
- Wrong date of birth
Requirement:
- Correct within reasonable time
- Notify third parties who received inaccurate data (sometimes)
Right to Erasure ("Right to be Forgotten")
Right: Request deletion of data
Conditions (Must be Met):
- Data no longer necessary for purpose
- Consent withdrawn (if that was basis)
- Object to processing and no legitimate interest
- Processing unlawful
- Legal obligation to erase
- Data collected from children
Exceptions (Cannot Erase):
- Legal obligation to keep (tax records, etc.)
- Legitimate interest outweighs
- Vital interest at stake
Practical: Can implement "anonymization" (removes identification) vs. deletion
Right to Restrict Processing
Right: Stop processing but keep data (middle ground)
When Available:
- Accuracy disputed (stop processing while verifying)
- Processing unlawful (restrict instead of erase)
- Data no longer needed but needed for legal claim
- Right to object pending decision
Right to Data Portability
Right: Receive data in structured, portable format; transfer to another service
Conditions:
- Data you provided
- Processing based on consent or contract
- Processed by automated means
Format: Usually CSV or other machine-readable format
Practical Impact: Supports switching service providers (e.g., email, social media)
Right to Object
Right: Stop processing for direct marketing, legitimate interests, scientific research
Types:
- Marketing Objection:
- "Don't send me promotional emails"
- Must be honored immediately
- No justification required
- Legitimate Interest Objection:
- "Stop processing my data for analytics"
- Organization must stop unless legitimate interest outweighs
- May lose some functionality
Practical: Clear unsubscribe mechanism; honor objections promptly
Right Against Automated Decision-Making
Right: Protection from decisions based entirely on automated processing (no human review)
Examples of Prohibited:
- Loan denial based entirely on algorithm (no review)
- Job candidate rejection by AI alone
- Insurance denial by algorithm
Exception: Automated processing is OK if:
- Requested (individual asks for it)
- Necessary for contract
- Authorized by law
With Right: Meaningful human review required
Data Protection Obligations
Privacy Notice (Transparency)
When Required: When data collected (directly or indirectly)
Required Disclosure:
- Identity and contact of controller (your organization)
- Purpose of processing
- Legal basis
- Recipients of data
- Retention period
- Data subject rights (access, erasure, etc.)
- Complaint procedure (APDP contact)
- If applicable: Automated decision-making, profiling, data source
Format: Clear, accessible language; can be in-app or website
Timing:
- At collection (if direct)
- Within 1 month (if collected indirectly)
Data Protection Impact Assessments (DPIA)
When Required:
- High-risk processing (extensive data, vulnerable groups, profiling, surveillance, etc.)
- Likely to result in high risk to individuals
- Automated decision-making with legal effects
Content:
- Description of processing and purposes
- Risk assessment (what could go wrong?)
- Mitigation measures
- Residual risk evaluation
- Third-party consultation (if needed)
Timeline: Conduct before processing begins
Outcome:
- Document findings
- If high risk remains: Consult APDP before proceeding
- Adapt processes if necessary
Data Processing Agreements (DPA)
When Required: When using data processor (vendor, cloud provider, payroll processor)
Purpose:
- Define roles (controller vs. processor)
- Specify data, processing instructions
- Require processor implement security measures
- Allow data subject rights requests through controller
- Allow audits and inspections
Key Clauses:
- Processor location and sub-processor rules
- Security and confidentiality obligations
- Assistance with individual rights requests
- Data deletion/return at contract end
- Liability and indemnification
Requirement: In writing (no verbal agreement)
Cost: Usually included in the vendor contract; some processors charge for a negotiated DPA
Data Breach Notification
Mandatory Notification Timeline:
- To APDP: Within 72 hours of discovery (unless low risk)
- To affected individuals: Without undue delay if high risk
- To processors and third parties: If requested
What to Include:
- Type of breach (unauthorized access, loss, encryption failure)
- Data categories affected
- Approximate number of individuals
- Likely consequences
- Measures taken/proposed
Low Risk Exception:
- If data was encrypted and attacker doesn't have key
- No notification required (but should still document)
Investigation:
- Document what happened
- When discovered
- How many records affected
- Response measures taken
Documentation: Keep records for APDP audit
Insurance: Data breach liability insurance recommended (€5,000–€50,000 annual coverage typical)
International Data Transfers
Transfers out of Monaco
General rule: Personal data may leave Monaco only where the destination ensures an adequate level of protection, or where appropriate safeguards are in place.
Two directions to keep straight:
- Monaco → abroad is governed by Law No. 1.565 and assessed by the APDP
- EU → Monaco is governed by EU law. The European Commission has not issued an adequacy decision for Monaco, so an EU counterparty may need safeguards to send you data — expect the question in supplier due diligence
Mechanisms:
1. Adequate level of protection
Where the destination country's regime is recognised as adequate, the transfer can proceed without additional instruments. Transfers to EU member states are routine in practice.
2. Standard Contractual Clauses (SCCs)
Model contract terms binding the recipient to equivalent protections. This is the workhorse mechanism for transfers to countries without an adequacy finding, and the EU's own SCCs are widely used as the template in Monaco practice. Assess each transfer on its facts — there is no blanket approval.
3. Binding Corporate Rules (BCRs)
Internal rules governing transfers within a multinational group, submitted to the authority for approval. Suitable for groups with regular intra-group flows; the approval process is long.
4. Individual Consent
Risky: Consent not reliable mechanism (individual may not understand risks; can be withdrawn)
Limited Use: Only for specific, voluntary transfers
Practical Implementation
Data Inventory & Mapping
Steps:
- List all data you collect (names, emails, addresses, IPs, cookies, etc.)
- Document purpose for each data type
- Identify legal basis
- Note retention period
- List processors/recipients
- Assess risks (DPIA if needed)
Outcome:
- Privacy notice creation
- DPA review with vendors
- Deletion schedule implementation
Privacy by Design
Principle: Build privacy into system design from start
Practical Measures:
- Minimize data collected (only what's necessary)
- Default to "off" for optional data collection
- Encryption of sensitive data
- Access controls (employees see only necessary data)
- Regular deletion of archived data
- Privacy settings explanations for users
Consent Management
If Using Consent Basis:
- Cookie management platform (CMP) for website cookies
- Checkboxes for email/marketing opt-ins
- Clear, separate (not bundled) consent options
- Easy withdrawal/unsubscribe
- Document proof of consent
- Honor requests promptly
Compliance: Use a consent management platform that maps to Law No. 1.565 (GDPR-grade tooling is generally sufficient); test it regularly
Privacy Training
Employee Training:
- What data we process
- Why we need it
- How to handle requests
- What constitutes breach
- Who to contact (DPO, privacy officer)
Frequency: Annual minimum; new hires during onboarding
Data Deletion Procedures
Schedule:
- Retention period per data type
- Automatic deletion triggers
- Secure deletion methods (overwrite, shred physical)
- Exception procedures (legal hold, disputes)
Documentation:
- Deletion logs (what, when, why)
- Proof of deletion (audit trails)
- Exception tracking
Violations & Penalties
Administrative fines
Law No. 1.565 gave the APDP a fining power the CCIN never had: administrative fines of up to €10 million, or 4% of worldwide annual turnover, whichever is higher. The ceiling is the statutory maximum, not a typical outcome — the amount actually imposed is set case by case.
Criminal penalties also remain available under Monegasque law for the most serious violations, including unlawful processing and failure to comply with the authority's orders.
Context Matters:
- Severity of violation
- Duration of processing
- Number of individuals affected
- Prior violations
- Cooperation with APDP
- Extent of damage
Other Remedies
Individual Rights:
- Right to compensation (sue for damages)
- Injunctive relief (court stops processing)
- Public apology (if damage to reputation)
Administrative Actions:
- APDP warnings/reprimands
- Corrective orders
- Conditional processing restrictions
- Certification requirements
Professional Support
Data Protection Officer (DPO)
When required — appointment of a délégué à la protection des données is mandatory for public authorities, and for organisations whose core activities involve large-scale regular monitoring of individuals or large-scale processing of sensitive data. The DPO's contact details are notified to the APDP.
For everyone else: advisable. Small Monaco businesses commonly designate an internal privacy contact rather than a formal DPO, and buy in expertise for specific projects.
Responsibilities:
- Ensure and monitor compliance
- Conduct staff training
- Handle individual rights requests
- Act as the contact point for the APDP
- Maintain the record of processing activities and related documentation
Where to get help
Start with the APDP's own fiches pratiques at apdp.mc — they are free, Monaco-specific and cover the questions most businesses actually have. Monaco's law firms and the larger accountancy practices all publish on Law No. 1.565 and advise on it; fees vary widely by scope, so ask for a written estimate against a defined deliverable (record of processing, DPIA, policy set) rather than an open-ended retainer.
Related Guides
- Data privacy in Monaco: the APDP and Law No. 1.565 — the legal framework, authority and transitional deadlines
- Extended Monaco — e-government data handling
- Registering a business in Monaco — the wider compliance picture
Information current as of August 2026. Monaco data protection law was substantially rewritten by Law No. 1.565 of 3 December 2024; consult a qualified data protection professional before implementing processing systems.
Frequently asked questions
The information provided is for general guidance only. For official procedures, always consult the official sources.
Related pages
See all guidesAccountants and Fiduciaries in Monaco: What They Help With
Guide to the role of accountants and fiduciaries, when to engage them, and how they support companies in Monaco.
Accounting and Auditing Firms in Monaco
Guide to accounting services, auditing firms, and financial reporting services in Monaco for businesses and individuals.
Finding an accountant in Monaco: regulatory and professional guide
Guide to choosing an accountant in Monaco: regulatory requirements, responsibilities, VAT handling, social charges, annual accounts, and how to select the right firm.
Accounting and Bookkeeping Obligations in Monaco
Reference for accounting and bookkeeping requirements for businesses operating in Monaco: records, auditors, annual accounts.
