Law / Monaco

Loi sur la Protection des Données Personnelles, autorite de controle et sanctions

Loi n. 1.565 du 3 decembre 2024, arts. 37-57, 102-106 (supervisory authority, sanctions and right to reparation)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 13 December 2024.

An enforcement supervision rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Comply with the Authority's formal notice to bring processing into conformity or to satisfy a data subject's rights request, within the period it sets, since noncompliance can draw a daily penalty of up to 10,000 euros that does not apply to the State or the Commune.
  • Cooperate with the Authority's checks and investigations, giving its members, agents, and sworn investigators the information, documents, and premises access they need, since only national security secrecy, attorney client privilege, journalistic source secrecy, and individual medical secrecy channelled through a designated physician can be raised against them.
  • Expect a person to be able to complain to the Authority about your processing and separately bring a court claim before the Tribunal de Premiere Instance, and expect a nonprofit body active in personal data protection to be able to do the same on that person's behalf.
  • Pay a person material or moral damages for the harm a violation of this law caused them, whether you are the controller or the processor, jointly and severally with any other controller or processor that took part in the same processing.
  • Expect an administrative fine of up to 5,000,000 euros or 2 percent of worldwide annual turnover, whichever is higher, for the narrower obligations Article 53 lists, rising to up to 10,000,000 euros or 4 percent of turnover for the core violations Article 54 lists, none of which apply to the State or the Commune.
  • Expect a report to the Procureur General and possible prosecution under Penal Code Article 308-7 alongside, never instead of, an administrative fine, for conduct such as failing to keep a processing register, negligently failing to secure data, or collecting sensitive data outside a legal exception.

If you get it wrong

Criminal exposureYes

Private right of actionYes

Criminal exposure note

Monaco's Penal Code Article 308-7 (Section XII, created by Law 1.565) criminalises specific personal-data conduct in two tiers, separate from the Articles 53-54 administrative fines. The lower tier, one to six months imprisonment and or a fine of EUR 9,000 to 18,000 (Article 26, class 3), covers obstructing an investigation or withholding requested information, failing to keep a processing register under Article 27, retaining data beyond the period necessary for its purpose, negligently failing to secure data under Article 31 or disclosing data that harms a person's reputation or private or family life, breaching Articles 23 or 32, and an unlawful cross-border transfer under Chapter VIII. The higher tier, three months to one year imprisonment and or a fine of EUR 18,000 to 90,000 (Article 26, class 4), covers unauthorized video-surveillance data collection, fraudulent, unfair or unlawful collection, misuse for incompatible purposes, processing despite a data subject's objection, unauthorized processing of criminal-offence or conviction data, and unauthorized processing of sensitive-category data.

Penalty structure

Law 1.565 Article 54 sets the higher administrative fine tier, up to EUR 10,000,000 or, for an undertaking, up to 4% of total worldwide annual turnover for the preceding financial year, whichever is higher, for breaches including the lawfulness and characteristics of processing, consent, data subject rights, unauthorized processing of sensitive or criminal-record data, unlawful cross-border transfer, and non-compliance with an injunction of the Authority's restricted panel. Article 53 sets a lower tier, up to EUR 5,000,000 or 2% of turnover, whichever is higher, for narrower obligations (consent verification under Article 6, cooperation with the Authority, security by design under Article 23, the Articles 24-28 accountability obligations, security measures under Article 31, breach notification under Article 32, codes of conduct, impact assessments, and video-surveillance notification). Both tiers are lower in absolute euro terms than the GDPR's own EUR 20,000,000 and EUR 10,000,000 caps, though the percentage-of-turnover tiers, 4% and 2%, are identical. Under Article 51, most of these corrective measures, including the administrative fine, do not apply to the State or the Commune.

Rule
Higher of
As of
19 September 2026
Currency
EUR
Fixed cap
10,000,000
Turnover percentage cap
4

Who enforces it

Enforcement body

Autorite de Protection des Donnees Personnelles (A.P.D.P.), Monaco's independent administrative supervisory authority.

What it reaches

Excludes recording-derived identifiersNo

Obligation class

Governance, Reporting

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 37 creates the Autorite de Protection des Donnees Personnelles as an independent administrative authority, and Article 39 lets a person who believes their rights under this law have been ignored complain to its president, without prejudice to a separate court action before the Tribunal de Premiere Instance.

Article 103 lets a nonprofit body active in personal data protection complain to the Authority or go to court on a person's behalf, including to claim the Article 106 damages right for them.

Articles 46 to 49 give the Authority's members, agents, and sworn investigators the power to check and investigate a controller's processing, and only national security secrecy, attorney client privilege, journalistic source secrecy, and, through a physician the president designates, individual medical secrecy can be raised against them.

Article 50 lets the president issue a formal notice to bring processing into conformity, and Article 51 lets the Authority's restricted panel, after a contradictory procedure, impose a warning, an order to comply that can carry a daily penalty of up to 10,000 euros, a temporary or permanent limitation or ban on the processing, a certification withdrawal, a suspension of binding corporate rules, a suspension of a transfer, or an administrative fine, none of which besides the warning and the compliance order apply to the State or the Commune.

Article 53 caps the lighter tier of fine at 5,000,000 euros or 2 percent of worldwide annual turnover, whichever is higher, for the narrower obligations it lists, and Article 54 caps the heavier tier at 10,000,000 euros or 4 percent of turnover, whichever is higher, for the core violations it lists, including unlawful sensitive data processing, denial of data subject rights, and an unlawful transfer.

Penal Code Article 308-7, created by this law, separately criminalises specific conduct in two tiers, one to six months' imprisonment or a fine for the lighter offences and three months to a year or a fine for the heavier ones, including collecting sensitive data such as biometric or genetic data outside a legal exception.

Article 106 gives any person who has suffered material or moral harm from a violation of this law a court enforceable damages claim against the controller or the processor, distinct from the Article 39 administrative complaint route, and every controller that took part in the processing answers for the whole of the harm so the person recovers in full.

Monaco's biometric definition is drafted broadly enough that it does not exclude an identifier derived from a photo, video, or audio recording, the way Washington's RCW 19.375 does.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • high_risk_decisions
  • is_listed_company

Read the law

Journal de Monaco n. 8725 and the consolidated text at legimonaco.mc, both read in full (179,076 characters at legimonaco.mc, not truncated)

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app