Law / Monaco

Loi sur la Protection des Données Personnelles, transfert des données

Loi n. 1.565 du 3 decembre 2024, arts. 96-101 (transfer of personal data)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 13 December 2024.

A cross border transfer rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Before transferring personal data outside Monaco, confirm that the destination country, territory, or international organisation has an adequate level of protection, and treat every European Union member state as meeting that standard.
  • Absent an adequacy finding, rely on an appropriate safeguard, such as an executory international commitment, standard clauses the Authority has approved, binding corporate rules the Authority has approved, an approved certification mechanism, or an approved code of conduct.
  • Absent both an adequacy finding and a safeguard, transfer personal data only under a listed exception, such as the person's informed explicit consent, an important public interest ground, a legal claim, a public register meant to inform the public, or contract necessity, and tell the Authority where you rely on a rare, non repetitive transfer touching a limited number of people instead.
  • Get the Authority's authorisation before a transfer that rests on ad hoc contractual clauses or particular safeguards outside articles 97 to 99, and treat its silence for two months, renewable once, as a refusal.
  • Do not treat a foreign court's or authority's order to transfer or disclose personal data out of Monaco as enforceable unless an international agreement between that state and Monaco provides for it.

What it reaches

Obligation class

Transfer, Access restriction

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 97 lets personal data be transferred abroad where the destination country, territory, or international organisation has an adequate level of protection, and it deems every European Union member state adequate on that basis alone.

Article 98 lets a transfer to a country without an adequacy finding proceed instead under an appropriate safeguard, an executory international commitment, Authority approved standard clauses, Authority approved binding corporate rules, an approved certification mechanism, or an approved code of conduct.

Article 99 lets a transfer proceed absent both an adequacy finding and a safeguard where the person has given informed explicit consent, or under a separate list, the safeguarding of vital interests, an important public interest ground, a legal claim, a public register, or contract necessity, and lets a rare, non repetitive transfer touching a limited number of people proceed on the controller's own compelling legitimate interests once the Authority is told.

Article 100 lets the Authority itself authorise a transfer resting on specific contractual clauses or particular safeguards, and its silence for two months, renewable once, counts as a refusal. Article 101 refuses to recognise or enforce a foreign court's or authority's order compelling a transfer or a disclosure out of Monaco unless an international agreement between that state and Monaco provides for it.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • processes_biometrics

Read the law

Journal de Monaco n. 8725 and the consolidated text at legimonaco.mc, both read in full (179,076 characters at legimonaco.mc, not truncated)

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app