Law note · Monaco

Loi sur la Protection des Donnees Personnelles

cite Loi n. 1.565 du 3 decembre 2024 relative a la protection des donnees a caractere personnel, Journal de Monaco n. 8725 stage In effect since 2024-12-13 reviewed 2026-08-24

Law 1.565 replaced Law 1.165 (1993), transposes Council of Europe Convention 108+ obligations, ratified by Monaco 6 March 2025, and is structured around General Data Protection Regulation (GDPR)-style principles. Article 118, read directly at both legimonaco.mc and the Journal de Monaco, states plainly that Law 1.165 is repealed, and the law was signed by Prince Albert II on 3 December 2024 and published in Journal de Monaco n. 8725 on 13 December 2024.

No standalone entry-into-force clause was found across all 118 articles read directly, including the closing and transitional provisions, so effective_date here is that Journal de Monaco publication date, 13 December 2024, not an express commencement date the law states for itself; a widely circulated 14 December 2024 figure is secondary-sourced only and is not used.

Primary text confirms biometric data as a GDPR Article 4(14)-style special category at Article 2(7) and (9), with Article 7 setting special protections, plus a narrower Article 77 rule requiring the prior opinion of the supervisory authority before administrative or judicial authorities process genetic or biometric data for authentication, and an employer exemption for biometric processing strictly necessary for workplace access control.

Article 106 is a direct GDPR Article 82 equivalent civil damages right, distinct from the Article 39 administrative complaint route. A cross-border transfer regime exists at Articles 97 to 100, but Monaco itself does not currently hold an EU adequacy decision, so transfers from the EU into Monaco need their own safeguard, typically standard contractual clauses, a fact about EU law's treatment of Monaco rather than about what Monaco's own law requires outbound.

What it asks of an app

  • Establish a lawful basis before processing personal data of a person in Monaco under Law 1.565.
  • Obtain a lawful basis, such as explicit consent, before processing a biometric identifier of a person in Monaco, other than for workplace access control strictly necessary for that purpose.
  • Rely on an adequacy determination or an appropriate safeguard, such as standard contractual clauses, before transferring personal data of a person in Monaco outside the country, under Articles 97 to 100.
  • Expect a person in Monaco to have a court-enforceable damages claim under Article 106 for material or moral harm from an infringement of this law, separate from an administrative complaint under Article 39.

When LexLint raises it

Declared activities: crawls_web, trains_models, generates_content, deploys_chatbot, automated_outreach, high_risk_decisions, processes_voice, processes_biometrics

Primary source: Journal de Monaco n. 8725 and the consolidated text at legimonaco.mc, both read in full through crawler infrastructure (195,692 characters at the Journal de Monaco, not truncated)

← Back to the example  ·  Lint your app →