Law / San Marino

San Marino Law No. 171, personal data breach notification

Legge 21 dicembre 2018 n. 171, articoli 34-35 (violazione dei dati personali)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 21 December 2018.

A breach notification rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Notify the Data Protection Authority without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in San Marino, under Article 34.
  • Communicate the breach to the affected data subject without undue delay where it is likely to result in a high risk to their rights and freedoms, in clear and plain language.
  • As a processor, notify the controller without undue delay after becoming aware of a personal data breach.
  • Describe in the notification the nature of the breach, including where possible the categories and approximate number of data subjects and of records concerned, the contact point, the likely consequences and the measures taken, and document every breach, its effects and the remedial action.

What it reaches

Obligation class

Breach notice, Reporting

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 34(1) requires the controller, in the case of a personal data breach, to notify it to the Data Protection Authority without undue delay and, where feasible, not later than 72 hours after having become aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons, and to accompany a later notification with reasons for the delay.

Article 34(2) requires the processor to notify the controller without undue delay after becoming aware of a breach, and article 34(3) fixes what the notification must describe: the nature of the breach including, where possible, the categories and approximate number of data subjects and of personal data records concerned, the name and contact details of the data protection officer or other contact point, the likely consequences, and the measures taken or proposed to address it and mitigate its adverse effects.

Article 34(5) requires the controller to document every breach, its effects and the remedial action taken.

Article 35(1) requires the controller to communicate the breach to the data subject without undue delay where it is likely to result in a high risk to the rights and freedoms of natural persons, in clear and plain language, and article 35(3) excuses that communication only where protective measures such as encryption render the data unintelligible, where subsequent measures make the high risk no longer likely, or where it would involve a disproportionate effort and a public communication of equal effect is made instead.

Law 171/2018 was approved by the Great and General Council on 12 December 2018 and promulgated by the Captains Regent on 21 December 2018, the date carried in the law's own official title, and it states no separate entry-into-force clause, so that promulgation date is the day these provisions began to bind.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • processes_biometrics
  • operates_essential_service

Read the law

English-translation PDF hosted by dataguidance.com, read in full (201,720 characters, not truncated)

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app