San Marino Law No. 171, the Data Protection Authority, remedies and fines
Legge 21 dicembre 2018 n. 171, articoli 51-75 (Autorita Garante, rimedi e sanzioni)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 21 December 2018.
An enforcement supervision rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Expect a data subject to be able to complain to the San Marino Data Protection Authority, to object to its decision and to seek judicial protection, alongside a claim for compensation against you.
- Answer the Authority's requests for information and documents, and expect verifications, including the special verifications article 63 provides for.
- Expect joint and several liability where more than one controller or processor is involved in the same infringing processing, and expect to have to prove you are not responsible for the event that caused the damage in order to be exempted.
- Do not publish or disseminate news or images identifying a child involved in legal proceedings.
If you get it wrong
Criminal exposureYes
Private right of actionYes
Criminal exposure note
Article 75(2) makes an infringement of the Article 75(1) prohibition on publishing or disseminating news or images identifying a child involved in legal proceedings a criminal offence, punishable under Article 192 bis of the San Marino Criminal Code. A second, narrower criminal cross-reference at Article 121(5) applies Article 377 of the Criminal Code to an electronic-communications provider's or operator's breach of its secrecy duty over a Judicial Authority data-preservation order. Both are specific, sector-limited criminal offences layered on top of the law, distinct from the general administrative-fine regime of Title VIII (Arts. 72 to 73), which is purely administrative and carries no criminal penalty of its own.
Penalty structure
Article 72(2) sets the higher administrative-fine tier, up to EUR 10,000,000 or 4 percent of total annual turnover of the previous financial year, whichever is higher, for infringements of the basic principles of processing including consent (Arts. 4, 5, 6, 8), the data subjects' rights (Arts. 12 to 22), cross-border transfer (Title V of Part I), and non-compliance with a Data Protection Authority order, limitation or suspension under Article 59(2) or a failure to provide access under Article 59(1). A separate, lower tier under Article 72(1) caps the controller/processor, certification-body and monitoring-body obligations (Arts. 7, 11, 24 to 40, 42 to 44) at EUR 5,000,000 or 2 percent, whichever is higher. San Marino's own fixed caps are exactly half GDPR Article 83's EUR 20,000,000 / 10,000,000 figures while matching its 4 percent / 2 percent turnover percentages; San Marino is not an EU member state, so GDPR Article 83's fixed euro amounts do not apply here by operation of law and the law sets its own, lower fixed caps.
- Rule
- Higher of
- As of
- 2 September 2026
- Currency
- EUR
- Fixed cap
- 10,000,000
- Turnover percentage cap
- 4
Who enforces it
Enforcement body
San Marino Data Protection Authority
Enforcement record
The Authority (agpdp.sm is its own official site; the garanteprivacy.sm URL is not reachable) publishes an annual 'Provvedimenti' (decisions) register, itemised by numbered, dated decision and its type: opinions (pareri), right-to-be-forgotten complaints under Article 66, video-surveillance authorisations, certificate-issuance requests, data-breach notices, reports (segnalazioni), and formal injunctions (ingiunzioni) for failure to adopt security measures. By year, 2019 and 2020 each list roughly two dozen to thirty decisions (including a security-measures injunction in 2020); 2021 lists 7 (including two injunctions, one specifically for failing to verify minors' ages); 2022 lists 6 (predominantly video-surveillance authorisations); no decisions are published for 2023; and 2024, the most recent year listed, has only 2 (one under appeal). None of the published decision titles states a monetary fine amount, so fines_per_year, total_fines and median_fine cannot be verified from this register and are omitted rather than estimated. Secondary Italian legal-press coverage separately reports a EUR 4 million fine against Meta/Facebook confirmed on appeal around 2019, which is not recorded here because it could not be confirmed against the primary decision text.
- As of
- 2 September 2026
- Trend
- Falling
- Source link
- https://agpdp.sm/pub1/garante/it/provvedimenti.html
What it reaches
Obligation class
Governance, Reporting, Prohibition
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Articles 52 to 59 establish the San Marino Data Protection Authority, fix the fit and proper requirements of its members, guarantee its autonomy and independence, and set its competence, tasks and powers, and articles 60 to 63 let it request information and documents and carry out verifications, including special ones.
Article 65 sets the remedies open to a data subject, article 66 the complaint to the Authority, article 67 the decision on it, article 68 reporting, article 69 objection and article 70 judicial protection.
Article 71 entitles any person who has suffered material or non-material damage from an infringement of the law to compensation from the controller or processor, makes each controller involved liable for the damage caused by infringing processing, and makes a processor liable where it has not complied with obligations directed to processors or has acted outside the controller's lawful instructions, with joint and several liability where more than one is involved.
Article 72(1) subjects the controller's and processor's own obligations to administrative fines of up to five million euros or two per cent of total annual turnover of the previous financial year, whichever is higher, and article 72(2) sets the higher tier for the basic principles, the data subject's rights and the transfer rules. Article 73 fixes the procedure for imposing fines, and article 75 bars publishing or disseminating news or images identifying a child involved in legal proceedings.
Law 171/2018 was approved by the Great and General Council on 12 December 2018 and promulgated by the Captains Regent on 21 December 2018, the date carried in the law's own official title, and it states no separate entry-into-force clause, so that promulgation date is the day these provisions began to bind.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbothigh_risk_decisionsis_listed_company
Read the law
English-translation PDF hosted by dataguidance.com, read in full (201,720 characters, not truncated)
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.