Law note · San Marino
San Marino Law No. 171 on the Protection of Natural Persons
Law 171/2018 was approved by the Great and General Council on 12 December 2018 and promulgated by the Captains Regent on 21 December 2018, the date carried in the law's own official title; no separate entry-into-force clause distinct from that promulgation date was located in the sections reviewed, so effective_date here is that promulgation date rather than a separately confirmed commencement date.
Read directly, it is a close structural clone of the General Data Protection Regulation (GDPR), including sharing GDPR's own article numbers for the same content, such as Article 22 for automated individual decision-making. Article 8(1) prohibits processing biometric data for unique identification absent one of the Article 8(2) exceptions, which mirror GDPR's own list including explicit consent, employment-law obligations, vital interests, and data manifestly made public by the subject.
Article 22 gives a person in San Marino a complete right against a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects, with a right to human intervention where a carve-out applies.
Articles 45 to 50 establish a full GDPR Chapter V-style cross-border transfer regime (adequacy, binding corporate rules, standard clauses, and narrow derogations), and Articles 34 and 35 require breach notification to the Data Protection Authority within 72 hours where feasible, and to affected individuals without undue delay for a high-risk breach.
Article 71 is a direct GDPR Article 82 equivalent civil damages right, including joint-and-several liability among multiple controllers or processors.
What it asks of an app
- Establish a lawful basis before processing personal data of a person in San Marino under Law 171/2018.
- Obtain explicit consent or another Article 8(2) exception before capturing or storing a biometric identifier of a person in San Marino; Article 8(1) prohibits biometric processing for unique identification absent one.
- Rely on an EU adequacy decision, a bilateral treaty, an appropriate safeguard such as binding corporate rules or standard clauses, or a narrow derogation before transferring personal data of a person in San Marino outside the country, under Articles 45 to 50.
- Provide a meaningful human review before finalizing a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects for a person in San Marino, under Article 22.
- Notify the Data Protection Authority without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in San Marino, under Article 34.
When LexLint raises it
Declared activities: crawls_web, trains_models, generates_content, deploys_chatbot, automated_outreach, high_risk_decisions, processes_voice, processes_biometrics
Primary source: English-translation PDF hosted by dataguidance.com, read in full through crawler infrastructure (201,720 characters, not truncated)