Law / Vatican City

General Regulation on the Protection of Personal Data, Data Protection Officer and complaints

Decreto n. DCLVII del 30 aprile 2024, Arts. 10 and 25 (Data Protection Officer and complaints)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 30 April 2024.

An enforcement supervision rule binding government bodies.

As of 19 September 2026.

What it requires

  • Where this Regulation binds your processing, route a written complaint from the Interested party that your treatment violates the Regulation to the Data Protection Officer, a function assigned to the General Councillor of Vatican City State who acts independently and autonomously, except in a matter involving the judicial authority of Vatican City State.
  • Expect no separate external supervisory authority, fine, or criminal offence provision beyond the Data Protection Officer's complaint function and any recourse to Vatican judicial authorities.

If you get it wrong

Criminal exposureNo

Criminal exposure note

No fine, penalty, or criminal offence provision for a violation of the Regulation is stated in the promulgation announcement; the only stated remedy is a written complaint to the Data Protection Officer, with the Data Controller's preliminary involvement and a possible recourse to Vatican judicial authorities.

Who enforces it

Enforcement body

Data Protection Officer function, assigned to the General Councillor of Vatican City State

What it reaches

Obligation class

Governance, Reporting

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 25 gives the Interested party the right to make a written complaint to the Data Protection Officer where they feel a data treatment violates the Regulation, except in cases involving the judicial authority of Vatican City State. Article 10, paragraph 2 assigns the Data Protection Officer function to the General Councillor of Vatican City State, and paragraph 3 has that officer carry out the responsibility and exercise power independently and autonomously.

The complaint procedure sits alongside the preliminary involvement of the Data Controller and a possible recourse to Vatican judicial authorities, and no separate external supervisory authority, fine, or criminal offence provision is stated for the Regulation.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot

Read the law

Official announcement at vaticanstate.va
a secondary reproduction of the decree's own three operative articles at rivistadirittoereligioni.com

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app