General Regulation on the Protection of Personal Data, Data Protection Officer and complaints
Decreto n. DCLVII del 30 aprile 2024, Arts. 10 and 25 (Data Protection Officer and complaints)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 30 April 2024.
An enforcement supervision rule binding government bodies.
As of 19 September 2026.
What it requires
- Where this Regulation binds your processing, route a written complaint from the Interested party that your treatment violates the Regulation to the Data Protection Officer, a function assigned to the General Councillor of Vatican City State who acts independently and autonomously, except in a matter involving the judicial authority of Vatican City State.
- Expect no separate external supervisory authority, fine, or criminal offence provision beyond the Data Protection Officer's complaint function and any recourse to Vatican judicial authorities.
If you get it wrong
Criminal exposureNo
Criminal exposure note
No fine, penalty, or criminal offence provision for a violation of the Regulation is stated in the promulgation announcement; the only stated remedy is a written complaint to the Data Protection Officer, with the Data Controller's preliminary involvement and a possible recourse to Vatican judicial authorities.
Who enforces it
Enforcement body
Data Protection Officer function, assigned to the General Councillor of Vatican City State
What it reaches
Obligation class
Governance, Reporting
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 25 gives the Interested party the right to make a written complaint to the Data Protection Officer where they feel a data treatment violates the Regulation, except in cases involving the judicial authority of Vatican City State. Article 10, paragraph 2 assigns the Data Protection Officer function to the General Councillor of Vatican City State, and paragraph 3 has that officer carry out the responsibility and exercise power independently and autonomously.
The complaint procedure sits alongside the preliminary involvement of the Data Controller and a possible recourse to Vatican judicial authorities, and no separate external supervisory authority, fine, or criminal offence provision is stated for the Regulation.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbot
Read the law
Official announcement at vaticanstate.va
a secondary reproduction of the decree's own three operative articles at rivistadirittoereligioni.com
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.