Law / San Marino

San Marino

privacy

San Marino is not a General Data Protection Regulation (GDPR) jurisdiction. Its comprehensive regime is Law No. 171 of 21 December 2018 on the Protection of Natural Persons with regard to the Processing of Personal Data, read directly and found to be a close structural clone of the GDPR, in several places sharing GDPR's own article numbers for the same content. San Marino does not currently hold an EU adequacy decision.

Primary text confirms biometric data as an explicit special category with a full permitted-exceptions list, a complete GDPR Article 22 equivalent right against solely automated decisions, a GDPR Chapter V-style cross-border transfer regime, 72-hour breach notification, and a full GDPR Article 82 equivalent civil damages right.

3 instruments named 1 researched in detail As of 2026-08-24

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Comprehensive regime

San Marino Law No. 171 on the Protection of Natural Persons

cite Legge 21 dicembre 2018 n. 171, sulla tutela delle persone fisiche con riguardo al trattamento dei dati personali stage In effect since 2018-12-21 source English-translation PDF hosted by dataguidance.com, read in full through crawler infrastructure (201,720 characters, not truncated)

Law 171/2018 was approved by the Great and General Council on 12 December 2018 and promulgated by the Captains Regent on 21 December 2018, the date carried in the law's own official title; no separate entry-into-force clause distinct from that promulgation date was located in the sections reviewed, so effective_date here is that promulgation date rather than a separately confirmed commencement date.

Read directly, it is a close structural clone of the General Data Protection Regulation (GDPR), including sharing GDPR's own article numbers for the same content, such as Article 22 for automated individual decision-making. Article 8(1) prohibits processing biometric data for unique identification absent one of the Article 8(2) exceptions, which mirror GDPR's own list including explicit consent, employment-law obligations, vital interests, and data manifestly made public by the subject.

Article 22 gives a person in San Marino a complete right against a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects, with a right to human intervention where a carve-out applies.

Articles 45 to 50 establish a full GDPR Chapter V-style cross-border transfer regime (adequacy, binding corporate rules, standard clauses, and narrow derogations), and Articles 34 and 35 require breach notification to the Data Protection Authority within 72 hours where feasible, and to affected individuals without undue delay for a high-risk breach.

Article 71 is a direct GDPR Article 82 equivalent civil damages right, including joint-and-several liability among multiple controllers or processors.

What it asks of an app

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.