Law / Holy See (Vatican City)

Holy See (Vatican City)

privacy

Vatican City State's only personal data instrument is Decree No. DCLVII of 30 April 2024, promulgating a General Regulation on the Protection of Personal Data, issued ad experimentum for a three-year period. Its scope is genuinely narrow: the Regulation binds Vatican City State institutions, implemented by the Governorate, within Vatican City State territory or the Lateran Treaty extraterritorial zones, and names no private-sector entity at all.

Vatican City State has no ordinary private commercial sector at meaningful scale, so this instrument's practical effect is government and institutional processing, not a general private-sector personal data regime. An earlier lead attributing a biometric-data prohibition to this decree, sourced to a secondary commentary sentence, was checked directly against that page's full crawled text and found not to appear anywhere in it; that claim is retracted and is not recorded here.

5 instruments named 1 researched in detail As of 2026-08-24

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Comprehensive regime

General Regulation on the Protection of Personal Data for Vatican City State

cite Decreto n. DCLVII del 30 aprile 2024 (ad experimentum, three-year period) stage In effect since 2024-04-30 source Official announcement at vaticanstate.va

Decree DCLVII promulgates a General Regulation on the Protection of Personal Data, issued ad experimentum for a three-year period by the Pontifical Commission of Vatican City State. Read directly, the decree's own three articles promulgate the Regulation, repeal conflicting prior provisions and practices, and set entry into force on the same date as promulgation, 30 April 2024, with no separate vacatio legis.

The Regulation's implementation is the responsibility of the Governorate, within the limits of Vatican City State territory or the Lateran Treaty extraterritorial zones, and excludes purely personal processing and anonymous data. Data subjects may exercise access, rectification, erasure, portability, and restriction rights against the Governorate as Data Controller.

Enforcement runs through a Data Protection Officer function assigned to the General Councillor of Vatican City State, described as independent and autonomous, rather than a separate external supervisory authority of the kind other jurisdictions in this batch have.

No lawful-basis list beyond a general legitimate-purpose-and-consent standard, no biometric-data provision, no cross-border transfer rule, no breach-notification duty, and no private right of action were established in this research; a specific biometric-data prohibition claim from a secondary source did not survive a direct check of that source's own text and is not recorded.

What it asks of an app

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.