General Regulation on the Protection of Personal Data for Vatican City State
Decree DCLVII promulgates a General Regulation on the Protection of Personal Data, issued ad experimentum for a three-year period by the Pontifical Commission of Vatican City State. Read directly, the decree's own three articles promulgate the Regulation, repeal conflicting prior provisions and practices, and set entry into force on the same date as promulgation, 30 April 2024, with no separate vacatio legis.
The Regulation's implementation is the responsibility of the Governorate, within the limits of Vatican City State territory or the Lateran Treaty extraterritorial zones, and excludes purely personal processing and anonymous data. Data subjects may exercise access, rectification, erasure, portability, and restriction rights against the Governorate as Data Controller.
Enforcement runs through a Data Protection Officer function assigned to the General Councillor of Vatican City State, described as independent and autonomous, rather than a separate external supervisory authority of the kind other jurisdictions in this batch have.
No lawful-basis list beyond a general legitimate-purpose-and-consent standard, no biometric-data provision, no cross-border transfer rule, no breach-notification duty, and no private right of action were established in this research; a specific biometric-data prohibition claim from a secondary source did not survive a direct check of that source's own text and is not recorded.
What it asks of an app →