Loi sur la Protection des Données Personnelles
Loi n. 1.565 du 3 decembre 2024 relative a la protection des donnees a caractere personnel Journal de Monaco n. 8725, arts. 1, 3-6, 9, 21-36, 58-63, 78-87 (scope, lawful basis, and controller and processor obligations)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 13 December 2024.
A comprehensive regime rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Establish one of the lawful bases Article 5 lists, such as consent, contract necessity, a legal obligation, vital interests, an important public interest ground, or legitimate interest, before processing personal data of a person in Monaco.
- Take consent only as a free, specific, informed and unambiguous act, present a bundled consent request separately from other terms, and do not make consent a condition of a good or service unless the processing is indispensable to providing it.
- Build data protection by design and by default into a processing operation, so that by default only the personal data necessary for each specific purpose is processed, collected, retained, or made accessible.
- Keep a written record of your processing activities covering the particulars Article 27 lists, and make it available to the Authority on request, unless you are an undertaking of fewer than 50 employees in Monaco whose processing is occasional, low risk, and free of sensitive or criminal record data.
- Designate a data protection officer wherever you are a public body, your core activities require large scale regular and systematic monitoring, or your core activities involve large scale processing of sensitive or criminal record data, and let that officer report to top management free of instructions.
- Carry out a data protection impact assessment before processing likely to create a high risk to a person's rights and freedoms, such as large scale profiling with legal effects, large scale sensitive data processing, large scale public area surveillance, or large scale use of a digital identifier, and consult the Authority first where the assessment still shows a high risk you cannot mitigate.
- Take appropriate technical and organisational security measures, including pseudonymisation and encryption, proportionate to the risk of destruction, loss, alteration, or unauthorised disclosure of or access to the personal data you process.
- Get the Minister of State's prior authorisation before installing a video surveillance system in a place open to the public or filming a public way, and do not keep recorded images for more than 30 days.
What it reaches
Obligation class
Governance, Consent, Security, DPIA, Contract terms, Retention
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Law 1.565 replaced Law 1.165 of 1993, transposes Council of Europe Convention 108 plus obligations, and was ratified by Monaco on 6 March 2025. Article 118 states plainly that Law 1.165 is repealed, and the law was signed by Prince Albert II on 3 December 2024 and published in Journal de Monaco No. 8725 on 13 December 2024.
No standalone entry into force clause was found across all 118 articles, including the closing and transitional provisions, so the effective date here is that Journal de Monaco publication date, 13 December 2024, not an express commencement date the law states for itself.
Article 5 sets six lawful bases for processing personal data, consent, legal obligation, contract necessity, vital interests, an important public interest ground reserved to public bodies and their delegates, and legitimate interest, and bars a public body from relying on legitimate interest for the performance of its own missions.
Article 6 requires consent to rest on a free, specific, informed and unambiguous act, requires a bundled consent request to be presented separately from other terms, and bars making consent a condition of a good or service unless the processing is indispensable to providing it.
Article 23 requires data protection by design and by default, so that only the data necessary for each specific purpose is processed and personal data is not made accessible to an indefinite number of people without the person's own action. Article 27 requires a written record of processing activities, with a narrow exemption for an undertaking of fewer than 50 employees in Monaco whose processing is occasional, low risk, and free of sensitive or criminal record data.
Articles 28 to 30 require a data protection officer wherever a public body processes data, core activities require large scale regular and systematic monitoring, or core activities involve large scale processing of sensitive or criminal record data, and require that officer to report to top management free of any instruction.
Articles 35 and 36 require a data protection impact assessment before processing likely to create a high risk, and require the controller to consult the Authority first where the assessment still shows a high risk the controller cannot mitigate. Article 31 requires security measures, including pseudonymisation and encryption, proportionate to the risk of destruction, loss, alteration, or unauthorised disclosure of or access to personal data.
A video surveillance system installed in a place open to the public, or filming a public way, needs the Minister of State's prior authorisation under Article 85, and Article 84 caps the retention of recorded images at 30 days.
When LexLint raises it
crawls_webtrains_modelsgenerates_contentdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometrics
Read the law
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.