Law / San Marino

San Marino Law No. 171 on the Protection of Natural Persons

Legge 21 dicembre 2018 n. 171, articoli 1-7, 9-11 e 23-44 (principi, basi giuridiche e obblighi del titolare)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 21 December 2018.

A comprehensive regime rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Establish a lawful basis before processing personal data of a person in San Marino under Law 171/2018.
  • Take consent only where you can demonstrate the data subject gave it, and for an information society service offered to a child, only on the terms article 7 sets.
  • Build data protection into the design of your processing and make it the default, and keep records of your processing activities.
  • Implement technical and organisational measures giving a level of security appropriate to the risk, and cooperate with the Data Protection Authority in the performance of its tasks.
  • Carry out a data protection impact assessment before processing likely to result in a high risk, and consult the Data Protection Authority beforehand where the assessment shows that risk remains.
  • Designate a data protection officer where the law requires one, give them the position article 39 prescribes, and let them carry out the tasks article 40 lists.
  • Where you engage a processor, govern the engagement as article 29 requires, and settle each party's responsibilities in an arrangement where you are a joint controller.

What it reaches

Obligation class

Consent, Security, DPIA, Governance

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 3 fixes the law's territorial and material scope. Article 4 carries the processing principles and article 5 the lawful bases, while article 6 sets the conditions for valid consent and article 7 the conditions for a child's consent to an information society service. Articles 10 and 11 govern data on criminal convictions and processing that does not require identification.

Article 26 places responsibility for compliance on the controller, article 27 requires data protection by design and by default, article 28 governs joint controllers, article 29 the engagement of a processor and article 30 processing under the authority of either. Article 31 requires records of processing activities and article 32 cooperation with the Data Protection Authority. Article 33 requires technical and organisational measures giving a level of security appropriate to the risk.

Article 36 requires a data protection impact assessment where processing is likely to result in a high risk, and article 37 prior consultation of the Authority where the assessment shows that risk. Articles 38 to 40 govern the designation, position and tasks of the data protection officer, and articles 41 to 44 the codes of conduct, their monitoring, certification and certification bodies.

Law 171/2018 was approved by the Great and General Council on 12 December 2018 and promulgated by the Captains Regent on 21 December 2018, the date carried in the law's own official title, and it states no separate entry-into-force clause, so that promulgation date is the day these provisions began to bind.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • generates_content

Read the law

English-translation PDF hosted by dataguidance.com, read in full (201,720 characters, not truncated)

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app