Law / Vatican City

General Regulation on the Protection of Personal Data for Vatican City State

Decreto n. DCLVII del 30 aprile 2024 (ad experimentum, three-year period), Arts. 1, 2, 11, 12 and 13 (purpose, scope and controller duties)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 30 April 2024.

A comprehensive regime rule binding government bodies.

As of 19 September 2026.

What it requires

  • This decree binds Vatican City State institutions processing personal data via the Governorate, within Vatican City State territory or the Lateran Treaty extraterritorial zones. It does not establish a general private-sector personal data regime, and no ordinary commercial or consumer-facing application's obligations under it are confirmed. Review it if your app crawls, trains on, or deploys a chatbot against data belonging to a Vatican City State institution.
  • Where this Regulation binds your processing, identify the Data Controller as the Governorate, represented by the General Secretary, and put in place organizational and technical security measures suitable to protect the personal data you process. Appoint a Representative in writing where the Regulation calls for one, and record the activity in the Register of treatment activities.

What it reaches

Obligation class

Governance, Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 1 of the Regulation states rules on the protection of physical persons with regard to the treatment of personal data and norms on the free movement of such data, respecting human dignity and fundamental freedoms. Article 2, paragraph 1 makes implementation of the Regulation the responsibility of the Governorate, within the limits of the territory of Vatican City State, or for activities the Governorate carries out in the zones named in the Lateran Treaty.

Article 2, paragraph 2 excludes from that implementation personal data treatment a physical person carries out for exclusively personal reasons and does not destine for systemic circulation, data the Interested party has made clearly public, and anonymous data.

Article 11, paragraph 1 identifies the Data Controller as the Governorate, represented by the General Secretary, who decides the purposes and methods of data treatment, and paragraph 2 requires identifying organizational and technical security measures suitable to guaranteeing personal data protection.

Article 12 lets the Data Controller choose, from the senior roles of the Bodies of the Governorate, those responsible for treatment, who implement the Regulation and may appoint Representatives, and Article 13 has the Data Controller and each person responsible for treatment designate one or more Representatives in a written document, authorized to put security measures into action and identified in the Register of treatment activities.

The Regulation is modelled on the European Union's General Data Protection Regulation, but names no private-sector entity and Vatican City State has no ordinary private commercial sector at meaningful scale, so its practical effect is government and institutional processing rather than a general private-sector regime.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot

Read the law

Official announcement at vaticanstate.va
a secondary reproduction of the decree's own three operative articles at rivistadirittoereligioni.com

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app