Law / Monaco

Monaco

All 9 named instruments researched to a stage, across four of the six areas of law we track: 9 in force. As of 19 September 2026.

When they take effect9 of 9 carry a date. Earlier is before 2014.
Before 2014: 2 instruments (2 in force) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 1 instrument (1 in force) 2017: 0 instruments 2018: 0 instruments 2019: 0 instruments 2020: 0 instruments ’20 2021: 0 instruments 2022: 0 instruments 2023: 0 instruments 2024: 6 instruments (6 in force) 2025: 0 instruments 2026: 0 instruments ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 1
  2. Privacy law 6
  3. Scraping law 1
  4. Cybersecurity law none researched
  5. Age gating law none researched
  6. News aggregation law 1

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law1 instrument, 1 in force

Research summary (275 words)

Monaco has no AI-transparency, output-labelling, high-risk-system, training-data, governance, or sector-specific AI statute. Monaco is not a European Union or European Economic Area member state, so the EU AI Act (Regulation (EU) 2024/1689) has no domestic force in Monaco absent its own implementing statute, and none has been identified.

Loi n. 1.565 du 3 decembre 2024 relative a la protection des donnees a caractere personnel carries an automated-decision-making right at its Article 39 route and a civil-damages right at Article 106, but those duties attach to personal data rather than to an AI system as such, so they are researched under this jurisdiction's privacy topic rather than here.

One provision does bind a person for the way it treats an AI-generated depiction: Code penal Article 294-3, inserted by Loi n. 1.344 du 26 decembre 2007 relative au renforcement de la repression des crimes et delits contre l'enfant, criminalises fixing, recording, producing, procuring, transmitting, offering, disseminating, importing, exporting, possessing or knowingly accessing a pornographic image or representation of a minor.

Its definition of a pornographic image expressly extends to a realistic image of a minor engaged in sexually explicit conduct, and the law defines a realistic image as including an altered image of a natural person created in whole or in part by digital methods, so the prohibition reaches a computer-generated or artificial-intelligence-generated depiction on the same footing as a photograph of a real child.

Article 294-4 separately requires a telecommunications or electronic communications network operator or service provider who becomes aware of such an image through its professional activity to act to prevent public access to it and to make it available to the judicial authority.

AI prohibited practices

Code Pénal Arts. 294-3 to 294-4, Child Sexual Abuse Material Including Realistic and AI-Generated Depictions

Code penal art. 294-3, 294-3-1 et 294-4 (Titre II, Chapitre Ier, Section VII, Crimes et delits envers l'enfant), art. 294-3 et 294-4 crees par la loi n. 1.344 du 26 decembre 2007 relative au renforcement de la repression des crimes et delits contre l'enfant, art. 294-3-1 cree par la loi n. 1.513 du 3 decembre 2021Official consolidated Code penal text, legimonaco.mc

In force since 28 December 2007. Binds public and private bodies.

What this law does

Article 294-3 punishes, with three to five years' imprisonment and the Code penal article 26 chiffre 3 fine, fixing, recording, producing, procuring or transmitting the image or representation of a minor with a view to its dissemination where that image or representation is pornographic, and knowingly offering or disseminating, importing or exporting such an image by any means; attempt is punished identically.

Knowingly possessing such an image, or knowingly accessing one, is punished with six months to two years' imprisonment and the chiffre 2 fine. The penalty rises to five to ten years and the chiffre 4 fine where an electronic communications network was used to disseminate the image to an undetermined public.

The article applies equally to a pornographic image of a person whose physical appearance is that of a minor unless it is established that the person was at least eighteen years old on the day the image was fixed or recorded. It does not apply where the images were collected for the investigation or prosecution of a criminal offence.

The article's own definition of a pornographic image lists, as a third category alongside a real minor and a person appearing as a minor engaged in sexually explicit conduct, a realistic image representing a minor engaged in sexually explicit conduct, and it defines a realistic image as including, notably, an altered image of a natural person created in whole or in part by digital methods; the prohibition and every offence built on it therefore reach a computer-generated or artificial-intelligence-generated depiction of a minor exactly as they reach a photograph of a real child.

Article 294-3-1, inserted in 2021, extends the offences at Article 294-3 to an image or representation that is not pornographic but is of a nature to harm a minor's dignity.

Article 294-4 requires a telecommunications or electronic-communications network operator or service provider, or one of its agents, who becomes aware of an image or representation covered by Article 294-3 through its professional activity, to act to bar public access to it and to make it available to the judicial authority for the investigation, establishment and prosecution of criminal offences.

Failing to do so is punished by one year's imprisonment and the chiffre 4 fine, without prejudice to the penalties incurred by the perpetrators, co-perpetrators or accomplices of the underlying offence.

What it requires

Privacy law6 instruments, 6 in force

Research summary (206 words)

Monaco is not a General Data Protection Regulation (GDPR) jurisdiction, but its comprehensive privacy statute, Loi n. 1.565 du 3 decembre 2024 relative a la protection des donnees a caractere personnel, closely tracks the GDPR's structure and is filed here as six provision-scoped instruments, each holding the family of duties its own articles state, rather than as a single row. It repeals and replaces the older Loi n. 1.165 du 23 decembre 1993, and Article 118 confirms the repeal.

No standalone commencement clause was found across all 118 articles, so the effective date recorded here is the law's confirmed publication date in the Journal de Monaco, 13 December 2024, rather than a separately stated commencement date, and a widely circulated 14 December 2024 figure is secondary sourced only and is not used.

Reading the full text confirms a real cross-border transfer chapter, a 72 hour breach clock that runs to the Authority alone rather than to the affected person as well, and a narrower rule for biometric and genetic data processed by public authorities for authentication, alongside the general prohibition on processing any sensitive category of data. Monaco does not currently hold an EU adequacy decision, unlike Andorra, and a renewed adequacy request was pending as of the sources found.

Breach notification

Loi sur la Protection des Données Personnelles, notification des violations de données

Loi n. 1.565 du 3 decembre 2024, art. 32 (personal data breach notification)Journal de Monaco n. 8725 and the consolidated text at legimonaco.mc, both read in full (179,076 characters at legimonaco.mc, not truncated)

In force since 13 December 2024. Binds public and private bodies.

What this law does

Article 32.I requires the controller to notify the Authority of a personal data breach as soon as possible and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to create a risk to the rights and freedoms of the persons concerned, and a notification made after that window must be accompanied by the reasons for the delay.

The notification to the Authority must describe the nature of the breach, including where possible the categories and approximate number of affected persons and records, a contact point, the likely consequences, and the measures taken or proposed, and the controller must document every breach, its facts, its effects, and the remedial steps taken. A processor must notify the controller of a breach as soon as it becomes aware of it, with no fixed number of hours stated.

Article 32.II requires the controller to communicate a breach likely to create a high risk to a person's rights and freedoms to that person as soon as possible, in clear language, but states no fixed number of hours for that communication the way it does for the Authority, and excuses it only where the affected data were already rendered unintelligible by measures such as encryption, where later measures mean the risk is no longer likely to materialise, or where individual notice would take disproportionate effort and an equally effective public communication is made instead.

The Authority can still require the controller to communicate the breach to the person if it has not done so. Article 32.I sets the 72 hour period for the notice to the Authority alone; article 32.II gives the notice to the affected person no fixed period, only "dans les meilleurs delais".

What it requires

Comprehensive regime

Loi sur la Protection des Données Personnelles

Loi n. 1.565 du 3 decembre 2024 relative a la protection des donnees a caractere personnel Journal de Monaco n. 8725, arts. 1, 3-6, 9, 21-36, 58-63, 78-87 (scope, lawful basis, and controller and processor obligations)Journal de Monaco n. 8725 and the consolidated text at legimonaco.mc, both read in full (179,076 characters at legimonaco.mc, not truncated)

In force since 13 December 2024. Binds public and private bodies.

What this law does

Law 1.565 replaced Law 1.165 of 1993, transposes Council of Europe Convention 108 plus obligations, and was ratified by Monaco on 6 March 2025. Article 118 states plainly that Law 1.165 is repealed, and the law was signed by Prince Albert II on 3 December 2024 and published in Journal de Monaco No. 8725 on 13 December 2024.

No standalone entry into force clause was found across all 118 articles, including the closing and transitional provisions, so the effective date here is that Journal de Monaco publication date, 13 December 2024, not an express commencement date the law states for itself.

Article 5 sets six lawful bases for processing personal data, consent, legal obligation, contract necessity, vital interests, an important public interest ground reserved to public bodies and their delegates, and legitimate interest, and bars a public body from relying on legitimate interest for the performance of its own missions.

Article 6 requires consent to rest on a free, specific, informed and unambiguous act, requires a bundled consent request to be presented separately from other terms, and bars making consent a condition of a good or service unless the processing is indispensable to providing it.

Article 23 requires data protection by design and by default, so that only the data necessary for each specific purpose is processed and personal data is not made accessible to an indefinite number of people without the person's own action. Article 27 requires a written record of processing activities, with a narrow exemption for an undertaking of fewer than 50 employees in Monaco whose processing is occasional, low risk, and free of sensitive or criminal record data.

Articles 28 to 30 require a data protection officer wherever a public body processes data, core activities require large scale regular and systematic monitoring, or core activities involve large scale processing of sensitive or criminal record data, and require that officer to report to top management free of any instruction.

Articles 35 and 36 require a data protection impact assessment before processing likely to create a high risk, and require the controller to consult the Authority first where the assessment still shows a high risk the controller cannot mitigate. Article 31 requires security measures, including pseudonymisation and encryption, proportionate to the risk of destruction, loss, alteration, or unauthorised disclosure of or access to personal data.

A video surveillance system installed in a place open to the public, or filming a public way, needs the Minister of State's prior authorisation under Article 85, and Article 84 caps the retention of recorded images at 30 days.

What it requires

Cross border transfer

Loi sur la Protection des Données Personnelles, transfert des données

Loi n. 1.565 du 3 decembre 2024, arts. 96-101 (transfer of personal data)Journal de Monaco n. 8725 and the consolidated text at legimonaco.mc, both read in full (179,076 characters at legimonaco.mc, not truncated)

In force since 13 December 2024. Binds public and private bodies.

What this law does

Article 97 lets personal data be transferred abroad where the destination country, territory, or international organisation has an adequate level of protection, and it deems every European Union member state adequate on that basis alone.

Article 98 lets a transfer to a country without an adequacy finding proceed instead under an appropriate safeguard, an executory international commitment, Authority approved standard clauses, Authority approved binding corporate rules, an approved certification mechanism, or an approved code of conduct.

Article 99 lets a transfer proceed absent both an adequacy finding and a safeguard where the person has given informed explicit consent, or under a separate list, the safeguarding of vital interests, an important public interest ground, a legal claim, a public register, or contract necessity, and lets a rare, non repetitive transfer touching a limited number of people proceed on the controller's own compelling legitimate interests once the Authority is told.

Article 100 lets the Authority itself authorise a transfer resting on specific contractual clauses or particular safeguards, and its silence for two months, renewable once, counts as a refusal. Article 101 refuses to recognise or enforce a foreign court's or authority's order compelling a transfer or a disclosure out of Monaco unless an international agreement between that state and Monaco provides for it.

What it requires

Data subject rights

Loi sur la Protection des Données Personnelles, droits de la personne concernée

Loi n. 1.565 du 3 decembre 2024, arts. 10-20 (rights of the data subject)Journal de Monaco n. 8725 and the consolidated text at legimonaco.mc, both read in full (179,076 characters at legimonaco.mc, not truncated)

In force since 13 December 2024. Binds public and private bodies.

What this law does

Article 10 requires the controller to act on a rights request concisely, understandably, and in an easily accessible form, in clear and plain language, with particular care where the information is meant for a minor, and to answer within one month of receipt, extendable by two months for a complex or repeated request.

Article 11 lists what a controller must tell a person at collection, its identity and contact details, the purposes and legal basis of the processing, any legitimate interest relied on, the categories of data, the retention period or the criteria for setting one, whether a reply is mandatory, the right to withdraw consent, the recipients, how to exercise the access, objection, rectification, erasure, restriction, or portability rights, the right to complain to the Authority, the data protection officer's contact details if any, the existence of automated decision making including profiling, and any transfer outside Monaco and its safeguards under Articles 97 to 100.

Article 12 gives a right of access to confirmation of processing and a copy of the data, Article 13 a right to rectification, and Article 14 a right to erasure in the listed cases, including where the data were collected from a minor for an information society service and the person later asks for their removal.

Article 15 gives a right to restrict processing in the listed cases, and Article 16 requires every recipient the data were disclosed to be told of a rectification, erasure, or restriction unless that is impossible or disproportionately burdensome. Article 17 gives an unqualified right to object to processing for direct marketing, including any profiling tied to it, which the controller must flag separately no later than the first communication.

Article 18 gives a right to receive personal data in a structured, commonly used, and machine readable format and to have it transmitted directly to another controller where technically possible. Article 19 bars a decision that produces legal effects or significantly affects a person from resting solely on automated processing, including profiling, unless a listed exception applies, and even then guarantees at least a right to human intervention, to express a view, and to contest the decision.

Article 20 lets a deceased person's ascendant, descendant to the second degree, surviving spouse, cohabitant, or registered partner exercise the access, rectification, erasure, restriction, objection, and portability rights over that person's data where they show an interest.

What it requires

Enforcement supervision

Loi sur la Protection des Données Personnelles, autorite de controle et sanctions

Loi n. 1.565 du 3 decembre 2024, arts. 37-57, 102-106 (supervisory authority, sanctions and right to reparation)Journal de Monaco n. 8725 and the consolidated text at legimonaco.mc, both read in full (179,076 characters at legimonaco.mc, not truncated)

In force since 13 December 2024. Binds public and private bodies.

What this law does

Article 37 creates the Autorite de Protection des Donnees Personnelles as an independent administrative authority, and Article 39 lets a person who believes their rights under this law have been ignored complain to its president, without prejudice to a separate court action before the Tribunal de Premiere Instance.

Article 103 lets a nonprofit body active in personal data protection complain to the Authority or go to court on a person's behalf, including to claim the Article 106 damages right for them.

Articles 46 to 49 give the Authority's members, agents, and sworn investigators the power to check and investigate a controller's processing, and only national security secrecy, attorney client privilege, journalistic source secrecy, and, through a physician the president designates, individual medical secrecy can be raised against them.

Article 50 lets the president issue a formal notice to bring processing into conformity, and Article 51 lets the Authority's restricted panel, after a contradictory procedure, impose a warning, an order to comply that can carry a daily penalty of up to 10,000 euros, a temporary or permanent limitation or ban on the processing, a certification withdrawal, a suspension of binding corporate rules, a suspension of a transfer, or an administrative fine, none of which besides the warning and the compliance order apply to the State or the Commune.

Article 53 caps the lighter tier of fine at 5,000,000 euros or 2 percent of worldwide annual turnover, whichever is higher, for the narrower obligations it lists, and Article 54 caps the heavier tier at 10,000,000 euros or 4 percent of turnover, whichever is higher, for the core violations it lists, including unlawful sensitive data processing, denial of data subject rights, and an unlawful transfer.

Penal Code Article 308-7, created by this law, separately criminalises specific conduct in two tiers, one to six months' imprisonment or a fine for the lighter offences and three months to a year or a fine for the heavier ones, including collecting sensitive data such as biometric or genetic data outside a legal exception.

Article 106 gives any person who has suffered material or moral harm from a violation of this law a court enforceable damages claim against the controller or the processor, distinct from the Article 39 administrative complaint route, and every controller that took part in the processing answers for the whole of the harm so the person recovers in full.

Monaco's biometric definition is drafted broadly enough that it does not exclude an identifier derived from a photo, video, or audio recording, the way Washington's RCW 19.375 does.

What it requires

Sensitive categories

Loi sur la Protection des Données Personnelles, données sensibles et mineurs

Loi n. 1.565 du 3 decembre 2024, arts. 2, 6-8, 77 (sensitive data, biometric data and minors)Journal de Monaco n. 8725 and the consolidated text at legimonaco.mc, both read in full (179,076 characters at legimonaco.mc, not truncated)

In force since 13 December 2024. Binds public and private bodies.

What this law does

Article 2 defines sensitive data as data revealing political, religious, philosophical, or trade union opinions or affiliations, racial or ethnic origin, genetic data, biometric data used to uniquely identify a person, or data about health, sex life, or sexual orientation, and defines biometric data broadly enough to include a facial image or fingerprint data.

Article 7 opens by prohibiting the processing of sensitive data outright, then lists the exceptions that lift the ban, including the person's explicit consent, vital interests, a religious or political body's own members, data the person has manifestly made public, a legal claim, an important public interest ground set by Monegasque law, preventive or occupational medicine and public health, archiving, research, or statistics, and a narrow employer exception for biometric data strictly necessary to control access to the workplace and to the devices and applications employees use for their duties.

Article 6 sets a separate consent floor for a minor using an information society service, and where the minor is under 15 the processing is lawful only with consent from the minor together with the authorisation of whoever holds parental authority.

Article 77 adds a narrower rule reaching only administrative and judicial authorities acting in the exercise of their public powers, requiring the Authority's opinion before they process genetic or biometric data for authentication or identity control, and requiring organisational safeguards such as storing raw biometric data separately from any template derived from it. Article 8 bars any interconnection between the judicial criminal record and any other file or processing operation.

Reading the statute did not surface a general private sector biometric identifier statute of the kind Illinois or Washington enact; Monaco instead treats biometric and genetic data as one item within its ordinary special category regime.

What it requires

Scraping law1 instrument, 1 in force

Research summary (262 words)

Monaco has no scraping-specific statute. Unauthorized access to, and interference with, an information system is reached by the Code penal's Section IV, Des delits relatifs aux systemes d'information (articles 389-1 to 389-9), created by Loi n. 1.435 du 8 novembre 2016 relative a la lutte contre la criminalite technologique.

Because the base access offence at Article 389-1 requires fraudulently accessing or remaining within a system, a scraper reading a public, unauthenticated page without defeating any access control falls outside a plain reading of the provision, though no reported Monaco decision has tested the point.

Copyright is governed by Loi n. 491 du 24 novembre 1948 sur la protection des oeuvres litteraires et artistiques, which carries only a narrow set of exceptions, quotation and press-review under Articles 15 and 16, researched under this jurisdiction's aggregation topic; the 1948 law has no text-and-data-mining exception or machine-readable opt-out mechanism of the kind the EU's Digital Single Market Copyright Directive introduced, and Monaco is not an EU or EEA member state, so that Directive has no domestic force.

No sui generis database right, comparable to the one EU Directive 96/9/EC created, has been identified in Monaco's copyright statute. No Monaco-specific case law on the lawfulness of scraping a public page, on terms-of-service enforceability, or on robots.txt's legal weight was located.

Personal data scraped from a public Monaco website remains subject to Loi n. 1.565 du 3 decembre 2024 relative a la protection des donnees a caractere personnel, researched under this jurisdiction's privacy topic, which carries no general exemption for information the data subject has made public.

Computer misuse

Code Pénal Arts. 389-1 to 389-9, Unauthorized Access, System Interference and Data Damage

Code penal art. 389-1 a 389-9 (Titre II, Chapitre II, Section IV, Des delits relatifs aux systemes d'information), crees par la loi n. 1.435 du 8 novembre 2016 relative a la lutte contre la criminalite technologiqueOfficial consolidated Code penal text, legimonaco.mc

In force since 18 November 2016. Binds public and private bodies.

What this law does

Article 389-1 punishes fraudulently accessing or remaining within all or part of an information system with two years' imprisonment and the fine under Code penal article 26 chiffre 3, which may be doubled depending on the circumstances. Article 389-2 punishes fraudulently hindering or altering the functioning of all or part of an information system with five years' imprisonment and the chiffre 4 fine.

Article 389-3 punishes fraudulently introducing, damaging, erasing, deteriorating, modifying, altering, deleting, extracting, holding, reproducing, transmitting or rendering inaccessible computer data, or acting to modify or suppress its processing or transmission mode, with five years and the chiffre 4 fine; Article 389-4 punishes knowingly using data so damaged, erased, deteriorated, modified or altered with the same penalty.

Article 389-5 punishes technically intercepting non-public data transmissions to, from or within an information system, including electromagnetic emissions carrying such data, with three years and the chiffre 4 fine.

Article 389-6 punishes fraudulently producing, importing, holding, offering, transferring, disseminating, obtaining for use, or making available a device, tool, or password or access code principally designed or adapted to commit the offences at Articles 389-1 to 389-5, with the penalty for the underlying offence or the most severely punished one, subject to an exemption for authorized testing, research, or protection of an information system.

Article 389-7 punishes fraudulently introducing, altering, erasing or deleting computer data to produce inauthentic data with intent that it be relied on as authentic, with five years and the chiffre 4 fine. Article 389-8 punishes fraudulently causing financial harm to another through data manipulation or system interference with intent to obtain an unlawful economic benefit, with five years' imprisonment and the chiffre 4 fine, whose maximum may be raised to the amount of the profit realised.

Article 389-9 punishes participating in an organized group or agreement formed to prepare, commit, facilitate, or receive the proceeds of one or more of the offences at Articles 389-1 to 389-8 with the penalty for the offence itself or the most severely punished one. Article 389-11 sets the fine for a legal person at up to 1,000,000 euros.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (246 words)

Monaco has no press-publisher neighbouring right and no mandatory platform-to-publisher bargaining code. Monaco is not a European Union or European Economic Area member state, so the EU Digital Single Market Copyright Directive's Article 15 neighbouring right, and any national transposition of it, has no domestic force in Monaco absent its own implementing statute, and none has been identified.

Monaco's copyright statute, Loi n. 491 du 24 novembre 1948 sur la protection des oeuvres litteraires et artistiques, as amended, is the only law reaching an aggregator's reproduction of news content: it permits a press outlet to reproduce a topical article on economic, political or religious discussion, and permits short quotations from newspapers and periodicals even in the form of a press review.

The 1948 law predates the concept of a machine-readable text-and-data-mining reservation, and no text-and-data-mining exception or opt-out mechanism has been added to it since. No Monaco statute or reported decision addresses whether a hyperlink is itself a communication to the public, or whether framing or inline display changes the answer, and no hot-news or misappropriation doctrine distinct from ordinary copyright law has been identified.

Monaco's press-freedom statute, Loi n. 1.299 du 15 juillet 2005 sur la liberte d'expression publique, separately provides that reproducing an imputation already judged defamatory is presumed made in bad faith absent proof to the contrary; this is a defamation-liability rule rather than one of the six mechanisms this topic tracks, so it is noted here rather than recorded as an instrument.

Snippet reproduction

Loi n. 491 du 24 novembre 1948, Quotation and Press-Review Exceptions

Loi n. 491 du 24 novembre 1948 sur la protection des oeuvres litteraires et artistiques, art. 15 et 16Official consolidated text of Loi n. 491 du 24 novembre 1948, legimonaco.mc

In force since 29 November 1948. Binds public and private bodies.

What this law does

Article 15 permits a topical article on economic, political or religious discussion to be reproduced by the press unless reproduction of it is expressly reserved, with the source always to be clearly indicated; short quotations from newspaper articles and periodical collections are permitted even in the form of a press review.

Article 16 permits publishing borrowings from a literary or artistic work, with the source and author named, where the publication has a scientific or educational character or constitutes an anthology (chrestomathie).

Article 21 defines counterfeiting (contrefacon) as any publication, reproduction or other divulgation, whole or partial, of a literary or artistic work made in bad faith and in disregard of the author's patrimonial or moral rights, expressly including an adaptation or arrangement that keeps a work's characteristic features without itself presenting the character of a new original work.

Article 23 punishes counterfeiting with the fine under Code penal article 26 chiffre 3, and Article 24 applies the same penalty to distributing, exhibiting, importing or exporting a counterfeit work. Article 28 makes prosecution for an offence under this law conditional on a complaint by the author or his successors in title.

The law carries no text-and-data-mining exception or machine-readable opt-out mechanism, and a reproduction of a literary or artistic work outside the closed exceptions of Articles 15 and 16 requires the author's authorization under the general reproduction right of Article 3.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.