Law / San Marino

San Marino

8 of 10 named instruments researched to a stage, across three of the six areas of law we track: 8 in force. As of 19 September 2026.

  1. AI law none researched
  2. Privacy law 6
  3. Scraping law 1
  4. Cybersecurity law none researched
  5. Age gating law none researched
  6. News aggregation law 1

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law6 instruments, 6 in force

Research summary (115 words)

San Marino is not a General Data Protection Regulation (GDPR) jurisdiction. Its comprehensive regime is Law No. 171 of 21 December 2018 on the Protection of Natural Persons with regard to the Processing of Personal Data, confirmed at primary source and found to be a close structural clone of the GDPR, in several places sharing GDPR's own article numbers for the same content. San Marino does not currently hold an EU adequacy decision.

Primary text confirms biometric data as an explicit special category with a full permitted-exceptions list, a complete GDPR Article 22 equivalent right against solely automated decisions, a GDPR Chapter V-style cross-border transfer regime, 72-hour breach notification, and a full GDPR Article 82 equivalent civil damages right.

Breach notification

San Marino Law No. 171, personal data breach notification

Legge 21 dicembre 2018 n. 171, articoli 34-35 (violazione dei dati personali)English-translation PDF hosted by dataguidance.com, read in full (201,720 characters, not truncated)

In force since 21 December 2018. Binds public and private bodies.

What this law does

Article 34(1) requires the controller, in the case of a personal data breach, to notify it to the Data Protection Authority without undue delay and, where feasible, not later than 72 hours after having become aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons, and to accompany a later notification with reasons for the delay.

Article 34(2) requires the processor to notify the controller without undue delay after becoming aware of a breach, and article 34(3) fixes what the notification must describe: the nature of the breach including, where possible, the categories and approximate number of data subjects and of personal data records concerned, the name and contact details of the data protection officer or other contact point, the likely consequences, and the measures taken or proposed to address it and mitigate its adverse effects.

Article 34(5) requires the controller to document every breach, its effects and the remedial action taken.

Article 35(1) requires the controller to communicate the breach to the data subject without undue delay where it is likely to result in a high risk to the rights and freedoms of natural persons, in clear and plain language, and article 35(3) excuses that communication only where protective measures such as encryption render the data unintelligible, where subsequent measures make the high risk no longer likely, or where it would involve a disproportionate effort and a public communication of equal effect is made instead.

Law 171/2018 was approved by the Great and General Council on 12 December 2018 and promulgated by the Captains Regent on 21 December 2018, the date carried in the law's own official title, and it states no separate entry-into-force clause, so that promulgation date is the day these provisions began to bind.

What it requires

Comprehensive regime

San Marino Law No. 171 on the Protection of Natural Persons

Legge 21 dicembre 2018 n. 171, articoli 1-7, 9-11 e 23-44 (principi, basi giuridiche e obblighi del titolare)English-translation PDF hosted by dataguidance.com, read in full (201,720 characters, not truncated)

In force since 21 December 2018. Binds public and private bodies.

What this law does

Article 3 fixes the law's territorial and material scope. Article 4 carries the processing principles and article 5 the lawful bases, while article 6 sets the conditions for valid consent and article 7 the conditions for a child's consent to an information society service. Articles 10 and 11 govern data on criminal convictions and processing that does not require identification.

Article 26 places responsibility for compliance on the controller, article 27 requires data protection by design and by default, article 28 governs joint controllers, article 29 the engagement of a processor and article 30 processing under the authority of either. Article 31 requires records of processing activities and article 32 cooperation with the Data Protection Authority. Article 33 requires technical and organisational measures giving a level of security appropriate to the risk.

Article 36 requires a data protection impact assessment where processing is likely to result in a high risk, and article 37 prior consultation of the Authority where the assessment shows that risk. Articles 38 to 40 govern the designation, position and tasks of the data protection officer, and articles 41 to 44 the codes of conduct, their monitoring, certification and certification bodies.

Law 171/2018 was approved by the Great and General Council on 12 December 2018 and promulgated by the Captains Regent on 21 December 2018, the date carried in the law's own official title, and it states no separate entry-into-force clause, so that promulgation date is the day these provisions began to bind.

What it requires

Cross border transfer

San Marino Law No. 171, transfers of personal data abroad

Legge 21 dicembre 2018 n. 171, articoli 45-50 (trasferimenti verso paesi terzi)English-translation PDF hosted by dataguidance.com, read in full (201,720 characters, not truncated)

In force since 21 December 2018. Binds public and private bodies.

What this law does

Article 45 permits a transfer of personal data to a foreign country or an international organisation only on the conditions this Title lays down, including for onward transfers from there to another country or organisation.

Article 46 governs transfer on the basis of a decision that the destination affords an adequate level of protection, article 47 transfer subject to appropriate safeguards such as standard data protection clauses, article 48 binding corporate rules and what they must specify, and article 49 the recognition of judgements and decisions of foreign countries.

Article 50 sets the narrow derogations that permit a transfer in the absence of an adequacy decision or appropriate safeguards, including the data subject's explicit consent after being informed of the risks, contractual necessity, important reasons of public interest, legal claims, vital interests, and a transfer from a public register.

Law 171/2018 was approved by the Great and General Council on 12 December 2018 and promulgated by the Captains Regent on 21 December 2018, the date carried in the law's own official title, and it states no separate entry-into-force clause, so that promulgation date is the day these provisions began to bind.

What it requires

Data subject rights

San Marino Law No. 171, rights of the data subject

Legge 21 dicembre 2018 n. 171, articoli 12-22 (diritti dell'interessato)English-translation PDF hosted by dataguidance.com, read in full (201,720 characters, not truncated)

In force since 21 December 2018. Binds public and private bodies.

What this law does

Article 13 fixes the information a controller gives when it collects personal data from the data subject, and article 14 the information due where the data came from elsewhere.

Article 15 gives a right of access, article 16 a right to rectification, article 17 a right to erasure described as the right to be forgotten, article 18 a right to restriction of processing, article 19 the duty to notify recipients of a rectification, erasure or restriction, article 20 a right to data portability and article 21 a right to object, including to direct marketing.

Article 22 gives the data subject the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them, and where a carve-out applies the controller must implement suitable measures to safeguard the data subject's rights, freedoms and legitimate interests, at least the right to obtain human intervention, to express a point of view and to contest the decision.

Articles 23 and 24 set the restrictions on those rights, including for reasons of justice, and article 25 carries the rights of deceased persons. Law 171/2018 was approved by the Great and General Council on 12 December 2018 and promulgated by the Captains Regent on 21 December 2018, the date carried in the law's own official title, and it states no separate entry-into-force clause, so that promulgation date is the day these provisions began to bind.

What it requires

Enforcement supervision

San Marino Law No. 171, the Data Protection Authority, remedies and fines

Legge 21 dicembre 2018 n. 171, articoli 51-75 (Autorita Garante, rimedi e sanzioni)English-translation PDF hosted by dataguidance.com, read in full (201,720 characters, not truncated)

In force since 21 December 2018. Binds public and private bodies.

What this law does

Articles 52 to 59 establish the San Marino Data Protection Authority, fix the fit and proper requirements of its members, guarantee its autonomy and independence, and set its competence, tasks and powers, and articles 60 to 63 let it request information and documents and carry out verifications, including special ones.

Article 65 sets the remedies open to a data subject, article 66 the complaint to the Authority, article 67 the decision on it, article 68 reporting, article 69 objection and article 70 judicial protection.

Article 71 entitles any person who has suffered material or non-material damage from an infringement of the law to compensation from the controller or processor, makes each controller involved liable for the damage caused by infringing processing, and makes a processor liable where it has not complied with obligations directed to processors or has acted outside the controller's lawful instructions, with joint and several liability where more than one is involved.

Article 72(1) subjects the controller's and processor's own obligations to administrative fines of up to five million euros or two per cent of total annual turnover of the previous financial year, whichever is higher, and article 72(2) sets the higher tier for the basic principles, the data subject's rights and the transfer rules. Article 73 fixes the procedure for imposing fines, and article 75 bars publishing or disseminating news or images identifying a child involved in legal proceedings.

Law 171/2018 was approved by the Great and General Council on 12 December 2018 and promulgated by the Captains Regent on 21 December 2018, the date carried in the law's own official title, and it states no separate entry-into-force clause, so that promulgation date is the day these provisions began to bind.

What it requires

Sensitive categories

San Marino Law No. 171, special categories of personal data

Legge 21 dicembre 2018 n. 171, articolo 8 (categorie particolari di dati personali)English-translation PDF hosted by dataguidance.com, read in full (201,720 characters, not truncated)

In force since 21 December 2018. Binds public and private bodies.

What this law does

Article 8(1) prohibits processing personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, and the processing of genetic data, of biometric data for the purpose of uniquely identifying a natural person, and of data concerning health or a natural person's sex life or sexual orientation.

Article 8(2) lifts that prohibition only in the cases it lists, which mirror the General Data Protection Regulation (GDPR)'s: the data subject's explicit consent to one or more specified purposes; obligations and rights in the field of employment, social security and social protection law; the vital interests of the data subject or another person where the data subject is incapable of consenting; processing in the course of the legitimate activities of a foundation, association or other not-for-profit body with a political, philosophical, religious or trade union aim, confined to its members and not disclosed onward without consent; data manifestly made public by the data subject; legal claims and courts acting judicially; substantial public interest; preventive or occupational medicine and the provision of health or social care by or under the responsibility of a professional bound by secrecy; public health; and archiving in the public interest, scientific or historical research or statistics.

Because the prohibition attaches to biometric data processed for unique identification, biometric material derived from an ordinary recording is not carved out of it. Law 171/2018 was approved by the Great and General Council on 12 December 2018 and promulgated by the Captains Regent on 21 December 2018, the date carried in the law's own official title, and it states no separate entry-into-force clause, so that promulgation date is the day these provisions began to bind.

What it requires

Scraping law1 instrument, 1 in force

Research summary (314 words)

San Marino has no scraping-specific statute, so general law governs each dimension separately.

Law No. 114 of 23 August 2016 inserted Article 182-bis into the Criminal Code, criminalising unlawful access to a computer or telematics system protected by security measures; because the offence's trigger is unlawful entry against a security measure, reading a public, unauthenticated page without defeating any access control falls outside a plain reading of the provision, and no reported San Marino decision has tested the point.

No San Marino court has ruled on the enforceability of a browsewrap or clickwrap terms-of-service against a scraper.

Law No. 8 of 25 January 1991 on copyright protection permits, as a free use, brief analysis and quotation justified by a critical, polemic, pedagogic, scientific or informative character, and separately permits reproduction of news and information in conformity with journalists' codes of conduct and source attribution, but San Marino has not enacted a text-and-data-mining exception of the kind now found in the EU's Digital Single Market Directive, so training a model on scraped copyrighted text rests only on those general free-use grounds.

The 1991 law confers no sui generis database right, and its neighbouring rights, added by Law No. 63 of 24 June 1997, cover only performers and artists, not compilations.

San Marino's comprehensive data protection statute, Law No. 171 of 21 December 2018, applies to personal data without a general carve-out for information the data subject has not manifestly made public, so scraping personal data from a public San Marino website remains subject to that law's lawful-basis and cross-border-transfer duties (see the privacy topic for that instrument).

No San Marino statute or reported case establishes a scraping-specific unfair-competition, misappropriation or trespass doctrine beyond the 1991 copyright law's narrow rule against reproducing the regular columns or repeating the title of a periodical, and none assigns legal weight to a robots.txt directive or imposes an AI-training-specific rule.

Computer misuse

Computer Crimes Law, Unlawful Access to Computer or Telematics Systems

Legge 23 agosto 2016 n. 114 (Computer Crimes), art. 2, inserting art. 182-bis of the Criminal CodeOfficial English translation of Law No. 114 of 23 August 2016, published by the Consiglio Grande e Generale (San Marino's parliament)

In force. Binds public and private bodies.

What this law does

Law No. 114 of 23 August 2016 introduced criminal-law protection against computer crimes by inserting new articles into the Criminal Code.

Article 182-bis punishes anyone who unlawfully enters a computer or telematics system protected by security measures, or remains there against the express or tacit will of the person entitled to exclude them, with second-degree imprisonment; the punishment rises to third-degree imprisonment for a public official, a private investigator, a system operator, or where violence or destruction of data is involved, and to third or fourth-degree imprisonment where the system is one of public interest.

A separate paragraph punishes, with first-degree imprisonment and a fine of up to 5,500.00 euro, anyone who holds or has access to means suited to enter a protected system in order to obtain an undue profit or cause damage, rising to second-degree imprisonment and a fine from 5,500.00 to 10,500.00 euro where the public-official or system-operator aggravating circumstance applies; a further paragraph punishes, with second-degree imprisonment and a fine of up to 10,500.00 euro, anyone holding or accessing without justified reason equipment or programmes designed to alter a system or its data.

Because the core offence's trigger is defeating a security measure or exceeding an express or tacit exclusion, a plain reading does not reach reading a public, unauthenticated page. The same law separately inserted an interception offence (art. 190-bis), a data and system damage offence (art. 203-bis), and a computer fraud offence (art. 204-ter) into the Criminal Code, not further detailed on this instrument.

The law's own text states that it enters into force on the fifth day following its legal publication, but no stated calendar day for that publication appears in the text, so no effective date is recorded.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (268 words)

San Marino has no press-publisher neighbouring right and no mandatory platform-to-publisher bargaining code; San Marino is not a European Union member state, so the Digital Single Market Directive's Article 15 neighbouring right has no domestic force absent its own implementing statute, and none has been identified.

Law No. 8 of 25 January 1991 on copyright protection, as amended, is the only law reaching an aggregator's reproduction of news content: it permits brief quotation of another work for a critical, polemic, pedagogic, scientific or informative purpose, and separately permits the reproduction of news and information generally, conditioned on conformity with journalists' codes of conduct and on the source being quoted, while separately prohibiting the reproduction of the regular columns of a periodical and the reuse of a periodical's own title within three years of its prior use.

No San Marino statute or reported decision addresses whether a hyperlink is itself a communication to the public, or whether framing or inline display changes the answer, and no hot-news or misappropriation doctrine distinct from ordinary copyright law has been identified. The 1991 law predates the concept of a machine-readable text-and-data-mining reservation, so no opt-out mechanism of that kind exists.

Law No. 211 of 5 December 2014 on publishing and the profession of media operators separately defines and licenses 'news outlets' and 'online news outlets', and excludes a site that only republishes articles not produced within the publication itself from that licensed category, but this is a professional-registration and licensing framework rather than a reproduction-rights mechanism, so it does not itself create or limit any of the six registered aggregation law families.

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.