Law No. 1.565 of 3 December 2024 replaced Monaco's 1993 law on personal information. Nearly two years on, the data protection authority (Autorité de protection des données personnelles, APDP) has taken a position on several practical points: a first public formal notice, a reminder on breach notification, a ban on one use of biometrics and a critical opinion on data transfers outside Europe. Read together, these texts show what the authority already expects of businesses established in Monaco.
The framework
Law No. 1.565 of 3 December 2024 was published in the Journal de Monaco on 13 December 2024. It replaces the former system of prior formalities with a principle of accountability: the controller ensures that processing complies with the law "and is able to demonstrate it" (Art. 22).
Infringements are punishable by an administrative fine of up to EUR 5 million or, for an undertaking, 2% of total worldwide annual turnover for the preceding financial year, whichever is higher. The cap rises to EUR 10 million or 4% for other infringements, including those concerning data subject rights and transfer rules (Arts. 53 and 54).
1. The one-year grace period was narrower than it seems
The law granted a one-year period, which ended in December 2025, but not to everyone and not for everything. It only benefited processing already lawfully implemented with the former supervisory Commission (Commission de contrôle des informations nominatives) and still in operation. It only covered the principles in Chapter II of the law, provided the processing had not been substantially modified, as well as the record of processing activities and the data protection officer (Art. 109, referring to Arts. 27 to 30 and Art. 31(4)).
For the impact assessment required to reassess risks, the period is three years, until December 2027.
Everything else has applied since the law entered into force: a written contract with each processor (Art. 26), security measures (Art. 31), breach notification (Art. 32) and the rights of data subjects (Arts. 10 et seq.). Processing that was never declared under the former law benefited from no grace period at all.
2. An access request is handled within a month, not after the summer
On 10 September 2026, the President of the APDP issued the authority's first public formal notice, against a private school. A parent had requested access to their child's data on 14 April 2026, including emails concerning the child.
The reply of 13 May was partial; nearly five months after the request, it had still not been met. The decision sets several benchmarks.
- The time limit is one month from receipt of the request. A request by email is deemed received on the date the email is received: the authority used 14 April, the date of the email, not 23 April, the date on which the school said it had received it. In the case of a complex request or multiple requests, the period may only be extended by two months if the person is informed, with reasons, within the first month (Art. 10).
- Complexity is not presumed: "the mere fact that responding to a request requires significant effort does not make the request complex".
- Emails cannot be refused as a matter of principle. Those the person sent or received are disclosed, where appropriate with third parties' names redacted; those that merely mention the person are reviewed case by case.
- The reply includes all the information required by law, including the right to lodge a complaint with the APDP (Art. 12).
The school relied on the summer period. The authority replied that the controller must ensure that, "whatever the time of year or the workload, the legal time limits will be met", and found a breach of the accountability principle (Art. 22).
The formal notice, with a fifteen-day deadline, was made public because of the seriousness of the breaches and the school's inaction despite the authority's interventions (Art. 50).
3. A breach is notified before it is fully understood
On 16 July 2026, the APDP noted a significant increase in data breaches notified after more than 72 hours without real justification. It stated that exceeding the time limit "cannot be justified by waiting for the results of ongoing technical analyses or for internal investigations to be completed" (Art. 32).
Notification may be made in stages: a brief summary as soon as the controller becomes aware of the incident, with detailed information to follow. The controller records the exact date and time it became aware, and the steps taken until notification.
Every breach is also recorded in a register, even where it does not have to be notified; the APDP publishes a template.
4. What was permitted yesterday may no longer be
Since the law entered into force, using biometric data to monitor working hours is no longer permitted, including where hand geometry is used (APDP statement of 16 March 2026). Such data is sensitive where it is used to identify a person (Arts. 2 and 7).
An employer may only process it where strictly necessary to control access to workplaces, devices and applications (Art. 7). Such systems are deemed likely to present a high risk (Ministerial Order No. 2025-361 of 14 July 2025): a prior impact assessment is required, documenting the choice of biometrics over a less intrusive technology.
Biometric access systems installed before the law have three years to undergo this assessment. Biometric time clocks, however, must be replaced.
5. A transfer outside Europe cannot rely on EU law alone
Transfers to a country outside the European Union require Monaco to have found that the country offers adequate protection, through a list set by ministerial order after an opinion from the APDP (Art. 97). Until that order is adopted, the list drawn up in 2009 by the former Commission still applies.
Consulted on the draft list, the APDP issued a critical opinion (Deliberation No. 2026-07 of 20 May 2026). The draft copies the European Union's list without any analysis of its own, whereas EU decisions protect data transferred from the Union, not data collected in Monaco.
The authority notes in particular that the EU-US Data Privacy Framework does not apply to data collected in the Principality, and that Monaco businesses working with US companies enter into additional contractual commitments. It asks for at least the United States, Japan, South Korea, Brazil and Israel to be removed.
The order has not yet been published. In practice, a tool hosted or administered outside Europe cannot rely on EU adequacy alone: the transfer must rest on one of the safeguards provided by Monaco law (Art. 98) or, failing that, on one of the strictly limited derogations (Art. 99).
The EU standard contractual clauses do not settle the matter either. Pending the standard protection clauses it is to adopt, the APDP states that the EU clauses "are not sufficient to safeguard a transfer of data from the Principality of Monaco to a country without an adequate level of protection".
6. What this means in practice
For a business established in Monaco, these positions translate into six points to check.
- Identify processing that never had a grace period. Only processing already declared to the former Commission had one year to comply. Processing that had never been declared, and all processing set up since, had to comply as soon as the law came into force.
- Put every provider handling data under contract. Any provider processing data on the business's behalf must be bound by a written contract: what it may do with the data, how it protects it, what happens to it at the end of the engagement.
- Be able to answer an access request within one month. The time limit runs from receipt, even during holidays. It must be clear who receives the request, who gathers the data, emails included, and who replies, with all the information required by law.
- Notify a breach without waiting for the investigation to end. The 72-hour time limit does not stretch to cover internal analyses: a brief initial notification, completed later, is expected. The time the incident was discovered is recorded, and every incident is logged in a register, even when it does not have to be notified.
- Replace biometric time clocks. Biometrics can no longer be used to monitor working hours. They remain possible for access to premises, devices and applications, but only after an impact assessment.
- Check what each transfer outside Europe relies on. A tool hosted or administered outside the European Union can rely neither on EU adequacy decisions nor on the EU standard contractual clauses alone. Each transfer must rest on a safeguard provided by Monaco law or, failing that, on one of the few exceptions allowed.
Conclusion
The APDP's first public formal notice concerns neither a massive leak nor a sophisticated technology. It concerns an access request left unanswered and a one-month deadline that was not met. As with anti-money laundering, the requirement is not only to comply, but to be able to demonstrate it.
Anthony Raymond · October 2026
General information, not legal advice. Quotations from the law and from APDP documents are our translation of the French originals. For a question about your situation: contact form.
Sources
- Law No. 1.565 of 3 December 2024 on the protection of personal data, Arts. 2, 7, 10, 12, 22, 26 to 32, 50, 53, 54, 97 to 99 and 109 (Legimonaco).
- Ministerial Order No. 2025-361 of 14 July 2025.
- APDP, public formal notice of 10 September 2026 (apdp.mc).
- APDP, statements of 16 March 2026 (biometrics and working hours) and 16 July 2026 (breach notification); breach register template (July 2025).
- APDP, Deliberation No. 2026-07 of 20 May 2026, opinion on the draft ministerial order setting the list of countries with an adequate level of protection; practical sheet "Transfers: update on standard protection clauses" of 22 May 2026 (apdp.mc).