19/02/2026

Data Protection Essentials #1 – GDPR and Law No. 1.565 – common inspiration, distinct approaches

Phoenix Data Protection Essentials #1

Today’s focus: GDPR and Law No. 1.565 – common inspiration, distinct approaches

Monaco’s law on personal data protection is often presented as a “local GDPR”.

In practice, however, certain differences must be taken into account by Monaco-based businesses.

1️⃣ Purpose of the frameworks

👉 GDPR: to harmonise the rules and enable the free movement of personal data within the EU.
💡 Approach: harmonisation.

👉 Law No. 1.565: to ensure a level of protection equivalent to that provided by the GDPR while establishing Monaco’s own legal framework.
💡 Approach: sovereignty.

2️⃣ Intervention of the supervisory authority

👉 GDPR: no prior authorisation. Organisations consult the supervisory authority only where a high residual risk remains.
💡 Approach: organisations act first; the supervisory authority intervenes primarily afterwards (during inspections).

👉 Law No. 1.565: prior authorisation requirements apply to certain sensitive processing activities (criminal offence data, biometric data and health data).
💡 Approach: the supervisory authority may intervene before the processing activity is implemented, not only during an inspection.

3️⃣ Administrative sanctions

👉 GDPR: up to €20 million or 4% of worldwide annual turnover.
💡 Approach: a single maximum penalty.

👉 Law No. 1.565: up to €5 million or 2% of worldwide annual turnover, or up to €10 million or 4% of worldwide annual turnover.
💡 Approach: a two-tier system of maximum penalties depending on the nature of the infringement.

4️⃣ International data transfers

👉 GDPR:
A list of countries recognised as providing an adequate level of protection by the European Commission (27 EU Member States and 15 third countries),
Alternative transfer mechanisms through Standard Contractual Clauses.
💡 Hierarchical approach.

👉 Law No. 1.565:
A separate list of adequate countries: 27 EU Member States and 15 third countries (distinct from the EU list),
Equivalent contractual mechanisms currently being adapted.
💡 A hierarchical approach currently being adapted.

⚠️ A transfer that complies with the GDPR does not necessarily comply with Monaco law.

➡️ In practice

This new regulatory framework is still recent and is therefore expected to evolve.

At present, the differences between the EU and Monaco have a direct impact on the international exchanges of Monaco-based businesses. Compliance is becoming a key factor in building trust.