Phoenix Data Protection Essentials #1
Today’s focus: GDPR and Law No. 1.565 – common inspiration, distinct approaches
Monaco’s law on personal data protection is often presented as a “local GDPR”.
In practice, however, certain differences must be taken into account by Monaco-based businesses.
1️⃣ Purpose of the frameworks
👉 GDPR: to harmonise the rules and enable the free movement of personal data within the EU.
💡 Approach: harmonisation.
👉 Law No. 1.565: to ensure a level of protection equivalent to that provided by the GDPR while establishing Monaco’s own legal framework.
💡 Approach: sovereignty.
2️⃣ Intervention of the supervisory authority
👉 GDPR: no prior authorisation. Organisations consult the supervisory authority only where a high residual risk remains.
💡 Approach: organisations act first; the supervisory authority intervenes primarily afterwards (during inspections).
👉 Law No. 1.565: prior authorisation requirements apply to certain sensitive processing activities (criminal offence data, biometric data and health data).
💡 Approach: the supervisory authority may intervene before the processing activity is implemented, not only during an inspection.
3️⃣ Administrative sanctions
👉 GDPR: up to €20 million or 4% of worldwide annual turnover.
💡 Approach: a single maximum penalty.
👉 Law No. 1.565: up to €5 million or 2% of worldwide annual turnover, or up to €10 million or 4% of worldwide annual turnover.
💡 Approach: a two-tier system of maximum penalties depending on the nature of the infringement.
4️⃣ International data transfers
👉 GDPR:
A list of countries recognised as providing an adequate level of protection by the European Commission (27 EU Member States and 15 third countries),
Alternative transfer mechanisms through Standard Contractual Clauses.
💡 Hierarchical approach.
👉 Law No. 1.565:
A separate list of adequate countries: 27 EU Member States and 15 third countries (distinct from the EU list),
Equivalent contractual mechanisms currently being adapted.
💡 A hierarchical approach currently being adapted.
⚠️ A transfer that complies with the GDPR does not necessarily comply with Monaco law.
➡️ In practice
This new regulatory framework is still recent and is therefore expected to evolve.
At present, the differences between the EU and Monaco have a direct impact on the international exchanges of Monaco-based businesses. Compliance is becoming a key factor in building trust.




