Compliance Node Overview
Monaco's Law No. 1.165 of 17 December 1993 on the Automated Processing of Personal Information, significantly reformed by Law No. 1.353 of 4 December 2008 (entering into force in 2009) and further updated by subsequent sovereign ordinances and legislative amendments progressively aligning Monaco's data protection framework with European standards, constitutes Monaco's primary personal data protection legislation. Monaco is a sovereign microstate in Western Europe with a civil law legal system closely associated with France; although not a member of the European Union, Monaco participates in the EU Customs Union and has deep economic and institutional ties with France and the EU, driving progressive alignment of Monaco's data protection framework with EU GDPR standards. The supervisory authority is the Commission de Contrôle des Informations Nominatives (CCIN), an independent constitutional institution established under Monaco's legal framework whose mandate covers oversight and enforcement of personal data protection standards throughout the Principality. Key features of Monaco's personal data protection framework as amended: (1) Scope - applies to personal data processing by persons established in Monaco or processing data of individuals in Monaco; (2) Data processing principles - processing must comply with: lawfulness; purpose limitation; proportionality; accuracy; storage limitation; and security; (3) Sensitive personal data - enhanced protection for: racial or ethnic origin; political opinions; religious or philosophical beliefs; trade union membership; health status; sexual life; criminal records; and financial status; (4) Lawful processing conditions - consent; contractual necessity; legal obligation; vital interests; public interest; or legitimate interests; (5) Data subject rights - right of access; right to rectification; right to deletion; and right to object to processing; (6) CCIN notification - controllers must notify the CCIN before commencing processing activities; the CCIN maintains a register of processing activities; (7) Security obligations - controllers must implement technical and organisational security measures appropriate to the risk; (8) Cross-border transfers - personal data may only be transferred outside Monaco to countries providing adequate protection or with CCIN authorisation; (9) CCIN enforcement - investigates complaints, conducts inspections, issues recommendations and formal notices, and may impose sanctions; and (10) Progressive GDPR alignment - Monaco's framework has been progressively aligned with EU GDPR standards through successive legislative reforms reflecting Monaco's close relationship with the EU. Monaco's data protection framework supports its position as a leading wealth management, private banking, and luxury services centre serving high-net-worth individuals from across Europe and beyond.
Pillar: Cybersecurity · Authority: Commission de Contrôle des Informations Nominatives - CCIN (Monaco) · Version: 1.0.0 · Last updated:
Primary source: https://www.ccin.mc/
SHA-256 integrity: 37f5de76f8eb74138469e56c888453bcef3768bd5176c3547139456cd76eed90
Primary Citations — 7 traced to source
- Law No. 1.165 of 17 December 1993 on Automated Processing of Personal Information as amended by Law No. 1.353 of 4 December 2008 and subsequent sovereign ordinances (Monaco) - processing principles: lawfulness, purpose limitation, proportionality, accuracy, storage limitation, security; sensitive personal data: racial/ethnic origin, political opinions, religious beliefs, trade union membership, health, sexual life, criminal records, financial status; data subject rights: access, rectification, deletion, objection; CCIN pre-processing notification required; prior CCIN authorisation for sensitive data processing; cross-border transfer restrictions; CCIN enforcement authority
- Commission de Contrôle des Informations Nominatives - CCIN (Monaco) - independent constitutional supervisory authority established under Monaco's legal framework; mandate covers oversight and enforcement of personal data protection standards; receives processing notifications; maintains public register of notified processing; grants prior authorisation for sensitive and high-risk processing; investigates complaints; conducts inspections; issues formal notices and recommendations; imposes sanctions; ccin.mc is the official CCIN portal
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.