APDP Public Notice: What It Means
Compliance·7 min read·11 September 2026

APDP Public Notice: What It Means

Monaco's APDP has published a formal notice over a mishandled data access request. What every Monaco business should fix before it receives one.

On 10 September 2026, the President of Monaco's data protection authority, the APDP, published a public formal notice (mise en demeure publique) against the International School of Monaco. The organisation has 15 days from receipt to hand over the personal data it failed to provide. The closure of the notice will be published too, and the decision is due to be anonymised six months after publication.

The details of the case matter less than what it signals. Law No. 1.565 of 3 December 2024 gave the APDP the power to name organisations that fall short, and it has now used it. The trigger was not a data breach, a hacked server or a rogue marketing campaign. It was something far more ordinary: a data subject access request that was answered late, partially and without the mandatory information. If your business could not produce a complete answer to such a request within a month, this decision is written for you.

What happened, in short

According to the published decision, a parent emailed the school's data protection officer on 14 April 2026 asking for their child's administrative file, health data, and emails mentioning the child and family, plus the standard information on purposes, retention periods and recipients. The school replied on 13 May with some documents and information, but told the parent that only emails they had sent themselves — and that mentioned no third parties — could be released. No mention of the right to complain to the APDP was included.

The parent complained to the APDP on 22 May. The authority wrote to the school in July and August, spelling out the rules. By early September, the school was still saying that checks were "ongoing" and that the end of the summer break would make it easier to respond. The APDP found breaches of three articles of Law 1.565 — Article 10 (deadlines), Article 12 (content of the right of access) and Article 22 (accountability) — and made the notice public "given the seriousness of the breaches and the inaction of the controller despite the Authority's interventions".

Five rules the APDP has now spelled out

The decision reads like a checklist. Here is what it establishes for every organisation processing personal data in Monaco:

  1. The clock starts when the email lands. A request sent by email is deemed received on the date the email arrives — not when someone reads it, logs it or forwards it. The school argued it had received the request nine days later; the APDP disagreed.
  2. One month means one month. The controller must respond in writing within one month. The deadline can be extended by two months for complex or multiple requests, but the requester must be told, with reasons, inside that first month. An extension mentioned only in letters to the regulator does not count.
  3. "It's a lot of work" is not "complex". The APDP states plainly that the mere fact that a request requires significant effort does not make it complex within the meaning of the law.
  4. Emails are personal data. A blanket refusal to release emails is not acceptable. Emails where the requester is sender or recipient must be provided, with third-party names redacted if necessary. Emails that merely mention the person require a case-by-case assessment of third-party rights, with identities masked.
  5. The response has mandatory content. Article 12 lists what must be included: purposes, data categories, recipients, retention periods, the source of data not collected from the person, the existence of any transfer to a country without adequate protection, the rights to rectification and erasure, and the right to lodge a complaint with the APDP. Leaving items out is itself a breach.

The accountability finding is the one to worry about

The most uncomfortable part of the decision is the finding under Article 22, the accountability principle. The APDP's position is that a controller must have procedures that allow it to respond within the legal deadline "regardless of the time of year or the workload". Summer holidays, staff absences and a busy DPO are not defences.

The authority also noted inconsistencies between what the organisation told the regulator and what it had actually told the requester. When the APDP investigates a complaint about an individual's rights, it asks for the full correspondence between complainant and controller. Anything you claim to have done must be visible in that correspondence.

This is the point at which most Monaco SMEs are exposed. They have a privacy policy and a register of processing, often produced in the rush of late 2025. What they do not have is a repeatable process for the day a customer, employee, ex-employee or parent writes in and asks for everything you hold on them.

What a compliant process looks like

You do not need a legal department. You need a documented workflow that anyone in the business can follow:

  • A visible intake channel. A dedicated email address or a form on your website, referenced in your privacy policy, so requests do not get lost in a shared inbox. This is one of the things we build into every site alongside APDP-aligned data protection foundations.
  • Same-day logging. Record the date of receipt, the identity check performed and the deadline. Put the one-month date in a shared calendar.
  • A data map you can actually search. Know where personal data lives: website forms, CRM and email marketing platforms, HR software, booking tools, and the mailboxes of staff. If you cannot find it, you cannot disclose it.
  • A response template built on Article 12. Every item in the list, every time, including the sentence about the right to complain to the APDP.
  • An email search and redaction procedure. Decide in advance who runs the search, how third-party identities are masked, and how the results are delivered securely.
  • An extension letter template. If a request is genuinely complex, send a reasoned extension notice before day 30 — not a vague promise.
  • Cover for absences. Name a deputy for the DPO or the person handling requests, and test the process once a year.

Well-designed systems make this far easier. A modern website and CRM stack with a single customer record and export functions turns a two-week scramble into an afternoon's work.

What is at stake if you ignore it

A public formal notice is the corrective step, not the sanction. If a notice remains without effect, the APDP's restricted formation can impose compliance orders with daily penalties, restrictions on processing, and administrative fines that, for the most serious categories of breach, run to several million euros or a percentage of worldwide turnover. The exact thresholds and procedure should be confirmed with the APDP or a qualified adviser — but the direction of travel is clear.

Two reminders on context. Monaco is not an EU member state and the GDPR does not apply here by default; Law 1.565 is Monaco's own framework, built to comparable standards and enforced by the APDP, which replaced the CCIN. And this decision shows that enforcement now includes reputational exposure: the organisation's name is on the regulator's website today.

If you want a clear picture of where personal data sits across your website, CRM and mailboxes — and a request-handling process your team can run without you — get in touch. We build and maintain the systems that hold this data, and we work alongside legal advisers for the specifics of the law.

data protectionapdpcompliancemonaco
BSS Digital Agency

BSS Digital Agency

Digital agency based in Monaco. Web, apps, AI, marketing.

Get in touch