Data Breaches in Monaco: 72 Hours
Compliance & Data Protection·6 min read·29 July 2026

Data Breaches in Monaco: 72 Hours

The APDP reports a sharp rise in notified breaches in 2026. What Monaco businesses must do in the first 72 hours under Law No. 1.565 — and how to prepare.

Monaco's data protection authority, the APDP, has publicly noted a significant increase in the number of personal data breaches notified to it since the beginning of 2026. That is not necessarily a sign that Monaco has become less safe — it is mostly a sign that businesses are finally learning the obligation exists. Law No. 1.565 of 3 December 2024 introduced a duty that many Monegasque companies still have not built a process for, and the moment you discover you need it is the worst possible moment to invent it.

This article is about the practical shape of that duty: what counts as a breach, what the 72-hour clock actually means, and what you should have ready before anything goes wrong.

What counts as a breach — it is broader than you think

Most owners picture a data breach as a hacker exfiltrating a customer database. That is one version. The legal definition is far wider, and covers any security incident leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data.

In practice, the incidents that actually reach authorities look mundane:

  • An employee emails a client list to the wrong recipient.
  • A newsletter goes out with every address in the "To" field instead of BCC.
  • A laptop or unencrypted USB stick is lost in a taxi.
  • A former employee's account is never deactivated and is used months later.
  • A misconfigured backup, form or cloud folder leaves data publicly reachable.
  • Ransomware encrypts your files — loss of access is itself a breach, even if nothing was copied out.

Note that the reflex "nothing was stolen, so nothing happened" is wrong. Losing access to data, or losing its integrity, counts.

The 72-hour clock, precisely

Article 32 of Law No. 1.565 requires the data controller to notify the APDP of a personal data breach without undue delay and, where feasible, within a maximum of 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of the people concerned. If you notify later than 72 hours, the notification must be accompanied by the reasons for the delay.

Three details matter for how you plan:

The clock starts at awareness, not at the incident. If a breach happened in March and you discover it in July, the countdown starts in July. Which means detection capability is not a technical nicety — it directly determines your legal exposure.

Seventy-two hours includes weekends. A Friday evening discovery does not give you until Wednesday. If nobody in your organisation is empowered to act outside office hours, you have a problem before you have an incident.

The notification must carry substance. It should describe the nature of the breach including, where possible, the categories and approximate number of people affected, and give the name and contact details of your data protection officer or another point of contact from whom more information can be obtained. The APDP publishes a notification form and contact details on its own site — use them rather than improvising.

You are not expected to have the full forensic picture in 72 hours. You are expected to report promptly and complete the picture as it emerges.

When you also have to tell the people affected

Notifying the regulator is one obligation. Article 32 also addresses telling the individuals themselves, without undue delay, where the breach is serious enough for them. That communication has to describe the breach in clear, plain language and cover the likely consequences and the measures you have taken.

The law contemplates exceptions — broadly, where the data was already protected by measures such as encryption that render it unintelligible to anyone unauthorised, where individual contact would require disproportionate effort (a public communication may then be used instead), or where subsequent measures mean the risk is no longer likely to materialise. The APDP can nonetheless require you to inform people.

The exact thresholds and how they apply to your particular incident are a matter for a qualified adviser — do not decide alone, under pressure, that your case fits an exception. That is precisely the judgement call regulators scrutinise afterwards.

The register you must keep even when you don't notify

This is the obligation most businesses miss entirely. Article 32 requires the controller to document every personal data breach — including the ones you conclude are not notifiable — recording the facts, the effects and the remedial action taken. The APDP publishes a downloadable register template, so there is no excuse for a blank page.

The register is what turns a defensible decision into a provable one. If you assessed an incident as low risk and chose not to notify, the register is your evidence that you assessed it at all. Without it, "we judged it wasn't serious" is indistinguishable from "we didn't notice."

Getting ready before it happens

A breach response is a business process with a technical component, not the other way round. What is worth having in place:

  • A named decision-maker and a deputy, reachable outside working hours, with the authority to notify.
  • A one-page internal procedure: who is told, in what order, and what gets recorded.
  • An asset map — what personal data sits in your website, CRM, booking tool, mailing platform and backups, and who your processors are. If that data is spread across disconnected tools, it is a good reason to consolidate your email marketing and CRM setup.
  • Contracts with your suppliers requiring them to alert you fast. Your host, agency and payment platform will often detect an incident before you do.
  • Basic technical hygiene: current software, enforced updates, restricted admin accounts, encrypted devices, tested backups. Most of this is ordinary website maintenance rather than a special project, and it is what lets you say honestly that data was protected.
  • Reduced surface area: if your online store or forms collect data you never use, stop collecting it. Data you do not hold cannot leak.

A Monaco-specific reminder

Monaco is not an EU member state and is not under the GDPR. It has its own framework — Law No. 1.565 of 3 December 2024, supervised by the APDP — built to a comparable standard but distinct, with its own texts, forms and expectations. Advice written for French or EU companies is a useful analogy and a poor substitute. And if you use processors outside Monaco, the obligations still fall on you as controller.

If you would like a clear-eyed look at where personal data actually sits in your website, store or client systems — and what you could realistically tell the APDP within 72 hours — get in touch. We can help you align the technical side of your APDP compliance before you need it; for legal interpretation of Law No. 1.565, consult a qualified Monegasque adviser.

data protectionapdpcompliancemonaco
BSS Digital Agency

BSS Digital Agency

Digital agency based in Monaco. Web, apps, AI, marketing.

Get in touch