
DPO Forum Monaco: 24 September
Monaco's first DPO Forum runs on 24 September 2026, opened by the APDP. What the agenda signals about enforcement — and what to fix before you go.
A first edition, and the timing is the point
On Thursday 24 September 2026, Le Méridien Beach Plaza hosts the first DPO Forum Monaco — a single day built around personal data protection, cybersecurity and artificial intelligence, running from 9:30 through the late afternoon.
A new conference in the Principality is not usually news. This one earns attention for a narrower reason: the opening slot belongs to Agnès Lepaulmier, Secretary General of the APDP, presenting Law n° 1.565 and the authority that enforces it.
Monaco's data protection regime is young. Law n° 1.565 of 3 December 2024, with its implementing Sovereign Ordinance n° 11.327 of 10 July 2025, replaced a framework most businesses had long stopped thinking about, and the APDP took over from the CCIN with a broader mandate and stronger powers. What does not yet exist in any volume is practice — the accumulated sense of what the regulator actually expects, which in older jurisdictions comes from years of decisions, sanctions and published guidance.
Until that body of practice builds up, listening to the authority describe its own priorities in a room of practitioners is the cheapest research a Monaco business can do.
What the agenda signals
The programme is worth reading as a document in its own right. A first edition's agenda tends to reflect what the organisers believe the local market is genuinely worried about, and this one leans in a clear direction.
Three round tables anchor the day. The first, on data protection in the Principality, pairs the APDP with practitioners — Marion Soler of the Data Protection Club and Alexandre Pechenet, a DPO and compliance director — under a title promising legal framework and concrete application. The second turns to AI and digital trust, moderated by Antoine Mahérault of the AFCDP. The third, run with Clusir Sud PACA and ADIM, asks how organisations get from regulatory requirements to actual resilience. A separate session by Saber Othmani of DPOption makes the case that AI governance is a precondition for controlling AI systems, not a document produced after they are already in use.
Read together, the emphasis has moved off paperwork. The 2025 conversation in Monaco was about registers, privacy notices and whether you needed to appoint a DPO. The 2026 conversation is about whether any of that survives contact with the systems a business is actually running — and AI is where the pressure sits.
Who should actually go
Nominally this is an event for Data Protection Officers, internal and external. In practice the useful attendee list is wider: whoever signs off your tools, whoever owns the website, and whoever would have to write the incident notification if something went wrong at 6pm on a Friday.
In a Monaco SME that is often two or three people wearing other hats — a managing director, an office manager, an external IT provider. Those are precisely the people who benefit most, because the day is structured around translation: what the text says, versus what you do on Monday. Sessions run in French.
If you have already appointed a DPO, send them and send someone operational alongside. The recurring failure mode in small organisations is a compliance lead who understands the law but has no visibility into which SaaS tools marketing signed up for last quarter.
Four things worth checking before 24 September
Walking in with your own situation mapped turns a conference into a working session.
Your processing register. Not whether it exists — whether it matches reality. Most registers are accurate on the day they are written and stale within a quarter. Compare it against the tools currently connected to your site and your CRM.
Your consent layer. Tag managers, analytics, pixels, chat widgets, embedded booking systems. Cookie banners in the Principality frequently fire trackers before any choice is made, which undermines the whole exercise. This is a technical check, not a legal one — our note on cookie consent for Monaco websites covers the mechanics, and it is worth pairing with a proper review of your data protection compliance posture.
Your AI inventory. List every AI tool in use across the business, including the ones nobody formally approved. For each: what data goes in, where it is hosted, and whether it retains inputs. Most companies discover the list is longer than expected. If you are still building that stack deliberately, do it with governance attached — that is the argument the AI automation side of the day will keep returning to.
Your breach procedure. Who decides it is a breach, who contacts the APDP, and how fast. If the honest answer is "we'd figure it out", the round table on resilience is your session.
Where Monaco differs — and it matters in the room
Several agenda items reference NIS2, the Cyber Resilience Act and the EU AI Act. Worth being precise about why they appear: Monaco is not an EU member state, and these instruments do not apply to Monegasque businesses automatically the way they do to French or Italian ones.
They still matter here, through three routes. Your customers or parent group may be EU-based and pass obligations down contractually. Your suppliers are frequently EU vendors adapting their products to those rules. And Monegasque law has consistently drawn on European standards while adapting them to local text — Law 1.565 being the clearest example.
The practical consequence: do not assume French guidance transfers verbatim, and do not assume it is irrelevant either. Where the answer affects a real decision, verify it with a Monegasque lawyer or specialist adviser rather than a search result.
Practical details
The forum takes place at Le Méridien Beach Plaza, 22 avenue Princesse Grace, on Thursday 24 September 2026. Registration is handled online, with tickets at a modest rate for end-user organisations, reduced pricing for members of partner associations such as the AFCDP and the Data Protection Club, a higher tier for vendors, and a limited number of complimentary places. Pricing, programme and speaker line-up can change — confirm the current details with the organisers before booking.
For a first edition, the value is less in the slides than in the room: the APDP, the local DPO community and the security practitioners who work with Monaco businesses, in one place, before the practice hardens.
If reviewing your site's tracking, consent handling or AI tooling ahead of the forum would be useful, get in touch — a short technical audit is usually enough to tell you where you stand.
Related services