
Do You Need a DPO in Monaco?
Monaco's Law 1.565 makes a Data Protection Officer mandatory for some businesses. How to tell whether yours is one — and what to do either way.
The question most Monaco businesses have not actually answered
Since Law No. 1.565 of 3 December 2024 came into the picture — with its implementing Sovereign Ordinance No. 11.327 of 10 July 2025 — most companies in the Principality have worked through the obvious items. Privacy notice: updated. Cookie banner: replaced. Processing register: started, at least.
The Data Protection Officer question tends to get postponed, because it looks binary and expensive: either you hire someone, or you hope nobody asks. That framing is wrong on both counts. For most Monaco SMEs the appointment is not legally required, and for the ones where it is, the role does not have to be a full-time hire.
What follows is how to work out which case you are in. It is an orientation, not legal advice — Monegasque data protection law is young, the APDP's practice is still forming, and anything close to the line deserves a lawyer or a specialist adviser.
When the appointment is mandatory
Under Article 29 of Law 1.565, designating a DPO — a délégué à la protection des données — is compulsory in three situations.
One: you are a public body or carry out a public mission. Public-law entities, private bodies entrusted with a general-interest mission, and public service concessionaires all fall in scope. Courts acting in their judicial capacity are excluded.
Two: your core activity involves regular, systematic monitoring of people on a large scale. The operative words are core activity. Tracking that is incidental to what you sell is different from tracking that is what you sell. A platform whose product is behavioural profiling is in scope; a restaurant with Google Analytics on its site is not.
Three: your core activity involves large-scale processing of sensitive data, or of data relating to criminal convictions and offences. Health data, biometric data, and data revealing beliefs or origins are the usual triggers here.
If none of the three describes your business, the appointment is voluntary. Most Monaco retailers, restaurants, agencies, real estate firms and hospitality operators land in that category — but read the second and third tests carefully before concluding it, because "large scale" is judged on volume, reach and duration, not on headcount.
Where Monaco businesses misjudge it
Three patterns come up repeatedly.
The first is assuming that a small company cannot be caught. Scale in this analysis refers to the processing, not the payroll. A five-person company running a wellness app with health records for tens of thousands of users is doing large-scale sensitive processing.
The second is the reverse: assuming that holding some sensitive data automatically requires a DPO. A clinic's own patient files, or an employer's sickness records, are sensitive — but they are not necessarily large-scale core activity processing in the sense the article means.
The third is the group structure. Monaco businesses frequently sit inside a wider international group. A shared DPO across group entities is workable, provided that person is genuinely reachable from each establishment. What does not work is naming a contact in another country whom your Monaco staff have never spoken to and who does not know what you process.
What the role actually involves
The DPO's brief under the law is advisory and supervisory rather than executive. The person informs and advises the organisation on its obligations, monitors compliance including through internal audits, advises on impact assessments where asked, acts as the APDP's point of contact, and cooperates with the Authority.
Three practical constraints follow. The DPO must have real expertise in data protection law and practice, proportionate to what you process, and must keep it current. The DPO must be able to report without being penalised for what they find. And the DPO must not sit in a position that creates a conflict of interest — which normally rules out the person who decides how and why the data is processed. In a small company, the IT manager or the marketing lead is usually the wrong choice for exactly that reason.
External DPOs are permitted, and for most organisations in scope in Monaco they are the sensible route: a fractional specialist with genuine Monegasque expertise, on a defined engagement, costs a fraction of a hire and is more likely to know current APDP practice than a repurposed internal manager.
If you do not need one, you still need the substance
The obligations that make a DPO useful apply whether or not you appoint one. The processing register, the lawful basis for each activity, the security measures, the breach notification path, the impact assessments for higher-risk processing — none of that is contingent on the appointment.
So the productive version of the question is not "must we appoint a DPO?" but "who owns this file, and do they have the time and standing to do it?" Naming an accountable person internally, even where the law does not compel it, is what turns compliance from an annual panic into a routine.
Note also the medium-term horizon: the law allows a phased period for completing the impact analyses required for higher-risk processing, with the outer deadline falling in December 2027. That sounds distant until you count how many processing activities a typical business has never formally documented.
A sequence that works
Start with the register, not the org chart. You cannot judge whether you meet the Article 29 tests until you know what you actually process — and building the register usually surfaces two or three activities nobody had thought about, typically in marketing tooling, recruitment, or CCTV.
Then apply the three tests honestly, and write down your reasoning either way. A short documented assessment concluding "not required, because…" is far better than silence if the APDP ever asks.
Then fix the gaps the register exposed. In practice these cluster in predictable places: consent capture on the website and its cookie and consent layer, the customer data sitting in your email marketing and CRM stack, third-country transfers hidden inside ordinary SaaS tools, and increasingly the AI tools staff have adopted without anyone assessing what personal data goes into them.
Then, and only then, decide on the appointment. If you are in scope, notify the APDP of your designated DPO and make their contact details available as required. If you are not, put the file on someone's objectives anyway.
The reasonable position for late 2026
Monaco's regime is close enough to European standards that most well-run practices transfer, and different enough that assuming GDPR guidance applies verbatim is a mistake — Monaco is not an EU member state, and Law 1.565 with the APDP is the framework that governs here. Penalties under the law are substantial, but enforcement pressure is not the strongest argument for getting this right. Client data in a market this small is reputational, and a mishandled breach travels faster in Monaco than anywhere.
If you want a clear read on your website, consent flows, CRM and analytics before you decide anything about a DPO, get in touch.
Related services