Monaco's Adequate Country List
Compliance·6 min read·13 August 2026

Monaco's Adequate Country List

Monaco is preparing the Ministerial Order listing countries with adequate data protection. The APDP has objected. What it means for Monaco businesses.

One Document Will Decide Where Your Data Can Go

Every Monaco business that uses a CRM, an email platform, a cloud host or an analytics tool is already sending personal data outside the Principality. Under Monaco's data protection law, whether that transfer is straightforward or requires extra contractual work depends on one thing: whether the destination country appears on Monaco's official list of countries offering an adequate level of protection.

That list is currently being rewritten — and the process has not been smooth. The draft Ministerial Order intended to establish it has been submitted, Monaco's data protection authority has reviewed it, and the authority raised serious objections. Until the order is published, the rules you operate under are older than most of the tools you use.

What Law 1.565 Actually Sets Up

Monaco's data protection framework is Law No. 1.565 of 3 December 2024. It is a modern, European-standard regime, but it is Monegasque law — Monaco is not an EU member state, and the GDPR does not apply to Monaco businesses by default. That distinction matters constantly in practice, because most compliance advice online is written for EU companies.

Article 97 of Law 1.565 sets out the mechanism: the list of countries, territories and international organisations considered to offer an adequate level of protection is adopted by Ministerial Order, after the opinion of the Autorité de Protection des Données Personnelles (APDP). The list is meant to be updated regularly and published both in the Journal de Monaco and on the APDP's website.

The logic is simple. If your data is going to a country on the list, the transfer rests on that adequacy finding. If it is not, you need another legal basis — typically contractual guarantees with your provider, plus documentation showing you assessed the risk.

Why the APDP Pushed Back

In May 2026, the APDP issued its opinion on the government's draft order (Deliberation No. 2026-07 of 20 May 2026). It was not a rubber stamp.

The authority's central criticism was that the draft list largely reproduces the European Union's own adequacy decisions — minus the European Patent Organisation — without an independent analysis of whether those foreign legal regimes actually protect data transferred from Monaco and the people that data belongs to. An EU adequacy decision assesses protection for data coming from the EU. It does not automatically say anything about data coming from the Principality.

The APDP also flagged that the draft imports the EU's partial adequacy findings — arrangements covering only certain sectors or certain types of data — without explaining what they mean in a Monegasque context, given that this partial mechanism does not exist as such in Monaco law. And it stated plainly that, in its view, data transferred to some of the countries on the government's proposed list would not in fact receive adequate protection.

The APDP's opinion is advisory rather than binding, so the final order may or may not follow it. But a documented disagreement between the government and the supervisory authority is a signal: this list may be revised, and it may be revised again after publication.

What Applies Right Now

Here is the part most businesses miss. Pending the publication of the new Ministerial Order, the previous list — established in 2009 by the CCIN, the APDP's predecessor — remains valid.

A list drawn up in 2009 predates essentially the entire modern cloud market. So if you are checking a destination country today, you are checking it against a document written before the mainstream adoption of the SaaS tools that now run marketing, sales and customer service — while a replacement sits in the pipeline.

The practical consequence: do not assume that because a provider is fine for a French or Italian company, it is automatically fine for you. And do not assume the position will hold. Verify the current list on the APDP's website, and take professional advice on anything material — this is an area where the correct answer genuinely depends on the specific transfer, and guessing is not a strategy.

What This Means for Your Tool Stack

Most Monaco businesses are more exposed than they realise, simply because the standard toolkit is international by default: a US analytics platform, a US or Irish email provider, a cloud host with data centres across several regions, a support widget, an AI assistant processing customer messages.

None of that is a problem in itself. The problem is not knowing where the data goes. If you cannot answer "which countries does our customer data touch, and under what contract", you cannot demonstrate compliance whichever version of the list ends up in force.

This is the moment to map it. A clear inventory makes you resilient to whatever the final order says — and it makes the eventual switch cheap if a provider turns out to sit outside the new list. The same discipline that keeps a multilingual website maintainable applies here: know your dependencies before you need to change them.

Four Things Worth Doing Before the Order Lands

Map your data flows. List every tool holding customer or prospect data, where it is hosted, and where its sub-processors sit. Your email marketing and CRM stack is usually the biggest concentration.

Check your contracts. Confirm you have transfer guarantees in writing with each provider, not just a link to a generic policy page. If a country falls off the list, those contracts become your fallback.

Prefer flexibility over lock-in. Where a European or Monaco-hosted option exists and performs equally well, it reduces your exposure to list changes without costing you anything strategically.

Write it down. Under Law 1.565 the burden is on you to show you assessed the transfer. Undocumented good judgement counts for nothing in a review. Structured APDP compliance work is far cheaper done calmly now than reactively later.

Get Your Transfers in Order

The adequacy list will be published sooner or later, and given the APDP's objections it may look different from the draft. Businesses that already know where their data lives will adapt in an afternoon. Businesses that do not will spend weeks reconstructing it under pressure.

If you want help mapping your data flows, reviewing your website and marketing stack, or building a digital strategy that survives a regulatory change, get in touch — we work with Monaco businesses every day and we will tell you plainly what needs attention. For binding legal interpretation of Law 1.565, consult a qualified Monaco lawyer.

data protectionAPDPlaw 1.565data transfersmonaco
BSS Digital Agency

BSS Digital Agency

Digital agency based in Monaco. Web, apps, AI, marketing.

Get in touch