Article 29 Working Party Issues Favorable Opinion on the Level of Protection of Personal Data in the Principality of Monaco
Time 2 Minute Read

On July, 19, 2012, the Article 29 Working Party (the “Working Party”) issued an Opinion finding that the Principality of Monaco ensures an “adequate level of protection” for personal data within the meaning of the European Data Protection Directive (Article 25 of Directive 95/46/EC) (the “Directive”). Under the Directive, strict conditions apply to personal data transfers to countries outside the European Economic Area that are not considered to provide an “adequate” level of data protection.

In order to assess whether the Principality of Monaco guarantees an adequate level of protection, the Working Party focused on Monaco’s 1993 Act on the protection of personal data (as amended in 2009). The Working Party’s favorable findings are based primarily on a review of this Act with respect to relevant provisions in the Directive, such as the data collection transparency requirement and the right of access for data subjects.

This Opinion paves the way for a final adequacy ruling by the European Commission down the road. For example, after the Working Party issued a favorable opinion regarding the adequacy of Uruguay’s data protection regime in October 2010, the European Commission formally approved Uruguay’s status as a country providing adequate protection on August 21, 2012.

To date, the European Commission has recognized only a limited number of jurisdictions (Andorra, Argentina, Canada, Faeroe Islands, Guernsey, the Isle of Man, Israel, Jersey, Switzerland, Uruguay and the U.S. Department of Commerce Safe Harbor Privacy Principles) as providing an adequate level of data protection.

You May Also Be Interested In

Time 2 Minute Read

On March 3, 2026, the European Commission published draft guidelines intended to clarify the application of the Cyber Resilience Act and opened a public consultation to gather feedback from stakeholders.

Time 2 Minute Read

On January 30, 2026, the Cybersecurity Administration of China released a Q&A document on policies and regulations for the security management of cross-border data transfers. 

Time 4 Minute Read

On January 20, 2026, the European Commission proposed a comprehensive new cybersecurity package aimed at strengthening the EU’s cybersecurity resilience and enhancing its capacity to manage evolving threats.

Time 1 Minute Read

On January 26, 2026, the Brazilian data protection authority (“ANPD”) announced that Brazil and the European Union agreed to mutually recognize the adequacy of each other’s data protection networks.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page