Skip to main content

Monaco’s Facial Recognition Bill: Public Security, Data Protection and the Rule of Law

Monaco facial recognition law and public security

Monaco’s proposed legal framework governing facial recognition in public-security video systems marks an important development for public law, security policy and data protection in the Principality. The stated objective is not the generalised surveillance of the population, but the targeted identification of individuals who are already subject to searches, investigations or official alerts.

A Targeted Legal Framework for Biometric Identification

This distinction is legally significant. Biometric identification involves one of the most sensitive categories of personal data because it enables the identification of individuals in public spaces.

Even where its use pursues legitimate objectives—such as preventing serious crime or locating wanted persons—the legal framework should clearly define:

  • the categories of individuals who may be identified;
  • the databases that may be consulted;
  • the authorities empowered to authorise searches;
  • applicable data retention periods;
  • the independent oversight mechanisms.

The debate is not new. Monaco’s data protection authority (APDP) has consistently emphasised that remote biometric identification in public spaces has significant implications for fundamental rights. It has stated that any such system must be supported by clear legal safeguards, including necessity, proportionality, temporal and geographical limitations as well as effective oversight.

Compliance Implications for Businesses

This balance is relevant not only for residents and visitors, but also for businesses operating:

  • CCTV systems;
  • smart-building technologies;
  • hospitality venues;
  • retail premises;
  • private security infrastructure.

If enacted, the legislation should be closely monitored by companies, property owners and regulated entities. Any interaction between private surveillance systems and public-security infrastructure may raise important compliance obligations under Monaco’s data protection framework, including requirements relating to:

  • transparency;
  • purpose limitation;
  • data minimisation;
  • security measures;
  • accountability.

Looking Ahead

Our Data Protection team is happy to advise on the current and new statutory framework. For any questions regarding updating current Data Protection Policies and/or practical implementation, feel free to contact us.