What Is Decree DCLVII, General Regulation on the Protection of Personal Data of Vatican City State?
The supplied research confirms Decree DCLVII as a personal-data regulation for the distinct Vatican City State. It is effective immediately ad experimentum for three years and supports written requests for access, rectification, erasure, portability, objection, restriction, and objection to direct marketing. The regulation also provides a complaint route to the Data Protection Officer (DPO). The supplied materials distinguish Vatican City State from the Holy See, and no Holy See-wide general personal-data regime was located in this pass. This is a bounded evidence profile based on the supplied Vatican City State sources. It does not extend the Decree’s scope to the Holy See as a whole or treat the located DPO route as evidence of a broader Holy See-wide regulator.
At a glance
- Full name
- Decree DCLVII, General Regulation on the Protection of Personal Data of Vatican City State
- Short code
- Decree DCLVII
- Jurisdiction
- Holy See
- Enacted
- 2024
- Last major update
- Promulgated and entered into force on 30 April 2024, ad experimentum for three years; no later amendment or replacement was established in the supplied summary
- Regulator
- Data Protection Officer (DPO) for Vatican City State
- Private right of action
- Limited
- Statutory citation
- Decree DCLVII, General Regulation on the Protection of Personal Data
Scope, who Decree DCLVII covers
Protected data
Data subject rights
Written right of access
Written right to rectification
Written right to erasure
Written right to portability
Written right to object
Written right to restriction
Written objection to direct marketing
Right to complain to the DPO
Notable features
The official decree was promulgated and entered into force on 30 April 2024, ad experimentum for three years. It applies to the distinct Vatican City State and should not be extended to the Holy See as a whole.
Enforcement & penalties
Regulator: Data Protection Officer (DPO) for Vatican City State
Penalties: The supplied summary and sources did not provide a consolidated penalty schedule; no penalty amount or timeline is stated here.
Private right of action: The supplied research identifies a DPO complaint route but does not establish a separate standalone private damages action. This is an evidence limitation, not a definitive statement about every possible remedy.
Relevance to data brokers
No Holy See- or Vatican City State-specific data-broker, people-search, public-record suppression, or broker-removal route was located. The Decree’s general request and DPO complaint routes should not be presented as a guaranteed broker-specific deletion process.
Generate requests in under 60 seconds
Generate removal requests for 1,034 US/global profiles, $9
FAQ
Does Decree DCLVII apply to the Holy See as a whole?+
The supplied research identifies Decree DCLVII as applying to the distinct Vatican City State. No Holy See-wide general personal-data regime was located in this pass.
What requests does Decree DCLVII support?+
The supplied sources support written access, rectification, erasure, portability, objection, restriction, and direct-marketing objection requests, plus a DPO complaint route.
Is there a Vatican City State data-broker opt-out route?+
No Holy See- or Vatican City State-specific data-broker, people-search, public-record, or broker-removal route was located in the supplied research.
Official sources & citations
Other international privacy regimes
Decree DCLVII sits in a global ecosystem of data-protection laws. Compare with other jurisdictions that shape cross-border data flows:
