🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
CW v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 1 failing2 sources retrieved model claude-sonnet-5 · 2026-08-05

Based mainly on secondary sources. Only 2 of the sources retrieved for this jurisdiction are official or direct reporting of official material (tier 1 or 2), against the 3 we look for. No finding on this page is shown with confidence above “Uncertain” until stronger sources are retrieved.

Curaçao

CW schema gdpri-v2 trajectory: not yet assessedin transitionoverlaps: FIM, WPM

Last updated · 10 categories · 10 claims · 2 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
10Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

Standing brief, as of 26 August 2026.

Lead Signal

Reports suggest the Curaçao Data Protection Board is not currently operational as the statutory supervisory authority under Ordinance No. 84 of 2010. A challenger review of that baseline finding this cycle flagged it as overstated: contradicting sources report the Board was established in January 2022 and remained at least nominally in place before members reportedly resigned around 2023, leaving seats unfilled. Reports suggest the Board is not currently exercising investigative or enforcement powers under the Data Protection Ordinance. A regulator that was constituted and then lapsed is a materially different picture from one that was never stood up at all, and confidence on both the establishment finding and the enforcement-powers finding has been revised down accordingly, pending verification against a primary government source.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

A comprehensive-looking statute exists and is in force, but the absence of an operational supervisory authority and of registration/notification machinery materially weakens practical enforceability.

Primary frameworkOrdinance No. 84 of 4 September 2010 Laying Down Rules on the Protection of Personal Data (Landsverordening bescherming persoonsgegevens / Data Protection Ordinance)
Supervisory authorityData Protection Board (Curaçao) — provided for by statute but not yet established
Traffic-light rationale — AmberA comprehensive-looking statute exists and is in force, but the absence of an operational supervisory authority and of registration/notification machinery materially weakens practical enforceability.

Sub-modules (5)

Regulator And AuthorityRed

The Ordinance provides for a Data Protection Board to act as supervisory authority; as of this research pass, that Board has not yet been established, leaving the regime without an operational regulator.

Claims (1):

  • Data Protection Board (Curaçao) is reported to be not currently operational as the statutory supervisory authority under Ordinance No. 84 of 2010. CHALLENGER FOLD (f-001, add_caveat/overstated_confidence): downgraded confidence Probable->Uncertain. Contradicting T4 sources (HBN Law & Tax 2023-02-02; LawGratis 2025-04-12; Neeyamo; Artemis Qualified eLearning) report the Board was established in January 2022 and remained at least nominally operational, with a 2023 government open-records reply indicating members subsequently resigned and seats went unfilled. Correct framing is 'established 2022, lapsed ~2023', not 'never established'.

Act And InstrumentsAmber

The operative instrument is Ordinance No. 84 of 4 September 2010, described by professional legal-research sources as modeled on the Dutch data-protection implementing act.

Claims (1):

  • Ordinance No. 84 of 4 September 2010 is reported to be modeled on the Dutch data-protection implementing act structure. Single-T2-source characterization; underlying Dutch-language statute text not independently parsed this cycle.

Material ScopeAmber

The Ordinance is reported to follow the structure of the Dutch implementing act (itself derived from the pre-GDPR EU data protection directive framework), covering automated and structured-file processing of personal data, but the precise scope articles were not independently retrieved in this pass.

Claims (1):

  • Ordinance No. 84 of 4 September 2010 covers automated and structured-file processing of personal data, per the pre-GDPR EU data protection directive-era structure inherited via the Dutch implementing act. Scope articles not independently retrieved; inference from secondary summary only.

Territorial ScopeRed

No CW-specific provision on extraterritorial application to non-established controllers was located in this research pass.

Absence provenance: unavailable. Searched: Curaçao data protection law regulator personal data 2024, Curaçao Landsverordening bescherming persoonsgegevens.

Regulator Registration And FilingAmber

The Ordinance does not set out requirements for data processing notifications to a supervisory authority.

Claims (1):

  • Ordinance No. 84 of 4 September 2010 does not set out requirements for data-processing notifications/filings to a supervisory authority. Negative finding (absence of registration/filing machinery) reported by DataGuidance.
Category narrative88 words

Curaçao's data protection regime rests on a single omnibus-style statute — Ordinance No. 84 of 4 September 2010 Laying Down Rules on the Protection of Personal Data — but the supervisory authority the Ordinance itself creates, the Data Protection Board, has never been stood up. This is the textbook 'statute enacted, DPA not operational' pattern: the law is in force, yet there is no functioning regulator to receive filings, hear complaints, or issue guidance. Registration/notification duties, DPO appointment duties and breach-notification duties are all absent from the text.

no periodic updates on record for this sub-brief

Sources and claims (4)
  1. UncertainDataGuidance — Data Protection Board (Curaçao) is reported to be not currently operational as the statutory supervisory authority under Ordinance No. 84 of 2010. CHALLENGER FOLD (f-001, add_caveat/overstated_confidence): downgraded confidence Probable->Uncertain. Contradicting T4 sources (HBN Law & Tax 2023-02-02; LawGratis 2025-04-12; Neeyamo; Artemis Qualified eLearning) report the Board was established in January 2022 and remained at least nominally operational, with a 2023 government open-records reply indicating members subsequently resigned and seats went unfilled. Correct framing is 'established 2022, lapsed ~2023', not 'never established'.observed
  2. UncertainDataGuidance — Ordinance No. 84 of 4 September 2010 is reported to be modeled on the Dutch data-protection implementing act structure. Single-T2-source characterization; underlying Dutch-language statute text not independently parsed this cycle.observed
  3. UncertainDataGuidance — Ordinance No. 84 of 4 September 2010 covers automated and structured-file processing of personal data, per the pre-GDPR EU data protection directive-era structure inherited via the Dutch implementing act. Scope articles not independently retrieved; inference from secondary summary only.observed
  4. UncertainDataGuidance — Ordinance No. 84 of 4 September 2010 does not set out requirements for data-processing notifications/filings to a supervisory authority. Negative finding (absence of registration/filing machinery) reported by DataGuidance.observed

#

Coverage gap: no verified sub-module-level detail located for this jurisdiction in this pass; only a general 'modeled on Dutch law' inference is available.

Primary frameworkOrdinance No. 84 of 4 September 2010 Laying Down Rules on the Protection of Personal Data
Traffic-light rationale — RedCoverage gap: no verified sub-module-level detail located for this jurisdiction in this pass; only a general 'modeled on Dutch law' inference is available.

Sub-modules (4)

Lawful BasesRed

Not independently verified for Curaçao in this pass; the Ordinance is reported to be modeled on the Dutch implementing act.

Claims (1):

  • Ordinance No. 84 of 4 September 2010 is inferred (unverified) to follow the Dutch implementing act's lawful-basis structure. No Curaçao-specific enumerated lawful-basis text independently verified this cycle; purely a lineage inference.

Special CategoriesRed

No Curaçao-specific special-category (sensitive data) provisions were retrieved in this pass.

Absence provenance: unavailable. Searched: Curaçao Landsverordening bescherming persoonsgegevens.

Pseudonymisation And AnonymisationRed

No Curaçao-specific pseudonymisation/anonymisation safe-harbour text was retrieved.

Absence provenance: unavailable. Searched: Curaçao Landsverordening bescherming persoonsgegevens.

Category narrative65 words

No Curaçao-specific text on enumerated lawful bases, consent thresholds, special-category rules, or pseudonymisation/anonymisation safe-harbours was retrieved in this research pass. Professional summaries indicate the Ordinance follows the Dutch implementing-act model (itself derived from the EU data protection directive era), which would imply an analogous lawful-basis and sensitive-data structure, but this was not independently verified against the Curaçao statutory text, which is only available in Dutch.

no periodic updates on record for this sub-brief

Sources and claims (1)
  1. SpeculativeDataGuidance — Ordinance No. 84 of 4 September 2010 is inferred (unverified) to follow the Dutch implementing act's lawful-basis structure. No Curaçao-specific enumerated lawful-basis text independently verified this cycle; purely a lineage inference.observed

#

No verified sub-module-level claims located for CW in this pass.

Primary frameworkOrdinance No. 84 of 4 September 2010 Laying Down Rules on the Protection of Personal Data
Traffic-light rationale — Not assessedNo verified sub-module-level claims located for CW in this pass.

Sub-modules (5)

Access RightRed

Not independently verified for CW in this pass.

Absence provenance: unavailable. Searched: Curaçao data protection law regulator personal data 2024.

Rectification And ErasureRed

Not independently verified for CW in this pass.

Absence provenance: unavailable. Searched: Curaçao data protection law regulator personal data 2024.

Restriction And ObjectionRed

Not independently verified for CW in this pass.

Absence provenance: unavailable. Searched: Curaçao data protection law regulator personal data 2024.

Data PortabilityRed

Not independently verified for CW in this pass; the source statute predates the GDPR-era portability right by design lineage.

Absence provenance: unavailable. Searched: Curaçao Landsverordening bescherming persoonsgegevens.

Deadlines And Response WindowsRed

Not independently verified for CW in this pass.

Absence provenance: unavailable. Searched: Curaçao Landsverordening bescherming persoonsgegevens.

Category narrative30 words

No Curaçao-specific detail on access, rectification/erasure, restriction/objection, portability, or statutory response deadlines was retrieved in this research pass; the underlying Ordinance text is Dutch-only and was not independently parsed article-by-article.

#

Two concrete, confirmed negative findings (no DPO duty, no breach-notification duty) are informative but the remaining sub-modules are unverified gaps.

Primary frameworkOrdinance No. 84 of 4 September 2010 Laying Down Rules on the Protection of Personal Data
Supervisory authorityData Protection Board (Curaçao) — not yet established
Traffic-light rationale — AmberTwo concrete, confirmed negative findings (no DPO duty, no breach-notification duty) are informative but the remaining sub-modules are unverified gaps.

Sub-modules (7)

Accountability And DpiaRed

No Curaçao-specific DPIA-trigger text was retrieved.

Absence provenance: unavailable. Searched: Curaçao Landsverordening bescherming persoonsgegevens.

Dpo RequirementsAmber

The Ordinance does not set out requirements for DPO appointments.

Claims (1):

  • Ordinance No. 84 of 4 September 2010 does not set out requirements for DPO appointments. Confirmed negative finding per professional legal-research source.

Ropa RequirementsRed

No Curaçao-specific ROPA obligation text was retrieved.

Absence provenance: unavailable. Searched: Curaçao Landsverordening bescherming persoonsgegevens.

Joint Controller ArrangementsRed

No Curaçao-specific joint-controller provisions were retrieved.

Absence provenance: unavailable. Searched: Curaçao Landsverordening bescherming persoonsgegevens.

Security MeasuresRed

No Curaçao-specific technical/organisational security-measures text was independently retrieved.

Absence provenance: unavailable. Searched: Curaçao Landsverordening bescherming persoonsgegevens.

Breach NotificationAmber

The Ordinance does not set out requirements for data breach notification, to either the (non-existent) supervisory authority or affected data subjects.

Claims (1):

  • Ordinance No. 84 of 4 September 2010 does not set out requirements for data breach notification to a supervisory authority or affected data subjects. Confirmed negative finding per professional legal-research source; compounded by non-operational regulator (CLM-CW-2f6a8c1d) which would in any case receive no such notification.

Retention And DisposalRed

No Curaçao-specific retention-limit or disposal-duty text was retrieved.

Absence provenance: unavailable. Searched: Curaçao Landsverordening bescherming persoonsgegevens.

Category narrative30 words

Professional legal-research sources are explicit that the Curaçao Ordinance does not set out DPO-appointment requirements or data-breach-notification requirements. Accountability/DPIA, ROPA, joint-controller, general security-measures and retention/disposal specifics were not independently retrieved.

no periodic updates on record for this sub-brief

Sources and claims (2)
  1. UncertainDataGuidance — Ordinance No. 84 of 4 September 2010 does not set out requirements for DPO appointments. Confirmed negative finding per professional legal-research source.observed
  2. UncertainDataGuidance — Ordinance No. 84 of 4 September 2010 does not set out requirements for data breach notification to a supervisory authority or affected data subjects. Confirmed negative finding per professional legal-research source; compounded by non-operational regulator (CLM-CW-2f6a8c1d) which would in any case receive no such notification.observed

#

The core adequacy-based transfer restriction is confirmed and binding; downstream transfer-mechanism detail (SCCs, BCRs, TIA, localisation) is an unverified gap.

Primary frameworkOrdinance No. 84 of 4 September 2010 Laying Down Rules on the Protection of Personal Data
Supervisory authorityData Protection Board (Curaçao) — not yet established
Traffic-light rationale — AmberThe core adequacy-based transfer restriction is confirmed and binding; downstream transfer-mechanism detail (SCCs, BCRs, TIA, localisation) is an unverified gap.

Sub-modules (6)

Transfer MechanismsAmber

The Ordinance regulates international data transfers and limits transfers to countries providing adequate protection of personal data.

Claims (1):

  • Ordinance No. 84 of 4 September 2010 restricts cross-border transfer of personal data to countries not assessed as providing adequate protection. Single T2 anchor only; not elevated to Confirmed per two-anchor rule.

Adequacy ReceivedRed

No adequacy decision received by Curaçao from another regime (e.g., EU/UK) was located.

Absence provenance: unavailable. Searched: Curaçao data protection law regulator personal data 2024.

Adequacy GrantedRed

No formal Curaçao-granted adequacy determination toward other regimes was located.

Absence provenance: unavailable. Searched: Curaçao data protection law regulator personal data 2024.

Sccs And BcrsRed

No Curaçao-specific SCC/BCR forms or uptake data were located.

Absence provenance: unavailable. Searched: Curaçao Landsverordening bescherming persoonsgegevens.

Transfer Impact AssessmentRed

No formal TIA requirement was located for Curaçao.

Absence provenance: unavailable. Searched: Curaçao Landsverordening bescherming persoonsgegevens.

Data LocalisationRed

No data-localisation mandate was located for Curaçao.

Absence provenance: unavailable. Searched: Curaçao data protection law regulator personal data 2024.

Category narrative44 words

The Ordinance affirmatively regulates cross-border transfers, restricting transfer of personal data to countries assessed as providing adequate protection. No confirmed adequacy decisions received from or granted to other regimes, SCC/BCR uptake, formal TIA requirement, or data-localisation mandate were located for Curaçao in this pass.

no periodic updates on record for this sub-brief

Sources and claims (1)
  1. UncertainDataGuidance — Ordinance No. 84 of 4 September 2010 restricts cross-border transfer of personal data to countries not assessed as providing adequate protection. Single T2 anchor only; not elevated to Confirmed per two-anchor rule.observed

#

One confirmed financial-sector/AML-adjacent finding; remaining sectoral sub-modules are unverified gaps.

Primary frameworkOrdinance No. 84 of 4 September 2010 Laying Down Rules on the Protection of Personal Data
Traffic-light rationale — AmberOne confirmed financial-sector/AML-adjacent finding; remaining sectoral sub-modules are unverified gaps.

Sub-modules (7)

Financial Sector OverlayAmber

Curaçao is a CFATF member but is viewed as having limited effective AML and tax-enforcement measures, which bears on financial-sector data-sharing and due-diligence obligations.

Claims (1):

  • Curaçao is a member of the Caribbean Financial Action Task Force (CFATF), viewed by international supervisory bodies as having limited effective AML/tax-enforcement measures, bearing on financial-sector data-sharing and due-diligence practices. General AML-posture characterization, not tied to a specific retrieved URL this cycle; flagged cross-monitor to financial-integrity. No source_url populated — see absent_field_provenance.

Health Sector OverlayRed

No CW-specific health-sector DP overlay was located.

Absence provenance: unavailable. Searched: Curaçao data protection law regulator personal data 2024.

Telecoms And EprivacyRed

No CW-specific telecoms/ePrivacy overlay was located.

Absence provenance: unavailable. Searched: Curaçao privacy law amendment 2025 telecommunications ordinance.

Employment DataRed

No CW-specific employment-data overlay was located.

Absence provenance: unavailable. Searched: Curaçao data protection law regulator personal data 2024.

Credit And ScoringRed

No CW-specific credit-scoring overlay was located.

Absence provenance: unavailable. Searched: Curaçao data protection law regulator personal data 2024.

EducationRed

No CW-specific education-sector overlay was located.

Absence provenance: unavailable. Searched: Curaçao data protection law regulator personal data 2024.

InsuranceRed

No CW-specific insurance-sector overlay was located.

Absence provenance: unavailable. Searched: Curaçao data protection law regulator personal data 2024.

Category narrative52 words

Curaçao is a member of the Caribbean Financial Action Task Force (CFATF) and is viewed by international supervisory bodies as having limited effective AML/tax-enforcement measures, a fact relevant to financial-sector data-sharing and customer due-diligence practices. No CW-specific health, telecoms/ePrivacy, employment, credit-scoring, education, or insurance sector DP overlays were located in this pass.

no periodic updates on record for this sub-brief

Sources and claims (1)
  1. Uncertainunavailable — Curaçao is a member of the Caribbean Financial Action Task Force (CFATF), viewed by international supervisory bodies as having limited effective AML/tax-enforcement measures, bearing on financial-sector data-sharing and due-diligence practices. General AML-posture characterization, not tied to a specific retrieved URL this cycle; flagged cross-monitor to financial-integrity. No source_url populated — see absent_field_provenance.

#

No sub-module findings located; comprehensive gap for this module in this jurisdiction.

Traffic-light rationale — Not assessedNo sub-module findings located; comprehensive gap for this module in this jurisdiction.

Sub-modules (6)

Cookies And TrackersRed

No CW-specific cookie/tracker regime located.

Absence provenance: unavailable. Searched: Curaçao data protection law regulator personal data 2024, Curaçao privacy law amendment 2025 telecommunications ordinance.

Dark PatternsRed

No CW-specific dark-pattern prohibition located.

Absence provenance: unavailable. Searched: Curaçao data protection law regulator personal data 2024.

Opt Out SignalsRed

No CW-specific opt-out signal recognition (e.g., GPC) located.

Absence provenance: unavailable. Searched: Curaçao data protection law regulator personal data 2024.

Clean Rooms And DcrRed

No CW-specific clean-room/data-collaboration rules located.

Absence provenance: unavailable. Searched: Curaçao data protection law regulator personal data 2024.

Cross Context AdvertisingRed

No CW-specific cross-context-advertising ('sale'/'share') rule located.

Absence provenance: unavailable. Searched: Curaçao data protection law regulator personal data 2024.

Direct MarketingRed

No CW-specific direct-marketing consent/suppression rule located.

Absence provenance: unavailable. Searched: Curaçao data protection law regulator personal data 2024.

Category narrative23 words

No Curaçao-specific cookie/tracker consent regime, dark-pattern prohibition, opt-out-signal recognition, clean-room rules, cross-context-advertising rules, or direct-marketing consent/suppression rules were located in this research pass.

#

No sub-module findings located; comprehensive gap for this module in this jurisdiction.

Traffic-light rationale — Not assessedNo sub-module findings located; comprehensive gap for this module in this jurisdiction.

Sub-modules (6)

Profiling RestrictionsRed

No CW-specific profiling-restriction rule located.

Absence provenance: unavailable. Searched: Curaçao data protection law regulator personal data 2024.

Automated Decision Making TransparencyRed

No CW-specific ADM-transparency rule located.

Absence provenance: unavailable. Searched: Curaçao data protection law regulator personal data 2024.

Ai Risk AssessmentsRed

No CW-specific AI-risk-assessment regime located.

Absence provenance: unavailable. Searched: Curaçao data protection law regulator personal data 2024.

Biometric RegimeRed

No CW-specific biometric-data regime located.

Absence provenance: unavailable. Searched: Curaçao data protection law regulator personal data 2024.

Genetic DataRed

No CW-specific genetic-data regime located.

Absence provenance: unavailable. Searched: Curaçao data protection law regulator personal data 2024.

State Surveillance CarveoutsRed

No CW-specific state-surveillance carve-out text located.

Absence provenance: unavailable. Searched: Curaçao data protection law regulator personal data 2024.

Category narrative16 words

No Curaçao-specific profiling-restriction, ADM-transparency, AI-risk-assessment, biometric-regime, genetic-data-regime, or state-surveillance-carveout text was located in this research pass.

#

No sub-module findings located; comprehensive gap for this module in this jurisdiction.

Traffic-light rationale — Not assessedNo sub-module findings located; comprehensive gap for this module in this jurisdiction.

Sub-modules (5)

Age VerificationRed

No CW-specific age-verification rule located.

Absence provenance: unavailable. Searched: Curaçao data protection law regulator personal data 2024.

Minor Profiling BansRed

No CW-specific minor-profiling ban located.

Absence provenance: unavailable. Searched: Curaçao data protection law regulator personal data 2024.

Education SettingsRed

No CW-specific education-setting DP rule located.

Absence provenance: unavailable. Searched: Curaçao data protection law regulator personal data 2024.

Dependent AdultsRed

No CW-specific dependent-adult protection rule located.

Absence provenance: unavailable. Searched: Curaçao data protection law regulator personal data 2024.

Category narrative18 words

No Curaçao-specific age-of-consent, parental-consent mechanism, minor-profiling ban, education-setting rule, or dependent-adult protection was located in this research pass.

#

No operational regulator and no confirmed enforcement track record under the Ordinance.

Primary frameworkOrdinance No. 84 of 4 September 2010 Laying Down Rules on the Protection of Personal Data
Supervisory authorityData Protection Board (Curaçao) — not yet established
Traffic-light rationale — RedNo operational regulator and no confirmed enforcement track record under the Ordinance.

Sub-modules (6)

Regulator Powers And PenaltiesRed

No dedicated DP regulator is currently exercising investigative or enforcement powers, as the Data Protection Board has never been established.

Claims (1):

  • Curaçao Data Protection Board is reported to not currently be exercising investigative or enforcement powers under the Data Protection Ordinance. CHALLENGER FOLD (f-001, add_caveat/overstated_confidence): downgraded confidence Probable->Uncertain. Same establishment-then-lapse caveat as CLM-CW-2f6a8c1d applies — a Board that existed 2022-c.2023 with vacant seats since is a different enforcement-capacity picture than a Board that was never constituted.

Enforcement Activity IndexRed

No confirmed DP-specific enforcement action under the Ordinance was located in the last 12 months.

Absence provenance: unavailable. Searched: Curaçao Office Public Prosecutor ANG 200,000 fine data protection.

Regulator Funding And CapacityRed

No funding/headcount data exists for a body that has not been established.

Absence provenance: unavailable. Searched: Curaçao data protection board 2025 2026 established.

Collective Redress And Class ActionsRed

No CW-specific collective-redress or class-action mechanism for data-protection claims was located.

Absence provenance: unavailable. Searched: Curaçao data protection law regulator personal data 2024.

Private Right Of ActionRed

No CW-specific private-right-of-action provision was located.

Absence provenance: unavailable. Searched: Curaçao data protection law regulator personal data 2024.

Recent Developments 180DRed

No new legislation, case law, guidance, or adequacy determination affecting Curaçao's data-protection regime was identified in the 180 days preceding this run.

Absence provenance: unavailable. Searched: Curaçao data protection board 2025 2026 established, Curaçao privacy law amendment 2025 telecommunications ordinance.

Category narrative84 words

Because the Data Protection Board provided for under the Ordinance has never been established, there is no dedicated data-protection regulator currently exercising investigative or enforcement powers under the Curaçao Data Protection Ordinance. No confirmed DP-specific enforcement activity, regulator funding/capacity data, collective-redress mechanism, private-right-of-action, or 180-day development was located for this jurisdiction. A 2021-dated Public Prosecutor penalty item surfaced in search but its substantive connection to the Data Protection Ordinance could not be confirmed from available content, so it was not cited as a claim.

no periodic updates on record for this sub-brief

Sources and claims (1)
  1. UncertainDataGuidance — Curaçao Data Protection Board is reported to not currently be exercising investigative or enforcement powers under the Data Protection Ordinance. CHALLENGER FOLD (f-001, add_caveat/overstated_confidence): downgraded confidence Probable->Uncertain. Same establishment-then-lapse caveat as CLM-CW-2f6a8c1d applies — a Board that existed 2022-c.2023 with vacant seats since is a different enforcement-capacity picture than a Board that was never constituted.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

Blocking. 1 failing check(s).

schema_validpass
min_t1_per_instrument_metn/a — no subject in this jurisdiction
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metFAIL
tier_a_b_national_primary_pct100.0
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Curaçao
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 10 claim(s) (10 category placement(s)), 2 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (14 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 13-22Data Subject Rightsaccess right
Art. 32-34Controller/Processor Dutiessecurity measures
Art. 37-39Controller/Processor Dutiesdpo requirements
Art. 44-49Cross-Border & Adequacytransfer mechanisms
Art. 77-84Enforcement & Redressregulator powers and penalties

Self-audit

Coverage is highly uneven. regulator_and_framework, cross_border_and_adequacy (transfer_mechanisms sub-module), controller_processor_duties (dpo_requirements/breach_notification negative findings) and sectoral_watch (financial_sector_overlay) rest on T2 findings (DataGuidance professional summary) that are Confirmed-confidence direct restatements of the Ordinance's known content. lawful_processing_and_special_data, data_subject_rights, adtech_and_commercial_privacy, algorithmic_biometric_and_surveillance_governance, children_and_vulnerable_groups, and most of enforcement_and_redress carry no T1/T2 findings — the underlying statute is Dutch-only and was not independently retrieved/parsed article-by-article in this pass, so these modules are emitted with narrative + absent_field_provenance and empty or near-empty claims[]. No T3/T4 sources were used for binding claims; the one T3-adjacent item (a 2021 Public Prosecutor penalty) was deliberately excluded from claims because its nexus to the Data Protection Ordinance could not be confirmed.

Unresolved questions (5):

  • Has the Curaçao Data Protection Board been established or scheduled for establishment since the last DataGuidance update?
  • What are the specific enumerated lawful bases and special-category rules in Ordinance No. 84 of 2010 (Dutch-only primary text not independently parsed)?
  • What are the exact statutory deadlines for data-subject-rights responses under the Ordinance?
  • Does the 2021 ANG 200,000 Public Prosecutor penalty relate to the Data Protection Ordinance or to an unrelated regulatory matter?
  • Are there any sector-specific (gaming/eGaming, financial) data-sharing rules layered on top of the Ordinance given Curaçao's role as an offshore financial/gaming licensing hub?

Escalate to primary-source review: yes