🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
IM v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing12 sources retrieved model claude-sonnet-5 · 2026-08-05

Isle of Man

IM schema gdpri-v2 trajectory: not yet assessedregulated (omnibus)

Last updated · 10 categories · 27 claims · 24 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
27Claimsbaseline..claims[]
2Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

Latest update · 28 September 2026

Lead Signal

The Isle of Man's data-protection framework remains anchored by dual adequacy status, and this cycle confirms both strands are current. The European Commission's adequacy decision for the Island, first adopted in April 2004, was reaffirmed following a periodic review in January 2024, which concluded the decision continues to provide adequate protection, subject to closer ongoing monitoring. Separately, the Data Protection (Law Enforcement) (Adequacy) (Isle of Man) Regulations 2025 (UK SI 2025/89) came into force on 20 February 2025, confirming that the Isle of Man provides a level of protection of personal data essentially equivalent to that in the UK, and enabling UK competent authorities to transfer personal data to Isle of Man authorities for law-enforcement purposes without case-by-case authorisation.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Comprehensive GDPR-equivalent statute in force with an active, independent regulator and established enforcement track record.

Primary frameworkData Protection Act 2018 (Isle of Man), operationalised via the Data Protection (Application of GDPR) Order 2018 and the LED Implementing Regulations 2018
Supervisory authorityIsle of Man Information Commissioner
Traffic-light rationale — GreenComprehensive GDPR-equivalent statute in force with an active, independent regulator and established enforcement track record.

Sub-modules (5)

Regulator And AuthorityGreen

The Isle of Man Information Commissioner is the independent authority for information rights on the Island, including data protection.

Claims (1):

  • Isle of Man Information Commissioner serves as the independent regulatory authority for information rights, including data protection, on the Isle of Man. Standing institutional fact anchored on a T3 overview source only; no dedicated Manx statute page independently confirmed in this pass.

Act And InstrumentsGreen

The Applied GDPR Order 2018 and LED Implementing Regulations 2018 give the EU GDPR/LED domestic legal effect under the Data Protection Act 2018.

Claims (2):

  • Data Protection (Application of GDPR) Order 2018 gives domestic legal effect to the EU GDPR under the Isle of Man's Data Protection Act 2018, with local adaptations. Core instrument establishing the Manx GDPR-equivalent regime.
  • LED Implementing Regulations 2018 gives domestic legal effect to the EU Law Enforcement Directive under the Isle of Man's Data Protection Act 2018. Establishes the separate law-enforcement processing regime alongside the Applied GDPR.

Material ScopeGreen

Manx enforcement practice confirms the Applied GDPR's substantive articles (e.g. Arts 12 and 15 on access/transparency) are directly enforced against controllers, including government departments and health bodies.

Claims (1):

  • Isle of Man Information Commissioner enforces Applied GDPR substantive articles (e.g. Arts 12 and 15 on access/transparency) against controllers including government departments and health bodies. Anchored on two enforcement actions (DHA 2020, Manx Care 2021), both T3-tier sources.

Territorial ScopeGreen

The Isle of Man is deemed a Member State of the EU solely for the purposes of the GDPR and LED, a bespoke construct enabling continuity of data flows.

Claims (1):

  • Isle of Man is deemed a Member State of the EU solely for the purposes of the GDPR and LED, a bespoke construct enabling continuity of data flows. Standing territorial-scope construct.

Regulator Registration And FilingRed

No Manx-specific controller registration/notification-fee instrument (analogous to the UK's Data Protection (Charges and Information) Regulations 2018) was identified in this research pass.

Absence provenance: unavailable. Searched: Isle of Man Data Protection Act 2018 registration fee notification requirement, Isle of Man Information Commissioner official website gov.im data protection.

Category narrative102 words

The Isle of Man (a self-governing British Crown Dependency, not part of the UK or EU) operates a GDPR-equivalent omnibus regime. It has chosen to adopt the EU GDPR and the Law Enforcement Directive (LED) by order under its own Data Protection Act 2018, principally via the Data Protection (Application of GDPR) Order 2018 ('Applied GDPR') and the LED Implementing Regulations 2018, with local adaptations. The Isle of Man Information Commissioner is the independent regulator overseeing data protection, the Unsolicited Communications Regulations, and Freedom of Information law. Registration/filing specifics for controllers under the Manx regime were not located in this research pass.

Periodic update · new data 2026-09-28

Regulator & Framework

The Isle of Man Information Commissioner is a separate statutory supervisory authority from the UK Information Commissioner's Office, notwithstanding the similarity in naming and function. The core statutory basis for data protection on the Island is the Data Protection Act 2018, which applies the GDPR and the Law Enforcement Directive as Manx domestic law via the GDPR and LED Implementing Regulations 2018. This replaced the earlier Data Protection Act 2002 and remains the stable foundation of the regime.

The one active development within this module this cycle is procedural rather than substantive: the Information Commissioner has proposed revised annual data-protection registration fees, including fee adjustments and exemptions, following a public consultation exercise. The proposal's finalisation date and the instrument through which it will take effect have not yet been confirmed from the sources retrieved this cycle.

Outlook

The fee-revision proposal is expected to move toward finalisation, provisionally estimated around Q4 2026, though this is held at Uncertain confidence given the absence of a confirmed instrument or date. Confirmation of the finalised fee schedule would be the clearest marker of progress in this module.

Sources and claims (5)
  1. ProbableDataGuidance — Isle of Man Information Commissioner serves as the independent regulatory authority for information rights, including data protection, on the Isle of Man. Standing institutional fact anchored on a T3 overview source only; no dedicated Manx statute page independently confirmed in this pass.observed
  2. ProbableDataGuidance — Data Protection (Application of GDPR) Order 2018 gives domestic legal effect to the EU GDPR under the Isle of Man's Data Protection Act 2018, with local adaptations. Core instrument establishing the Manx GDPR-equivalent regime.observed
  3. ProbableDataGuidance — LED Implementing Regulations 2018 gives domestic legal effect to the EU Law Enforcement Directive under the Isle of Man's Data Protection Act 2018. Establishes the separate law-enforcement processing regime alongside the Applied GDPR.observed
  4. ProbableDataGuidance — Isle of Man Information Commissioner enforces Applied GDPR substantive articles (e.g. Arts 12 and 15 on access/transparency) against controllers including government departments and health bodies. Anchored on two enforcement actions (DHA 2020, Manx Care 2021), both T3-tier sources.observed
  5. ProbableDataGuidance — Isle of Man is deemed a Member State of the EU solely for the purposes of the GDPR and LED, a bespoke construct enabling continuity of data flows. Standing territorial-scope construct.observed

#

Core lawful-basis and special-category architecture is inherited wholesale from GDPR, but the specific Manx adaptations to consent thresholds and pseudonymisation/anonymisation safe-harbours were not independently verified in primary Manx legislative text during this pass.

Primary frameworkApplied GDPR (Data Protection (Application of GDPR) Order 2018)
Supervisory authorityIsle of Man Information Commissioner
Traffic-light rationale — AmberCore lawful-basis and special-category architecture is inherited wholesale from GDPR, but the specific Manx adaptations to consent thresholds and pseudonymisation/anonymisation safe-harbours were not independently verified in primary Manx legislative text during this pass.

Sub-modules (4)

Lawful BasesAmber

The Applied GDPR's Article 6 lawful-basis framework operates as adopted domestic law.

Claims (1):

  • Applied GDPR Article 6 governs lawful bases for processing, operating as adopted domestic law in the Isle of Man. Inferred from wholesale GDPR adoption; no Manx-specific departure independently verified.

Special CategoriesGreen

A 2020 Manx enforcement notice against the Department of Home Affairs directly invoked the special-category exemption under 'paragraph 8 of Schedule 9 of the GDPR', evidencing an operative Schedule 9-style special-category exemption regime under the Applied GDPR.

Claims (1):

  • Department of Home Affairs (Isle of Man) invoked the paragraph 8 Schedule 9 exemption (protection of the rights of others) to restrict a subject access request response — an Article 15(4)-type access-right exemption, corrected from the original framing that mischaracterised it as an Article 9 special-category processing exemption. CORRECTED per Challenger finding f-001 (hard_flag, cross_domain_conflation): the underlying DataGuidance source describes DHA relying on the paragraph 8 Schedule 9 exemption to restrict SAR response on protection-of-third-party-rights grounds — an access-right exemption, not a special-category (Art 9) processing ground. Reclassified from lawful_processing_and_special_data/special_categories to data_subject_rights/access_right. No confirmed Manx-specific special-category enforcement precedent exists (see gap gdpri-int-15).

Pseudonymisation And AnonymisationRed

No Manx-specific pseudonymisation/anonymisation guidance or safe-harbour text was located.

Absence provenance: unavailable. Searched: Isle of Man Data Protection Act 2018 pseudonymisation anonymisation.

Category narrative53 words

Because the Isle of Man has adopted the full text of the EU GDPR domestically (with adaptations), the Article 6 lawful bases and Article 9 special-category regime are understood to apply as adopted. Direct Manx enforcement evidence confirms the operative special-category exemption schedule (mirroring UK DPA 2018 Schedule 9) is applied in practice.

Sources and claims (2)
  1. UncertainDataGuidance — Applied GDPR Article 6 governs lawful bases for processing, operating as adopted domestic law in the Isle of Man. Inferred from wholesale GDPR adoption; no Manx-specific departure independently verified.observed
  2. ProbableDataGuidance — Department of Home Affairs (Isle of Man) invoked the paragraph 8 Schedule 9 exemption (protection of the rights of others) to restrict a subject access request response — an Article 15(4)-type access-right exemption, corrected from the original framing that mischaracterised it as an Article 9 special-category processing exemption. CORRECTED per Challenger finding f-001 (hard_flag, cross_domain_conflation): the underlying DataGuidance source describes DHA relying on the paragraph 8 Schedule 9 exemption to restrict SAR response on protection-of-third-party-rights grounds — an access-right exemption, not a special-category (Art 9) processing ground. Reclassified from lawful_processing_and_special_data/special_categories to data_subject_rights/access_right. No confirmed Manx-specific special-category enforcement precedent exists (see gap gdpri-int-15).observed

#

Access right is demonstrably enforced with real cases; deadlines are evidenced through an enforcement action citing multi-month delay.

Primary frameworkApplied GDPR (Data Protection (Application of GDPR) Order 2018)
Supervisory authorityIsle of Man Information Commissioner
Traffic-light rationale — GreenAccess right is demonstrably enforced with real cases; deadlines are evidenced through an enforcement action citing multi-month delay.

Sub-modules (5)

Access RightGreen

Two separate Manx enforcement notices (DHA, 2020; Manx Care, 2021) found continuous failures to comply with the right of access under Applied GDPR Articles 12 and 15.

Claims (2):

  • Isle of Man Information Commissioner issued enforcement notice against the Department of Home Affairs (2020) for continuous failure to comply with the right of access under Applied GDPR Articles 12 and 15. Direct Manx enforcement precedent on access rights.
  • Isle of Man Information Commissioner issued enforcement notice against Manx Care (2021) for continuous failure to comply with the right of access under Applied GDPR Articles 12 and 15. Second Manx enforcement precedent on access rights, against the public healthcare provider.

Rectification And ErasureAmber

Rectification/erasure rights are presumed inherited from the fully-adopted Applied GDPR text; no independent Manx enforcement precedent located.

Absence provenance: unavailable. Searched: Isle of Man Data Protection Act 2018 rectification erasure right to be forgotten.

Restriction And ObjectionAmber

Restriction/objection rights are presumed inherited from the Applied GDPR; no Manx-specific precedent located.

Absence provenance: unavailable. Searched: Isle of Man Data Protection Act 2018 restriction objection profiling opt-out.

Data PortabilityAmber

Portability right presumed inherited from the Applied GDPR; no Manx-specific precedent located.

Absence provenance: unavailable. Searched: Isle of Man data portability GDPR.

Deadlines And Response WindowsGreen

The Manx Care enforcement action evidenced regulatory intolerance of subject access delay of more than four months, consistent with the GDPR's one-month (extendable) statutory response deadline being applied in practice.

Claims (1):

  • Isle of Man Information Commissioner found non-compliance exceeding four months for a subject access request response, consistent with GDPR's one-month (extendable) statutory response deadline being applied in practice. Evidences operative deadline enforcement via the Manx Care case.
Category narrative75 words

The Manx Information Commissioner has directly enforced data subject access rights (Applied GDPR Articles 12 and 15) against both a government department (2020) and the publicly-owned healthcare provider Manx Care (2021), including for prolonged non-compliance exceeding four months. This provides strong evidentiary confirmation of an operative, enforced access-rights regime; other rights (rectification, erasure, restriction, objection, portability) are presumed inherited from the same Applied GDPR text but lack independent Manx enforcement evidence located in this pass.

no periodic updates on record for this sub-brief

Sources and claims (3)
  1. ProbableDataGuidance — Isle of Man Information Commissioner issued enforcement notice against the Department of Home Affairs (2020) for continuous failure to comply with the right of access under Applied GDPR Articles 12 and 15. Direct Manx enforcement precedent on access rights.observed
  2. ProbableDataGuidance — Isle of Man Information Commissioner issued enforcement notice against Manx Care (2021) for continuous failure to comply with the right of access under Applied GDPR Articles 12 and 15. Second Manx enforcement precedent on access rights, against the public healthcare provider.observed
  3. ProbableDataGuidance — Isle of Man Information Commissioner found non-compliance exceeding four months for a subject access request response, consistent with GDPR's one-month (extendable) statutory response deadline being applied in practice. Evidences operative deadline enforcement via the Manx Care case.observed

#

Security and breach-notification obligations are actively enforced with a live, named 2025 investigation; other accountability sub-modules rely on inherited-adoption inference only.

Primary frameworkApplied GDPR (Data Protection (Application of GDPR) Order 2018)
Supervisory authorityIsle of Man Information Commissioner
Traffic-light rationale — GreenSecurity and breach-notification obligations are actively enforced with a live, named 2025 investigation; other accountability sub-modules rely on inherited-adoption inference only.

Sub-modules (7)

Accountability And DpiaAmber

Accountability/DPIA obligations (Applied GDPR Arts 5 and 35) are presumed inherited from the wholesale GDPR adoption.

Absence provenance: unavailable. Searched: Isle of Man Data Protection Act 2018 DPIA accountability.

Dpo RequirementsAmber

DPO appointment thresholds are presumed inherited from Applied GDPR Article 37; no Manx-specific guidance located.

Absence provenance: unavailable. Searched: Isle of Man Data Protection Act 2018 data protection officer requirements.

Ropa RequirementsAmber

Records-of-processing obligations are presumed inherited from Applied GDPR Article 30; no Manx-specific guidance located.

Absence provenance: unavailable. Searched: Isle of Man Data Protection Act 2018 records of processing activities ROPA.

Joint Controller ArrangementsAmber

Joint-controller rules presumed inherited from Applied GDPR Article 26; no Manx-specific guidance located.

Absence provenance: unavailable. Searched: Isle of Man joint controller GDPR.

Security MeasuresGreen

The 2025 joint investigation into the Prospect cyber incident explicitly examines whether the affected controller had adequate technical and organisational measures, evidencing an operative Article-32-style security standard enforced by the Manx Commissioner.

Claims (1):

  • Isle of Man Information Commissioner (joint with UK ICO, Jersey and Guernsey) is investigating whether the Prospect controller had adequate technical and organisational security measures under an Article 32-equivalent standard. Live, ongoing investigation opened December 2025; not yet a concluded decision.

Breach NotificationGreen

A personal data breach affecting a Manx-linked controller (Prospect) was reported to the Information Commissioner's Office and triggered a joint cross-jurisdictional investigation launched by the UK, Guernsey, Jersey and Isle of Man regulators in December 2025, evidencing an operative breach-notification and cross-authority cooperation framework.

Claims (1):

  • Manx-linked controller (Prospect) reported a personal data breach that triggered a joint cross-jurisdictional investigation launched by the UK, Guernsey, Jersey and Isle of Man regulators in December 2025. Evidences an operative breach-notification and cross-authority cooperation framework.

Retention And DisposalAmber

Retention/disposal obligations presumed inherited from Applied GDPR storage-limitation principle; no Manx-specific guidance located.

Absence provenance: unavailable. Searched: Isle of Man data retention disposal GDPR.

Category narrative83 words

Security-of-processing and breach-notification obligations are demonstrably live and enforced in the Isle of Man: the Commissioner is currently (as of late 2025) engaged in a joint cross-jurisdictional breach investigation (with the UK ICO and the Jersey and Guernsey authorities) into a cyber incident affecting a Manx-linked controller, examining whether adequate technical and organisational security measures were in place. DPIA, DPO, ROPA, joint-controller and retention specifics are presumed inherited from the fully-adopted Applied GDPR text but lack independently located Manx enforcement or guidance evidence.

Periodic update · new data 2026-09-28

Controller/Processor Duties

Reports suggest 16,600 individuals may have been impacted by data breaches in the Isle of Man during Q4 2025/26, according to secondary-source reporting. This figure has not been corroborated against the Isle of Man Information Commissioner's own annual report this pass, and it is treated with corresponding caution as a reported rather than confirmed statistic. No detail on the nature, sector, or cause of the underlying breaches contributing to this figure has been located this cycle, nor has any accompanying enforcement or notification-compliance finding been identified.

Outlook

Corroboration of the breach-volume figure against the Information Commissioner's own published annual report would resolve the current uncertainty and would also clarify whether this represents a genuine increase in breach-notification activity or a reporting artefact.

Sources and claims (2)
  1. ProbableICO — Isle of Man Information Commissioner (joint with UK ICO, Jersey and Guernsey) is investigating whether the Prospect controller had adequate technical and organisational security measures under an Article 32-equivalent standard. Live, ongoing investigation opened December 2025; not yet a concluded decision.observed
  2. ProbableICO — Manx-linked controller (Prospect) reported a personal data breach that triggered a joint cross-jurisdictional investigation launched by the UK, Guernsey, Jersey and Isle of Man regulators in December 2025. Evidences an operative breach-notification and cross-authority cooperation framework.observed

#

Dual adequacy (EU-received and UK-received) is well documented and recently reconfirmed; granted-adequacy and data-localisation sub-modules lack confirmed Manx-specific sources.

Primary frameworkApplied GDPR transfer provisions (Chapter V equivalent) and Commission Decision 2004/411/EC
Supervisory authorityIsle of Man Information Commissioner
Traffic-light rationale — GreenDual adequacy (EU-received and UK-received) is well documented and recently reconfirmed; granted-adequacy and data-localisation sub-modules lack confirmed Manx-specific sources.

Sub-modules (6)

Transfer MechanismsGreen

Post-Brexit, Manx controllers/processors cannot transfer personal data to third countries (including the UK) absent an adequacy finding, Article 46 safeguards, or applicable Part 5/Schedule 10 LED-equivalent provisions.

Claims (1):

  • Isle of Man controllers and processors must rely on adequacy findings, Article 46 safeguards, or Part 5/Schedule 10 LED-equivalent provisions for transfers to third countries, with the UK becoming a third country for these purposes from 1 January 2021 (end of the Brexit transition period), formalised by the European Commission's UK adequacy decision C(2021) 4800 of 28 June 2021. CORRECTED per Challenger finding f-003 (soft_flag, factual/quantitative error): original claim conflated EU exit day (31 Jan/1 Feb 2020) with the actual end of the Brexit transition period (31 Dec 2020/1 Jan 2021), when the UK became a third country for transfer purposes, later formalised by Commission Implementing Decision (EU) 2021/1772 (C(2021) 4800) of 28 June 2021.

Adequacy ReceivedGreen

The Isle of Man received an EU adequacy finding in 2004 (retained and reconfirmed in 2024) and is separately treated as adequate under the UK GDPR, with additional UK law-enforcement-specific adequacy regulations laid and reflected in ICO guidance from February 2025.

Claims (3):

  • Commission Decision 2004/411/EC grants an EU adequacy finding for the Isle of Man, originally under Directive 95/46/EC and retained in force under GDPR. Direct T1 EUR-Lex source; single anchor so held at Probable pending a second independent T1-T2 confirming instrument.
  • European Commission 2024 first-review report reconfirmed the Isle of Man's adequacy status as one of eleven adequacy partners whose safeguards remain adequate. T1 EUR-Lex report confirming continuity of the 2004 adequacy finding.
  • UK adequacy regulations for Isle of Man law-enforcement processing were made and reflected in the ICO's adequacy list update of February 2025. Confirms a separate, UK-side, law-enforcement-specific adequacy determination for the Isle of Man distinct from the general UK GDPR Schedule 21 adequacy treatment.

Adequacy GrantedRed

No confirmed Manx-specific instrument was located describing the Isle of Man's own grant of adequacy findings to other third countries.

Absence provenance: unavailable. Searched: Isle of Man adequacy decisions granted third countries.

Sccs And BcrsAmber

Article 46-style additional safeguards (implying SCC/BCR-equivalent mechanisms) are referenced as an available transfer basis for Manx controllers under the post-Brexit transfer framework.

Claims (1):

  • Applied GDPR Article 46-equivalent safeguards provide an available transfer basis (SCC/BCR-equivalent mechanisms) for Manx controllers under the post-Brexit transfer framework. Referenced only generically; no Manx-specific SCC/BCR text independently verified.

Transfer Impact AssessmentRed

No Manx-specific transfer impact assessment requirement or guidance was located.

Absence provenance: unavailable. Searched: Isle of Man transfer impact assessment Schrems.

Data LocalisationGreen

No evidence of a data-localisation mandate was found for the Isle of Man.

Absence provenance: unavailable. Searched: Isle of Man data localisation requirement.

Category narrative118 words

The Isle of Man holds a long-standing EU adequacy finding (Commission Decision 2004/411/EC, originally under Directive 95/46/EC and retained in force under GDPR), reconfirmed in the European Commission's 2024 first-review report as one of eleven adequacy partners whose safeguards remain adequate. The Isle of Man is also already treated as adequate for transfers under the UK GDPR (Schedule 21, DPA 2018), and in 2024/2025 the UK made separate adequacy regulations specifically for Isle of Man law-enforcement processing, with the ICO updating its adequacy list accordingly in February 2025. Post-Brexit, Manx controllers must rely on adequacy findings, Article 46 safeguards, or Part 5/Schedule 10 LED-equivalent provisions for transfers to third countries (including the UK itself, from 1 February 2020).

Periodic update · new data 2026-09-28

Cross-Border & Adequacy

The Isle of Man holds a long-standing European Commission adequacy decision, first adopted in April 2004. A periodic review concluded in January 2024 found that the decision continues to provide adequate protection, albeit subject to closer ongoing monitoring going forward, placing the Island among the group of adequacy-holding jurisdictions the Commission reviews periodically rather than treating the original decision as a one-time, permanent grant.

Separately, and on the UK side, the Data Protection (Law Enforcement) (Adequacy) (Isle of Man) Regulations 2025, UK Statutory Instrument 2025/89, came into force on 20 February 2025. This instrument formally confirms that the Isle of Man provides a level of protection of personal data essentially equivalent to that in the UK, and it enables UK competent authorities to transfer personal data to Isle of Man authorities for law-enforcement purposes without needing case-by-case authorisation for each transfer. This is a confirmed, dated, Tier-1-sourced instrument.

Taken together, the Isle of Man now holds both a reaffirmed EU adequacy status and a confirmed UK law-enforcement adequacy mechanism, a dual-track position that few Crown Dependencies can claim with equal currency on both fronts. This positions the Island favourably for cross-border personal-data flows with both the EU and the UK, though the January 2024 EU review's note of closer ongoing monitoring indicates the adequacy status is not being treated as indefinitely settled by the Commission.

Outlook

No further review of the EU adequacy decision has been scheduled or signalled this cycle beyond the closer ongoing monitoring noted in the January 2024 review. The UK law-enforcement adequacy mechanism under SI 2025/89 is now in force and no further change is pending. The principal marker to watch is any further Commission commentary arising from its heightened monitoring of the Island's adequacy status.

2 earlier distinct update(s)
Periodic update · new data 2026-09-21

Cross-Border & Adequacy

The Isle of Man occupies an unusually strong dual-adequacy position for a jurisdiction of its size. It holds a standalone European Union adequacy decision, distinct from the UK's own adequacy status, granted in 2004 -- one of the longest-running such decisions held by any Crown Dependency. This finding rests on a Tier-3 source and carries Probable confidence, since the primary European Commission adequacy decision text was not directly retrieved this cycle, though the underlying fact of a 2004-era Isle of Man adequacy decision is well established in secondary commentary.

More recently, the UK Data Protection (Law Enforcement) (Adequacy) (Isle of Man) Regulations 2025 came into force on 20 February 2025. This followed a UK Information Commissioner's Office published opinion setting out the adequacy assessment process the UK Government followed and the factors it considered in assessing the Isle of Man for law-enforcement data transfers specifically -- a narrower category of adequacy than general commercial-processing adequacy, covering data transferred for law-enforcement purposes under the UK's own data protection framework. This is a Confirmed, Tier-1-sourced finding directly from the UK ICO's own published opinion.

Taken together, the Island now has two distinct adequacy positions covering two different transfer categories and two different counterpart jurisdictions: EU adequacy for general processing since 2004, and UK law-enforcement adequacy since February 2025. This dual position gives Manx-based controllers and processors a comparatively favourable cross-border transfer environment relative to jurisdictions holding only one adequacy status or none, though the practical benefit of the EU adequacy decision to Manx businesses is itself somewhat dependent on the continuing stability of the UK's own EU adequacy status, since much Isle of Man data flow to the EU is understood to route via or alongside UK data flows.

Outlook

The UK law-enforcement adequacy instrument is newly in force as of February 2025 and its practical operation -- how UK law-enforcement bodies actually exercise data-transfer arrangements with Isle of Man counterparts under it -- is worth monitoring in future cycles as the instrument matures. On the EU side, the Island's adequacy position is a long-standing, stable feature rather than one under near-term review, and no signal this cycle suggests the European Commission is reconsidering it.

Periodic update · new data 2026-09-14

Cross-Border & Adequacy

The Isle of Man holds a long-standing EU adequacy decision, first granted in 2004 and reaffirmed in 2024, distinct from the adequacy statuses held by the UK, Guernsey and Jersey. This general-purpose adequacy finding is now joined by a second, narrower instrument: the UK's Data Protection (Law Enforcement) (Adequacy) (Isle of Man) Regulations 2025 confirm that the Isle of Man provides an adequate level of protection for personal data transferred from the UK for law-enforcement purposes. This confirmed, in-force development followed a positive Opinion from the UK Information Commissioner under section 74A of the UK Data Protection Act 2018, and represents a materially significant addition to the Island's cross-border transfer architecture, since it closes a gap that previously existed for law-enforcement-purpose transfers specifically, as distinct from the Island's general-purpose EU adequacy coverage.

The combination of long-standing EU general-purpose adequacy and new UK law-enforcement-purpose adequacy positions the Isle of Man distinctly among the Crown Dependencies, and materially reduces friction for Island-based controllers and public authorities engaged in cross-border data transfers with both the EU and the UK.

Outlook

No threat to either the EU or the new UK law-enforcement adequacy finding was evidenced this cycle. The development to watch is whether Guernsey or Jersey pursue equivalent UK law-enforcement-purpose adequacy instruments, which would affect the Isle of Man's relative positioning among the three Crown Dependencies.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (5)
  1. ProbableDataGuidance — Isle of Man controllers and processors must rely on adequacy findings, Article 46 safeguards, or Part 5/Schedule 10 LED-equivalent provisions for transfers to third countries, with the UK becoming a third country for these purposes from 1 January 2021 (end of the Brexit transition period), formalised by the European Commission's UK adequacy decision C(2021) 4800 of 28 June 2021. CORRECTED per Challenger finding f-003 (soft_flag, factual/quantitative error): original claim conflated EU exit day (31 Jan/1 Feb 2020) with the actual end of the Brexit transition period (31 Dec 2020/1 Jan 2021), when the UK became a third country for transfer purposes, later formalised by Commission Implementing Decision (EU) 2021/1772 (C(2021) 4800) of 28 June 2021.observed
  2. ProbableEUR-Lex — Commission Decision 2004/411/EC grants an EU adequacy finding for the Isle of Man, originally under Directive 95/46/EC and retained in force under GDPR. Direct T1 EUR-Lex source; single anchor so held at Probable pending a second independent T1-T2 confirming instrument.observed
  3. ProbableEUR-Lex — European Commission 2024 first-review report reconfirmed the Isle of Man's adequacy status as one of eleven adequacy partners whose safeguards remain adequate. T1 EUR-Lex report confirming continuity of the 2004 adequacy finding.observed
  4. ProbableICO — UK adequacy regulations for Isle of Man law-enforcement processing were made and reflected in the ICO's adequacy list update of February 2025. Confirms a separate, UK-side, law-enforcement-specific adequacy determination for the Isle of Man distinct from the general UK GDPR Schedule 21 adequacy treatment.observed
  5. UncertainICO — Applied GDPR Article 46-equivalent safeguards provide an available transfer basis (SCC/BCR-equivalent mechanisms) for Manx controllers under the post-Brexit transfer framework. Referenced only generically; no Manx-specific SCC/BCR text independently verified.observed

#

Two sectoral overlays are evidenced (health, telecoms/unsolicited communications); financial services, employment, credit, education and insurance overlays are unconfirmed gaps.

Supervisory authorityIsle of Man Information Commissioner
Traffic-light rationale — AmberTwo sectoral overlays are evidenced (health, telecoms/unsolicited communications); financial services, employment, credit, education and insurance overlays are unconfirmed gaps.

Sub-modules (7)

Financial Sector OverlayRed

No financial-sector data-protection overlay instrument specific to the Isle of Man was confirmed in this research pass, despite the Island's status as an international financial centre.

Absence provenance: unavailable. Searched: Isle of Man financial services data protection overlay banking secrecy.

Health Sector OverlayAmber

Manx Care, the Island's publicly-owned health and social care provider, has been the subject of Manx Information Commissioner enforcement action for failure to comply with data subject access rights under the Applied GDPR.

Claims (1):

  • Manx Care was subject to Isle of Man Information Commissioner enforcement action for failure to comply with data subject access rights under the Applied GDPR. Only confirmed Manx health-sector overlay evidence located.

Telecoms And EprivacyAmber

The Isle of Man Information Commissioner's statutory remit expressly includes the Unsolicited Communications Regulations alongside the data protection legislation, indicating an operative ePrivacy-equivalent regime, though its detailed content was not independently verified in this pass.

Claims (1):

  • Isle of Man Information Commissioner holds statutory remit over the Unsolicited Communications Regulations alongside the data protection legislation, indicating an operative ePrivacy-equivalent regime. Regulator remit confirmed; detailed regulatory content not independently verified.

Employment DataRed

No Manx employment-specific data protection overlay was located.

Absence provenance: unavailable. Searched: Isle of Man employment data protection code.

Credit And ScoringRed

No Manx credit-scoring-specific data protection overlay was located.

Absence provenance: unavailable. Searched: Isle of Man credit scoring data protection.

EducationRed

No Manx education-sector-specific data protection overlay was located.

Absence provenance: unavailable. Searched: Isle of Man education sector data protection.

InsuranceRed

No Manx insurance-sector-specific data protection overlay was located.

Absence provenance: unavailable. Searched: Isle of Man insurance sector data protection.

Category narrative68 words

Direct sectoral evidence located in this pass is limited to the health/social-care sector (Manx Care, the publicly-owned health and social care provider, subject to Applied GDPR access-right enforcement) and telecoms/e-privacy (the Unsolicited Communications Regulations, which sit alongside the data protection legislation within the Information Commissioner's statutory remit). The Isle of Man is a significant offshore financial centre, but no financial-sector overlay instrument was independently confirmed in this pass.

Sources and claims (2)
  1. ProbableDataGuidance — Manx Care was subject to Isle of Man Information Commissioner enforcement action for failure to comply with data subject access rights under the Applied GDPR. Only confirmed Manx health-sector overlay evidence located.observed
  2. UncertainDataGuidance — Isle of Man Information Commissioner holds statutory remit over the Unsolicited Communications Regulations alongside the data protection legislation, indicating an operative ePrivacy-equivalent regime. Regulator remit confirmed; detailed regulatory content not independently verified.observed

#

Only the existence of an Unsolicited Communications Regulations regime is confirmed; substantive adtech/commercial-privacy detail is an unconfirmed gap.

Supervisory authorityIsle of Man Information Commissioner
Traffic-light rationale — RedOnly the existence of an Unsolicited Communications Regulations regime is confirmed; substantive adtech/commercial-privacy detail is an unconfirmed gap.

Sub-modules (6)

Cookies And TrackersRed

No Manx-specific cookie/tracker consent guidance was located beyond the general existence of the Unsolicited Communications Regulations regime.

Absence provenance: unavailable. Searched: Isle of Man Unsolicited Communications Regulations 2005 PECR marketing cookies.

Dark PatternsRed

No Manx dark-pattern prohibition was located.

Absence provenance: unavailable. Searched: Isle of Man dark patterns data protection.

Opt Out SignalsRed

No Manx opt-out-signal (e.g. GPC-equivalent) framework was located.

Absence provenance: unavailable. Searched: Isle of Man Global Privacy Control opt-out signal.

Clean Rooms And DcrRed

No Manx data clean-room/collaboration-room rule was located.

Absence provenance: unavailable. Searched: Isle of Man data clean room data collaboration.

Cross Context AdvertisingRed

No Manx cross-context-advertising ('sale'/'share') framework analogous to CPRA was located; not expected given GDPR-model regime.

Absence provenance: unavailable. Searched: Isle of Man cross-context advertising sale share personal data.

Direct MarketingAmber

Direct marketing communications are understood to fall within the Isle of Man Information Commissioner's Unsolicited Communications Regulations remit, alongside the data protection legislation.

Claims (1):

  • Direct marketing communications regime falls within the Isle of Man Information Commissioner's Unsolicited Communications Regulations remit. Existence of regime confirmed only at the level of regulator remit.
Category narrative38 words

The Isle of Man Information Commissioner's remit over the 'Unsolicited Communications Regulations' indicates an operative direct-marketing/ePrivacy-equivalent regime, but detailed cookie-consent, dark-pattern, opt-out-signal and cross-context-advertising rules specific to the Isle of Man were not located in this research pass.

Sources and claims (1)
  1. UncertainDataGuidance — Direct marketing communications regime falls within the Isle of Man Information Commissioner's Unsolicited Communications Regulations remit. Existence of regime confirmed only at the level of regulator remit.observed

#

Core ADM/profiling protection is inherited via full GDPR adoption; AI-specific and biometric/genetic-specific regimes are unconfirmed gaps; a distinct law-enforcement carve-out regime is confirmed to exist.

Primary frameworkApplied GDPR (general) and LED Implementing Regulations 2018 (law enforcement)
Supervisory authorityIsle of Man Information Commissioner
Traffic-light rationale — AmberCore ADM/profiling protection is inherited via full GDPR adoption; AI-specific and biometric/genetic-specific regimes are unconfirmed gaps; a distinct law-enforcement carve-out regime is confirmed to exist.

Sub-modules (6)

Profiling RestrictionsAmber

Profiling restrictions (GDPR Art 22-equivalent) are presumed inherited from the fully-adopted Applied GDPR text; no Manx-specific enforcement precedent located.

Claims (1):

  • Applied GDPR Article 22-equivalent provisions govern profiling restrictions as inherited domestic law in the Isle of Man. Inferred from wholesale GDPR adoption; no Manx-specific enforcement precedent located.

Automated Decision Making TransparencyAmber

ADM transparency obligations are presumed inherited from the Applied GDPR; no Manx-specific guidance located.

Absence provenance: unavailable. Searched: Isle of Man automated decision making transparency GDPR.

Ai Risk AssessmentsRed

No Isle of Man AI-specific risk-assessment regime (EU AI Act interface or local equivalent) was located.

Absence provenance: unavailable. Searched: Isle of Man AI Act artificial intelligence risk assessment data protection.

Biometric RegimeRed

No Manx biometric-specific statute or guidance was located beyond the general special-category treatment inherited from the Applied GDPR.

Absence provenance: unavailable. Searched: Isle of Man biometric data facial recognition regime.

Genetic DataRed

No Manx genetic-data-specific statute or guidance was located beyond the general special-category treatment inherited from the Applied GDPR.

Absence provenance: unavailable. Searched: Isle of Man genetic data regime.

State Surveillance CarveoutsAmber

The LED Implementing Regulations 2018 establish a distinct legal regime for law-enforcement/competent-authority processing, separate from the general Applied GDPR, evidencing a formal state-processing carve-out structure.

Claims (1):

  • LED Implementing Regulations 2018 establish a distinct legal regime for law-enforcement/competent-authority processing, separate from the general Applied GDPR. Formal state-processing carve-out structure confirmed.
Category narrative49 words

Algorithmic/ADM and profiling protections are presumed inherited from the wholesale adoption of the GDPR (including Article 22), and a distinct law-enforcement/state-processing regime exists via the LED Implementing Regulations 2018, separate from the general Applied GDPR. No Isle of Man-specific AI risk-assessment regime, biometric-specific statute, or genetic-data-specific statute was located.

Periodic update · new data 2026-09-21

Algorithmic, Biometric & Surveillance Governance

The Isle of Man's algorithmic-governance posture this cycle is defined by a single, notable but non-binding development: the Isle of Man Information Commissioner's office joined 61 regulators globally, alongside the Guernsey and Jersey data protection authorities, in issuing a statement of concern about growing misuse of AI systems. Reports suggest this reflects a coordinated multi-jurisdiction regulatory posture on AI risk rather than a unilateral Isle of Man initiative, and it is understood to have been issued via the Commissioner's own news channel. No dedicated Isle of Man AI-specific or biometric-specific regulatory instrument -- whether guidance, code of practice, or binding rule -- has been identified this cycle; the joint statement is the extent of the Island's documented engagement with algorithmic governance at this time.

This finding is reported at Probable confidence, reflecting that the joint statement itself is confirmed via a Tier-1 source (the Commissioner's own news feed) but that its practical implications for how the Isle of Man will supervise or enforce against AI-related data-protection harms remain undefined. The statement of concern format -- a joint expression of regulatory anxiety rather than a rule, code or enforcement priority -- means it creates no new binding obligation on controllers or processors operating on the Island, and readers should not treat it as equivalent to an AI-specific code of practice or statutory instrument.

Outlook

The question worth tracking into the next cycle is whether the joint statement of concern is followed by any Isle-of-Man-specific guidance, code of practice, or enforcement priority addressing AI or algorithmic processing under the existing Data Protection Act 2018/GDPR-equivalent framework. Absent such a follow-on instrument, the Island's algorithmic-governance position remains defined entirely by the general lawful-processing and accountability principles of its GDPR-equivalent regime rather than by any AI-specific rule.

Sources and claims (2)
  1. UncertainDataGuidance — Applied GDPR Article 22-equivalent provisions govern profiling restrictions as inherited domestic law in the Isle of Man. Inferred from wholesale GDPR adoption; no Manx-specific enforcement precedent located.observed
  2. ProbableDataGuidance — LED Implementing Regulations 2018 establish a distinct legal regime for law-enforcement/competent-authority processing, separate from the general Applied GDPR. Formal state-processing carve-out structure confirmed.observed

#

This entire module rests on inference from wholesale GDPR adoption; no Manx-specific children's-data source was independently confirmed.

Supervisory authorityIsle of Man Information Commissioner
Traffic-light rationale — RedThis entire module rests on inference from wholesale GDPR adoption; no Manx-specific children's-data source was independently confirmed.

Sub-modules (5)

Age VerificationRed

No Manx-specific age-verification requirement was located.

Absence provenance: unavailable. Searched: Isle of Man age verification children data protection.

Minor Profiling BansRed

No Manx-specific minor-profiling ban was located.

Absence provenance: unavailable. Searched: Isle of Man minor profiling ban children's code.

Education SettingsRed

No Manx education-settings-specific data protection rule was located.

Absence provenance: unavailable. Searched: Isle of Man education settings data protection children.

Dependent AdultsRed

No Manx dependent-adults-specific data protection provision was located.

Absence provenance: unavailable. Searched: Isle of Man dependent adults vulnerable data protection.

Category narrative64 words

No Isle of Man-specific instrument confirming the exact digital age-of-consent figure, parental-consent mechanism, minor-profiling ban, education-settings rule, or dependent-adults protection was located in this research pass. The Isle of Man's adoption of the GDPR 'with adaptations specific to the requirements of the Isle of Man' leaves open whether it mirrors the UK's age-13 Article 8 threshold or another figure within the 13-16 GDPR range.

no periodic updates on record for this sub-brief

Sources and claims (1)
  1. SpeculativeDataGuidance — Applied GDPR Article 8-equivalent provision (Isle of Man adaptation) has an unconfirmed digital age of consent, possibly mirroring the UK's age of 13, but this was not independently verified in primary Manx legislative text. Only general 'adoption with adaptations' language located; the specific enacted age figure was not found.observed

#

Clear, repeated, and recent (through Dec 2025) enforcement activity confirms an active regulator; funding/capacity and redress-mechanism sub-modules remain unconfirmed gaps.

Primary frameworkData Protection Act 2018 (Isle of Man) enforcement provisions
Supervisory authorityIsle of Man Information Commissioner
Traffic-light rationale — GreenClear, repeated, and recent (through Dec 2025) enforcement activity confirms an active regulator; funding/capacity and redress-mechanism sub-modules remain unconfirmed gaps.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

The Commissioner can issue enforcement notices requiring compliance, with failure to comply risking a penalty and/or contempt proceedings.

Claims (1):

  • Isle of Man Information Commissioner can issue enforcement notices requiring compliance, with failure to comply risking a penalty and/or contempt proceedings. Regulator powers confirmed via demonstrated enforcement practice.

Enforcement Activity IndexGreen

Documented enforcement actions include the 2020 DHA enforcement notice, the 2021 Manx Care enforcement notice, a reported 2022 Manx Care fine, and the December 2025 joint breach investigation.

Claims (2):

  • Isle of Man Information Commissioner issued enforcement notices against DHA (2020) and Manx Care (2021), plus a reported 2022 fine against Manx Care whose amount and full basis remain unverified. 2022 fine reported only via T4 source; amount/basis not independently confirmed (see gap gdpri-int-14).
  • UK ICO, Guernsey, Jersey and Isle of Man regulators opened a joint cross-jurisdictional breach investigation (Prospect incident) in December 2025. Most recent and most material enforcement development located this cycle.

Regulator Funding And CapacityRed

No Manx-specific regulator funding/headcount data was located.

Absence provenance: unavailable. Searched: Isle of Man Information Commissioner funding headcount budget.

Collective Redress And Class ActionsRed

No Manx-specific collective-redress or class-action mechanism for data protection claims was located.

Absence provenance: unavailable. Searched: Isle of Man collective redress class action data protection.

Private Right Of ActionRed

No Manx-specific private-right-of-action provision for data protection claims was located.

Absence provenance: unavailable. Searched: Isle of Man private right of action data protection court.

Recent Developments 180DAmber

No Isle of Man-specific data protection development strictly within the last 180 days (i.e. since approximately February 2026) was identified; the most recent substantive development located is the joint UK/Guernsey/Jersey/Isle of Man breach investigation opened in December 2025, which falls just outside the strict 180-day window from the current date.

Absence provenance: unavailable. Searched: Isle of Man Information Commissioner 2026 data protection.

Claims (1):

  • Isle of Man Information Commissioner (joint with UK/Guernsey/Jersey) opened a joint breach investigation in December 2025, the most recent substantive development though falling just outside the strict 180-day window from the current run date. No development strictly within 180 days was located; this is the nearest qualifying development.
Category narrative98 words

The Isle of Man Information Commissioner has a demonstrated enforcement track record: enforcement notices against the Department of Home Affairs (2020) and Manx Care (2021) for access-right failures, a reported fine against Manx Care (2022, details not independently verified), and a live joint cross-jurisdictional breach investigation with the UK ICO and Jersey/Guernsey authorities (opened December 2025) into a cyber incident. Regulator funding/capacity, collective redress, and private-right-of-action mechanisms specific to the Isle of Man were not confirmed in this pass; no development strictly within the last 180 days (since approximately February 2026) was identified beyond the ongoing 2025 investigation.

Periodic update · new data 2026-09-28

Enforcement & Redress

The most recent developments in this module are administrative rather than adjudicative. A new Information Commissioner has been in post since September 2024, and the most recent activity associated with the office includes a proposed Data Asset Register initiative and the fee-revision consultation discussed under Regulator & Framework above. No specific enforcement action, fine, or redress decision has been identified for the Isle of Man this cycle.

The reported increase in breach-impacted individuals for Q4 2025/26, discussed under Controller/Processor Duties, has not yet translated into any identified enforcement response from the Information Commissioner, and the underlying figure itself remains uncorroborated against a primary source this cycle.

Outlook

With a relatively new Information Commissioner in post, the direction of enforcement posture under this office is still establishing itself. The proposed Data Asset Register initiative and the fee-revision consultation are the two concrete markers of current regulatory activity; any enforcement action arising from the reported Q4 2025/26 breach figures, once corroborated, would be a significant marker for this module.

1 earlier distinct update(s)
Periodic update · new data 2026-09-21

Enforcement & Redress

The Isle of Man's enforcement and redress picture this cycle rests on notably thinner primary sourcing than its framework and adequacy position. The Island's data protection regime is reported to cap the maximum administrative fine at GBP 1,000,000, materially lower than the EU GDPR ceiling of EUR 20,000,000 or 4% of global annual turnover. This figure is reported only, not confirmed: it rests on a single Tier-3 aggregator source, and the primary statutory penalty provisions of the Data Protection Act 2018 and the GDPR and LED Implementing Regulations 2018 were not directly retrieved this cycle to verify the figure against the legislation itself.

On enforcement activity, the Isle of Man Information Commissioner is reported to have issued at least three Enforcement Notices since April 2024, including urgent notices. This too rests on the same single Tier-3 aggregator source, with no primary enforcement-notice register located this cycle to corroborate the count or characterise the substance of those notices. Reports suggest an active but modest enforcement posture, though the underlying evidentiary basis for that characterisation remains thin.

Separately, the Office of the Data Protection Supervisor, now operating as the Information Commissioner's office, is reported to be funded by a mix of Isle of Man Treasury funding and registration fees, while remaining institutionally independent of the Isle of Man Government. This funding-and-capacity finding rests on a Tier-4 source and is reported at Uncertain confidence; it bears on the regulator's practical enforcement capacity but has not been independently corroborated against a primary budgetary or statutory source.

Outlook

The clearest gap to close in the next cycle is primary-source verification of the statutory maximum administrative fine, ideally sourced directly to legislation.gov.im or an equivalent primary Isle of Man legislative database, which would allow this figure to move from Uncertain to a more assertive confidence tier. A primary Isle of Man Information Commissioner enforcement-notice register, if one exists in published form, would similarly firm up the currently thin enforcement-activity count.

Sources and claims (4)
  1. ProbableDataGuidance — Isle of Man Information Commissioner can issue enforcement notices requiring compliance, with failure to comply risking a penalty and/or contempt proceedings. Regulator powers confirmed via demonstrated enforcement practice.observed
  2. UncertainDataGuidance — Isle of Man Information Commissioner issued enforcement notices against DHA (2020) and Manx Care (2021), plus a reported 2022 fine against Manx Care whose amount and full basis remain unverified. 2022 fine reported only via T4 source; amount/basis not independently confirmed (see gap gdpri-int-14).observed
  3. ProbableICO — UK ICO, Guernsey, Jersey and Isle of Man regulators opened a joint cross-jurisdictional breach investigation (Prospect incident) in December 2025. Most recent and most material enforcement development located this cycle.observed
  4. ProbableICO — Isle of Man Information Commissioner (joint with UK/Guernsey/Jersey) opened a joint breach investigation in December 2025, the most recent substantive development though falling just outside the strict 180-day window from the current run date. No development strictly within 180 days was located; this is the nearest qualifying development.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metpass
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct64.71
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Isle of Man
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 27 claim(s) (27 category placement(s)), 24 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 8Children & Vulnerable Groupsparental consent
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 82Enforcement & Redresscollective redress and class actions
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

regulator_and_framework, data_subject_rights, controller_processor_duties (breach/security sub-modules), cross_border_and_adequacy (adequacy_received), and enforcement_and_redress are supported by T1-T3 primary/secondary sources including EU Commission adequacy decisions, EUR-Lex texts, UK ICO opinions/guidance, and DataGuidance reporting of named Manx enforcement notices. lawful_processing_and_special_data and algorithmic_biometric_and_surveillance_governance rely substantially on inference from the Isle of Man's wholesale adoption of the GDPR text, supported by only one directly-cited Manx enforcement precedent (Schedule 9 special-category exemption). sectoral_watch and adtech_and_commercial_privacy are only thinly evidenced (health sector via Manx Care; telecoms via the Unsolicited Communications Regulations remit) with most other sub-modules carrying explicit absent_field_provenance. children_and_vulnerable_groups is almost entirely unconfirmed (T4/absent) for the Isle of Man specifically, since the exact 'adaptations' the Island made to GDPR Article 8 were not located in any indexed primary or secondary source.

Unresolved questions (6):

  • What is the exact digital age of consent (Article 8-equivalent) adopted by the Isle of Man's Applied GDPR Order, and does it match the UK's age of 13?
  • Does the Isle of Man operate its own controller registration/notification-fee scheme analogous to the UK ICO's fee-payer register, and if so under what instrument?
  • Is there a Manx financial-services-specific data protection overlay given the Island's status as an international financial centre (relevant to potential financial_integrity/world_payments overlap)?
  • What was the confirmed monetary amount and full basis of the reported 2022 Manx Care fine?
  • Does the Isle of Man's own law recognise or grant adequacy findings to third countries independently of EU/UK determinations?
  • What are the detailed contents of the Isle of Man's Unsolicited Communications Regulations (cookie consent, telemarketing rules, penalties)?

Escalate to primary-source review: yes