#
No standing position recorded for this category.
Cross-border transfer flexibility is confirmed under Article 20 of the Personal Data Protection Act (PDPA), which permits transfers of personal data outside Macau without prior approval from the data-protection authority in certain circumstances, including explicit consent or contractual necessity. This is a derogation from what is otherwise a prior-authorisation default for cross-border transfers, and it gives controllers a materially faster compliance pathway for transfers falling within the listed exceptions.
Breach-notification absence is a structural feature of the PDPA rather than a gap under active repair: the statute does not require specific action in the event of a data breach. Reports suggest the only adjacent notification channel runs through Macau's Cybersecurity Committee, of which the data-protection bureau is a member, and to which critical-infrastructure operators must separately report cybersecurity incidents. This creates a two-track system in which data breaches as such carry no PDPA-mandated notification duty, while a narrower category of cybersecurity incidents affecting critical infrastructure does.
Enforcement intensity has declined: the data-protection authority's investigations resulted in penalties in 25% of cases in 2023, falling to 17% of cases in 2024. There is understood to be no collective-redress mechanism protecting the aggregate interests of data subjects in Macau, leaving individual civil claims, where a compensation right exists under the statute, as the only private redress avenue, albeit one with no confirmed case law located this cycle.
The possible GPDP-to-PDPB reorganisation and the AMCM/GPDP institutional separation are relevant to the crypto monitor's treatment of Macau, where AMCM's virtual-asset prohibition operates entirely outside the data-protection authority's remit; readers following Macau's virtual-asset regulatory posture through the crypto monitor should not conflate AMCM enforcement with data-protection enforcement, as the two run through structurally separate authorities. No direct connection to the financial-integrity or world-payments monitors was identified in this cycle's data-protection material.
Whether the Personal Data Protection Bureau formally supersedes or merely operates alongside the GPDP name, and whether dspdp.gov.mo is now the authoritative regulator domain, remains open and would clarify the practical face of Macau's data-protection enforcement going forward. The declining penalty rate across 2023-2024 also warrants continued observation: it is not yet possible to distinguish an administrative capacity transition from a genuine reduction in enforcement intensity, and either reading carries different implications for compliance risk assessment in Macau.
No standing position recorded for this category.
No standing position recorded for this category.
No standing position recorded for this category.
No standing position recorded for this category.
No standing position recorded for this category.
No standing position recorded for this category.
No standing position recorded for this category.
No standing position recorded for this category.
No standing position recorded for this category.
No standing position recorded for this category.
Filters combine as OR inside a group and AND across groups.
No failing checks.
schema_valid | pass |
min_t1_per_instrument_met | pass |
min_quoted_text_present | waived — floor 0% |
translation_provenance_recorded | n/a — no subject in this jurisdiction |
egress_verified | pass |
source_tier_integrity_ok | pass |
jurisdiction_source_floor_met | pass |
tier_a_b_national_primary_pct | 50.0 |
aggregator_only_jurisdiction_count | 0 |
manual_override |
Provenance only. Nothing below gates publication or affects the render.
| Field | Value |
|---|---|
trust.lawyer_review.status | never_reviewed |
trust.lawyer_review.reviewer | no reviewer on record |
trust.content_source | ai_generated |
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 0 sub-module(s), 0 claim(s) (0 category placement(s)), 6 source(s) in the cumulative register.
Think something on this page is wrong? Report an error.
Cross-reference: which category/sub-module covers each UK GDPR article (14 mapped).
| Article | Category | Sub-module |
|---|---|---|
Art. 5 | Controller/Processor Duties | accountability and dpia |
Art. 6 | Lawful Processing & Special Data | lawful bases |
Art. 7 | Lawful Processing & Special Data | consent thresholds |
Art. 9 | Lawful Processing & Special Data | special categories |
Art. 22 | Algorithmic, Biometric & Surveillance Governance | automated decision making transparency |
Art. 25 | Controller/Processor Duties | accountability and dpia |
Art. 28 | Controller/Processor Duties | joint controller arrangements |
Art. 30 | Controller/Processor Duties | ropa requirements |
Art. 35 | Controller/Processor Duties | accountability and dpia |
Art. 13-22 | Data Subject Rights | access right |
Art. 32-34 | Controller/Processor Duties | security measures |
Art. 37-39 | Controller/Processor Duties | dpo requirements |
Art. 44-49 | Cross-Border & Adequacy | transfer mechanisms |
Art. 77-84 | Enforcement & Redress | regulator powers and penalties |