PAschema gdpri-v2trajectory: not yet assessedregulated (omnibus)overlaps: FIM, WPM, Crypto
Last updated · 10 categories · 24
claims · 19 sources in the cumulative register
10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
24Claimsbaseline..claims[]
10Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix(sums to 10 rendered categories; click to filter)
No red categories; 34 sub-modules are flagged red.
Jurisdiction brief
Standing brief, as of 23 August 2026.
Lead Signal
Panama's Autoridad Nacional de Transparencia y Acceso a la Información (ANTAI) approved Resolution ANTAI-DG-003-2026 on 26 March 2026, implementing Standard Contractual Clauses under the Reglamento de Implementación de la Protección de Datos (RIPD) for international transfers of personal data. This is Panama's first formal, standardised cross-border transfer mechanism under its Data Protection Law, and it reduces the legal uncertainty that previously attended cross-border data flows out of Panama, since controllers and processors now have a recognised contractual instrument to rely on rather than case-by-case assessment. Because this is Panama's first standardised instrument of this kind, it is best read as an infrastructure development for the cross-border-transfer regime generally, rather than as a change to underlying substantive data-protection standards; the safeguards these clauses are designed to carry across borders are those already established under the Data Protection Law, not new ones introduced by this resolution.
Other Developments
Standardised clauses fill a gap in the omnibus framework. Panama's Data Protection Law did not previously specify a standardised transfer mechanism comparable to well-known Standard Contractual Clauses models used elsewhere; ANTAI's 2026 resolution addresses that gap directly by adopting an RIPD-specific SCC instrument. Standard Contractual Clauses of this kind typically operate by imposing contractual data-protection obligations on the data importer that mirror the exporting jurisdiction's substantive protections, giving the exporting controller a documented basis for arguing that adequate safeguards travel with the data. ANTAI's adoption of this model formalises that pathway for Panama-origin transfers for the first time; previously, controllers relying on contractual safeguards for cross-border transfers did so without a regulator-approved standard template to point to.
Cross-Monitor Connections
Cross-border data-transfer developments of this kind intersect with the financial-integrity monitor's coverage of Panama's beneficial-ownership and AML/CFT information-sharing architecture, insofar as both regimes govern what information may move across Panama's borders and under what safeguards, though the two frameworks are legally distinct: ANTAI's transfer clauses govern personal data specifically, not beneficial-ownership or transaction data held under AML/CFT law. Organisations operating in both spaces should not assume the new SCC mechanism extends to financial-integrity data-sharing obligations, which remain governed separately.
Outlook
The item to watch next cycle is whether ANTAI publishes implementing guidance clarifying the scope of the new RIPD Standard Contractual Clauses — for instance, whether they are available for use with any destination jurisdiction or are restricted to specific transfer scenarios — and whether any adequacy-style jurisdiction list develops alongside the new contractual mechanism. No Tier-1 (ANTAI primary text or gazette) source was directly retrieved this cycle for the resolution itself; a primary-source confirmation would raise confidence in the mechanism's exact scope and effective date.
trust tier: ai_unverified
Standing brief, as of 23 August 2026.
Regulatory Status
Panama's data-protection cross-border regime advanced this cycle with ANTAI's approval of Resolution ANTAI-DG-003-2026, implementing RIPD Standard Contractual Clauses for international personal-data transfers — the jurisdiction's first standardised transfer mechanism under Law No. 81 of 2019 and Executive Decree No. 285 of 2021.
Outlook
Watch for ANTAI implementing guidance clarifying the new clauses' scope and for any Tier-1 primary-source confirmation of the resolution's text and effective date.
10 of 10 categories
Signal
Density
Selections OR within a group, AND across groups. Press / to search.
A comprehensive statute is in force with a designated regulator and implementing regulation; territorial scope and registration/filing mechanics remain under-documented in public sources.
Primary frameworkLaw No. 81 of 26 March 2019 on the Protection of Personal Data (as regulated by Executive Decree No. 285 of 28 May 2021)
Traffic-light rationale — GreenA comprehensive statute is in force with a designated regulator and implementing regulation; territorial scope and registration/filing mechanics remain under-documented in public sources.
Sub-modules (5)
Regulator And AuthorityGreen
Article 17 of Law 81 designates ANTAI as the competent authority, exercised via its Dirección de Protección de Datos Personales.
Claims (1):
Article 17 of Law 81 of 26 March 2019 designates ANTAI as the competent authority for personal data protection matters in Panama, exercised through its Dirección de Protección de Datos Personales.
Act And InstrumentsGreen
Core instrument is Law 81/2019, implemented by Executive Decree 285/2021 which adds operational detail including a DPO figure, sanction criteria, breach and transfer procedures.
Claims (3):
Law No. 81 of 2019 establishes the principles, rights, obligations and procedures regulating the protection of personal data in Panama, considering its interrelation with privacy and other rights.
Executive Decree No. 285 of 28 May 2021 regulates Law 81, introducing the figure of the Data Protection Officer ('Oficial de Protección de Datos Personales') and setting criteria for the application of sanctions.
Executive Decree No. 285 includes provisions on information-gathering requirements, data breach procedures, and international data transfer procedures implementing Law 81.
Material ScopeGreen
Law 81 defines personal data broadly as any information concerning an identified or identifiable natural person.
Claims (1):
Law 81's glossary defines personal data as any information concerning natural persons that identifies them or renders them identifiable.
Territorial ScopeAmber
No specific provision on extraterritorial/non-established-controller application was located in the sources reviewed.
Absence provenance: unavailable. Searched: Law 81 text (antai.gob.pa PDF), ANTAI legislación page, dataguidance.com Panama jurisdiction notes.
Regulator Registration And FilingAmber
No dedicated public database-registration/filing regime (akin to a national RUB) was identified; sanctions provisions reference closure of 'registros de la base de datos' but this appears administrative/punitive rather than an ex ante filing obligation.
Panama's omnibus regime is Law No. 81 of 26 March 2019 on the Protection of Personal Data, supervised by the Autoridad Nacional de Transparencia y Acceso a la Información (ANTAI) through its Dirección de Protección de Datos Personales. ANTAI combines data-protection and transparency/access-to-information mandates in one body, structurally similar to Hungary's NAIH and Montenegro's AZLP. The law entered into force on 29 March 2021 (two years after promulgation) and is implemented by Executive Decree No. 285 of 28 May 2021.
Sources and claims (5)
ConfirmedANTAI — Article 17 of Law 81 of 26 March 2019 designates ANTAI as the competent authority for personal data protection matters in Panama, exercised through its Dirección de Protección de Datos Personales.observed
ConfirmedANTAI — Law No. 81 of 2019 establishes the principles, rights, obligations and procedures regulating the protection of personal data in Panama, considering its interrelation with privacy and other rights.observed
ConfirmedANTAI — Executive Decree No. 285 of 28 May 2021 regulates Law 81, introducing the figure of the Data Protection Officer ('Oficial de Protección de Datos Personales') and setting criteria for the application of sanctions.observed
ConfirmedDataGuidance — Executive Decree No. 285 includes provisions on information-gathering requirements, data breach procedures, and international data transfer procedures implementing Law 81.observed
ConfirmedANTAI — Law 81's glossary defines personal data as any information concerning natural persons that identifies them or renders them identifiable.observed
Traffic-light rationale — AmberCore consent and special-category concepts are confirmed, but pseudonymisation/anonymisation treatment is undocumented in the sources reviewed.
Sub-modules (4)
Lawful BasesGreen
General rule is consent-based processing, with exceptions enumerated in Article 8 of Law 81.
Claims (1):
Under Law 81, processing of personal data generally requires the data subject's consent, subject to exceptions established in Article 8 of the Law.
Consent ThresholdsGreen
Lawful processing requires prior, informed, and unequivocal consent of the data subject.
Claims (1):
For processing of personal data to be lawful under Law 81, it must be carried out with the prior, informed, and unequivocal consent of the data subject.
Special CategoriesAmber
Law 81 defines sensitive data categories and establishes a Personal Data Protection Council.
Claims (1):
Law 81 defines sensitive personal data categories and establishes a Personal Data Protection Council as part of the regime's institutional architecture.
Pseudonymisation And AnonymisationRed
No pseudonymisation/anonymisation safe-harbour text was located in the sources reviewed.
Law 81 requires consent as the general lawful basis for processing, subject to statutory exceptions in Article 8, and mandates that consent be prior, informed and unequivocal. The law also defines sensitive data and establishes a Personal Data Protection Council; pseudonymisation/anonymisation safe-harbour definitions were not located in available sources.
Sources and claims (3)
ConfirmedANTAI — Under Law 81, processing of personal data generally requires the data subject's consent, subject to exceptions established in Article 8 of the Law.observed
ConfirmedDataGuidance — For processing of personal data to be lawful under Law 81, it must be carried out with the prior, informed, and unequivocal consent of the data subject.observed
ConfirmedDataGuidance — Law 81 defines sensitive personal data categories and establishes a Personal Data Protection Council as part of the regime's institutional architecture.observed
Traffic-light rationale — AmberSubstantive rights are confirmed and enumerated by ANTAI itself; deadline/response-window specifics are an evidence gap.
Sub-modules (5)
Access RightGreen
Right of access allows data subjects to obtain and know the origin and purpose of their personal data held by public or private institutions.
Claims (1):
Law 81 grants data subjects a right of access to obtain and know the origin and purpose of their personal data held for storage or processing by public or private institutions.
Rectification And ErasureGreen
Rights of rectification and cancellation allow correction or deletion of incorrect, irrelevant, incomplete, outdated, inaccurate, false or impertinent personal data.
Claims (1):
Data subjects have rights of rectification and cancellation permitting them to request correction or deletion of personal data that is incorrect, irrelevant, incomplete, outdated, inaccurate, false or impertinent.
Restriction And ObjectionGreen
Right of opposition allows data subjects, on legitimate grounds, to refuse provision of data or object to specific processing, and to revoke consent.
Claims (1):
Data subjects have a right of opposition permitting them, for well-founded and legitimate reasons, to refuse to provide personal data or object to specific processing, and to revoke previously given consent.
Data PortabilityAmber
Law 81 recognizes a right to data portability among the fundamental rights of data subjects.
Claims (1):
Law 81 enumerates portability among the fundamental rights recognized to the personal data subject.
Deadlines And Response WindowsRed
No specific statutory response-time deadlines for controller action on rights requests were located.
Absence provenance: unavailable. Searched: ANTAI FAQ page, Ley 81 PDF, dataguidance.com Panama data subject rights note.
Key findings (3)
— source on file
— source on file
— source on file
Category narrative30 words
Law 81 grants data subjects rights of access, rectification, cancellation (erasure), opposition (including consent revocation), and portability. Specific statutory response-time deadlines for controllers were not located in the sources reviewed.
Sources and claims (4)
ConfirmedANTAI — Law 81 grants data subjects a right of access to obtain and know the origin and purpose of their personal data held for storage or processing by public or private institutions.observed
ConfirmedANTAI — Data subjects have rights of rectification and cancellation permitting them to request correction or deletion of personal data that is incorrect, irrelevant, incomplete, outdated, inaccurate, false or impertinent.observed
ConfirmedANTAI — Data subjects have a right of opposition permitting them, for well-founded and legitimate reasons, to refuse to provide personal data or object to specific processing, and to revoke previously given consent.observed
ProbableANTAI — Law 81 enumerates portability among the fundamental rights recognized to the personal data subject.observed
Security/accountability and DPO elements are confirmed at a structural level; DPIA, ROPA, joint-controller and retention specifics are evidence gaps pending fuller decree-text review.
Primary frameworkExecutive Decree No. 285 of 28 May 2021 (regulating Law No. 81 of 2019)
Traffic-light rationale — AmberSecurity/accountability and DPO elements are confirmed at a structural level; DPIA, ROPA, joint-controller and retention specifics are evidence gaps pending fuller decree-text review.
Sub-modules (7)
Accountability And DpiaAmber
No specific DPIA-trigger provisions were located; general accountability of controllers/custodians is confirmed via Decree 285 Arts. 58-59.
Claims (1):
Articles 58 and 59 of Executive Decree 285 empower ANTAI's Dirección de Protección de Datos Personales to sanction the data controller ('responsable del tratamiento') and the database custodian for infractions of Law 81, and establish that both are responsible for compliance and subject to oversight.
Dpo RequirementsAmber
Decree 285 introduces the 'Oficial de Protección de Datos Personales' figure; appointment thresholds and independence criteria were not detailed in available sources.
Claims (1):
Executive Decree No. 285 introduces the figure of the 'Oficial de Protección de Datos Personales' (Data Protection Officer) as part of the implementing rules for Law 81.
Ropa RequirementsRed
No records-of-processing (ROPA) obligation text was located.
Decree 285 (Arts. 58-59) holds the data controller and database custodian responsible for compliance and subject to ANTAI oversight and sanction for infractions of Law 81.
Claims (1):
Articles 58 and 59 of Executive Decree 285 empower ANTAI's Dirección de Protección de Datos Personales to sanction the data controller ('responsable del tratamiento') and the database custodian for infractions of Law 81, and establish that both are responsible for compliance and subject to oversight.
Breach NotificationAmber
Decree 285 establishes procedures for handling personal data breaches, though specific notification thresholds/timelines to regulator and subjects were not located.
Claims (1):
Executive Decree 285 includes procedures for handling data breaches as part of the implementing regulation of Law 81.
Retention And DisposalRed
No retention-limit or disposal-duty text was located.
Executive Decree 285 (2021) creates a Data Protection Officer figure, holds both the data controller ('responsable del tratamiento') and database custodian accountable for compliance under Articles 58-59, and includes breach-handling and cross-border transfer procedures. DPIA triggers, ROPA obligations, joint-controller rules and retention/disposal duties were not located in the sources reviewed.
Sources and claims (3)
ConfirmedANTAI — Executive Decree No. 285 introduces the figure of the 'Oficial de Protección de Datos Personales' (Data Protection Officer) as part of the implementing rules for Law 81.observed
ConfirmedANTAI — Articles 58 and 59 of Executive Decree 285 empower ANTAI's Dirección de Protección de Datos Personales to sanction the data controller ('responsable del tratamiento') and the database custodian for infractions of Law 81, and establish that both are responsible for compliance and subject to oversight.observed
ProbableDataGuidance — Executive Decree 285 includes procedures for handling data breaches as part of the implementing regulation of Law 81.observed
Traffic-light rationale — AmberA transfer mechanism exists in statute and decree, but adequacy, SCC/BCR, TIA and localisation specifics are undocumented in the sources reviewed.
Sub-modules (6)
Transfer MechanismsGreen
Cross-border processing of confidential/sensitive/restricted data is permitted if protection-standard compliance is demonstrated; Decree 285 adds transfer procedures.
Claims (2):
Law 81 permits cross-border processing of confidential, sensitive, or restricted personal data where compliance with data-protection standards is demonstrated.
Executive Decree 285 includes procedures governing international data transfers as part of the implementing regulation of Law 81.
Adequacy ReceivedRed
No adequacy decision received by Panama from another regime was located.
No data-localisation mandate (partial or absolute) was located; the law's cross-border permission language suggests transfers are conditionally allowed rather than restricted, but this is inferential.
Law 81 permits cross-border processing/transfer of confidential, sensitive, or restricted personal data where compliance with data-protection standards is demonstrated, and Executive Decree 285 adds procedural detail for international transfers. No formal adequacy decisions received from or granted to other regimes, SCC/BCR forms, transfer-impact-assessment mandates, or data-localisation rules were located.
No new data since the standing brief. 1 periodic run re-emitted it unchanged.
Sources and claims (2)
ConfirmedDataGuidance — Law 81 permits cross-border processing of confidential, sensitive, or restricted personal data where compliance with data-protection standards is demonstrated.observed
ProbableDataGuidance — Executive Decree 285 includes procedures governing international data transfers as part of the implementing regulation of Law 81.observed
The 'minimum standard' relationship to sector-specific laws is confirmed at a general level, but no sector-specific overlay instruments were individually verified.
Primary frameworkLaw No. 81 of 2019 (as minimum standard vis-à-vis sector-specific laws)
Traffic-light rationale — AmberThe 'minimum standard' relationship to sector-specific laws is confirmed at a general level, but no sector-specific overlay instruments were individually verified.
Sub-modules (7)
Financial Sector OverlayAmber
Law 81 is confirmed as the general minimum-compliance standard applicable across sectors including finance; no dedicated banking-secrecy/DP interface text was located.
Claims (1):
ANTAI resolutions state that Law 81 constitutes the general framework for personal-data-protection rights in Panama and must be considered the minimum compliance standard in relation to any special sector-specific law on the matter.
Health Sector OverlayRed
No health-sector-specific DP overlay text was located.
Absence provenance: unavailable. Searched: Panama health data law searches, ANTAI legislación page.
Telecoms And EprivacyRed
No telecoms/ePrivacy-specific overlay text was located.
ANTAI resolutions confirm that Law 81 functions as the general framework and minimum compliance standard applicable to any sector-specific law addressing personal data protection in Panama. No sector-specific overlay instruments for health, telecoms/ePrivacy, employment, credit-scoring, education, or insurance were located in the sources reviewed; the financial sector is flagged given Panama's role as a regional financial/banking center but no dedicated financial-sector DP overlay text was retrieved.
Sources and claims (1)
ProbableANTAI — ANTAI resolutions state that Law 81 constitutes the general framework for personal-data-protection rights in Panama and must be considered the minimum compliance standard in relation to any special sector-specific law on the matter.observed
No adtech/commercial-privacy-specific instrument was identified; general consent-based processing under Law 81 is the only applicable baseline and is already captured under lawful_processing_and_special_data.
Traffic-light rationale — Not assessedNo adtech/commercial-privacy-specific instrument was identified; general consent-based processing under Law 81 is the only applicable baseline and is already captured under lawful_processing_and_special_data.
Sub-modules (6)
Cookies And TrackersRed
No cookie/tracker-specific consent regime was located.
No cookie/tracker-consent regime, dark-pattern prohibition, opt-out-signal framework, clean-room rules, cross-context-advertising rules, or direct-marketing-specific suppression regime distinct from Law 81's general consent requirement was located in the sources reviewed.
Traffic-light rationale — Not assessedNo algorithmic/biometric/surveillance-governance-specific instrument was identified for this JID in the sources reviewed.
No Article-22-analogue profiling restriction, ADM transparency right, AI-specific risk-assessment requirement, biometric-data regime, genetic-data regime, or state-surveillance carve-out text specific to Panama's Law 81 framework was located in the sources reviewed.
No age-of-consent, parental-consent mechanism, minor-profiling ban, education-settings-specific rule, or dependent-adults provision specific to Law 81 was located in the sources reviewed.
Powers, penalties and case-level enforcement activity are documented from primary ANTAI resolutions, but funding/capacity metrics and collective-redress mechanisms remain evidence gaps.
Primary frameworkLaw No. 81 of 2019; Executive Decree No. 285 of 2021
Traffic-light rationale — AmberPowers, penalties and case-level enforcement activity are documented from primary ANTAI resolutions, but funding/capacity metrics and collective-redress mechanisms remain evidence gaps.
Sub-modules (6)
Regulator Powers And PenaltiesGreen
ANTAI's Data Protection Directorate can investigate and sanction violations, with fines of B/.1,000-10,000 or closure of database registries for very serious infractions.
Claims (2):
Law 81 establishes sanctions for non-compliance ranging from B/.1,000 to B/.10,000, or, for very serious infractions, closure of the database registries.
ANTAI, through its Dirección de Datos Personales, holds the authority to conduct investigations and impose sanctions on natural or legal persons who violate Law 81.
Enforcement Activity IndexAmber
ANTAI has issued complaint-driven admission and closure resolutions in individual data-protection cases (e.g., ANTAI-PDP-065-2022 admission; ANTAI-PDP-009-2022 closure), indicating an active but complaint-triggered enforcement posture; a systematic 12-month enforcement/fines index was not located.
Claims (2):
ANTAI has issued formal admission resolutions in individual data-protection complaints, such as Resolución de Admisión No. ANTAI-PDP-065-2022, evidencing an operating complaint-intake process.
ANTAI has issued closure resolutions concluding data-protection investigations, such as Resolución de Cierre No. ANTAI-PDP-009-2022, indicating active case-level enforcement under Law 81.
Regulator Funding And CapacityRed
No published headcount or budget data specific to the Dirección de Protección de Datos Personales was located.
Law 81 requires compensation for damages arising from improper personal data treatment, indicating a civil-liability avenue for data subjects.
Claims (1):
Law 81 requires compensation for damages resulting from improper treatment of personal data.
Recent Developments 180DAmber
ANTAI's legislación page lists Circular No. DS-002-2026 on compliance obligations in personal-data-protection matters among its 2026 issuances.
Claims (1):
ANTAI's 2026 issuances list Circular No. DS-002-2026 addressing 'Cumplimiento de obligaciones en materia de Protección de Datos Personales' (compliance with personal-data-protection obligations).
Key findings (3)
— source on file
— source on file
— source on file
Category narrative79 words
ANTAI's Dirección de Protección de Datos Personales holds investigative and sanctioning powers over natural and legal persons violating Law 81, with fines ranging from B/.1,000 to B/.10,000 and closure of database registries for very serious infractions. ANTAI has issued individual complaint-driven resolutions (admissions and closures) evidencing an operating enforcement docket, and Law 81 provides for compensation of damages from improper data treatment. A 2026 ANTAI circular addresses ongoing compliance obligations; regulator funding/capacity data and collective-redress/class-action mechanisms were not located.
Sources and claims (6)
ConfirmedANTAI — Law 81 establishes sanctions for non-compliance ranging from B/.1,000 to B/.10,000, or, for very serious infractions, closure of the database registries.observed
ConfirmedANTAI — ANTAI, through its Dirección de Datos Personales, holds the authority to conduct investigations and impose sanctions on natural or legal persons who violate Law 81.observed
ConfirmedANTAI — ANTAI has issued formal admission resolutions in individual data-protection complaints, such as Resolución de Admisión No. ANTAI-PDP-065-2022, evidencing an operating complaint-intake process.observed
ConfirmedANTAI — ANTAI has issued closure resolutions concluding data-protection investigations, such as Resolución de Cierre No. ANTAI-PDP-009-2022, indicating active case-level enforcement under Law 81.observed
ConfirmedDataGuidance — Law 81 requires compensation for damages resulting from improper treatment of personal data.observed
ProbableANTAI — ANTAI's 2026 issuances list Circular No. DS-002-2026 addressing 'Cumplimiento de obligaciones en materia de Protección de Datos Personales' (compliance with personal-data-protection obligations).observed
No categories match.
Filters combine as OR inside a group and AND across
groups.
Publication gate
No failing checks.
schema_valid
pass
min_t1_per_instrument_met
n/a — no subject in this jurisdiction
min_quoted_text_present
waived — floor 0%
translation_provenance_recorded
n/a — no subject in this jurisdiction
egress_verified
pass
source_tier_integrity_ok
pass
jurisdiction_source_floor_met
pass
tier_a_b_national_primary_pct
71.43
aggregator_only_jurisdiction_count
0
manual_override
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for Panama
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
no reviewer on record
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 24 claim(s) (24 category placement(s)), 19 source(s) in the cumulative register.
T1 anchors (Law 81 text, ANTAI legislación page, ANTAI FAQ, ANTAI news items, and multiple ANTAI enforcement resolutions/PDFs) were verified and used to ground regulator_and_framework, lawful_processing_and_special_data, data_subject_rights, controller_processor_duties (partial), cross_border_and_adequacy (partial), sectoral_watch (general principle only), and enforcement_and_redress. T3 (DataGuidance news) supplemented cross-border, consent-standard, and breach/transfer characterizations per the seed's flag that T2/T3 coverage is thin. Four modules — adtech_and_commercial_privacy, algorithmic_biometric_and_surveillance_governance, children_and_vulnerable_groups, and most sectoral_watch sub-modules — carry no populated claims and are documented via absent_field_provenance, consistent with gap discipline for an under-published statute area.
Unresolved questions (7):
Does Law 81 or Decree 285 contain explicit statutory response-time deadlines for data-subject-rights requests?
What are the specific DPIA-trigger criteria, if any, under Decree 285?
Are there ROPA (records-of-processing) obligations for controllers under Panamanian law?
Does Panama have any sector-specific data-protection overlays (health, telecoms, employment, credit, education, insurance) distinct from Law 81's general 'minimum standard' status?
Has ANTAI published a 12-month enforcement/fines index or annual report with quantified statistics?
Does Panama have any data-localisation mandate, and what SCC/BCR-equivalent transfer instruments (if any) are recognized under Decree 285's transfer procedures?
What is the substantive content of Circular No. DS-002-2026 referenced on ANTAI's legislación page?