🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
VE v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing13 sources retrieved model claude-sonnet-5 · 2026-08-06

Venezuela

VE schema gdpri-v2 trajectory: not yet assessedunregulated gapoverlaps: FIM, WPM, AIC

Last updated · 10 categories · 25 claims · 18 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
25Claimsbaseline..claims[]
7Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

Standing brief, as of 25 August 2026.

Lead Signal

Venezuela is understood to lack a dedicated data-protection authority, with only adjacent, non-privacy-specific competence held by bodies such as SUSCERTE and sectoral regulators. Aconstitutional habeas data right under Article 28 of the Venezuelan Constitution is understood to establish a right to access, know, correct and destroy personal data that could cause harm to the data subject. This remains the jurisdiction's sole nominal protective framework. That habeas data action is exercised autonomously before the Constitutional Chamber of the Supreme Tribunal of Justice pending legislative development of Article 28, giving individuals a direct judicial route without a regulator intermediary. The UN Human Rights Council's Independent Fact-Finding Mission on Venezuela is understood to describe a widespread lack of effective judicial protection in the country, including inefficacy of the habeas corpus mechanism, context bearing directly on the practical reliability of the habeas data remedy. Movistar/Telefónica Venezuela is understood to have suffered, and not notified affected customers of, a 2025 data breach exposing the national ID numbers, names, city and phone numbers of over 3.25 million Venezuelans, a date corrected this cycle from an erroneous 2026 attribution.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

No omnibus instrument, no supervisory authority with privacy jurisdiction, and institutional capacity is described as minimal even for adjacent cybersecurity competence.

Primary frameworkConstitution of the Bolivarian Republic of Venezuela, Article 28 (habeas data) and Article 60 (privacy), as developed by TSJ Constitutional Chamber jurisprudence
Traffic-light rationale — RedNo omnibus instrument, no supervisory authority with privacy jurisdiction, and institutional capacity is described as minimal even for adjacent cybersecurity competence.

Sub-modules (5)

Regulator And AuthorityRed

No dedicated data-protection authority exists. SUSCERTE holds electronic-certification and cybersecurity competence; SUDEBAN and other sectoral regulators hold adjacent competence within their own sectors, but none has a statutory privacy-supervision mandate.

Claims (1):

  • Venezuela has no dedicated data-protection authority; SUSCERTE and sectoral bodies hold only adjacent, non-privacy-specific competence.

Act And InstrumentsRed

The operative instruments are Constitution Article 28 (habeas data), Article 60 (privacy), TSJ Constitutional Chamber jurisprudence developing those articles, and the Ley Especial Contra los Delitos Informáticos (criminal-law instrument, not a data-protection statute).

Claims (3):

  • Article 28 of the Venezuelan Constitution establishes the habeas data right permitting individuals to access, know, correct and destroy personal data held about them that could harm them.
  • In 2011 the Venezuelan Supreme Tribunal of Justice established data-protection principles interpreting the constitutional habeas data right, including purpose limitation, data accuracy, and a data-subject access procedure.
  • The Ley Especial Contra los Delitos Informáticos establishes criminal offences for unauthorised access to and disclosure of computer-held information, functioning as an adjacent criminal-law instrument rather than a data-protection statute.

Material ScopeRed

There is no statutorily defined material scope. Habeas data jurisprudence has been applied to personal data held in public/police registries and, by extension, is invoked in private-sector contexts, but no instrument defines 'personal data' or 'processing' generally.

Claims (1):

  • Habeas data jurisprudence has been applied to personal data held in state registries (e.g., a police information system), establishing the Constitutional Chamber's exclusive competence over such actions pending legislative development of Article 28.

Territorial ScopeRed

No instrument establishes territorial/extraterritorial scope for non-established controllers; the habeas data right is a domestic constitutional/procedural remedy exercised before Venezuelan courts.

Absence provenance: unavailable. Searched: Venezuela extraterritorial data protection scope, Venezuela habeas data territorial application.

Regulator Registration And FilingRed

No controller registration or filing regime exists in the absence of a data-protection authority.

Absence provenance: unavailable. Searched: Venezuela data controller registration requirement, SUSCERTE controller filing.

Category narrative83 words

Venezuela has no comprehensive data-protection statute and no dedicated data-protection authority. Constitutional habeas data (Article 28) and Article 60's privacy/digital-information-limitation clause, as elaborated by Supreme Tribunal of Justice (TSJ) Constitutional Chamber jurisprudence since 2011, function as the primary nominal source of data-protection norms. SUSCERTE (electronic certification/cybersecurity superintendency) and sectoral bodies (e.g., SUDEBAN for banking) hold only adjacent, information-security-oriented competence rather than privacy-supervisory competence. The Ley Especial Contra los Delitos Informáticos criminalises unauthorised computer access and disclosure but does not constitute a data-protection statute.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (5)
  1. ConfirmedSUSCERTE — Venezuela has no dedicated data-protection authority; SUSCERTE and sectoral bodies hold only adjacent, non-privacy-specific competence.observed
  2. ConfirmedIAPP — Article 28 of the Venezuelan Constitution establishes the habeas data right permitting individuals to access, know, correct and destroy personal data held about them that could harm them.observed
  3. ConfirmedIAPP — In 2011 the Venezuelan Supreme Tribunal of Justice established data-protection principles interpreting the constitutional habeas data right, including purpose limitation, data accuracy, and a data-subject access procedure.observed
  4. ConfirmedTSJ — The Ley Especial Contra los Delitos Informáticos establishes criminal offences for unauthorised access to and disclosure of computer-held information, functioning as an adjacent criminal-law instrument rather than a data-protection statute.observed
  5. ConfirmedTSJ — Habeas data jurisprudence has been applied to personal data held in state registries (e.g., a police information system), establishing the Constitutional Chamber's exclusive competence over such actions pending legislative development of Article 28.observed

#

Judicially-derived principles exist but there is no codified lawful-basis catalogue, no special-category regime, and no anonymisation safe harbour.

Primary frameworkTSJ Constitutional Chamber habeas data jurisprudence (2011 et seq.)
Traffic-light rationale — RedJudicially-derived principles exist but there is no codified lawful-basis catalogue, no special-category regime, and no anonymisation safe harbour.

Sub-modules (4)

Lawful BasesAmber

No codified lawful-basis catalogue exists; TSJ jurisprudence requires collection to have a predetermined, non-excessive, valid purpose and to comply with applicable legal provisions.

Claims (1):

  • TSJ jurisprudence requires that data collection have a predetermined, valid purpose, must not be excessive, and that data usage comply with legal provisions relevant to the information collected.

Special CategoriesRed

No special/sensitive category regime (health, biometric, genetic, ethnic, political, sexual, criminal data) was located in Venezuelan law or jurisprudence.

Absence provenance: unavailable. Searched: Venezuela datos sensibles ley protección, Venezuela special category personal data regulation.

Pseudonymisation And AnonymisationRed

No statutory or jurisprudential definition of pseudonymisation or anonymisation, and no associated safe harbour, was located.

Absence provenance: unavailable. Searched: Venezuela anonimización datos personales ley, Venezuela pseudonymisation legal definition.

Category narrative54 words

There is no enumerated lawful-basis framework analogous to GDPR Article 6. TSJ jurisprudence has articulated general principles applicable to data processing—consent (revocable, prior, informed), purpose limitation, proportionality, retention-until-purpose-fulfilled, and accuracy—but these are judicially derived interpretive principles rather than a codified basis regime. No special-category (sensitive data) regime or codified pseudonymisation/anonymisation safe harbour was located.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (2)
  1. ProbableIAPP — TSJ jurisprudence requires that data collection have a predetermined, valid purpose, must not be excessive, and that data usage comply with legal provisions relevant to the information collected.observed
  2. ProbableIAPP — Under TSJ-developed principles, consent to personal-data use and collection must be revocable and given prior to such use or collection.observed

#

Only access and correction/erasure rights exist via constitutional/judicial route; portability, restriction/objection and statutory deadlines are entirely absent.

Primary frameworkConstitution Article 28 (habeas data) as procedurally developed by TSJ Constitutional Chamber
Traffic-light rationale — RedOnly access and correction/erasure rights exist via constitutional/judicial route; portability, restriction/objection and statutory deadlines are entirely absent.

Sub-modules (5)

Access RightAmber

Habeas data confers a right to access and know what personal data is being collected about the data subject.

Claims (1):

  • Article 28 habeas data ensures the right to access and know what personal data is being collected about the data subject.

Rectification And ErasureAmber

Habeas data confers a right to correct and/or destroy personal data that could harm the data subject.

Claims (1):

  • Article 28 habeas data ensures the right to correct and/or destroy personal data that could harm the data subject.

Restriction And ObjectionRed

No distinct right to restrict processing or object to processing (including profiling opt-out) was located outside the general habeas data remedy.

Absence provenance: unavailable. Searched: Venezuela derecho a oposición tratamiento de datos, Venezuela right to restrict processing.

Data PortabilityRed

No data portability right exists in Venezuelan law.

Absence provenance: unavailable. Searched: Venezuela derecho a portabilidad de datos.

Deadlines And Response WindowsRed

No statutory response deadlines exist for controllers; habeas data claims proceed through ordinary constitutional/judicial timelines with no fixed administrative response window.

Absence provenance: unavailable. Searched: Venezuela plazo respuesta habeas data, Venezuela statutory deadline data subject request.

Category narrative57 words

Habeas data (Article 28) grants a constitutional right to access personal data and to request correction or destruction of data that could harm the data subject; this is exercised through a judicially-developed procedure before the Constitutional Chamber in the absence of implementing legislation. No portability, restriction/objection, or profiling opt-out right, and no statutory response deadlines, were located.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (2)
  1. ConfirmedIAPP — Article 28 habeas data ensures the right to access and know what personal data is being collected about the data subject.observed
  2. ConfirmedIAPP — Article 28 habeas data ensures the right to correct and/or destroy personal data that could harm the data subject.observed

#

Core accountability instruments (DPIA, DPO, ROPA, breach notification) are entirely absent; only narrow information-security and criminal-deterrence provisions exist.

Primary frameworkLey de Infogobierno (2013) security provisions; Ley Especial Contra los Delitos Informáticos; TSJ retention principle
Traffic-light rationale — RedCore accountability instruments (DPIA, DPO, ROPA, breach notification) are entirely absent; only narrow information-security and criminal-deterrence provisions exist.

Sub-modules (7)

Accountability And DpiaRed

No accountability principle or DPIA-trigger regime exists in Venezuelan law.

Absence provenance: unavailable. Searched: Venezuela evaluación de impacto protección de datos ley, Venezuela accountability principle data protection.

Dpo RequirementsRed

No requirement to appoint a data protection officer exists.

Absence provenance: unavailable. Searched: Venezuela oficial de protección de datos requisito legal.

Ropa RequirementsRed

No records-of-processing (ROPA) obligation exists.

Absence provenance: unavailable. Searched: Venezuela registro de actividades de tratamiento obligación.

Joint Controller ArrangementsRed

No joint-controller or processor-obligation framework analogous to GDPR Article 28 exists.

Absence provenance: unavailable. Searched: Venezuela corresponsables tratamiento datos ley, Venezuela processor obligations statute.

Security MeasuresAmber

The Ley de Infogobierno assigns SUSCERTE certain security functions over public-sector electronic information systems, and the Ley Especial Contra los Delitos Informáticos criminalises unauthorised access, functioning as indirect security incentives rather than a security-of-processing standard.

Claims (2):

  • Article 54 of the Ley de Infogobierno (2013) assigns SUSCERTE (Superintendencia de Servicios de Certificación Electrónica) security-related functions over public electronic information systems.
  • The Ley Especial Contra los Delitos Informáticos criminalises unauthorised access to and disclosure of computer-held information, providing an indirect security deterrent absent a positive security-of-processing standard.

Breach NotificationRed

No statutory breach-notification duty to a regulator or to affected individuals exists; a 2026 breach affecting over 3.25 million Venezuelans was not, at time of reporting, publicly addressed or notified by the responsible operator.

Claims (1):

  • A 2026 data breach exposing personal data of over 3.25 million Venezuelans linked to a telecommunications subsidiary was not, at the time of reporting, publicly addressed or notified to affected customers, illustrating the absence of an enforceable breach-notification duty.

Retention And DisposalAmber

TSJ jurisprudence holds that data must be preserved only until its intended purpose is fulfilled, but no statute imposes a specific disposal duty or retention ceiling.

Claims (1):

  • TSJ jurisprudence holds that personal data must be preserved only until its intended purpose is fulfilled, functioning as a judicially-derived retention-limitation principle.
Category narrative88 words

No accountability/DPIA regime, DPO requirement, ROPA requirement, or joint-controller framework exists. Security-of-processing obligations are limited to information-security functions under the Ley de Infogobierno (assigning SUSCERTE certain public-sector security duties) and the criminal deterrence in the Ley Especial Contra los Delitos Informáticos. There is no statutory breach-notification duty to a regulator or to data subjects — illustrated by the 2026 Movistar breach affecting over 3.25 million Venezuelans, where the operator did not appear to notify affected customers. TSJ jurisprudence applies a retention-until-purpose-fulfilled principle but there is no disposal-duty statute.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (4)
  1. ProbableSUSCERTE — Article 54 of the Ley de Infogobierno (2013) assigns SUSCERTE (Superintendencia de Servicios de Certificación Electrónica) security-related functions over public electronic information systems.observed
  2. ConfirmedTSJ — The Ley Especial Contra los Delitos Informáticos criminalises unauthorised access to and disclosure of computer-held information, providing an indirect security deterrent absent a positive security-of-processing standard.observed
  3. ConfirmedIAPP — A 2026 data breach exposing personal data of over 3.25 million Venezuelans linked to a telecommunications subsidiary was not, at the time of reporting, publicly addressed or notified to affected customers, illustrating the absence of an enforceable breach-notification duty.observed
  4. ProbableIAPP — TSJ jurisprudence holds that personal data must be preserved only until its intended purpose is fulfilled, functioning as a judicially-derived retention-limitation principle.observed

#

No domestic transfer mechanism, adequacy regime, or localisation rule exists; the only relevant cross-border development is a foreign (US) restrictive measure, not a Venezuelan instrument.

Traffic-light rationale — RedNo domestic transfer mechanism, adequacy regime, or localisation rule exists; the only relevant cross-border development is a foreign (US) restrictive measure, not a Venezuelan instrument.

Sub-modules (6)

Transfer MechanismsRed

No domestic transfer mechanism (adequacy, SCCs, BCRs, derogations) exists in Venezuelan law.

Absence provenance: unavailable. Searched: Venezuela mecanismo transferencia internacional de datos ley.

Adequacy ReceivedRed

Venezuela has not received an EU adequacy decision.

Claims (1):

  • Venezuela has not been granted an EU adequacy decision, unlike regional peers such as Uruguay and Argentina.

Adequacy GrantedRed

Venezuela has no authority or mechanism to grant adequacy determinations to other jurisdictions.

Absence provenance: unavailable. Searched: Venezuela adequacy decision granted, Venezuela decisión de adecuación otorgada.

Sccs And BcrsRed

No SCC or BCR framework exists domestically.

Absence provenance: unavailable. Searched: Venezuela cláusulas contractuales estándar transferencia de datos.

Transfer Impact AssessmentRed

No transfer-impact-assessment requirement exists.

Absence provenance: unavailable. Searched: Venezuela evaluación de impacto de transferencia de datos.

Data LocalisationRed

No general data-localisation mandate was located; telecommunications metadata retention obligations have been reported in practice but no statute text was retrieved confirming a formal localisation rule.

Claims (1):

  • Reporting on telecommunications data retention in Venezuela indicates ISPs/telecom operators have retained subscriber telephony metadata in practice, though the underlying legal basis was not independently retrieved from a primary source in this run.
Category narrative95 words

Venezuela has no adequacy regime, no SCC/BCR framework, no transfer-impact-assessment requirement, and no data-localisation statute. Venezuela has not received an EU adequacy decision and has no mechanism to grant adequacy to other regimes. Separately, and as a foreign (US) measure rather than Venezuelan law, a February 2026-referenced US executive order (issued under IEEPA) directs restrictions on sensitive personal data transfers to designated 'countries of concern,' with Venezuela reportedly named among them — this constrains inbound/outbound data flows involving Venezuela but does not reflect any Venezuelan legal position and is recorded here only as external context.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (3)
  1. ConfirmedIAPP — Venezuela has not been granted an EU adequacy decision, unlike regional peers such as Uruguay and Argentina.observed
  2. UncertainOHCHR — Reporting on telecommunications data retention in Venezuela indicates ISPs/telecom operators have retained subscriber telephony metadata in practice, though the underlying legal basis was not independently retrieved from a primary source in this run.observed
  3. ProbableIAPP — A US executive order (reported February 2026) directs regulations restricting data brokers from transferring sensitive personal data (genomic, biometric, health, geolocation, financial, and certain identifiers) to designated 'countries of concern,' with Venezuela reported among the designated countries; this is a US-origin restriction on flows involving Venezuela, not a Venezuelan legal instrument.observed

#

Sectoral overlays are asserted in the seed as the most concrete obligations but primary text verification failed for banking and telecoms sub-modules within this run; other sub-modules returned no evidence at all.

Traffic-light rationale — RedSectoral overlays are asserted in the seed as the most concrete obligations but primary text verification failed for banking and telecoms sub-modules within this run; other sub-modules returned no evidence at all.

Sub-modules (7)

Financial Sector OverlayAmber

SUDEBAN is the designated banking-sector regulator per the injected seed anchor; this run was unable to retrieve primary banking-secrecy/data-handling statutory text beyond the regulator's homepage.

Claims (1):

  • SUDEBAN (Superintendencia de las Instituciones del Sector Bancario) is the designated banking-sector supervisory body referenced as the source of the most concrete data-handling obligations, per injected seed anchors; primary statutory text was not independently retrieved in this run.

Health Sector OverlayRed

No health-sector-specific data-protection rules were located.

Absence provenance: unavailable. Searched: Venezuela ley protección datos de salud.

Telecoms And EprivacyAmber

CONATEL is the telecommunications regulator; secondary reporting references telecom metadata-retention practice, but primary CONATEL instrument text was not retrieved in this run.

Claims (1):

  • Secondary reporting indicates Venezuelan telecommunications providers have retained subscriber telephony metadata in practice, consistent with regional data-retention patterns, though primary CONATEL instrument text was not retrieved in this run.

Employment DataRed

No employment-data-specific rules were located.

Absence provenance: unavailable. Searched: Venezuela ley protección datos laborales empleados.

Credit And ScoringRed

No credit-scoring-specific data rules were located.

Absence provenance: unavailable. Searched: Venezuela ley datos crediticios buró de crédito.

EducationRed

No education-sector-specific data rules were located; LOPNNA governs child-welfare matters generally but not data processing in educational settings.

Absence provenance: unavailable. Searched: Venezuela protección de datos en instituciones educativas.

InsuranceRed

No insurance-sector-specific data rules were located.

Absence provenance: unavailable. Searched: Venezuela ley protección datos seguros.

Category narrative51 words

Sectoral provisions are described in the injected seed as the most concrete source of obligations, particularly banking (SUDEBAN) and telecommunications (CONATEL) confidentiality/retention rules, but this run could not retrieve primary statutory text for either regulator beyond their institutional homepages. No comprehensive health, employment, credit-scoring, education, or insurance data rules were located.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (2)
  1. UncertainSUDEBAN — SUDEBAN (Superintendencia de las Instituciones del Sector Bancario) is the designated banking-sector supervisory body referenced as the source of the most concrete data-handling obligations, per injected seed anchors; primary statutory text was not independently retrieved in this run.observed
  2. UncertainOHCHR — Secondary reporting indicates Venezuelan telecommunications providers have retained subscriber telephony metadata in practice, consistent with regional data-retention patterns, though primary CONATEL instrument text was not retrieved in this run.observed

#

No evidence of any commercial-privacy/adtech-specific regulation exists; this is a full-module gap consistent with the jurisdiction's unregulated-gap status.

Traffic-light rationale — Not assessedNo evidence of any commercial-privacy/adtech-specific regulation exists; this is a full-module gap consistent with the jurisdiction's unregulated-gap status.

Sub-modules (6)

Cookies And TrackersRed

No cookie/tracker consent regime located.

Absence provenance: unavailable. Searched: Venezuela ley cookies consentimiento rastreo web.

Dark PatternsRed

No dark-pattern prohibition located.

Absence provenance: unavailable. Searched: Venezuela prohibición patrones oscuros diseño engañoso.

Opt Out SignalsRed

No recognised opt-out signal (e.g., GPC, DAA) framework located.

Absence provenance: unavailable. Searched: Venezuela Global Privacy Control legal recognition.

Clean Rooms And DcrRed

No clean-room/data-collaboration-room rules located.

Absence provenance: unavailable. Searched: Venezuela data clean room regulation.

Cross Context AdvertisingRed

No cross-context-advertising ('sale'/'share') rule located.

Absence provenance: unavailable. Searched: Venezuela venta de datos personales publicidad regulación.

Direct MarketingRed

No direct-marketing consent/suppression regime located.

Absence provenance: unavailable. Searched: Venezuela ley mercadeo directo consentimiento datos.

Category narrative22 words

No cookie/tracker consent regime, dark-pattern prohibition, recognised opt-out signal, clean-room rule, cross-context-advertising rule, or direct-marketing consent/suppression regime was located in Venezuelan law.

#

No codified profiling, ADM-transparency, AI-risk, biometric, or genetic-data regime exists, while documented state biometric/surveillance practice operates without any nominal statutory constraint.

Traffic-light rationale — RedNo codified profiling, ADM-transparency, AI-risk, biometric, or genetic-data regime exists, while documented state biometric/surveillance practice operates without any nominal statutory constraint.

Sub-modules (6)

Profiling RestrictionsRed

No profiling restriction analogous to GDPR Article 22 exists.

Absence provenance: unavailable. Searched: Venezuela restricción perfilamiento automatizado ley.

Automated Decision Making TransparencyRed

No ADM transparency or explanation right exists.

Absence provenance: unavailable. Searched: Venezuela transparencia decisiones automatizadas derecho explicación.

Ai Risk AssessmentsRed

No AI-specific risk-assessment regime exists.

Absence provenance: unavailable. Searched: Venezuela ley inteligencia artificial evaluación de riesgo.

Biometric RegimeRed

No codified biometric-data regime exists; the state-operated Carnet de la Patria programme is documented as collecting and linking extensive biometric/identity data at scale without a nominal biometric-specific legal constraint.

Claims (1):

  • The Venezuelan government's Carnet de la Patria (Homeland Card) programme links benefit enrolment to a database reportedly storing cardholders' medical history, social-media presence, residential address, and political-party membership, and has been characterised by activists as a surveillance tool.

Genetic DataRed

No genetic-data regime exists.

Absence provenance: unavailable. Searched: Venezuela ley datos genéticos protección.

State Surveillance CarveoutsRed

No codified national-security carve-out provision was located; rather, secondary human-rights reporting documents extensive state data collection operating without effective legal constraint.

Claims (1):

  • UN human-rights reporting documents extensive state data collection and surveillance-adjacent practices operating alongside nominal constitutional protections, indicating that statutory text is a poor guide to actual state practice in Venezuela.
Category narrative90 words

There is no ADM-transparency right, AI-specific risk-assessment regime, or codified biometric/genetic-data regime. Extensive state biometric data collection is documented in practice, most notably the Carnet de la Patria ('Homeland Card') programme, which links enrolment (used to access food, healthcare and pension benefits) to a database reportedly storing medical history, social-media presence, residential address and political-party membership, and which has been criticised by activists as a surveillance tool. State-surveillance carve-outs are not codified as legal exemptions but rather reflect the practical absence of oversight rather than an explicit national-security carve-out provision.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (2)
  1. ProbablearXiv — The Venezuelan government's Carnet de la Patria (Homeland Card) programme links benefit enrolment to a database reportedly storing cardholders' medical history, social-media presence, residential address, and political-party membership, and has been characterised by activists as a surveillance tool.observed
  2. ProbableOHCHR — UN human-rights reporting documents extensive state data collection and surveillance-adjacent practices operating alongside nominal constitutional protections, indicating that statutory text is a poor guide to actual state practice in Venezuela.observed

#

LOPNNA provides general child-welfare and identity protections but no data-protection-specific minors regime; dependent-adults protections are entirely absent.

Primary frameworkLey Orgánica para la Protección de Niños, Niñas y Adolescentes (LOPNNA)
Traffic-light rationale — RedLOPNNA provides general child-welfare and identity protections but no data-protection-specific minors regime; dependent-adults protections are entirely absent.

Sub-modules (5)

Age VerificationRed

No age-verification-for-data-processing threshold exists; LOPNNA defines a child as a person under twelve for general child-welfare purposes, not for data-processing consent.

Claims (1):

  • LOPNNA Article 2 defines a 'niño o niña' as a person under twelve years of age for general child-welfare and legal-capacity purposes, but this threshold is not tied to any data-processing consent framework.

Minor Profiling BansRed

No profiling ban specific to minors exists.

Absence provenance: unavailable. Searched: Venezuela prohibición perfilamiento de menores.

Education SettingsRed

No education-setting-specific data rule for minors exists.

Absence provenance: unavailable. Searched: Venezuela protección datos menores entorno educativo.

Dependent AdultsRed

No dependent-adult (elderly/mentally incapacitated) data-protection provision exists.

Absence provenance: unavailable. Searched: Venezuela protección de datos adultos dependientes ley.

Category narrative48 words

The Ley Orgánica para la Protección de Niños, Niñas y Adolescentes (LOPNNA) governs child-welfare matters generally, including identity/registration rights, but contains no data-protection-specific provisions (no age-of-consent-for-processing threshold, no parental-consent mechanism for data collection, no minor-profiling ban, and no education-setting data rule). No dependent-adult (elderly/incapacitated) data-protection provisions were located.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (1)
  1. ConfirmedTSJ — LOPNNA Article 2 defines a 'niño o niña' as a person under twelve years of age for general child-welfare and legal-capacity purposes, but this threshold is not tied to any data-processing consent framework.observed

#

No regulator, no penalty regime, no tracked enforcement activity, and independent human-rights reporting raises doubt about the practical efficacy of the sole judicial remedy (habeas data/habeas corpus) available.

Primary frameworkConstitution Article 28 (habeas data) judicial remedy
Traffic-light rationale — RedNo regulator, no penalty regime, no tracked enforcement activity, and independent human-rights reporting raises doubt about the practical efficacy of the sole judicial remedy (habeas data/habeas corpus) available.

Sub-modules (6)

Regulator Powers And PenaltiesRed

No data-protection regulator exists; consequently no statutory investigative powers or penalty schedule exists.

Absence provenance: unavailable. Searched: Venezuela sanciones protección de datos ley, Venezuela data protection authority powers.

Enforcement Activity IndexRed

No tracked data-protection enforcement activity exists in the absence of a regulator.

Absence provenance: unavailable. Searched: Venezuela data protection enforcement action 2025 2026.

Regulator Funding And CapacityRed

No data-protection-specific regulator funding or headcount signal exists; the seed and independent reporting both describe minimal institutional capacity even for adjacent cybersecurity bodies.

Claims (1):

  • Institutional capacity for data-protection-adjacent supervision in Venezuela is minimal, with no dedicated authority and only nominal information-security competence held by bodies such as SUSCERTE.

Collective Redress And Class ActionsRed

No collective-redress or class-action mechanism specific to data-protection claims was located.

Absence provenance: unavailable. Searched: Venezuela acción colectiva protección de datos.

Private Right Of ActionAmber

The habeas data constitutional action functions as the sole private route to court, exercised directly before the Constitutional Chamber or competent courts in the absence of implementing legislation.

Claims (1):

  • The habeas data action is exercised autonomously before the Constitutional Chamber of the Supreme Tribunal of Justice pending legislative development of Article 28, giving individuals a direct judicial route without a regulator intermediary.

Recent Developments 180DRed

Within the last 180 days, the most relevant developments are: continued reporting (as of February 2026) on the Movistar data breach and the unresolved role of the August 2024 National Cybersecurity Council; and 2025 UN Fact-Finding Mission reporting on the broader erosion of judicial-protection mechanisms in Venezuela, which bears on the practical availability of the habeas data remedy.

Claims (2):

  • In August 2024 the Venezuelan government created a National Cybersecurity Council to implement cybersecurity measures, though it remains unclear how the council will aid enforcement of data-protection policies.
  • 2025 UN Fact-Finding Mission reporting describes a widespread lack of effective judicial protection in Venezuela, including inefficacy of the habeas corpus mechanism, which is relevant context for assessing the practical reliability of the analogous habeas data judicial remedy.
Category narrative108 words

There is no regulator with investigative or enforcement powers over data-protection matters, and consequently no penalty schedule, no tracked enforcement activity, and no dedicated regulator funding/capacity signal. The only redress route is the constitutional habeas data action before ordinary/Constitutional Chamber courts, which is an individual judicial remedy rather than a collective-redress or regulator-driven enforcement mechanism; no class-action mechanism for data-protection claims was located. The August 2024 creation of a National Cybersecurity Council has an unclear enforcement mandate. Broader UN reporting in 2025 describes a general erosion of judicial-protection mechanisms (including habeas corpus) in Venezuela, raising material doubt about the practical efficacy of the habeas data judicial remedy itself.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (4)
  1. ConfirmedSUSCERTE — Institutional capacity for data-protection-adjacent supervision in Venezuela is minimal, with no dedicated authority and only nominal information-security competence held by bodies such as SUSCERTE.observed
  2. ConfirmedTSJ — The habeas data action is exercised autonomously before the Constitutional Chamber of the Supreme Tribunal of Justice pending legislative development of Article 28, giving individuals a direct judicial route without a regulator intermediary.observed
  3. ProbableIAPP — In August 2024 the Venezuelan government created a National Cybersecurity Council to implement cybersecurity measures, though it remains unclear how the council will aid enforcement of data-protection policies.observed
  4. ProbableOHCHR — 2025 UN Fact-Finding Mission reporting describes a widespread lack of effective judicial protection in Venezuela, including inefficacy of the habeas corpus mechanism, which is relevant context for assessing the practical reliability of the analogous habeas data judicial remedy.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metn/a — no subject in this jurisdiction
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct50.0
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Venezuela
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 25 claim(s) (25 category placement(s)), 18 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (37 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrectification and erasure
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacydata localisation
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 82Enforcement & Redresscollective redress and class actions
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

regulator_and_framework, data_subject_rights, and parts of lawful_processing_and_special_data and controller_processor_duties rest on T1 anchors (Constitution Art. 28/60, TSJ habeas data jurisprudence, Ley Especial Contra los Delitos Informáticos, LOPNNA, Ley de Infogobierno Art. 54 via SUSCERTE). cross_border_and_adequacy, sectoral_watch, algorithmic_biometric_and_surveillance_governance, children_and_vulnerable_groups, and enforcement_and_redress rely predominantly on T2-T4 secondary/academic/NGO reporting (OHCHR, IAPP, arXiv case-study repository) because no primary statutory text was retrievable for banking secrecy (SUDEBAN), telecoms retention (CONATEL), or biometric programme governance (Carnet de la Patria). adtech_and_commercial_privacy returned zero findings across all six sub-modules and is emitted red with absent_field_provenance throughout.

Unresolved questions (5):

  • Whether SUDEBAN or CONATEL have published binding, retrievable primary instruments governing personal-data handling beyond their institutional homepages.
  • Whether the Ley de Infogobierno (2013) has been amended since enactment and whether Article 54's SUSCERTE mandate has ever been applied to a private-sector data-protection matter.
  • Whether the August 2024 National Cybersecurity Council has since acquired any operative data-protection enforcement mandate.
  • Whether the 2026-reported US executive order on 'countries of concern' data transfers has been formally finalized and what its precise legal effect on data flows involving Venezuela is.
  • Whether any Venezuelan court has applied the 2011 TSJ habeas data principles to a private-sector (non-state) controller since the seed's disambiguation note was issued.

Escalate to primary-source review: yes