Data Protection and Privacy 2025

MACAU SAR, CHINA Law and Practice Contributed by: Pedro Cortés and Luís Rôlo, Lektou, Advogados e Notários

political association or trade union membership, religion, private life, and racial or ethnic origin, and data concerning health or sex life, including genetic data. The authorisations for these types of processing shall be granted only if the con - troller provides guarantees of non-discrimination and sufficient security measures (indicated in the PDPA). Applications submitted to the PDPB for opinions, authorisations and notifications shall include the following information: • the name and address of the controller and of their representative, if any. • the purposes of the processing; • a description of the category or categories of data subjects and of the data or categories of personal data relating to them; • the recipients or categories of recipients to whom the data might be disclosed and in what circumstances; • the body entrusted with processing the infor - mation, if it is not the controller themselves; • any combinations of personal data process - ing; • the length of time for which personal data will be kept; • the form and circumstances in which the data subjects may be informed of, or may correct, the personal data relating to them; • proposed transfers of data to third countries or territories; and • a general description enabling a preliminary assessment to be made of the adequacy of the measures taken to ensure security. Without prejudice to the right to submit a com - plaint to the public authority, according to the law any person may have recourse to adminis - trative and legal means to guarantee compliance

with provisions of laws and regulations in the area of personal data protection. The PDPB is empowered to enforce those provi - sions of the PDPA that are of an administrative nature, under the PDPA and the Administrative Regulation 42/2023. Criminal cases are report - ed to, and handled by, the Public Prosecutor’s Office. Administrative Offences To start proceedings relating to alleged viola - tions, the PDPB must first take into account the actions of the alleged infringers, including the type of action and the intention of the agent, under the general administrative standards. Non-compliance with the special security meas - ures required by Article 16 of the PDPA – for sensitive data processing and for the creation and maintenance of records regarding suspicion of illegal activity, criminal offences and admin - istrative offences – is an administrative offence which may entail a fine between MOP4,000 and MOP40,000. Although the PDPA provides penalties for undue access, as well as for tampering with, or destruc - tion of, personal data, it does not specifically pro - vide for security breaches by the data control - ler. It should be noted, however, that the PDPA mandates that the data controller shall present the notification/authorisation request with a gen - eral description of the security measures, so that the PDPB may evaluate the adequacy of such measures. If the PDPB notifies the above-men - tioned entity to address any insufficiency in the security measures and no remedy is taken, then a fine of between MOP2,000 and MOP20,000 for individuals and of between MOP10,000 and MOP100,000 for legal persons may be imposed. Other potential enforcement penalties are out - lined below.

287 CHAMBERS.COM

Powered by