MACAU SAR, CHINA Law and Practice Contributed by: Pedro Cortés and Luís Rôlo, Lektou
accordance with applicable legislation and the security measures provided therein. Macau Cybersecurity Law In relation to the Macau Cybersecurity Law (Law No 13/2019, dated 24 June 2019), which seeks to bolster the protection of computer systems regarding cybercrimes and cybersecurity threats against public and private operators of critical infrastructures (as defined in the law), the dedi - cated structures referred to in the previous para - graph will also need to comply with the general responsibilities and cybersecurity duties pro - vided therein, namely: • organisational duties; • procedural, preventive and reactive duties; • self-evaluation duties; and • co-operation duties. The list of operators of critical infrastructures is defined by Dispatch of the Chief Executive. Cur - rently, under Dispatch 119/2024, there are 143 such operators, 78 of which are private com - panies belonging to the financial sector. There are four operators of radio or television broad - casting, and eight operators of telecommunica - tions networks or provision of internet services. Included, are also ten private entities classified as of public utility, operating solely in the sci - ence and technology field. As previously indi - cated, there is currently no specific legislation regarding AI. Although the PDPA includes the right of the data subject not to be exposed to individual automated decisions, no further stipu - lations regulate the issue of automated decision- making. In this regard, and without prejudice to the principles and provisos of the law regarding personal data processing, it is incumbent on the local legislature to update the law so as to ensure that AI-driven decision-making is com - patible with core legal principles such as trans -
parency, accountability, legality, and protection of fundamental rights.
4. Internet of Things 4.1 Machine-to-Machine Communications, Communications Secrecy and Data Protection Restrictions on a Project’s Scope With regard to the internet of things (IoT) projects and the data circulating therein, the main piece of legislation which would restrict the scope of a project in such an area would be the PDPA and its stipulations regarding personal data. The processing of personal data through any such device would necessarily have to comply with the applicable stipulations of the law: • it must be performed in a transparent man - ner and in strict observance of privacy rights and of the rights, freedoms and guarantees enshrined in the Macau Basic Law and in applicable legislation; and • it may only be carried out if the data subject has given their unequivocal consent, or if the processing is necessary for the purposes set out in the law. 4.2 Compliance and Governance There is currently no specific legislation on IoT in the MSAR. Companies should approach com - pliance under the perspective of personal data protection, where applicable. As information that is not, initially, deemed per - sonal data may become so, by means of cross- referencing other databases, companies need to be mindful of developments, both in technology and in the market landscape, and take the nec - essary steps to respect the data subjects’ rights in such an event.
203 CHAMBERS.COM
Powered by FlippingBook