{
 "jurisdiction_id": "IM",
 "jurisdiction": "Isle of Man",
 "url": "https://dataprotection.gi/jurisdictions/isle-of-man/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-05",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 0,
  "sub_modules": 57,
  "source_register": 12
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "green",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/isle-of-man/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "Comprehensive GDPR-equivalent statute in force with an active, independent regulator and established enforcement track record.",
   "claims": []
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "amber",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/isle-of-man/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Core lawful-basis and special-category architecture is inherited wholesale from GDPR, but the specific Manx adaptations to consent thresholds and pseudonymisation/anonymisation safe-harbours were not independently verified in primary Manx legislative text during this pass.",
   "claims": []
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "green",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/isle-of-man/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Access right is demonstrably enforced with real cases; deadlines are evidenced through an enforcement action citing multi-month delay.",
   "claims": []
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "green",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/isle-of-man/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Security and breach-notification obligations are actively enforced with a live, named 2025 investigation; other accountability sub-modules rely on inherited-adoption inference only.",
   "claims": []
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "green",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/isle-of-man/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "Dual adequacy (EU-received and UK-received) is well documented and recently reconfirmed; granted-adequacy and data-localisation sub-modules lack confirmed Manx-specific sources.",
   "claims": []
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/isle-of-man/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Two sectoral overlays are evidenced (health, telecoms/unsolicited communications); financial services, employment, credit, education and insurance overlays are unconfirmed gaps.",
   "claims": []
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "red",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/isle-of-man/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "Only the existence of an Unsolicited Communications Regulations regime is confirmed; substantive adtech/commercial-privacy detail is an unconfirmed gap.",
   "claims": []
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "amber",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/isle-of-man/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "Core ADM/profiling protection is inherited via full GDPR adoption; AI-specific and biometric/genetic-specific regimes are unconfirmed gaps; a distinct law-enforcement carve-out regime is confirmed to exist.",
   "claims": []
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "red",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/isle-of-man/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "This entire module rests on inference from wholesale GDPR adoption; no Manx-specific children's-data source was independently confirmed.",
   "claims": []
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "green",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/isle-of-man/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Clear, repeated, and recent (through Dec 2025) enforcement activity confirms an active regulator; funding/capacity and redress-mechanism sub-modules remain unconfirmed gaps.",
   "claims": []
  }
 ]
}