🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
CW · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 2 sources retrieved model claude-sonnet-5 ·

Curaçao

CW schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 0 claims · 2 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
0Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

A comprehensive-looking statute exists and is in force, but the absence of an operational supervisory authority and of registration/notification machinery materially weakens practical enforceability.

Primary frameworkOrdinance No. 84 of 4 September 2010 Laying Down Rules on the Protection of Personal Data (Landsverordening bescherming persoonsgegevens / Data Protection Ordinance)
Supervisory authorityData Protection Board (Curaçao) — provided for by statute but not yet established
Traffic-light rationale — AmberA comprehensive-looking statute exists and is in force, but the absence of an operational supervisory authority and of registration/notification machinery materially weakens practical enforceability.

Sub-modules (5)

Regulator And AuthorityRed

The Ordinance provides for a Data Protection Board to act as supervisory authority; as of this research pass, that Board has not yet been established, leaving the regime without an operational regulator.

Claims: CLM-CW-2f6a8c1d

Act And InstrumentsAmber

The operative instrument is Ordinance No. 84 of 4 September 2010, described by professional legal-research sources as modeled on the Dutch data-protection implementing act.

Claims: CLM-CW-7b3e91a0

Material ScopeAmber

The Ordinance is reported to follow the structure of the Dutch implementing act (itself derived from the pre-GDPR EU data protection directive framework), covering automated and structured-file processing of personal data, but the precise scope articles were not independently retrieved in this pass.

Claims: CLM-CW-c14d5f22

Territorial ScopeRed

No CW-specific provision on extraterritorial application to non-established controllers was located in this research pass.

Absence provenance: not recorded. Searched: Curaçao data protection law regulator personal data 2024, Curaçao Landsverordening bescherming persoonsgegevens.

Regulator Registration And FilingAmber

The Ordinance does not set out requirements for data processing notifications to a supervisory authority.

Claims: CLM-CW-9a02b7e4

Category narrative88 words

Curaçao's data protection regime rests on a single omnibus-style statute — Ordinance No. 84 of 4 September 2010 Laying Down Rules on the Protection of Personal Data — but the supervisory authority the Ordinance itself creates, the Data Protection Board, has never been stood up. This is the textbook 'statute enacted, DPA not operational' pattern: the law is in force, yet there is no functioning regulator to receive filings, hear complaints, or issue guidance. Registration/notification duties, DPO appointment duties and breach-notification duties are all absent from the text.

#

Coverage gap: no verified sub-module-level detail located for this jurisdiction in this pass; only a general 'modeled on Dutch law' inference is available.

Primary frameworkOrdinance No. 84 of 4 September 2010 Laying Down Rules on the Protection of Personal Data
Traffic-light rationale — RedCoverage gap: no verified sub-module-level detail located for this jurisdiction in this pass; only a general 'modeled on Dutch law' inference is available.

Sub-modules (4)

Lawful BasesRed

Not independently verified for Curaçao in this pass; the Ordinance is reported to be modeled on the Dutch implementing act.

Claims: CLM-CW-4e8f10c3

Special CategoriesRed

No Curaçao-specific special-category (sensitive data) provisions were retrieved in this pass.

Absence provenance: not recorded. Searched: Curaçao Landsverordening bescherming persoonsgegevens.

Pseudonymisation And AnonymisationRed

No Curaçao-specific pseudonymisation/anonymisation safe-harbour text was retrieved.

Absence provenance: not recorded. Searched: Curaçao Landsverordening bescherming persoonsgegevens.

Category narrative65 words

No Curaçao-specific text on enumerated lawful bases, consent thresholds, special-category rules, or pseudonymisation/anonymisation safe-harbours was retrieved in this research pass. Professional summaries indicate the Ordinance follows the Dutch implementing-act model (itself derived from the EU data protection directive era), which would imply an analogous lawful-basis and sensitive-data structure, but this was not independently verified against the Curaçao statutory text, which is only available in Dutch.

#

No verified sub-module-level claims located for CW in this pass.

Primary frameworkOrdinance No. 84 of 4 September 2010 Laying Down Rules on the Protection of Personal Data
Traffic-light rationale — RedNo verified sub-module-level claims located for CW in this pass.

Sub-modules (5)

Access RightRed

Not independently verified for CW in this pass.

Absence provenance: not recorded. Searched: Curaçao data protection law regulator personal data 2024.

Rectification And ErasureRed

Not independently verified for CW in this pass.

Absence provenance: not recorded. Searched: Curaçao data protection law regulator personal data 2024.

Restriction And ObjectionRed

Not independently verified for CW in this pass.

Absence provenance: not recorded. Searched: Curaçao data protection law regulator personal data 2024.

Data PortabilityRed

Not independently verified for CW in this pass; the source statute predates the GDPR-era portability right by design lineage.

Absence provenance: not recorded. Searched: Curaçao Landsverordening bescherming persoonsgegevens.

Deadlines And Response WindowsRed

Not independently verified for CW in this pass.

Absence provenance: not recorded. Searched: Curaçao Landsverordening bescherming persoonsgegevens.

Category narrative30 words

No Curaçao-specific detail on access, rectification/erasure, restriction/objection, portability, or statutory response deadlines was retrieved in this research pass; the underlying Ordinance text is Dutch-only and was not independently parsed article-by-article.

#

Two concrete, confirmed negative findings (no DPO duty, no breach-notification duty) are informative but the remaining sub-modules are unverified gaps.

Primary frameworkOrdinance No. 84 of 4 September 2010 Laying Down Rules on the Protection of Personal Data
Supervisory authorityData Protection Board (Curaçao) — not yet established
Traffic-light rationale — AmberTwo concrete, confirmed negative findings (no DPO duty, no breach-notification duty) are informative but the remaining sub-modules are unverified gaps.

Sub-modules (7)

Accountability And DpiaRed

No Curaçao-specific DPIA-trigger text was retrieved.

Absence provenance: not recorded. Searched: Curaçao Landsverordening bescherming persoonsgegevens.

Dpo RequirementsAmber

The Ordinance does not set out requirements for DPO appointments.

Claims: CLM-CW-83af6d51

Ropa RequirementsRed

No Curaçao-specific ROPA obligation text was retrieved.

Absence provenance: not recorded. Searched: Curaçao Landsverordening bescherming persoonsgegevens.

Joint Controller ArrangementsRed

No Curaçao-specific joint-controller provisions were retrieved.

Absence provenance: not recorded. Searched: Curaçao Landsverordening bescherming persoonsgegevens.

Security MeasuresRed

No Curaçao-specific technical/organisational security-measures text was independently retrieved.

Absence provenance: not recorded. Searched: Curaçao Landsverordening bescherming persoonsgegevens.

Breach NotificationAmber

The Ordinance does not set out requirements for data breach notification, to either the (non-existent) supervisory authority or affected data subjects.

Claims: CLM-CW-115cde90

Retention And DisposalRed

No Curaçao-specific retention-limit or disposal-duty text was retrieved.

Absence provenance: not recorded. Searched: Curaçao Landsverordening bescherming persoonsgegevens.

Category narrative30 words

Professional legal-research sources are explicit that the Curaçao Ordinance does not set out DPO-appointment requirements or data-breach-notification requirements. Accountability/DPIA, ROPA, joint-controller, general security-measures and retention/disposal specifics were not independently retrieved.

#

The core adequacy-based transfer restriction is confirmed and binding; downstream transfer-mechanism detail (SCCs, BCRs, TIA, localisation) is an unverified gap.

Primary frameworkOrdinance No. 84 of 4 September 2010 Laying Down Rules on the Protection of Personal Data
Supervisory authorityData Protection Board (Curaçao) — not yet established
Traffic-light rationale — AmberThe core adequacy-based transfer restriction is confirmed and binding; downstream transfer-mechanism detail (SCCs, BCRs, TIA, localisation) is an unverified gap.

Sub-modules (6)

Transfer MechanismsAmber

The Ordinance regulates international data transfers and limits transfers to countries providing adequate protection of personal data.

Claims: CLM-CW-6d9a4b3e

Adequacy ReceivedRed

No adequacy decision received by Curaçao from another regime (e.g., EU/UK) was located.

Absence provenance: not recorded. Searched: Curaçao data protection law regulator personal data 2024.

Adequacy GrantedRed

No formal Curaçao-granted adequacy determination toward other regimes was located.

Absence provenance: not recorded. Searched: Curaçao data protection law regulator personal data 2024.

Sccs And BcrsRed

No Curaçao-specific SCC/BCR forms or uptake data were located.

Absence provenance: not recorded. Searched: Curaçao Landsverordening bescherming persoonsgegevens.

Transfer Impact AssessmentRed

No formal TIA requirement was located for Curaçao.

Absence provenance: not recorded. Searched: Curaçao Landsverordening bescherming persoonsgegevens.

Data LocalisationRed

No data-localisation mandate was located for Curaçao.

Absence provenance: not recorded. Searched: Curaçao data protection law regulator personal data 2024.

Category narrative44 words

The Ordinance affirmatively regulates cross-border transfers, restricting transfer of personal data to countries assessed as providing adequate protection. No confirmed adequacy decisions received from or granted to other regimes, SCC/BCR uptake, formal TIA requirement, or data-localisation mandate were located for Curaçao in this pass.

#

One confirmed financial-sector/AML-adjacent finding; remaining sectoral sub-modules are unverified gaps.

Primary frameworkOrdinance No. 84 of 4 September 2010 Laying Down Rules on the Protection of Personal Data
Traffic-light rationale — AmberOne confirmed financial-sector/AML-adjacent finding; remaining sectoral sub-modules are unverified gaps.

Sub-modules (7)

Financial Sector OverlayAmber

Curaçao is a CFATF member but is viewed as having limited effective AML and tax-enforcement measures, which bears on financial-sector data-sharing and due-diligence obligations.

Claims: CLM-CW-3fa780c2

Health Sector OverlayRed

No CW-specific health-sector DP overlay was located.

Absence provenance: not recorded. Searched: Curaçao data protection law regulator personal data 2024.

Telecoms And EprivacyRed

No CW-specific telecoms/ePrivacy overlay was located.

Absence provenance: not recorded. Searched: Curaçao privacy law amendment 2025 telecommunications ordinance.

Employment DataRed

No CW-specific employment-data overlay was located.

Absence provenance: not recorded. Searched: Curaçao data protection law regulator personal data 2024.

Credit And ScoringRed

No CW-specific credit-scoring overlay was located.

Absence provenance: not recorded. Searched: Curaçao data protection law regulator personal data 2024.

EducationRed

No CW-specific education-sector overlay was located.

Absence provenance: not recorded. Searched: Curaçao data protection law regulator personal data 2024.

InsuranceRed

No CW-specific insurance-sector overlay was located.

Absence provenance: not recorded. Searched: Curaçao data protection law regulator personal data 2024.

Category narrative52 words

Curaçao is a member of the Caribbean Financial Action Task Force (CFATF) and is viewed by international supervisory bodies as having limited effective AML/tax-enforcement measures, a fact relevant to financial-sector data-sharing and customer due-diligence practices. No CW-specific health, telecoms/ePrivacy, employment, credit-scoring, education, or insurance sector DP overlays were located in this pass.

#

No sub-module findings located; comprehensive gap for this module in this jurisdiction.

Traffic-light rationale — RedNo sub-module findings located; comprehensive gap for this module in this jurisdiction.

Sub-modules (6)

Cookies And TrackersRed

No CW-specific cookie/tracker regime located.

Absence provenance: not recorded. Searched: Curaçao data protection law regulator personal data 2024, Curaçao privacy law amendment 2025 telecommunications ordinance.

Dark PatternsRed

No CW-specific dark-pattern prohibition located.

Absence provenance: not recorded. Searched: Curaçao data protection law regulator personal data 2024.

Opt Out SignalsRed

No CW-specific opt-out signal recognition (e.g., GPC) located.

Absence provenance: not recorded. Searched: Curaçao data protection law regulator personal data 2024.

Clean Rooms And DcrRed

No CW-specific clean-room/data-collaboration rules located.

Absence provenance: not recorded. Searched: Curaçao data protection law regulator personal data 2024.

Cross Context AdvertisingRed

No CW-specific cross-context-advertising ('sale'/'share') rule located.

Absence provenance: not recorded. Searched: Curaçao data protection law regulator personal data 2024.

Direct MarketingRed

No CW-specific direct-marketing consent/suppression rule located.

Absence provenance: not recorded. Searched: Curaçao data protection law regulator personal data 2024.

Category narrative23 words

No Curaçao-specific cookie/tracker consent regime, dark-pattern prohibition, opt-out-signal recognition, clean-room rules, cross-context-advertising rules, or direct-marketing consent/suppression rules were located in this research pass.

#

No sub-module findings located; comprehensive gap for this module in this jurisdiction.

Traffic-light rationale — RedNo sub-module findings located; comprehensive gap for this module in this jurisdiction.

Sub-modules (6)

Profiling RestrictionsRed

No CW-specific profiling-restriction rule located.

Absence provenance: not recorded. Searched: Curaçao data protection law regulator personal data 2024.

Automated Decision Making TransparencyRed

No CW-specific ADM-transparency rule located.

Absence provenance: not recorded. Searched: Curaçao data protection law regulator personal data 2024.

Ai Risk AssessmentsRed

No CW-specific AI-risk-assessment regime located.

Absence provenance: not recorded. Searched: Curaçao data protection law regulator personal data 2024.

Biometric RegimeRed

No CW-specific biometric-data regime located.

Absence provenance: not recorded. Searched: Curaçao data protection law regulator personal data 2024.

Genetic DataRed

No CW-specific genetic-data regime located.

Absence provenance: not recorded. Searched: Curaçao data protection law regulator personal data 2024.

State Surveillance CarveoutsRed

No CW-specific state-surveillance carve-out text located.

Absence provenance: not recorded. Searched: Curaçao data protection law regulator personal data 2024.

Category narrative16 words

No Curaçao-specific profiling-restriction, ADM-transparency, AI-risk-assessment, biometric-regime, genetic-data-regime, or state-surveillance-carveout text was located in this research pass.

#

No sub-module findings located; comprehensive gap for this module in this jurisdiction.

Traffic-light rationale — RedNo sub-module findings located; comprehensive gap for this module in this jurisdiction.

Sub-modules (5)

Age VerificationRed

No CW-specific age-verification rule located.

Absence provenance: not recorded. Searched: Curaçao data protection law regulator personal data 2024.

Minor Profiling BansRed

No CW-specific minor-profiling ban located.

Absence provenance: not recorded. Searched: Curaçao data protection law regulator personal data 2024.

Education SettingsRed

No CW-specific education-setting DP rule located.

Absence provenance: not recorded. Searched: Curaçao data protection law regulator personal data 2024.

Dependent AdultsRed

No CW-specific dependent-adult protection rule located.

Absence provenance: not recorded. Searched: Curaçao data protection law regulator personal data 2024.

Category narrative18 words

No Curaçao-specific age-of-consent, parental-consent mechanism, minor-profiling ban, education-setting rule, or dependent-adult protection was located in this research pass.

#

No operational regulator and no confirmed enforcement track record under the Ordinance.

Primary frameworkOrdinance No. 84 of 4 September 2010 Laying Down Rules on the Protection of Personal Data
Supervisory authorityData Protection Board (Curaçao) — not yet established
Traffic-light rationale — RedNo operational regulator and no confirmed enforcement track record under the Ordinance.

Sub-modules (6)

Regulator Powers And PenaltiesRed

No dedicated DP regulator is currently exercising investigative or enforcement powers, as the Data Protection Board has never been established.

Claims: CLM-CW-a02fe671

Enforcement Activity IndexRed

No confirmed DP-specific enforcement action under the Ordinance was located in the last 12 months.

Absence provenance: not recorded. Searched: Curaçao Office Public Prosecutor ANG 200,000 fine data protection.

Regulator Funding And CapacityRed

No funding/headcount data exists for a body that has not been established.

Absence provenance: not recorded. Searched: Curaçao data protection board 2025 2026 established.

Collective Redress And Class ActionsRed

No CW-specific collective-redress or class-action mechanism for data-protection claims was located.

Absence provenance: not recorded. Searched: Curaçao data protection law regulator personal data 2024.

Private Right Of ActionRed

No CW-specific private-right-of-action provision was located.

Absence provenance: not recorded. Searched: Curaçao data protection law regulator personal data 2024.

Recent Developments 180DRed

No new legislation, case law, guidance, or adequacy determination affecting Curaçao's data-protection regime was identified in the 180 days preceding this run.

Absence provenance: not recorded. Searched: Curaçao data protection board 2025 2026 established, Curaçao privacy law amendment 2025 telecommunications ordinance.

Category narrative84 words

Because the Data Protection Board provided for under the Ordinance has never been established, there is no dedicated data-protection regulator currently exercising investigative or enforcement powers under the Curaçao Data Protection Ordinance. No confirmed DP-specific enforcement activity, regulator funding/capacity data, collective-redress mechanism, private-right-of-action, or 180-day development was located for this jurisdiction. A 2021-dated Public Prosecutor penalty item surfaced in search but its substantive connection to the Data Protection Ordinance could not be confirmed from available content, so it was not cited as a claim.

No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Curaçao
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 0 claim(s), 4 source(s) in the cumulative register.