🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
IM · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 12 sources retrieved model claude-sonnet-5 ·

Isle of Man

IM schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 0 claims · 12 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
0Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Comprehensive GDPR-equivalent statute in force with an active, independent regulator and established enforcement track record.

Primary frameworkData Protection Act 2018 (Isle of Man), operationalised via the Data Protection (Application of GDPR) Order 2018 and the LED Implementing Regulations 2018
Supervisory authorityIsle of Man Information Commissioner
Traffic-light rationale — GreenComprehensive GDPR-equivalent statute in force with an active, independent regulator and established enforcement track record.

Sub-modules (5)

Regulator And AuthorityGreen

The Isle of Man Information Commissioner is the independent authority for information rights on the Island, including data protection.

Claims: CLM-IM-a1b2c3d4

Act And InstrumentsGreen

The Applied GDPR Order 2018 and LED Implementing Regulations 2018 give the EU GDPR/LED domestic legal effect under the Data Protection Act 2018.

Claims: CLM-IM-b2c3d4e5, CLM-IM-c3d4e5f6

Material ScopeGreen

Manx enforcement practice confirms the Applied GDPR's substantive articles (e.g. Arts 12 and 15 on access/transparency) are directly enforced against controllers, including government departments and health bodies.

Claims: CLM-IM-d4e5f6a7

Territorial ScopeGreen

The Isle of Man is deemed a Member State of the EU solely for the purposes of the GDPR and LED, a bespoke construct enabling continuity of data flows.

Claims: CLM-IM-e5f6a7b8

Regulator Registration And FilingRed

No Manx-specific controller registration/notification-fee instrument (analogous to the UK's Data Protection (Charges and Information) Regulations 2018) was identified in this research pass.

Absence provenance: not recorded. Searched: Isle of Man Data Protection Act 2018 registration fee notification requirement, Isle of Man Information Commissioner official website gov.im data protection.

Category narrative102 words

The Isle of Man (a self-governing British Crown Dependency, not part of the UK or EU) operates a GDPR-equivalent omnibus regime. It has chosen to adopt the EU GDPR and the Law Enforcement Directive (LED) by order under its own Data Protection Act 2018, principally via the Data Protection (Application of GDPR) Order 2018 ('Applied GDPR') and the LED Implementing Regulations 2018, with local adaptations. The Isle of Man Information Commissioner is the independent regulator overseeing data protection, the Unsolicited Communications Regulations, and Freedom of Information law. Registration/filing specifics for controllers under the Manx regime were not located in this research pass.

#

Core lawful-basis and special-category architecture is inherited wholesale from GDPR, but the specific Manx adaptations to consent thresholds and pseudonymisation/anonymisation safe-harbours were not independently verified in primary Manx legislative text during this pass.

Primary frameworkApplied GDPR (Data Protection (Application of GDPR) Order 2018)
Supervisory authorityIsle of Man Information Commissioner
Traffic-light rationale — AmberCore lawful-basis and special-category architecture is inherited wholesale from GDPR, but the specific Manx adaptations to consent thresholds and pseudonymisation/anonymisation safe-harbours were not independently verified in primary Manx legislative text during this pass.

Sub-modules (4)

Lawful BasesAmber

The Applied GDPR's Article 6 lawful-basis framework operates as adopted domestic law.

Claims: CLM-IM-f6a7b8c9

Special CategoriesGreen

A 2020 Manx enforcement notice against the Department of Home Affairs directly invoked the special-category exemption under 'paragraph 8 of Schedule 9 of the GDPR', evidencing an operative Schedule 9-style special-category exemption regime under the Applied GDPR.

Claims: CLM-IM-a7b8c9d0

Pseudonymisation And AnonymisationRed

No Manx-specific pseudonymisation/anonymisation guidance or safe-harbour text was located.

Absence provenance: not recorded. Searched: Isle of Man Data Protection Act 2018 pseudonymisation anonymisation.

Category narrative53 words

Because the Isle of Man has adopted the full text of the EU GDPR domestically (with adaptations), the Article 6 lawful bases and Article 9 special-category regime are understood to apply as adopted. Direct Manx enforcement evidence confirms the operative special-category exemption schedule (mirroring UK DPA 2018 Schedule 9) is applied in practice.

#

Access right is demonstrably enforced with real cases; deadlines are evidenced through an enforcement action citing multi-month delay.

Primary frameworkApplied GDPR (Data Protection (Application of GDPR) Order 2018)
Supervisory authorityIsle of Man Information Commissioner
Traffic-light rationale — GreenAccess right is demonstrably enforced with real cases; deadlines are evidenced through an enforcement action citing multi-month delay.

Sub-modules (5)

Access RightGreen

Two separate Manx enforcement notices (DHA, 2020; Manx Care, 2021) found continuous failures to comply with the right of access under Applied GDPR Articles 12 and 15.

Claims: CLM-IM-b8c9d0e1, CLM-IM-c9d0e1f2

Rectification And ErasureAmber

Rectification/erasure rights are presumed inherited from the fully-adopted Applied GDPR text; no independent Manx enforcement precedent located.

Absence provenance: not recorded. Searched: Isle of Man Data Protection Act 2018 rectification erasure right to be forgotten.

Restriction And ObjectionAmber

Restriction/objection rights are presumed inherited from the Applied GDPR; no Manx-specific precedent located.

Absence provenance: not recorded. Searched: Isle of Man Data Protection Act 2018 restriction objection profiling opt-out.

Data PortabilityAmber

Portability right presumed inherited from the Applied GDPR; no Manx-specific precedent located.

Absence provenance: not recorded. Searched: Isle of Man data portability GDPR.

Deadlines And Response WindowsGreen

The Manx Care enforcement action evidenced regulatory intolerance of subject access delay of more than four months, consistent with the GDPR's one-month (extendable) statutory response deadline being applied in practice.

Claims: CLM-IM-d0e1f2a3

Category narrative75 words

The Manx Information Commissioner has directly enforced data subject access rights (Applied GDPR Articles 12 and 15) against both a government department (2020) and the publicly-owned healthcare provider Manx Care (2021), including for prolonged non-compliance exceeding four months. This provides strong evidentiary confirmation of an operative, enforced access-rights regime; other rights (rectification, erasure, restriction, objection, portability) are presumed inherited from the same Applied GDPR text but lack independent Manx enforcement evidence located in this pass.

#

Security and breach-notification obligations are actively enforced with a live, named 2025 investigation; other accountability sub-modules rely on inherited-adoption inference only.

Primary frameworkApplied GDPR (Data Protection (Application of GDPR) Order 2018)
Supervisory authorityIsle of Man Information Commissioner
Traffic-light rationale — GreenSecurity and breach-notification obligations are actively enforced with a live, named 2025 investigation; other accountability sub-modules rely on inherited-adoption inference only.

Sub-modules (7)

Accountability And DpiaAmber

Accountability/DPIA obligations (Applied GDPR Arts 5 and 35) are presumed inherited from the wholesale GDPR adoption.

Absence provenance: not recorded. Searched: Isle of Man Data Protection Act 2018 DPIA accountability.

Dpo RequirementsAmber

DPO appointment thresholds are presumed inherited from Applied GDPR Article 37; no Manx-specific guidance located.

Absence provenance: not recorded. Searched: Isle of Man Data Protection Act 2018 data protection officer requirements.

Ropa RequirementsAmber

Records-of-processing obligations are presumed inherited from Applied GDPR Article 30; no Manx-specific guidance located.

Absence provenance: not recorded. Searched: Isle of Man Data Protection Act 2018 records of processing activities ROPA.

Joint Controller ArrangementsAmber

Joint-controller rules presumed inherited from Applied GDPR Article 26; no Manx-specific guidance located.

Absence provenance: not recorded. Searched: Isle of Man joint controller GDPR.

Security MeasuresGreen

The 2025 joint investigation into the Prospect cyber incident explicitly examines whether the affected controller had adequate technical and organisational measures, evidencing an operative Article-32-style security standard enforced by the Manx Commissioner.

Claims: CLM-IM-e1f2a3b4

Breach NotificationGreen

A personal data breach affecting a Manx-linked controller (Prospect) was reported to the Information Commissioner's Office and triggered a joint cross-jurisdictional investigation launched by the UK, Guernsey, Jersey and Isle of Man regulators in December 2025, evidencing an operative breach-notification and cross-authority cooperation framework.

Claims: CLM-IM-f2a3b4c5

Retention And DisposalAmber

Retention/disposal obligations presumed inherited from Applied GDPR storage-limitation principle; no Manx-specific guidance located.

Absence provenance: not recorded. Searched: Isle of Man data retention disposal GDPR.

Category narrative83 words

Security-of-processing and breach-notification obligations are demonstrably live and enforced in the Isle of Man: the Commissioner is currently (as of late 2025) engaged in a joint cross-jurisdictional breach investigation (with the UK ICO and the Jersey and Guernsey authorities) into a cyber incident affecting a Manx-linked controller, examining whether adequate technical and organisational security measures were in place. DPIA, DPO, ROPA, joint-controller and retention specifics are presumed inherited from the fully-adopted Applied GDPR text but lack independently located Manx enforcement or guidance evidence.

#

Dual adequacy (EU-received and UK-received) is well documented and recently reconfirmed; granted-adequacy and data-localisation sub-modules lack confirmed Manx-specific sources.

Primary frameworkApplied GDPR transfer provisions (Chapter V equivalent) and Commission Decision 2004/411/EC
Supervisory authorityIsle of Man Information Commissioner
Traffic-light rationale — GreenDual adequacy (EU-received and UK-received) is well documented and recently reconfirmed; granted-adequacy and data-localisation sub-modules lack confirmed Manx-specific sources.

Sub-modules (6)

Transfer MechanismsGreen

Post-Brexit, Manx controllers/processors cannot transfer personal data to third countries (including the UK) absent an adequacy finding, Article 46 safeguards, or applicable Part 5/Schedule 10 LED-equivalent provisions.

Claims: CLM-IM-a3b4c5d6

Adequacy ReceivedGreen

The Isle of Man received an EU adequacy finding in 2004 (retained and reconfirmed in 2024) and is separately treated as adequate under the UK GDPR, with additional UK law-enforcement-specific adequacy regulations laid and reflected in ICO guidance from February 2025.

Claims: CLM-IM-b4c5d6e7, CLM-IM-c5d6e7f8, CLM-IM-d6e7f8a9

Adequacy GrantedRed

No confirmed Manx-specific instrument was located describing the Isle of Man's own grant of adequacy findings to other third countries.

Absence provenance: not recorded. Searched: Isle of Man adequacy decisions granted third countries.

Sccs And BcrsAmber

Article 46-style additional safeguards (implying SCC/BCR-equivalent mechanisms) are referenced as an available transfer basis for Manx controllers under the post-Brexit transfer framework.

Claims: CLM-IM-e7f8a9b0

Transfer Impact AssessmentRed

No Manx-specific transfer impact assessment requirement or guidance was located.

Absence provenance: not recorded. Searched: Isle of Man transfer impact assessment Schrems.

Data LocalisationGreen

No evidence of a data-localisation mandate was found for the Isle of Man.

Absence provenance: not recorded. Searched: Isle of Man data localisation requirement.

Category narrative118 words

The Isle of Man holds a long-standing EU adequacy finding (Commission Decision 2004/411/EC, originally under Directive 95/46/EC and retained in force under GDPR), reconfirmed in the European Commission's 2024 first-review report as one of eleven adequacy partners whose safeguards remain adequate. The Isle of Man is also already treated as adequate for transfers under the UK GDPR (Schedule 21, DPA 2018), and in 2024/2025 the UK made separate adequacy regulations specifically for Isle of Man law-enforcement processing, with the ICO updating its adequacy list accordingly in February 2025. Post-Brexit, Manx controllers must rely on adequacy findings, Article 46 safeguards, or Part 5/Schedule 10 LED-equivalent provisions for transfers to third countries (including the UK itself, from 1 February 2020).

#

Two sectoral overlays are evidenced (health, telecoms/unsolicited communications); financial services, employment, credit, education and insurance overlays are unconfirmed gaps.

Supervisory authorityIsle of Man Information Commissioner
Traffic-light rationale — AmberTwo sectoral overlays are evidenced (health, telecoms/unsolicited communications); financial services, employment, credit, education and insurance overlays are unconfirmed gaps.

Sub-modules (7)

Financial Sector OverlayRed

No financial-sector data-protection overlay instrument specific to the Isle of Man was confirmed in this research pass, despite the Island's status as an international financial centre.

Absence provenance: not recorded. Searched: Isle of Man financial services data protection overlay banking secrecy.

Health Sector OverlayAmber

Manx Care, the Island's publicly-owned health and social care provider, has been the subject of Manx Information Commissioner enforcement action for failure to comply with data subject access rights under the Applied GDPR.

Claims: CLM-IM-f8a9b0c1

Telecoms And EprivacyAmber

The Isle of Man Information Commissioner's statutory remit expressly includes the Unsolicited Communications Regulations alongside the data protection legislation, indicating an operative ePrivacy-equivalent regime, though its detailed content was not independently verified in this pass.

Claims: CLM-IM-a9b0c1d2

Employment DataRed

No Manx employment-specific data protection overlay was located.

Absence provenance: not recorded. Searched: Isle of Man employment data protection code.

Credit And ScoringRed

No Manx credit-scoring-specific data protection overlay was located.

Absence provenance: not recorded. Searched: Isle of Man credit scoring data protection.

EducationRed

No Manx education-sector-specific data protection overlay was located.

Absence provenance: not recorded. Searched: Isle of Man education sector data protection.

InsuranceRed

No Manx insurance-sector-specific data protection overlay was located.

Absence provenance: not recorded. Searched: Isle of Man insurance sector data protection.

Category narrative68 words

Direct sectoral evidence located in this pass is limited to the health/social-care sector (Manx Care, the publicly-owned health and social care provider, subject to Applied GDPR access-right enforcement) and telecoms/e-privacy (the Unsolicited Communications Regulations, which sit alongside the data protection legislation within the Information Commissioner's statutory remit). The Isle of Man is a significant offshore financial centre, but no financial-sector overlay instrument was independently confirmed in this pass.

#

Only the existence of an Unsolicited Communications Regulations regime is confirmed; substantive adtech/commercial-privacy detail is an unconfirmed gap.

Supervisory authorityIsle of Man Information Commissioner
Traffic-light rationale — RedOnly the existence of an Unsolicited Communications Regulations regime is confirmed; substantive adtech/commercial-privacy detail is an unconfirmed gap.

Sub-modules (6)

Cookies And TrackersRed

No Manx-specific cookie/tracker consent guidance was located beyond the general existence of the Unsolicited Communications Regulations regime.

Absence provenance: not recorded. Searched: Isle of Man Unsolicited Communications Regulations 2005 PECR marketing cookies.

Dark PatternsRed

No Manx dark-pattern prohibition was located.

Absence provenance: not recorded. Searched: Isle of Man dark patterns data protection.

Opt Out SignalsRed

No Manx opt-out-signal (e.g. GPC-equivalent) framework was located.

Absence provenance: not recorded. Searched: Isle of Man Global Privacy Control opt-out signal.

Clean Rooms And DcrRed

No Manx data clean-room/collaboration-room rule was located.

Absence provenance: not recorded. Searched: Isle of Man data clean room data collaboration.

Cross Context AdvertisingRed

No Manx cross-context-advertising ('sale'/'share') framework analogous to CPRA was located; not expected given GDPR-model regime.

Absence provenance: not recorded. Searched: Isle of Man cross-context advertising sale share personal data.

Direct MarketingAmber

Direct marketing communications are understood to fall within the Isle of Man Information Commissioner's Unsolicited Communications Regulations remit, alongside the data protection legislation.

Claims: CLM-IM-b0c1d2e3

Category narrative38 words

The Isle of Man Information Commissioner's remit over the 'Unsolicited Communications Regulations' indicates an operative direct-marketing/ePrivacy-equivalent regime, but detailed cookie-consent, dark-pattern, opt-out-signal and cross-context-advertising rules specific to the Isle of Man were not located in this research pass.

#

Core ADM/profiling protection is inherited via full GDPR adoption; AI-specific and biometric/genetic-specific regimes are unconfirmed gaps; a distinct law-enforcement carve-out regime is confirmed to exist.

Primary frameworkApplied GDPR (general) and LED Implementing Regulations 2018 (law enforcement)
Supervisory authorityIsle of Man Information Commissioner
Traffic-light rationale — AmberCore ADM/profiling protection is inherited via full GDPR adoption; AI-specific and biometric/genetic-specific regimes are unconfirmed gaps; a distinct law-enforcement carve-out regime is confirmed to exist.

Sub-modules (6)

Profiling RestrictionsAmber

Profiling restrictions (GDPR Art 22-equivalent) are presumed inherited from the fully-adopted Applied GDPR text; no Manx-specific enforcement precedent located.

Claims: CLM-IM-c1d2e3f4

Automated Decision Making TransparencyAmber

ADM transparency obligations are presumed inherited from the Applied GDPR; no Manx-specific guidance located.

Absence provenance: not recorded. Searched: Isle of Man automated decision making transparency GDPR.

Ai Risk AssessmentsRed

No Isle of Man AI-specific risk-assessment regime (EU AI Act interface or local equivalent) was located.

Absence provenance: not recorded. Searched: Isle of Man AI Act artificial intelligence risk assessment data protection.

Biometric RegimeRed

No Manx biometric-specific statute or guidance was located beyond the general special-category treatment inherited from the Applied GDPR.

Absence provenance: not recorded. Searched: Isle of Man biometric data facial recognition regime.

Genetic DataRed

No Manx genetic-data-specific statute or guidance was located beyond the general special-category treatment inherited from the Applied GDPR.

Absence provenance: not recorded. Searched: Isle of Man genetic data regime.

State Surveillance CarveoutsAmber

The LED Implementing Regulations 2018 establish a distinct legal regime for law-enforcement/competent-authority processing, separate from the general Applied GDPR, evidencing a formal state-processing carve-out structure.

Claims: CLM-IM-d2e3f4a5

Category narrative49 words

Algorithmic/ADM and profiling protections are presumed inherited from the wholesale adoption of the GDPR (including Article 22), and a distinct law-enforcement/state-processing regime exists via the LED Implementing Regulations 2018, separate from the general Applied GDPR. No Isle of Man-specific AI risk-assessment regime, biometric-specific statute, or genetic-data-specific statute was located.

#

This entire module rests on inference from wholesale GDPR adoption; no Manx-specific children's-data source was independently confirmed.

Supervisory authorityIsle of Man Information Commissioner
Traffic-light rationale — RedThis entire module rests on inference from wholesale GDPR adoption; no Manx-specific children's-data source was independently confirmed.

Sub-modules (5)

Age VerificationRed

No Manx-specific age-verification requirement was located.

Absence provenance: not recorded. Searched: Isle of Man age verification children data protection.

Minor Profiling BansRed

No Manx-specific minor-profiling ban was located.

Absence provenance: not recorded. Searched: Isle of Man minor profiling ban children's code.

Education SettingsRed

No Manx education-settings-specific data protection rule was located.

Absence provenance: not recorded. Searched: Isle of Man education settings data protection children.

Dependent AdultsRed

No Manx dependent-adults-specific data protection provision was located.

Absence provenance: not recorded. Searched: Isle of Man dependent adults vulnerable data protection.

Category narrative64 words

No Isle of Man-specific instrument confirming the exact digital age-of-consent figure, parental-consent mechanism, minor-profiling ban, education-settings rule, or dependent-adults protection was located in this research pass. The Isle of Man's adoption of the GDPR 'with adaptations specific to the requirements of the Isle of Man' leaves open whether it mirrors the UK's age-13 Article 8 threshold or another figure within the 13-16 GDPR range.

#

Clear, repeated, and recent (through Dec 2025) enforcement activity confirms an active regulator; funding/capacity and redress-mechanism sub-modules remain unconfirmed gaps.

Primary frameworkData Protection Act 2018 (Isle of Man) enforcement provisions
Supervisory authorityIsle of Man Information Commissioner
Traffic-light rationale — GreenClear, repeated, and recent (through Dec 2025) enforcement activity confirms an active regulator; funding/capacity and redress-mechanism sub-modules remain unconfirmed gaps.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

The Commissioner can issue enforcement notices requiring compliance, with failure to comply risking a penalty and/or contempt proceedings.

Claims: CLM-IM-f4a5b6c7

Enforcement Activity IndexGreen

Documented enforcement actions include the 2020 DHA enforcement notice, the 2021 Manx Care enforcement notice, a reported 2022 Manx Care fine, and the December 2025 joint breach investigation.

Claims: CLM-IM-a5b6c7d8, CLM-IM-b6c7d8e9

Regulator Funding And CapacityRed

No Manx-specific regulator funding/headcount data was located.

Absence provenance: not recorded. Searched: Isle of Man Information Commissioner funding headcount budget.

Collective Redress And Class ActionsRed

No Manx-specific collective-redress or class-action mechanism for data protection claims was located.

Absence provenance: not recorded. Searched: Isle of Man collective redress class action data protection.

Private Right Of ActionRed

No Manx-specific private-right-of-action provision for data protection claims was located.

Absence provenance: not recorded. Searched: Isle of Man private right of action data protection court.

Recent Developments 180DAmber

No Isle of Man-specific data protection development strictly within the last 180 days (i.e. since approximately February 2026) was identified; the most recent substantive development located is the joint UK/Guernsey/Jersey/Isle of Man breach investigation opened in December 2025, which falls just outside the strict 180-day window from the current date.

Absence provenance: not recorded. Searched: Isle of Man Information Commissioner 2026 data protection.

Claims: CLM-IM-c7d8e9f0

Category narrative98 words

The Isle of Man Information Commissioner has a demonstrated enforcement track record: enforcement notices against the Department of Home Affairs (2020) and Manx Care (2021) for access-right failures, a reported fine against Manx Care (2022, details not independently verified), and a live joint cross-jurisdictional breach investigation with the UK ICO and Jersey/Guernsey authorities (opened December 2025) into a cyber incident. Regulator funding/capacity, collective redress, and private-right-of-action mechanisms specific to the Isle of Man were not confirmed in this pass; no development strictly within the last 180 days (since approximately February 2026) was identified beyond the ongoing 2025 investigation.

No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Isle of Man
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 0 claim(s), 12 source(s) in the cumulative register.