Skip to content

Library

VERIFIEDOpen accessLaw 10/2012, Art. 16-C · Law 8/2005 · Updated 23 July 2026

RG runs on personal data. Handling it is a duty too.

Exclusion lists, facial-recognition matches, interaction logs — the RG programme is a personal-data operation, and the monitoring room holds most of it. Lawful basis, consent and retention are the controls.

Operator duty · Surveillance responsibility

1 ·The duty in law

Exclusion records are personal data. Article 16-C of Law 10/2012 is what allows the DICJ to present, confirm and permit the use of data on interdicted persons — including interconnecting that data with other public entities and with the concessionaires — and it does so under Law 8/2005, the Personal Data Protection Act. That is the legal basis on which an exclusion list reaches a property's systems at all, and the reason RG records carry data-protection obligations rather than sitting outside them.

Consent recurs as a specific control: the Art. 16-B referral to the IAS may proceed only with the person's consent. Across the RG programme, the pattern holds — data is collected for a stated purpose, moved on a lawful basis, and kept no longer than that purpose requires.

2 ·The data RG generates

Exclusion / interdiction listsReceived from the DICJ and matched against patrons — the Art. 16-C interconnection is the lawful basis for it reaching your systems at all.
Facial-recognition matchesBiometric data generated to enforce exclusion and entry control. High-sensitivity; collected for a defined purpose and no other.
Interaction & referral recordsAt-risk observations, actions and consent. Personal, sometimes health-adjacent, and evidence for the annual report.
Seizure recordsIdentify the interdicted person and the responsible officer; retained for the enforcement decision.

3 ·Where the risk sits

The surveillance function is a large collector of sensitive personal data, and RG concentrates the most sensitive of it. The recurring failures are ordinary: purpose creep, where a facial-recognition system stood up for exclusion is quietly used for marketing or profiling; data moved before consent, where a referral or a share runs ahead of the Art. 16-B condition; and retention without limit, where exclusion and interaction records are kept indefinitely because no one set a schedule. Each is a data-protection breach that a well-run integrity department can create precisely because it holds so much.

4 ·The surveillance part

The monitoring room is the custodian of most RG personal data, so the controls are its to run. Keep each RG data set to its stated purpose and resist its reuse. Record the lawful basis for every interconnection with the DICJ or another entity. Capture consent before any referral or share that requires it, and store the consent with the record. Set and enforce a retention schedule so records are disposed of when their purpose ends. None of this is exotic — it is the same evidentiary discipline the rest of the section asks for, applied to the data itself.

A control built for exclusion is not a licence for everything

Biometric matching deployed to keep interdicted persons out is lawful for that purpose. Extending it to general patron profiling is a new purpose that needs its own basis. The narrower the stated purpose, the safer the system — and the easier it is to defend at inspection.

5 ·Cadence & timing

WhenWhat
At collectionRecord purpose and lawful basis; capture consent where the process requires it.
ContinuousHold each data set to its purpose; block reuse without a fresh basis.
On scheduleDispose of records at the end of their retention period.
PeriodicReview interconnections and access; confirm they still rest on a valid basis.

6 ·The correct pathway

  1. Inventory every RG data set — lists, biometrics, interaction and seizure records — and state each one’s purpose.
  2. Record the lawful basis for each interconnection (Art. 16-C) with the DICJ or another entity.
  3. Capture consent before any Art. 16-B referral or share that requires it; store it with the record.
  4. Confine each system to its purpose; treat any reuse as a new purpose needing its own basis.
  5. Set a retention period per data set and dispose on schedule.
  6. Review access and interconnections periodically; keep the review evidence.

7 ·Sources

  1. 1.Processing and interconnection of exclusion / interdiction dataLaw 10/2012 Art. 16-C, applying Law 8/2005, BO 52/2018, 27 Dec 2018DICJ may present, confirm and permit use of interdiction data, interconnecting with public entities and concessionaires, under the Personal Data Protection Act
  2. 2.IAS intervention requires the person’s consentLaw 10/2012 Art. 16-B, BO 52/2018Consent is a condition of moving personal data to the IAS
  3. 3.Personal Data Protection Act — the governing regimeLaw 8/2005, Personal Data Protection Act (Macao SAR)Purpose limitation, lawful basis and proportionality apply to all RG personal data

Legal provisions are VERIFIED against the Boletim Oficial. Risk framing, the surveillance responsibilities, the cadence and the pathway are Surveillance Intelligence Asia's own analysis, graded separately from the cited record.