Cyber Law at Macau
Macau's cybersecurity legal framework has evolved to address the growing digital threats and ensure the protection of critical infrastructure. Here's an overview of the key legislations and regulatory bodies:
🛡️ Cybersecurity Law (Law No. 13/2019)
Enacted on December 22, 2019, the Cybersecurity Law establishes a comprehensive system to safeguard Macau's information networks and critical infrastructures
Key Provisions:
Critical Infrastructure Protection: The law defines critical infrastructures as systems and networks whose disruption could harm public well-being, safety, or order
Real-Time Monitoring: The Cybersecurity Incidents Alert and Response Centre (CARIC), operated by the Judiciary Police, monitors the cyber status of critical infrastructure operators in real-time and issues warnings upon detecting attacks
Incident Reporting: Operators are required to report cybersecurity incidents to CARIC, which assists in investigations and provides technical and administrative support
Real-Name Registration: Mobile phone users must register with their real names to curb illegal activities such as fraud and spam messaging
💻 Computer Crime Combat Law (Law No. 11/2009, amended by Law No. 4/2020)
This law addresses cybercrimes and establishes procedures for electronic evidence collection.
Amendments in 2020:
Fraudulent Mobile Base Stations Operating fraudulent mobile base stations is now a criminal offense, punishable by imprisonment for up to five year.
Disclosure of Security Vulnerabilities Illegitimately exposing serious computer security vulnerabilities is a punishable offense.
Penalties Offenders may face fines or imprisonment, with penalties aggravated when crimes target critical infrastructure operators or government institution.
🏛️ Regulatory Authorities
*Cybersecurity Commission: Oversees the formulation and implementation of cybersecurity policies and strategies.
**Cybersecurity Incidents Alert and Response Centre (CARIC)*: Coordinates responses to cybersecurity incidents and provides support to critical infrastructure operators.
**Macau Computer Emergency Response Team Coordination Centre (MOCERT)*: Handles computer security incidents and promotes information security awareness.
🔐 Data protection
Macau's data protection is governed by the Personal Data Protection Act (PDPA), enacted as Law No. 8/205.
Updates:
**Personal Data Protection Bureau (PDPB)*: Established in 2023, the PDPB oversees data protection regulations and is under the direct authority of the Chief Executive.
⚖️ Enforcement and Compliance
Non-compliance with cybersecurity laws can result in penalties, including fines up to MOP 5 million and other sanctions such as exclusion from public procurement and subsides.
0 comments