BACK

Macao Personal Data Protection & Privacy Policy

Version 1.0 · Last Updated:

1. Purpose

This policy sets out Murzo Group's approach to personal data protection and privacy for Macao SAR-related activities under Law No. 8/2005, the Personal Data Protection Act of the Macao Special Administrative Region.

It is intended to support lawful, transparent, proportionate, and secure handling of personal data relating to customers, employees, workers, applicants, suppliers, visitors, reservations, Wi-Fi users, payment users, marketing contacts, CCTV subjects, and other individuals connected with Murzo Group's Macao operations or Macao-facing services.

2. Scope

This policy applies where Murzo Group processes personal data in Macao SAR, through a Macao establishment, in connection with Macao customers or employees, or through Macao-facing services, platforms, premises, events, reservations, Wi-Fi, payment systems, marketing activity, CCTV, supplier activity, or local operations.

It applies to automated processing and to structured manual records containing personal data. It also applies to identifiable images, voice, video, CCTV, access logs, device data, payment references, booking information, communications, and other information relating to an identified or identifiable natural person.

3. Relationship With Other Jurisdictions

Macao SAR has its own personal data protection framework. Mainland China, Hong Kong SAR, UK, EU, or other privacy requirements must not be treated as automatically satisfying Macao SAR requirements.

Where Macao activity overlaps with mainland China, Hong Kong SAR, EU, UK, or other jurisdictions, Murzo Group should consider each applicable legal framework separately and apply the stricter or more specific control where appropriate.

4. Privacy Principles

Murzo Group should process Macao-related personal data in line with core personal data protection principles, including transparency, lawful and fair processing, purpose limitation, adequacy, relevance, accuracy, security, confidentiality, respect for private life, and respect for individual rights.

  • Personal data should be collected for specified, explicit, and legitimate purposes
  • Personal data should be adequate, relevant, and not excessive for the purpose
  • Personal data should be accurate and updated where necessary
  • Personal data should not be kept longer than needed for the lawful purpose
  • Personal data should be protected by suitable technical and organisational controls

5. Customers, Reservations and Guest Services

Customer and reservation data may include names, contact details, booking details, preferences, purchase history, delivery details, arrival details, service requests, complaints, identity details where required, loyalty or account details, and communications.

Such data should be used for purposes such as handling reservations, providing services, managing accounts, responding to enquiries, processing payments, managing safety and security, complying with legal duties, resolving disputes, and improving services where lawful.

6. Employees, Applicants and Workers

Employee, applicant, contractor, and worker data may include identity details, contact details, right to work or local eligibility information, CVs, qualifications, references, payroll details, attendance records, rota records, performance information, disciplinary or grievance information, training records, security access records, and health or safety information where lawful and necessary.

Employment-related personal data must be handled with confidentiality and used only for legitimate HR, payroll, legal, safety, security, operational, contractual, and compliance purposes.

7. Suppliers, Partners and Business Contacts

Supplier and business contact data may include names, job titles, contact details, identification details where needed, bank or payment details, correspondence, due diligence information, access records, contract information, and performance records.

Supplier personal data should be limited to what is needed for procurement, contract management, payment, compliance checks, security, delivery, disputes, and relationship management.

8. CCTV, Images, Access Control and Security

CCTV, visitor logs, access control records, body-worn camera footage, incident footage, photographs, vehicle images, and security logs may be personal data where individuals can be identified.

CCTV and surveillance must be proportionate and used for legitimate purposes such as safety, security, access control, incident investigation, asset protection, fraud prevention, legal claims, and compliance. Signs, notices, access controls, retention limits, and disclosure controls should be used where appropriate.

CCTV must not be used for unnecessary worker monitoring, hidden surveillance, public embarrassment, unauthorised sharing, social media posting, or unrelated purposes unless lawful and approved.

9. Wi-Fi, Websites, Devices and Technical Data

Wi-Fi, website, app, platform, network, and device data may include IP addresses, MAC addresses, device identifiers, session times, authentication details, traffic logs, security logs, browser details, location-related data, and usage records.

Technical data should be used for network access, cyber security, troubleshooting, fraud prevention, capacity management, service delivery, legal compliance, and incident response. Users should be informed where appropriate, and technical monitoring must be proportionate to the risk and purpose.

10. Payments and Financial Data

Payment data may include transaction references, payer details, invoices, receipts, card or payment provider references, wallet references, bank details, refund details, tax information, chargeback evidence, and anti-fraud information.

Payment information must be handled securely and shared only with payment processors, banks, platforms, accountants, advisers, regulators, insurers, or other parties where needed for lawful payment, refund, fraud, tax, accounting, contractual, legal, or dispute purposes.

11. Marketing and Communications

Marketing personal data may include names, contact details, preferences, consent records, opt-out records, engagement data, event interest, customer segment information, and communication history.

Marketing must be lawful, fair, and not excessive. Murzo Group should respect opt-outs and objections where applicable, avoid misleading consent practices, and ensure that direct marketing, profiling, customer segmentation, and promotional communications follow Macao SAR law and any other applicable laws.

12. Sensitive Data and Higher-Risk Processing

Data revealing health, biometric identifiers, race or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, sex life, criminal allegations, security-sensitive information, children's data, or other higher-risk information requires additional care and must not be processed unless lawful, necessary, proportionate, and approved for the relevant purpose.

Higher-risk processing, interconnection of personal data, sensitive data processing, CCTV, cross-border transfers, and other regulated processing may require notification, authorisation, or advice from the competent Macao SAR public authority where applicable.

13. Data Subject Rights

Individuals may have rights under Macao Law No. 8/2005, including rights to information, access, correction, objection, and not being subject to certain automated individual decisions, as well as other rights or remedies provided by law.

Requests should be handled fairly, securely, and within applicable legal requirements. Murzo Group may need to verify identity, assess legal limits, protect third-party rights, and keep proportionate evidence of the request and response.

14. Cross-Border Transfers and Servers Outside Macao

Transfers of personal data outside Macao SAR must be assessed under Macao Law No. 8/2005. Transfer may depend on adequate protection in the destination, explicit consent, contractual necessity, important public interest, legal claims, vital interests, public register grounds, notification, authorisation, or other permitted conditions.

Where Murzo Group uses servers, cloud services, reservation systems, payroll systems, payment platforms, Wi-Fi systems, CRM tools, analytics tools, support systems, or suppliers located outside Macao SAR, the transfer position must be considered before use where Macao-related personal data is involved.

Mainland China governance, Hong Kong SAR arrangements, UK/EU safeguards, or supplier standard terms must not be assumed to satisfy Macao SAR cross-border transfer requirements unless the Macao position has been considered.

15. Processors and Third Parties

Where Murzo Group uses processors, suppliers, agencies, payment processors, reservation platforms, Wi-Fi providers, CCTV providers, payroll providers, marketing platforms, hosting providers, consultants, or other third parties to process Macao-related personal data, their role, instructions, confidentiality, security, transfer arrangements, access, support, and deletion obligations should be considered.

Third parties must not use Murzo Group personal data for their own purposes, AI training, marketing, resale, profiling, platform enrichment, or unrelated analytics unless authorised and lawful.

16. Security, Confidentiality and Access

Murzo Group should protect Macao-related personal data against unauthorised access, disclosure, alteration, loss, destruction, misuse, excessive access, accidental sharing, insecure transfer, malware, phishing, internal misuse, and supplier compromise.

Controls may include access limitation, passwords, MFA, encryption, secure transmission, locked storage, role-based permissions, confidentiality duties, staff awareness, supplier controls, backup, logging, incident escalation, and secure disposal where suitable.

17. Retention and Disposal

Personal data should not be retained longer than needed for the relevant purpose, legal duty, contract, complaint, employment matter, tax, accounting, security, reservation, payment, marketing, insurance, regulator, or dispute requirement.

When no longer needed, personal data should be deleted, anonymised, sealed, archived, or otherwise restricted where appropriate and lawful.

18. Complaints, Incidents and Authority Contact

Suspected unauthorised access, loss, disclosure, misuse, CCTV misuse, marketing misuse, payment data issue, Wi-Fi data issue, supplier breach, or cross-border transfer concern must be escalated promptly.

Murzo Group may contact affected individuals, suppliers, insurers, advisers, platforms, public authorities, or the Macao SAR personal data protection authority where required or appropriate.

19. Liability and Unauthorised Activity

Third parties must not present their own Macao personal data compliance, privacy notices, CCTV notices, reservation systems, payment processing, Wi-Fi monitoring, marketing consents, server locations, or transfer arrangements as Murzo Group arrangements unless approved in writing.

To the fullest extent permitted by law, Murzo Group does not accept responsibility for privacy breaches, unlawful marketing, unauthorised CCTV use, payment data misuse, Wi-Fi misuse, employee data misuse, supplier data misuse, or unlawful transfers caused by third parties acting outside written approval or outside Murzo Group control.

20. Review and Responsibility

Managers, system owners, customer service contacts, HR contacts, payment contacts, Wi-Fi or network contacts, CCTV contacts, marketing contacts, supplier owners, and authorised representatives are responsible for applying this policy where Macao-related personal data is involved.

Murzo Group may keep proportionate evidence of privacy notices, requests, decisions, transfer assessments, supplier instructions, complaints, incidents, and corrective actions where needed for legal, regulatory, customer, HR, security, payment, or dispute purposes. This policy should be reviewed when Macao SAR law, guidance, operations, suppliers, systems, reservations, payments, marketing, CCTV, Wi-Fi, or cross-border arrangements change.

Murzo Group signature