Constitution of the Democratic Republic of Timor-Leste, Section 38(2) (Personal data deferred to statute)
Constitution of the Democratic Republic of Timor-Leste (2002), Section 38(2)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 20 May 2002.
A comprehensive regime rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Treat Timor-Leste as having no personal-data-protection statute: the Constitution defers the concept of personal data and the general conditions for processing it to a law that has never been enacted, so there is no defined scope, no registration duty, no supervisory authority and no procedure to comply with.
- Rely on Section 38's own two operative rules, the access right and the sensitive-category consent bar, rather than on a statutory definition of personal data, because none exists to scope a Timor-Leste deployment against.
What it reaches
Obligation class
Governance
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Section 38(2) defers the concept of personal data, and the conditions applicable to processing it generally, to a law that Timor-Leste has never enacted. There is therefore no statutory definition of personal data, no lawful-basis scheme, no registration duty, no supervisory authority and no procedural mechanism behind the two operative rules Section 38 does state.
Adjacent Section 36 (honour and privacy) and Section 37 (inviolability of home and correspondence) protect related interests but create no personal-data-specific duty.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotprocesses_biometricsprocesses_voice
Read the law
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.