Insights

Data protection in the Caribbean: why Jamaica and Barbados are leading the pack

Most Caribbean countries have a data protection law on the books. Only a few have a regulator that can act on it. Two of them have moved decisively, and if your business touches their citizens' data, their rules already apply to you.

TeqNola · 7 September 2026

Laws on paper, regulators in waiting

Ask around the region and you will hear that "we have a Data Protection Act." Usually true. Antigua, Belize, the Cayman Islands, Guyana, Saint Kitts and Nevis, Saint Lucia, Trinidad and Tobago, Bermuda, Barbados and Jamaica all have one. The question that matters to a business is different: is there a commissioner with staff, a registration process, and the power to fine?

By that test the region splits into three groups.

CountryLawStatus
BarbadosData Protection Act 2019In force since 31 March 2021. Commissioner appointed July 2021.
JamaicaData Protection Act 2020Fully enforceable since 1 December 2023. Commissioner's office operating, registration open since June 2024.
Cayman IslandsData Protection Act 2017In force since 2019, with an active Ombudsman.
BermudaPersonal Information Protection Act 2016Fully operative from 1 January 2025.
Saint LuciaData Protection Act 2011Partially proclaimed in January 2023. Enforcement powers and most individual rights not yet in force.
Trinidad and TobagoData Protection Act 2011Still only partially proclaimed.
GuyanaData Protection Act 2023Passed, awaiting commencement.

Cayman and Bermuda are overseas territories with financial-centre obligations that pushed them early. Among independent CARICOM states, Barbados and Jamaica are the two that have built the machinery, and their laws are the ones most likely to reach a business that is not based there.

Barbados moved first

Barbados passed its Act in 2019 and brought it into force on 31 March 2021, then appointed a Data Protection Commissioner that July. It is modelled on the European GDPR, and it shows.

The practical effect is that Barbados stopped being a country where "we'll sort out privacy later" was a defensible plan, four years before most of its neighbours.

Jamaica built the enforcement machine

Jamaica passed its Act in June 2020 and gave the economy a three-year transition. It became fully enforceable on 1 December 2023. The Office of the Information Commissioner had been set up two years earlier so that it existed before the deadline, and it began accepting data controller registrations on 1 June 2024.

What makes the Jamaican regime unusual, even by GDPR standards:

The Commissioner has said publicly that formal enforcement is being brought online in stages, and as of early 2026 no penalties had been issued. Anyone reading that as "nothing will happen" should look at how registration has gone: open, paused for a portal upgrade, reopened for the 2025 to 2026 cycle. That is a regulator building capacity, not one losing interest.

Why this reaches a business in Saint Lucia

Saint Lucia's own Act was passed in 2011, amended in 2014, and partially proclaimed in January 2023. The sections that let a Commissioner investigate and penalise, and the sections that give individuals the right to access, correct and object, are not yet in force. Locally, the pressure is low.

The reach of the Jamaican and Barbadian laws changes that calculation. Both apply to data about their residents regardless of where the business sits. If you:

then part of your customer data is already governed by a law with a working regulator behind it. The Organisation of Eastern Caribbean States is drafting harmonised data protection legislation under the World Bank's Caribbean Digital Transformation Project, and when it lands it will look a lot like Barbados. Building to that standard now means building once.

What "built to the law" actually means

Compliance is not a privacy page. It is a set of decisions in the software, made before launch. From building a regional platform that holds job seekers' data across several islands, this is what it looks like in practice:

  1. Decide which markets you serve, and enforce it in code. If you have decided not to take on the obligations of a particular jurisdiction, the system should refuse that data at every point where it could enter, not rely on a dropdown and good intentions.
  2. Record the lawful basis for each kind of processing. Consent, contract, legitimate interest. Write it down, and make the product match what you wrote.
  3. Treat erasure as a pipeline, not a button. Grace period, dependent records, backups, evidence that it happened, and a documented reason for anything you keep.
  4. Version your privacy notice and terms. Keep every version that anyone ever agreed to, and make it impossible to change the live text without cutting a new version.
  5. Publish aggregates, not people. If you release statistics built from personal data, suppress small groups so no individual can be inferred.
  6. Have a breach runbook before you need one. Who decides whether an incident is notifiable, who tells the Commissioner, and how you reach 72 hours with something accurate to say.
  7. Get counsel to confirm the edge cases. Statistical aggregates, cross-border transfers, and what "large scale" means for you are questions a lawyer in the relevant jurisdiction should answer once, in writing.

None of this is exotic. All of it is cheaper before launch than after a letter arrives.

Where to start

TeqNola builds systems to this standard for businesses across Saint Lucia and the wider Caribbean, and runs them for the ones that would rather not. If you are not sure where your data sits, that is the first conversation.

Sources

Not sure where your data sits, or whose law it falls under?

That is the first conversation. We reply within one business day with a straight answer.

Let's talk