Laws on paper, regulators in waiting
Ask around the region and you will hear that "we have a Data Protection Act." Usually true. Antigua, Belize, the Cayman Islands, Guyana, Saint Kitts and Nevis, Saint Lucia, Trinidad and Tobago, Bermuda, Barbados and Jamaica all have one. The question that matters to a business is different: is there a commissioner with staff, a registration process, and the power to fine?
By that test the region splits into three groups.
| Country | Law | Status |
|---|---|---|
| Barbados | Data Protection Act 2019 | In force since 31 March 2021. Commissioner appointed July 2021. |
| Jamaica | Data Protection Act 2020 | Fully enforceable since 1 December 2023. Commissioner's office operating, registration open since June 2024. |
| Cayman Islands | Data Protection Act 2017 | In force since 2019, with an active Ombudsman. |
| Bermuda | Personal Information Protection Act 2016 | Fully operative from 1 January 2025. |
| Saint Lucia | Data Protection Act 2011 | Partially proclaimed in January 2023. Enforcement powers and most individual rights not yet in force. |
| Trinidad and Tobago | Data Protection Act 2011 | Still only partially proclaimed. |
| Guyana | Data Protection Act 2023 | Passed, awaiting commencement. |
Cayman and Bermuda are overseas territories with financial-centre obligations that pushed them early. Among independent CARICOM states, Barbados and Jamaica are the two that have built the machinery, and their laws are the ones most likely to reach a business that is not based there.
Barbados moved first
Barbados passed its Act in 2019 and brought it into force on 31 March 2021, then appointed a Data Protection Commissioner that July. It is modelled on the European GDPR, and it shows.
- A 72-hour breach notification duty to the Commissioner, and to affected individuals where the risk is high.
- A data privacy officer requirement for organisations that process personal data on any real scale.
- Fines of up to BBD 500,000, and up to three years' imprisonment for the most serious offences.
- Extraterritorial reach. The Act follows the data, not the office. A business outside Barbados that processes Barbadian residents' data can fall within it.
The practical effect is that Barbados stopped being a country where "we'll sort out privacy later" was a defensible plan, four years before most of its neighbours.
Jamaica built the enforcement machine
Jamaica passed its Act in June 2020 and gave the economy a three-year transition. It became fully enforceable on 1 December 2023. The Office of the Information Commissioner had been set up two years earlier so that it existed before the deadline, and it began accepting data controller registrations on 1 June 2024.
What makes the Jamaican regime unusual, even by GDPR standards:
- Every data controller must register with the Commissioner. Failing to register is an offence.
- A data protection officer is required for public bodies and for organisations whose processing is large scale or involves sensitive data.
- An annual data protection impact assessment must be filed within the first 90 days of each calendar year, covering all processing.
- Breach notification to the Commissioner without undue delay, with a 72-hour window as the working standard.
- Penalties for a body corporate can reach 4% of annual gross worldwide turnover.
- Extraterritorial reach by establishment or by equipment: a controller outside Jamaica that uses equipment in Jamaica to process data, other than for transit, is covered.
The Commissioner has said publicly that formal enforcement is being brought online in stages, and as of early 2026 no penalties had been issued. Anyone reading that as "nothing will happen" should look at how registration has gone: open, paused for a portal upgrade, reopened for the 2025 to 2026 cycle. That is a regulator building capacity, not one losing interest.
Why this reaches a business in Saint Lucia
Saint Lucia's own Act was passed in 2011, amended in 2014, and partially proclaimed in January 2023. The sections that let a Commissioner investigate and penalise, and the sections that give individuals the right to access, correct and object, are not yet in force. Locally, the pressure is low.
The reach of the Jamaican and Barbadian laws changes that calculation. Both apply to data about their residents regardless of where the business sits. If you:
- take bookings from Jamaican or Barbadian guests,
- sell online into either market, or
- run a regional service with users in either country,
then part of your customer data is already governed by a law with a working regulator behind it. The Organisation of Eastern Caribbean States is drafting harmonised data protection legislation under the World Bank's Caribbean Digital Transformation Project, and when it lands it will look a lot like Barbados. Building to that standard now means building once.
What "built to the law" actually means
Compliance is not a privacy page. It is a set of decisions in the software, made before launch. From building a regional platform that holds job seekers' data across several islands, this is what it looks like in practice:
- Decide which markets you serve, and enforce it in code. If you have decided not to take on the obligations of a particular jurisdiction, the system should refuse that data at every point where it could enter, not rely on a dropdown and good intentions.
- Record the lawful basis for each kind of processing. Consent, contract, legitimate interest. Write it down, and make the product match what you wrote.
- Treat erasure as a pipeline, not a button. Grace period, dependent records, backups, evidence that it happened, and a documented reason for anything you keep.
- Version your privacy notice and terms. Keep every version that anyone ever agreed to, and make it impossible to change the live text without cutting a new version.
- Publish aggregates, not people. If you release statistics built from personal data, suppress small groups so no individual can be inferred.
- Have a breach runbook before you need one. Who decides whether an incident is notifiable, who tells the Commissioner, and how you reach 72 hours with something accurate to say.
- Get counsel to confirm the edge cases. Statistical aggregates, cross-border transfers, and what "large scale" means for you are questions a lawyer in the relevant jurisdiction should answer once, in writing.
None of this is exotic. All of it is cheaper before launch than after a letter arrives.
Where to start
- List every country whose residents' data you hold. Not where your customers live in theory, where they actually are.
- If Jamaica or Barbados is on the list, treat their Acts as your baseline. They are the strictest you will meet in the region and they will keep you ahead of the OECS harmonised law.
- Fix the three things that fail most audits first: no recorded lawful basis, no way to delete a person completely, no breach plan.
TeqNola builds systems to this standard for businesses across Saint Lucia and the wider Caribbean, and runs them for the ones that would rather not. If you are not sure where your data sits, that is the first conversation.
Sources
- Jamaica Information Service, Enforcement provisions of Data Protection Act to be fully activated
- Office of the Prime Minister, Jamaica, Six-month grace period for data controller registration under the Data Protection Act
- Jamaica Information Service, Registration of data controllers begins June 1
- Jamaica Observer, OIC pauses data controller registration as portal upgrades continue, 2 January 2026
- Office of the Information Commissioner, Jamaica
- Office of the Information Commissioner, Jamaica, Will a data controller who does not comply with the requirements of the Act be penalised? (the 4% of turnover penalty)
- Office of the Information Commissioner, Jamaica, Obligations on data controllers under the Data Protection Act (the 90-day impact assessment filing)
- Ministry of Justice, Jamaica, The Data Protection Act, 2020 (PDF)
- Bartlett D. Morgan, Barbados' advanced privacy law now enforceable, 27 March 2021
- Government of Barbados, Data Protection Commission
- Attorney General's Office, Barbados, Data Protection Act, 2019-29 (PDF)
- Attorney General's Chambers, Saint Lucia, Data Protection Act, Cap 8
- Parliament of Trinidad and Tobago, Proclaim the remaining sections of the Data Protection Act
- DataGuidance, OECS launches data protection legislation project
- The UWI Data Protection Office, external resources by jurisdiction
