Skip to the content
Global Data RulesData governance rules, country by country

Jamaica

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.

The answer

Yes, with paperworkWork: HighEnforcement: Dormant

Jamaica lets personal data leave the island, but only to places that protect it well enough. You decide that yourself, because the government has never published a list of approved countries. The rules on paper are heavy: you must register, you may need a data protection officer, and breaking them is a crime, not just a fine. In practice almost nothing is enforced.

Data governance in Jamaica

The eight things that decide how you handle data about people in Jamaica. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. The law reaches a company with no office in Jamaica if it offers products or services to people in Jamaica, watches what they do in Jamaica, or uses equipment in Jamaica to handle the data. There is no size or revenue cut-off, so a one-person business is caught the same as a bank. If you have no establishment in Jamaica you must appoint a representative who is based there.

High confidenceNational rulesAppoint a local representativeLocal representative

Where the data is allowed to live

Yes, with conditions. The rule is that personal data must not go to a country outside Jamaica unless that country gives people adequate protection. Nobody in government has published a list of which countries pass, so in practice you make the judgement yourself and keep the reasoning. We found no industry in Jamaica that is banned from sending data abroad, and no rule anywhere requiring a copy to stay on the island.

High confidenceYes, with paperworkApproval each timeOfficial 'this country is safe' decisionAll industries

Sending data out of the country

There is no form to file and no approval to wait for. You must satisfy yourself that the destination protects people's data well enough, write down why, and list that country when you register. If the destination does not pass, you can still send data using one of the exceptions in the law, such as the person's clear consent or a genuine need to perform a contract. The government has published no list of approved countries and no standard contract you can sign, so nothing is pre-approved for you.

High confidenceApproval each timeOfficial 'this country is safe' decisionGovernment sign-off neededExplicit consentNeeded for a contractImportant public interestLegal claimsSomeone's life is at riskPut a transfer safeguard in place

The regulator, and whether it actually acts

The Office of the Information Commissioner is the regulator. It exists, it has a Commissioner and a deputy, and it answers the phone, but it is not enforcing. In June 2026 the responsible Minister told Parliament in plain words that the law is not being enforced because the office was set up with a temporary structure and too few trained staff. Its own website has published no annual reports, its oversight committee page is blank, and the registration system has been switched off since March 2026 with a promise that nobody will be penalised while it is down.

High confidenceDormantRegulator

How long you must keep it — and when to delete it

Jamaica sets no single number. The ceiling is a duty to get rid of personal data once you no longer need it, and to destroy it so thoroughly that it cannot be put back together or linked to anyone. You must also write down your own minimum and maximum keeping periods. The floor comes from other laws: banks and other financial firms must keep transaction records for at least seven years, and that beats the delete duty.

High confidenceDelete data after a periodKeep data for a minimum periodKeep records of processing

If something goes wrong

You have seventy-two hours to tell the regulator, and, unusually, seventy-two hours to tell the affected people as well. Most countries give you longer for the second one. Banks must also tell the Bank of Jamaica within seventy-two hours, and insurers, pension funds and investment firms must tell the Financial Services Commission within seventy-two hours. All these clocks start when you become aware, and they run at the same time. Missing the first one is a criminal offence.

High confidenceReport breaches to the regulatorTell affected peopleReport cyber incidents

What catches people out

Five things bite people here. Breaking this law is a crime, and a company can be fined up to four percent of its worldwide turnover by a court. Government bodies cannot be prosecuted at all. You must tell affected individuals within seventy-two hours, not merely as soon as reasonable. If your data protection officer lives abroad, you must give that officer a stand-in who lives in Jamaica. And you can be told to charge someone for a copy of their own data, which sounds generous but means you must have a fee process at all.

High confidenceCriminal liabilityPercentage of global turnoverAppoint a data protection officerAppoint a local representativeChildren's dataGet a parent's consent for childrenLet people see their data

What's changing next

The main thing coming is enforcement itself. In June 2026 the responsible Minister told Parliament that the regulator's full budget was approved, a working group is running, and the oversight committee appointments are nearly done, after which the enforcement provisions will be switched on. The Bank of Jamaica is consulting until 30 October 2026 on a new outsourcing and third-party risk standard for banks. A draft national artificial intelligence policy is due by November 2026, and the Act itself falls due for its first five-yearly review from 1 December 2026.

High confidenceProposedDraft lawGovernment policy document

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries3 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Banking

Standard of Sound Practice — Management of Cyber Risks

Statutory code of practice · Issued under the Banking Services Act, 2014

In forceYes, with paperwork

Banks and other deposit-taking institutions must run a cyber risk framework, do due diligence on cloud and other outside providers, and report a serious incident to the Bank of Jamaica within seventy-two hours. There is no requirement to keep the data in Jamaica.

In force since 29 November 2023

Enforced by Bank of Jamaica

High confidence
Finance

Industry Guidance — Management of Cyber Risks

Regulator guideline · Issued to licensees under the Insurance Act, the Pensions Act and the Securities Act

In forceYes, with paperwork

Insurers, pension funds and investment firms must report a cyber incident or data breach to the Financial Services Commission within seventy-two hours, and give the Commission an annual attestation on their controls. Cloud providers are expected to hold independent security assurance. There is no requirement to keep the data in Jamaica.

In force since 1 October 2025

Enforced by Financial Services Commission

High confidence
Government

GoJ ICT Policies, Standards and Guidelines Manual — Guidelines for Cloud Computing

Government policy document · PSG Manual version 1.2, Office of the Chief Information Officer, February 2018; republished by the ICT Authority

In forceYes, with paperwork

Government ministries and agencies may use overseas cloud services, but the provider's terms of service must be cleared by the Attorney General's Office and the head of the body must approve the use in writing. There is no ban on hosting government data abroad, and no approved-country list.

In force since 26 February 2018

Enforced by Jamaica ICT Authority

Medium confidence

Applies to every company4 rules

These bind you whatever business you are in, once the country's rules reach you.

The Data Protection Act, 2020

Act of parliament · Act No. 7 of 2020

In forceYes, with paperwork

Jamaica's general privacy law. It reaches foreign companies that serve or monitor people in Jamaica and makes them appoint a Jamaican representative. Data may leave the island only to countries you judge to protect it adequately, and there is no official list to lean on. Enforcement runs through the criminal courts, and a company can be fined up to four percent of worldwide turnover. Public authorities cannot be prosecuted.

In force since 1 December 2021But only enforceable from 1 December 2023

Enforced by Office of the Information Commissioner — not yet operational

Transfer model: Approval each time (the list is currently empty) · Accepted routes: Official 'this country is safe' decision, Government sign-off needed, Explicit consent, Needed for a contract, Important public interest, Legal claims, Someone's life is at risk

High confidence

The Data Protection Regulations, 2024 (the Minister's Regulations)

Directly binding regulation · Jamaica Gazette Supplement, Proclamations, Rules and Regulations, Vol. CXLVII No. 23A, 4 March 2024

In forceYes, with paperwork

The detailed rules under the Act. They set the breach forms, put a hard seventy-two hour deadline on telling affected individuals, require a Jamaica-resident stand-in where your data protection officer lives abroad, and let you charge a fee before answering a request for someone's own data.

In force since 1 March 2024

Enforced by Office of the Information Commissioner — not yet operational

High confidence

The Data Protection (Data Controller Registration) Regulations, 2024

Directly binding regulation · Jamaica Gazette Supplement, Proclamations, Rules and Regulations, 1 April 2024

SuspendedYes, with paperwork

Every data controller must register with the regulator, pay a fee, renew each year by the first of December, and name the countries it sends data to. The rule is still law, but the registration system has been switched off since March 2026 and the regulator has publicly promised not to impose liability while it is down. It can be switched back on without notice.

In force since 1 April 2024But only enforceable from 1 June 2024

Enforced by Office of the Information Commissioner — not yet operational

High confidence

Who you would hear from

  • Office of the Information Commissioner (OIC)

    The national data protection regulator for all sectors under the Data Protection Act, 2020

    Staffed but not enforcing. Celia Barclay has been Information Commissioner since 1 December 2021 and Ronald Frue is Deputy. The office answers complaints, runs a breach reporting form and maintains a public register of roughly five hundred data controllers. But on 2 June 2026 the responsible Minister told Parliament the law is not being enforced because the office has an interim structure, staffing below required levels and untrained key officers; the statutory Data Protection Oversight Committee has still not been appointed; the Reports page carries no annual report or enforcement statistics; and the registration portal has been offline since March 2026 with an express promise of no liability meanwhile. No published fine, prosecution or enforcement notice was found as at 19 August 2026.

  • Bank of Jamaica (BOJ)

    Banks, other deposit-taking institutions, financial holding companies, payment service providers, credit bureaux and money services

    Fully operational and actively issuing standards. Published new anti-money-laundering guidance notes gazetted 17 June 2026, a corporate governance standard in November 2025, and an outsourcing and third-party risk consultation in July 2026. Its own site is boj.org.jm, an .org.jm domain, but it is the statutory central bank's official website.

  • Financial Services Commission (FSC)

    Insurance, pensions, securities and unit trusts

    Operational. Issued binding-in-practice cyber risk guidance effective 1 October 2025 requiring 72-hour incident reporting and an annual control attestation. The Commission itself suffered a cyber event in September 2023, which it disclosed publicly. Its official website sits on fscjamaica.org rather than a .gov.jm domain.

  • Information and Communications Technology Authority (JAMICTA)

    Government ICT policy, standards and shared services for ministries, departments and agencies

    Established under the Information and Communications Technology Authority Act, 2019. Marked its first anniversary in 2026 and launched the Jamaica Data Exchange Platform. Publishes the government's ICT policies, standards and guidelines and the Government of Jamaica Data Protection Act Compliance Framework. It sets policy for public bodies; it is not a data protection regulator and cannot fine anyone.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • That the whole of the Data Protection Act, 2020 is in force, rather than only part of it

    The regulator's own mandate page says the Appointed Day Notice gazetted on 30 November 2021 brought into operation sections 2, 4, 56, 57, 60, 66, 74 and 77, the First Schedule and 'certain powers, duties and responsibilities', plus the transitional section. We could not retrieve the Appointed Day Notice itself or any later commencement notice covering the registration, standards and offence provisions. Everyone concerned, including the regulator and the Minister, behaves as though those provisions are operative, so we have recorded the Act as in force — but if you need certainty on a specific section, ask the Commissioner in writing.

  • That no Ministerial order has been made naming countries with adequate protection under section 31(5)(c), and none designating 'specified processing' under section 19

    This is a negative. We searched the regulator's legislation pages and the government sites we could reach on 19 August 2026 and found no such order. The Jamaica Gazette is not fully searchable online and the Ministry of Justice laws portal could not be reached because of a certificate problem, so we cannot prove the absence.

  • That the Office of the Information Commissioner has published no annual report and issued no enforcement decision

    The regulator's Reports page returns 'No available content' and none of its six press releases concerns an enforcement action. An annual report may have been tabled in Parliament without being posted online. Treat this as 'nothing published', not as 'nothing exists'.

  • Whether the data controller registration portal has reopened between 15 March 2026 and today

    The regulator's homepage on 19 August 2026 still says registration is temporarily paused, and no press release announcing reopening has been published. But the advisory promises notice through the office's channels rather than a dated commitment, so this can change at any time.

  • Sector rules for health, education, telecoms, gambling, mapping and defence

    We searched the Ministry of Health and Wellness, the Office of Utilities Regulation, the Betting Gaming and Lotteries Commission and the ICT Authority on 19 August 2026 and found no data localisation or cross-border rule in any of them. Coverage was thinner than for finance: the Ministry of Health site blocked automated retrieval, the Betting Gaming and Lotteries Commission site was intermittently unreachable, and the national cyber incident response team's site had an expired security certificate and could not be checked. Treat the absence of a telecoms or health rule as unverified rather than established.

  • The United States dollar approximations for Jamaican dollar penalties and fees

    Converted at roughly one hundred and sixty Jamaican dollars to the United States dollar. We could not read a live rate off the central bank's page, so treat every dollar figure as indicative and use the Jamaican figure for anything that matters.

  • Whether the Bank of Jamaica's draft outsourcing standard will contain any data location requirement in its final form

    The July 2026 text is a consultation draft and closes on 30 October 2026. As drafted it requires supervisory access and country risk assessment rather than local storage, but drafts change. It has no legal effect today and must not be planned around as binding.

Freshness and refresh

Freshness

Checked today — on 19 August 2026.

Re-checked every 60 days. Next check due 18 October 2026.

Read the exact prompt used to research this page

Put this next to another country

Jamaica versus

Compare

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.