Jamaica
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.
The answer
Jamaica lets personal data leave the island, but only to places that protect it well enough. You decide that yourself, because the government has never published a list of approved countries. The rules on paper are heavy: you must register, you may need a data protection officer, and breaking them is a crime, not just a fine. In practice almost nothing is enforced.
Data governance in Jamaica
The eight things that decide how you handle data about people in Jamaica. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. The law reaches a company with no office in Jamaica if it offers products or services to people in Jamaica, watches what they do in Jamaica, or uses equipment in Jamaica to handle the data. There is no size or revenue cut-off, so a one-person business is caught the same as a bank. If you have no establishment in Jamaica you must appoint a representative who is based there.
Section 3(1) of the Data Protection Act, 2020 applies the Act to a data controller that is established in Jamaica, or that although not established in Jamaica either uses equipment in Jamaica other than for transit, or processes the data of a person who is in Jamaica where the activity relates to offering products or services to people in Jamaica (payment or not) or to monitoring behaviour that takes place in Jamaica. Section 3(2) then says a controller in that second category 'shall appoint for the purposes of this Act a representative established in Jamaica'. Section 3(3) defines establishment to include a Jamaican company, a Jamaican partnership, an ordinarily resident individual, and any person maintaining an office, branch, agency or regular practice in Jamaica. There is no threshold provision anywhere in the Act.
Sources
- Official sourceOffice of the Information Commissioner, JamaicaData Protection Act, 2020 (Act No. 7 of 2020), section 3
oic.gov.jm
“A data controller falling within subsection (1)(b) shall appoint for the purposes of this Act a representative established in Jamaica.”
Link checked 19 August 2026
Where the data is allowed to live
Yes, with conditions. The rule is that personal data must not go to a country outside Jamaica unless that country gives people adequate protection. Nobody in government has published a list of which countries pass, so in practice you make the judgement yourself and keep the reasoning. We found no industry in Jamaica that is banned from sending data abroad, and no rule anywhere requiring a copy to stay on the island.
The eighth data protection standard, in section 31 of the Data Protection Act, 2020, is a self-assessed adequacy test copied in shape from older Commonwealth privacy laws. Adequacy is judged 'in all the circumstances of the case' against eight listed factors: the nature of the data, the country of origin, the country of final destination, the purposes and period of processing, the law in force in that country, its international obligations, any enforceable codes of conduct, and the security measures applied there. Section 31(4) then lists ten situations in which the standard does not apply at all, including the person's consent, necessity for a contract, substantial public interest, legal proceedings or legal advice, vital interests, transfers from a public register, terms approved by the Commissioner, transfers authorised by the Commissioner, and national security or crime prevention. Section 31(5)(c) lets the Minister publish an order naming countries deemed adequate; we found no such order as at 19 August 2026, and section 31(6) restricts any such order to what is needed to fulfil Jamaica's international obligations. Section 31(7) lets the Commissioner rule on a specific destination and issue a notice stating the determination. Sector check, run on 19 August 2026 across banking, payments, insurance, securities, pensions, health, telecoms, government cloud, education, gambling, mapping and defence: no localisation or mirroring requirement was found in any of them. The strongest sector overrides are supervisory, not geographic. The Bank of Jamaica's draft outsourcing standard would require that an offshore arrangement 'does not impair the ability of the licensee or the Supervisor to access, supervise, review, reconstruct' the information, and that records be producible in English on request; that draft is still out for consultation. The Financial Services Commission requires a 72-hour incident report. Government bodies must get the Attorney General's Office to approve the terms of service of any overseas cloud service. Registration particulars under section 16(2)(g) require every controller to name the countries it sends data to, so the state can see the flows even though it does not block them.
Sources
- Official sourceOffice of the Information Commissioner, JamaicaData Protection Act, 2020, section 31 (the eighth standard) and section 16(2)(g)
oic.gov.jm
“The eighth standard is that personal data shall not be transferred to a State or territory outside of Jamaica unless that State or territory ensures an adequate level of protection for the rights and freedoms of data subjects in relation to the processing of personal data.”
Link checked 19 August 2026
- Official sourceOffice of the Information Commissioner, JamaicaThe Data Protection Standards — 8. Cross-border transfers
oic.gov.jm
“In determining what is considered an 'adequate level of protection', the Commissioner would consider, among other things: the nature of the data; the State or territory of final destination; the laws of the State or Territory; the international obligations of the State or Territory; and the security measures taken by the State or territory.”
Link checked 19 August 2026
- Official sourceBank of JamaicaConsultation Paper on Standards for Outsourcing Arrangements and Third-Party Risk Management (July 2026)
boj.org.jm
Link checked 19 August 2026
Sending data out of the country
There is no form to file and no approval to wait for. You must satisfy yourself that the destination protects people's data well enough, write down why, and list that country when you register. If the destination does not pass, you can still send data using one of the exceptions in the law, such as the person's clear consent or a genuine need to perform a contract. The government has published no list of approved countries and no standard contract you can sign, so nothing is pre-approved for you.
Model: case-by-case self-assessment against a statutory adequacy test, with a broad set of statutory exceptions. There is no allowlist in force (the Minister's power under section 31(5)(c) has not been exercised as far as we could find) and no blocklist power at all. Two routes give you certainty if you want it: section 31(4)(h) covers a transfer 'made on terms (which may include contractual terms) that are of a kind approved by the Commissioner', and section 31(4)(i) covers a transfer 'authorised by the Commissioner'. We found no approved terms and no published authorisations, so both routes are theoretical today. Section 31(7) lets you ask the Commissioner to determine a destination's adequacy and obliges the Commissioner to issue a notice naming the relevant foreign supervisory authority and stating the determination. Practical consequence: the paperwork that matters is internal. Keep a written transfer assessment against the eight statutory factors, make sure your supplier contract carries the security duty in the seventh standard, and remember that section 16(2)(g) requires the destination countries to appear in your registration particulars, so the assessment and the register entry must agree.
Sources
- Official sourceOffice of the Information Commissioner, JamaicaData Protection Act, 2020, section 31(4)-(7)
oic.gov.jm
“the transfer is made on terms (which may include contractual terms) that are of a kind approved by the Commissioner as ensuring adequate safeguards for the rights and freedoms of data subjects”
Link checked 19 August 2026
- Official sourceOffice of the Information Commissioner, JamaicaData Protection (Data Controller Registration) Regulations, 2024 — Jamaica Gazette Supplement, 1 April 2024
oic.gov.jm
Link checked 19 August 2026
- Official sourceOffice of the Information Commissioner, JamaicaThe Data Protection Standards — cross-border transfers
oic.gov.jm
Link checked 19 August 2026
The regulator, and whether it actually acts
The Office of the Information Commissioner is the regulator. It exists, it has a Commissioner and a deputy, and it answers the phone, but it is not enforcing. In June 2026 the responsible Minister told Parliament in plain words that the law is not being enforced because the office was set up with a temporary structure and too few trained staff. Its own website has published no annual reports, its oversight committee page is blank, and the registration system has been switched off since March 2026 with a promise that nobody will be penalised while it is down.
Evidence of the rating, all from Jamaican government sources checked on 19 August 2026. (1) Minister without Portfolio Dr Andrew Wheatley, contributing to the 2026/27 Sectoral Debate on 2 June 2026: 'We have the law. What we have not yet done is fully enforce it.' He described the office as having 'functional areas unprovided for, staffing below the required level, and key officers without the specialised technical training that compliance oversight demands', and said enforcement provisions will be activated only once restructuring is complete. (2) The Data Protection Oversight Committee has still not been constituted. The Minister blamed the statutory requirement for a retired High Court judge and said the point 'warrants legislative review'; the Commissioner's own oversight committee page lists no members. (3) The Commissioner's Reports page returns 'No available content' — no annual report, no casework statistics, no enforcement decisions. (4) On 15 March 2026 the office told the public the registration portal was offline and that 'no liability under the Act will be imposed by the Commissioner on data controllers for processing personal data without registration during the period the platform is offline.' (5) Signs of movement, not enforcement: a Data Protection Working Group was constituted on 17 March 2026 after a public call in October 2025, and the office's full budget request for 2026/27 was approved. Note also section 72(3) of the Act: a public authority cannot be prosecuted at all, so roughly the largest holder of Jamaican personal data sits outside the penalty regime. Actual sanctions under the Act run through the criminal courts — the Parish Court and the Circuit Court — not through administrative fines by the Commissioner.
Sources
- Official sourceJamaica Information ServiceEnforcement Provisions of Data Protection Act to Be Fully Activated (4 June 2026)
jis.gov.jm
“We have the law. What we have not yet done is fully enforce it. There is a structural reason for this. The OIC was established with an interim organisational structure that was not adequate for the full scope of its regulatory mandate.”
Link checked 19 August 2026
- Official sourceOffice of the Information Commissioner, JamaicaAdvisory re Registration of Data Controllers: No Adverse Implications While System Offline (15 March 2026)
oic.gov.jm
“no liability under the Act will be imposed by the Commissioner on data controllers for processing personal data without registration during the period the platform is offline”
Link checked 19 August 2026
- Official sourceOffice of the Information Commissioner, JamaicaReports page (returns 'No available content')
oic.gov.jm
Link checked 19 August 2026
- Official sourceOffice of the Information Commissioner, JamaicaThe Data Protection Oversight Committee (page lists no members)
oic.gov.jm
Link checked 19 August 2026
- Official sourceOffice of the Information Commissioner, JamaicaStrengthening Privacy in Jamaica: OIC Launches Data Protection Working Group (17 March 2026)
oic.gov.jm
Link checked 19 August 2026
How long you must keep it — and when to delete it
Jamaica sets no single number. The ceiling is a duty to get rid of personal data once you no longer need it, and to destroy it so thoroughly that it cannot be put back together or linked to anyone. You must also write down your own minimum and maximum keeping periods. The floor comes from other laws: banks and other financial firms must keep transaction records for at least seven years, and that beats the delete duty.
Ceiling. The fifth data protection standard, in section 28 of the Act, says personal data must not be kept longer than necessary. The Data Protection (Disposal of Personal Data) Regulations, 2024 put flesh on it: a controller must regularly review all the personal data it holds, dispose of anything no longer needed, and 'develop policies, and implement procedures consistent with those policies, governing the retention and disposal of data and specifying the minimum and maximum periods for which personal data shall be kept before being disposed of'. Disposal must make the data incapable of further processing and incapable of identifying or being linked to the person, and must be permanent 'having regard to all reasonably foreseeable technological developments'. Those Regulations were made on 4 March 2024, affirmed by the Senate on 19 July 2024 and by the House on 17 June 2025, and published in the Jamaica Gazette Supplement on 17 September 2025. Floor. The Regulations themselves carve out data that must be kept under other law, under the Act's own record-keeping provisions, for a legal claim, or for a legitimate business purpose judged against sector standards. The clearest published floor is anti-money-laundering: the Bank of Jamaica's Guidance Notes, gazetted 17 June 2026, require regulated financial institutions to 'make and retain for a period of not less than seven years or such other period specified in writing by the supervisory authority a record of all complex, unusual or large business transactions'. A second, smaller clock: a controller must keep any personal data used to make a decision about a person long enough for that person to be able to ask for access to it. A third: an entry in the public register of data controllers lapses after twelve months unless the annual fee is paid. Conflict rule. The Disposal Regulations resolve it in favour of retention — the duty to dispose applies only to data that is no longer required for any of the listed reasons, one of which is retention required by law.
Sources
- Official sourceOffice of the Information Commissioner, JamaicaData Protection (Disposal of Personal Data) Regulations, 2024 — Jamaica Gazette Supplement, 17 September 2025
oic.gov.jm
“develop policies, and implement procedures consistent with those policies, governing the retention and disposal of data and specifying the minimum and maximum periods for which personal data shall be kept before being disposed of”
Link checked 19 August 2026
- Official sourceBank of JamaicaGuidance Notes on the Prevention of Money Laundering and Countering the Financing of Terrorism and Proliferation (gazetted 17 June 2026)
boj.org.jm
“make and retain for a period of not less than seven years or such other period specified in writing by the supervisory authority a record of all complex, unusual or large business transactions”
Link checked 19 August 2026
- Official sourceOffice of the Information Commissioner, JamaicaData Protection Act, 2020, sections 17(3) and 28 (fifth standard)
oic.gov.jm
Link checked 19 August 2026
If something goes wrong
You have seventy-two hours to tell the regulator, and, unusually, seventy-two hours to tell the affected people as well. Most countries give you longer for the second one. Banks must also tell the Bank of Jamaica within seventy-two hours, and insurers, pension funds and investment firms must tell the Financial Services Commission within seventy-two hours. All these clocks start when you become aware, and they run at the same time. Missing the first one is a criminal offence.
Clock one. Section 21(3) of the Act: the controller must report to the Commissioner any contravention of a data protection standard and any security breach affecting personal data 'within seventy-two hours after becoming aware'. Note the width — it is not limited to breaches, it covers any contravention of any of the eight standards. Regulation 10 of the Data Protection Regulations, 2024 prescribes Form 7 and requires further information to be reported as it emerges. Failing to report is an offence under section 21(2), punishable on summary conviction by a fine of up to two million Jamaican dollars (roughly twelve thousand United States dollars) or two years' imprisonment, or on indictment by an unlimited fine or seven years. Clock two. Regulation 10(4): notification to each affected individual 'shall be made within seventy-two hours after the data controller becomes aware'. This is the clock people miss, because in most comparable regimes notifying individuals is a 'without undue delay' duty and can be deferred. Section 21(4) sets out what the report must contain, including the categories and numbers of people and records affected and the contact details of your data protection officer. Clock three. The Bank of Jamaica's Standard of Sound Practice on the Management of Cyber Risks requires deposit-taking institutions to report incidents 'promptly to the Bank of Jamaica and appropriate authorities within 72 hours', and to inform their board within 72 hours. Clock four. The Financial Services Commission's Industry Guidance on the Management of Cyber Risks, effective 1 October 2025 for insurance, pensions and securities licensees: 'FIs must report cyber incidents and data breaches promptly to the Financial Services Commission within 72 hours', and the guidance names the Bank of Jamaica, the Jamaica Cyber Incident Response Team, the Office of the Information Commissioner, the Major Organised Crime and Anti-Corruption Agency, the Financial Investigations Division and the Jamaica Constabulary Force as other bodies that may need telling. Clock five, informal. The Government of Jamaica's own compliance framework tells public bodies to report to the Commissioner within 72 hours and to alert the Jamaica Cyber Incident Response Team and the police for cyber incidents.
Sources
- Official sourceOffice of the Information Commissioner, JamaicaData Protection Act, 2020, section 21(2)-(5)
oic.gov.jm
“The data controller shall report to the Commissioner ... any security breach in respect of the data controller's operations which affects or may affect personal data, within seventy-two hours after becoming aware of the contravention or security breach”
Link checked 19 August 2026
- Official sourceOffice of the Information Commissioner, JamaicaData Protection Regulations, 2024 (Minister's), regulation 10(4) — Jamaica Gazette Supplement, 4 March 2024
oic.gov.jm
“The notification made by a data controller pursuant to section 21(5) of the Act to a data subject whose personal data is affected by a contravention of any data protection standard or a security breach, shall be made within seventy-two hours after the data controller becomes aware”
Link checked 19 August 2026
- Official sourceFinancial Services Commission, JamaicaIndustry Guidance — Management of Cyber Risks, sections 4.6.6 and 4.10.1 (effective 1 October 2025)
fscjamaica.org
“Incidents must be reported promptly to the Financial Services Commission and appropriate authorities within 72 hours.”
Link checked 19 August 2026
- Official sourceBank of JamaicaStandard of Sound Practice — Management of Cyber Risks
boj.org.jm
Link checked 19 August 2026
What catches people out
Five things bite people here. Breaking this law is a crime, and a company can be fined up to four percent of its worldwide turnover by a court. Government bodies cannot be prosecuted at all. You must tell affected individuals within seventy-two hours, not merely as soon as reasonable. If your data protection officer lives abroad, you must give that officer a stand-in who lives in Jamaica. And you can be told to charge someone for a copy of their own data, which sounds generous but means you must have a fee process at all.
1. Criminal, not administrative. There is no power for the Commissioner to issue a fine. Contraventions go to the Parish Court or the Circuit Court. Processing in breach of a standard, or failing to report a breach, carries up to two million Jamaican dollars or two years on summary conviction, or an unlimited fine and seven years on indictment. On top of that, section 68(1) says that where a body corporate commits any offence under the Act it 'shall be liable to a fine not exceeding four percent of the annual gross worldwide turnover of that body corporate for the preceding year of assessment'. Directors and officers can be personally liable where the offence was committed with their consent or connivance. 2. Public authorities are immune from prosecution. Section 72(3): 'A public authority shall not be liable to prosecution under this Act.' The Act binds the Crown but the sanction does not reach it. If your risk analysis assumes government bodies face the same exposure as you, it is wrong. 3. The seventy-two hour clock to individuals. See question six. It is in regulation 10(4), not in the Act, so a reader of the statute alone will miss it. 4. People in Jamaica. Two separate requirements. A controller with no establishment in Jamaica must appoint a representative established in Jamaica. Separately, regulation 9(2) says that where the data protection officer resides outside Jamaica, the controller must ensure that officer 'has a representative who resides in Jamaica' and is tasked with making sure the officer's functions are carried out. So an offshore group privacy officer is not enough on its own. 5. Subject access is not free and not automatic. A person has thirty days to get their data, but the Minister's Regulations set fees, and regulation 5(4) says the controller 'is not obliged to provide information requested under section 6(2) of the Act until the applicable fees have been paid'. Public bodies may only waive the fee on hardship grounds. 6. A dormant pre-clearance regime. Section 19 lets the Minister designate categories of 'specified processing' that are particularly likely to cause substantial damage or distress. Once designated, you may not start that processing until you have filed registration particulars and either thirty days have passed or the Commissioner has issued an assessment notice. Doing it anyway is punishable by five million Jamaican dollars or five years, or ten years on indictment. No such order has been made, so the whole scheme sits idle — and can be switched on by a Gazette notice. 7. Children are anyone under eighteen, and rights are exercised by a parent or guardian with documentary proof of identity and relationship. 8. Who needs a data protection officer is broader than it looks: every public authority, anyone processing sensitive personal data or criminal conviction data, anyone processing personal data 'on a large scale', and any class the Commissioner names by Gazette notice.
Sources
- Official sourceOffice of the Information Commissioner, JamaicaData Protection Act, 2020, sections 19, 20, 21(2), 68 and 72(3)
oic.gov.jm
“where a body corporate commits an offence under this Act, the body corporate shall be liable to a fine not exceeding four percent of the annual gross worldwide turnover of that body corporate for the preceding year of assessment”
Link checked 19 August 2026
- Official sourceOffice of the Information Commissioner, JamaicaData Protection Regulations, 2024 (Minister's), regulations 5 and 9(2)
oic.gov.jm
“Where a data controller appoints a data protection officer who resides outside of Jamaica, the data controller shall ensure that the data protection officer has a representative who resides in Jamaica”
Link checked 19 August 2026
What's changing next
The main thing coming is enforcement itself. In June 2026 the responsible Minister told Parliament that the regulator's full budget was approved, a working group is running, and the oversight committee appointments are nearly done, after which the enforcement provisions will be switched on. The Bank of Jamaica is consulting until 30 October 2026 on a new outsourcing and third-party risk standard for banks. A draft national artificial intelligence policy is due by November 2026, and the Act itself falls due for its first five-yearly review from 1 December 2026.
Dated items in the next twelve months. • 30 October 2026 — the Bank of Jamaica's consultation on Standards for Outsourcing Arrangements and Third-Party Risk Management closes. It would apply to every deposit-taking institution and financial holding company, require country risk assessments for offshore arrangements, require that records be producible in English on request, and require 'timely and unrestricted' supervisory access to books, records, systems, data and personnel. It is a draft and has no legal effect yet. • November 2026 — the National Artificial Intelligence Task Force is to deliver a draft National AI Policy covering eight domains including ethics and legal frameworks, announced by the Minister on 2 June 2026. • From 1 December 2026 — section 77 of the Act requires the Act to be reviewed every five years from the first appointed day, which was 1 December 2021. The Minister has already flagged one target for that review: the requirement that the Data Protection Oversight Committee include a retired High Court judge, which he described as a bottleneck warranting legislative review. • No date — the reopening of the data controller registration portal. The regulator says the public will be told through its official channels. • Under consideration, no date — a 'data embassy', announced on 22 June 2026 as something the government is 'seriously going to start looking at', to store sovereign Jamaican data in another jurisdiction under embassy-like protection. Note the direction of travel: that is the opposite of localisation. Dormant switches — powers the government already holds that could change the picture without consultation. • Section 31(5) — the Minister may by Gazette order name the countries deemed to have adequate protection, and may prescribe what counts as substantial public interest. Never used. • Section 19 with section 74(3)(c) — the Minister may designate categories of 'specified processing' requiring a thirty-day standstill and a Commissioner assessment before processing may begin. Never used. • Section 15(2) — the Minister may exempt whole classes of processing or of controllers from the registration requirement. Used only to the extent of the classes already in the Act. • Section 20(6)(d) — the Commissioner may by Gazette notice name classes of controller that must appoint a data protection officer. • Section 33 — the Minister responsible for national security may certify personal data as exempt from provisions of the Act. • The Commissioner's March 2026 forbearance on registration is an advisory, not a legal amnesty. It can be withdrawn on the day the portal comes back, and the underlying offence in section 18 never stopped existing. • Political direction: the Minister told Parliament on 2 June 2026 that 'data sovereignty — Jamaica's right to control, govern, and benefit from the data generated within our borders — is not a technical concept. It is a national security and national development imperative.' There is no localisation rule today, but that is the language that usually precedes one.
Sources
- Official sourceJamaica Information ServiceEnforcement Provisions of Data Protection Act to Be Fully Activated (4 June 2026)
jis.gov.jm
“Data sovereignty - Jamaica's right to control, govern, and benefit from the data generated within our borders - is not a technical concept. It is a national security and national development imperative.”
Link checked 19 August 2026
- Official sourceBank of JamaicaConsultation Paper on Standards for Outsourcing Arrangements and Third-Party Risk Management (July 2026), closing 30 October 2026
boj.org.jm
Link checked 19 August 2026
- Official sourceJamaica Information ServiceAI Task Force to Develop Draft Policy By November (4 June 2026)
jis.gov.jm
Link checked 19 August 2026
- Official sourceJamaica Information ServiceGov't Exploring Data Embassy to Safeguard Digital Assets (22 June 2026)
jis.gov.jm
“This is where we can take our sovereign data and store it in a different jurisdiction... in an embassy that rivals or is similar to sovereign ground in a different country, where [it] can't be tampered with.”
Link checked 19 August 2026
- Official sourceOffice of the Information Commissioner, JamaicaData Protection Act, 2020, sections 15(2), 19, 20(6), 31(5), 33 and 77
oic.gov.jm
Link checked 19 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries3 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Standard of Sound Practice — Management of Cyber Risks
Statutory code of practice · Issued under the Banking Services Act, 2014
Banks and other deposit-taking institutions must run a cyber risk framework, do due diligence on cloud and other outside providers, and report a serious incident to the Bank of Jamaica within seventy-two hours. There is no requirement to keep the data in Jamaica.
Enforced by Bank of Jamaica
What it makes you do
- Report cyber incidents — within 72 hoursTo the Bank of Jamaica and other appropriate authorities.
- Secure the data
- Written vendor contractDue diligence on third-party and cloud providers, covering applications, data and infrastructure hosted in external data centres.
- Independent audit
Sources
- Official sourceBank of JamaicaStandard of Sound Practice — Management of Cyber Risks (final draft, 29 November 2023)
boj.org.jm
“reported promptly to the Bank of Jamaica and appropriate authorities within 72 hours”
Link checked 19 August 2026
- Official sourceBank of JamaicaConsultation Paper on Standards for Outsourcing Arrangements and Third-Party Risk Management (July 2026) — draft, consultation closes 30 October 2026
boj.org.jm
Link checked 19 August 2026
Industry Guidance — Management of Cyber Risks
Regulator guideline · Issued to licensees under the Insurance Act, the Pensions Act and the Securities Act
Insurers, pension funds and investment firms must report a cyber incident or data breach to the Financial Services Commission within seventy-two hours, and give the Commission an annual attestation on their controls. Cloud providers are expected to hold independent security assurance. There is no requirement to keep the data in Jamaica.
Enforced by Financial Services Commission
What it makes you do
- Report cyber incidents — within 72 hoursTo the Financial Services Commission, and in parallel to the Bank of Jamaica, the Jamaica Cyber Incident Response Team, the Office of the Information Commissioner, the anti-corruption agency, the Financial Investigations Division and the police as relevant.
- Secure the data
- Independent auditAnnual attestation to the Commission, alternating between self-attestation and independent attestation.
- Hold a security certificateThird-party providers expected to hold assurance such as a SOC 2 Type 2 report.
- Written vendor contract
Sources
- Official sourceFinancial Services Commission, JamaicaIndustry Guidance — Management of Cyber Risks
fscjamaica.org
“FIs must report cyber incidents and data breaches promptly to the Financial Services Commission within 72 hours along with relevant authorities”
Link checked 19 August 2026
- Official sourceFinancial Services Commission, JamaicaIndustry Guidance (Securities) — Management of Cyber Risks, date of effect 1 October 2025
fscjamaica.org
Link checked 19 August 2026
GoJ ICT Policies, Standards and Guidelines Manual — Guidelines for Cloud Computing
Government policy document · PSG Manual version 1.2, Office of the Chief Information Officer, February 2018; republished by the ICT Authority
Government ministries and agencies may use overseas cloud services, but the provider's terms of service must be cleared by the Attorney General's Office and the head of the body must approve the use in writing. There is no ban on hosting government data abroad, and no approved-country list.
Enforced by Jamaica ICT Authority
What it makes you do
- Written vendor contractTerms of service for an overseas cloud service must be approved by the Office of the Attorney General of Jamaica.
- Secure the dataSenior ICT staff must certify that security, privacy and ICT management requirements are addressed before use is approved.
- Keep records of processingThe certification must be retained with the investment documentation.
- Report cyber incidents — within 72 hoursPublic bodies report to the Information Commissioner within 72 hours and alert the national cyber incident team and police for cyber incidents.
Sources
- Official sourceJamaica ICT Authority / Office of the Chief Information OfficerGoJ ICT Policies, Standards and Guidelines Manual, Guidelines for Cloud Computing
icta.gov.jm
“For external (over-seas) Cloud Computing services that require users to agree to terms of service agreements, such agreements must be approved by the Office of the Attorney General of Jamaica”
Link checked 19 August 2026
- Official sourceJamaica ICT AuthorityGovernment of Jamaica Data Protection Act Compliance Framework, version 1.2, June 2024
icta.gov.jm
Link checked 19 August 2026
- Official sourceJamaica ICT AuthorityTechnology Codes of Practice — policies, standards, guidelines and ICT legislation
icta.gov.jm
Link checked 19 August 2026
Applies to every company4 rules
These bind you whatever business you are in, once the country's rules reach you.
The Data Protection Act, 2020
Act of parliament · Act No. 7 of 2020
Jamaica's general privacy law. It reaches foreign companies that serve or monitor people in Jamaica and makes them appoint a Jamaican representative. Data may leave the island only to countries you judge to protect it adequately, and there is no official list to lean on. Enforcement runs through the criminal courts, and a company can be fined up to four percent of worldwide turnover. Public authorities cannot be prosecuted.
Enforced by Office of the Information Commissioner — not yet operational
Transfer model: Approval each time (the list is currently empty) · Accepted routes: Official 'this country is safe' decision, Government sign-off needed, Explicit consent, Needed for a contract, Important public interest, Legal claims, Someone's life is at risk
What it makes you do
- Register or notify — from 1 December 2023Processing without being on the register is an offence. Annual renewal.
- Appoint a local representativeRequired of any controller not established in Jamaica.
- Appoint a data protection officer — applies at: Public authorities; anyone processing sensitive or criminal-conviction data; anyone processing personal data on a large scale; any class named by the Commissioner in the Gazette.
- Tell people what you do
- Get consent
- Secure the data
- Let people see their dataThirty days to respond. A fee may be charged and the controller need not respond until it is paid.
- Let people correct their data
- Let people object
- Limit automated decisions
- Report breaches to the regulator — within 72 hours
- Tell affected people — within 72 hours
- Put a transfer safeguard in place
- Delete data after a period
- Get a parent's consent for children — applies at: under 18
What it costs if you get it wrong
- Percentage of global turnover: 4% of annual gross worldwide turnoverAny offence under the Act committed by a body corporate (section 68)
- Criminal liability: JMD 2,000,000 or 2 years (summary); unlimited fine or 7 years (indictment) — about $13 thousandProcessing in breach of a data protection standard, or failing to report a breach (section 21)
- Criminal liability: JMD 2,000,000 or 6 months — about $13 thousandProcessing personal data without being registered (section 18)
- Criminal liability: JMD 5,000,000 or 5 years (summary); 10 years (indictment) — about $31 thousandCarrying on designated 'specified processing' without clearance (section 19). No designation order has been made.
- Claims by individualsCompensation for damage or distress caused by a contravention (section 69)
Sources
- Official sourceOffice of the Information Commissioner, JamaicaThe Data Protection Act, 2020 (Act No. 7 of 2020)
oic.gov.jm
Link checked 19 August 2026
- Official sourceOffice of the Information Commissioner, JamaicaOur Mandate — Appointed Day Notice of 30 November 2021 and the two-year transitional period
oic.gov.jm
“By Appointed Day Notice published in the Jamaica Gazette on 30 November 2021, Sections 2, 4, 56, 57, 60, 66, 74 and 77, and the First Schedule of the Act were also brought into operation as of 1 December 2021.”
Link checked 19 August 2026
The Data Protection Regulations, 2024 (the Minister's Regulations)
Directly binding regulation · Jamaica Gazette Supplement, Proclamations, Rules and Regulations, Vol. CXLVII No. 23A, 4 March 2024
The detailed rules under the Act. They set the breach forms, put a hard seventy-two hour deadline on telling affected individuals, require a Jamaica-resident stand-in where your data protection officer lives abroad, and let you charge a fee before answering a request for someone's own data.
Enforced by Office of the Information Commissioner — not yet operational
What it makes you do
- Report breaches to the regulator — within 72 hoursPrescribed Form 7. Further information must be reported as it emerges.
- Tell affected people — within 72 hoursRegulation 10(4). Much tighter than the international norm of 'without undue delay'.
- Appoint a data protection officerThe officer must report to senior or executive management, and may be an employee or a contractor.
- Appoint a local representativeRegulation 9(2): if the data protection officer lives outside Jamaica, that officer must have a Jamaica-resident representative.
- Let people see their data — 1 monthThirty days. Fees are set in the Second Schedule and the controller need not answer until they are paid.
Sources
- Official sourceOffice of the Information Commissioner, JamaicaThe Data Protection Regulations, 2024 (Minister's) — Jamaica Gazette Supplement, 4 March 2024
oic.gov.jm
“These Regulations may be cited as the Data Protection Regulations, 2024, and shall come into operation on the 1st day of March, 2024.”
Link checked 19 August 2026
The Data Protection (Data Controller Registration) Regulations, 2024
Directly binding regulation · Jamaica Gazette Supplement, Proclamations, Rules and Regulations, 1 April 2024
Every data controller must register with the regulator, pay a fee, renew each year by the first of December, and name the countries it sends data to. The rule is still law, but the registration system has been switched off since March 2026 and the regulator has publicly promised not to impose liability while it is down. It can be switched back on without notice.
Enforced by Office of the Information Commissioner — not yet operational
What it makes you do
- Register or notify — 1 yearFirst registration then annual renewal on or before 1 December each year. Changes to the particulars must be notified within fourteen days.
- Keep records of processingRegistration particulars must name every country the controller sends personal data to, directly or indirectly.
What it costs if you get it wrong
- Criminal liability: JMD 2,000,000 or 6 months — about $13 thousandProcessing personal data without registering (Act, section 18(1))
Sources
- Official sourceOffice of the Information Commissioner, JamaicaThe Data Protection (Data Controller Registration) Regulations, 2024, regulation 3(3) and Schedule of fees
oic.gov.jm
“thereafter, annually for so long as the entity concerned remains a data controller, on or before the 1st day of December in each year”
Link checked 19 August 2026
- Official sourceOffice of the Information Commissioner, JamaicaAdvisory re Registration of Data Controllers: No Adverse Implications While System Offline (15 March 2026)
oic.gov.jm
Link checked 19 August 2026
- Official sourceOffice of the Information Commissioner, JamaicaOffice of the Information Commissioner homepage — registration temporarily paused (checked 19 August 2026)
oic.gov.jm
Link checked 19 August 2026
- Official sourceOffice of the Information Commissioner, JamaicaRegister of Data Controllers for the 2023-2024 Registration Year Now Live (11 October 2024)
oic.gov.jm
Link checked 19 August 2026
The Data Protection (Disposal of Personal Data) Regulations, 2024
Directly binding regulation · Jamaica Gazette Supplement, Proclamations, Rules and Regulations, Vol. CXLVIII No. 339, 17 September 2025
The delete rule. You must regularly review all the personal data you hold, get rid of what you no longer need, and destroy it in a way that cannot be undone even by future technology. You must also write down your own minimum and maximum keeping periods. Data you are required to keep by other laws is carved out.
Enforced by Office of the Information Commissioner — not yet operational
What it makes you do
- Delete data after a periodRegular review of everything held; dispose of anything no longer needed.
- Keep records of processingA written retention and disposal policy stating minimum and maximum keeping periods is mandatory.
- Secure the dataDisposal must be permanent and must leave the data incapable of identifying or being linked to the person.
Sources
- Official sourceOffice of the Information Commissioner, JamaicaThe Data Protection (Disposal of Personal Data) Regulations, 2024 — Jamaica Gazette Supplement, 17 September 2025
oic.gov.jm
“in a manner that ensures the permanence of the disposal, having regard to all reasonably foreseeable technological developments”
Link checked 19 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
That the whole of the Data Protection Act, 2020 is in force, rather than only part of it
The regulator's own mandate page says the Appointed Day Notice gazetted on 30 November 2021 brought into operation sections 2, 4, 56, 57, 60, 66, 74 and 77, the First Schedule and 'certain powers, duties and responsibilities', plus the transitional section. We could not retrieve the Appointed Day Notice itself or any later commencement notice covering the registration, standards and offence provisions. Everyone concerned, including the regulator and the Minister, behaves as though those provisions are operative, so we have recorded the Act as in force — but if you need certainty on a specific section, ask the Commissioner in writing.
That no Ministerial order has been made naming countries with adequate protection under section 31(5)(c), and none designating 'specified processing' under section 19
This is a negative. We searched the regulator's legislation pages and the government sites we could reach on 19 August 2026 and found no such order. The Jamaica Gazette is not fully searchable online and the Ministry of Justice laws portal could not be reached because of a certificate problem, so we cannot prove the absence.
That the Office of the Information Commissioner has published no annual report and issued no enforcement decision
The regulator's Reports page returns 'No available content' and none of its six press releases concerns an enforcement action. An annual report may have been tabled in Parliament without being posted online. Treat this as 'nothing published', not as 'nothing exists'.
Whether the data controller registration portal has reopened between 15 March 2026 and today
The regulator's homepage on 19 August 2026 still says registration is temporarily paused, and no press release announcing reopening has been published. But the advisory promises notice through the office's channels rather than a dated commitment, so this can change at any time.
Sector rules for health, education, telecoms, gambling, mapping and defence
We searched the Ministry of Health and Wellness, the Office of Utilities Regulation, the Betting Gaming and Lotteries Commission and the ICT Authority on 19 August 2026 and found no data localisation or cross-border rule in any of them. Coverage was thinner than for finance: the Ministry of Health site blocked automated retrieval, the Betting Gaming and Lotteries Commission site was intermittently unreachable, and the national cyber incident response team's site had an expired security certificate and could not be checked. Treat the absence of a telecoms or health rule as unverified rather than established.
The United States dollar approximations for Jamaican dollar penalties and fees
Converted at roughly one hundred and sixty Jamaican dollars to the United States dollar. We could not read a live rate off the central bank's page, so treat every dollar figure as indicative and use the Jamaican figure for anything that matters.
Whether the Bank of Jamaica's draft outsourcing standard will contain any data location requirement in its final form
The July 2026 text is a consultation draft and closes on 30 October 2026. As drafted it requires supervisory access and country risk assessment rather than local storage, but drafts change. It has no legal effect today and must not be planned around as binding.
Freshness and refresh
Freshness
Checked today — on 19 August 2026.
Re-checked every 60 days. Next check due 18 October 2026.
Put this next to another country
Jamaica versus
Compare