Skip to the content
Global Data RulesData governance rules, country by country

Jamaica

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 19 August 2026.

If you collect data about people in Jamaica — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Yes, with paperworkWork: HighEnforcement: Dormant

You can send personal data out of Jamaica. It can only go to places that protect it well enough. You decide that yourself. The government has never published a list of approved countries. The written rules are heavy. You must register. You may need a data protection officer. Breaking the rules is a crime, not just a fine. Almost none of this is enforced today.

Data governance in Jamaica

The eight things that decide how you handle data about people in Jamaica. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. The law applies even if you have no office in Jamaica. It covers you if you offer products or services to people in Jamaica. It also covers you if you track what they do in Jamaica, or use equipment in Jamaica to handle the data. There is no size or revenue cut-off. A one-person business is covered the same as a bank. If you have no office or business base in Jamaica, you must appoint a representative who is based there.

What you have to do here:
Appoint a representative

Where the data is allowed to live

Yes, with conditions. Personal data can only go to a country that protects people's data well enough. The government has not published a list of which countries pass. So you make that judgement yourself and write down your reasoning. We found no industry that is banned from sending data abroad. We found no rule requiring a copy to stay on the island.

Ways to send data out:
Official 'this country is safe' decision

What to do: Get the paperwork for one of the routes below signed before any data leaves Jamaica.

Sending data out of the country

There is no form to file and no approval to wait for. Decide for yourself that the destination protects people's data well enough. Write down why. List that country when you register. If the destination does not pass, you can still send data under one of the exceptions in the law. Examples are the person's clear consent, or a real need to perform a contract. The government has published no list of approved countries and no standard contract you can sign. Nothing is pre-approved for you.

What you have to do here:
Put a transfer safeguard in place
Ways to send data out:
Official 'this country is safe' decision · Government sign-off needed · Explicit consent · Needed for a contract · Important public interest · Legal claims · To save someone’s life

What to do: Budget months, not weeks: government sign-off has to be in hand before the data moves.

The regulator, and whether it actually acts

The Office of the Information Commissioner is the regulator. It exists, it has a Commissioner and a deputy, and it answers the phone. But it is not enforcing the law. In June 2026 the responsible Minister told Parliament that the law is not being enforced. He said the office was set up with a temporary structure and too few trained staff. Its website has published no annual reports. Its oversight committee page is blank. The registration system has been switched off since March 2026, with a promise that nobody will be penalised while it is down.

How long you must keep it — and when to delete it

Jamaica sets no single number. You must get rid of personal data once you no longer need it. You must destroy it so thoroughly that it cannot be put back together or linked to anyone. You must also write down your own minimum and maximum keeping periods. Other laws set the floor. Banks and other financial firms must keep transaction records for at least seven years, and that beats the duty to delete.

What you have to do here:
Delete data after a period · Keep data for a minimum period · Keep records of how you use data

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

You have seventy-two hours to tell the regulator. You also have seventy-two hours to tell the people affected. Most countries give you longer for the second one. Banks must also tell the Bank of Jamaica within seventy-two hours. Insurers, pension funds and investment firms must tell the Financial Services Commission within seventy-two hours. All these clocks start when you find out, and they run at the same time. Missing the first one is a crime.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five things catch people out. Breaking this law is a crime, and a court can fine a company up to four percent of its worldwide turnover. Government bodies cannot be prosecuted at all. You must tell affected people within seventy-two hours, not just as soon as you reasonably can. If your data protection officer lives abroad, you must give that officer a stand-in who lives in Jamaica. And someone asking for a copy of their own data can be charged a fee, so you need a fee process at all.

What you have to do here:
Appoint a data protection officer · Appoint a representative · Get a parent's consent for children · Let people see their data
What it costs if you get it wrong:
Criminal liability · Percentage of global turnover

What's changing next

The main thing coming is enforcement itself. In June 2026 the responsible Minister told Parliament that the regulator's full budget was approved. A working group is running, and the oversight committee appointments are nearly done. After that the enforcement powers will be switched on. The Bank of Jamaica is consulting until 30 October 2026 on a new outsourcing and third-party risk standard for banks. A draft national artificial intelligence policy is due by November 2026. The Act itself falls due for its first five-yearly review from 1 December 2026.

What to do: Diarise 30 October 2026 — that is the date this changes.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries3 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Banking

Cloud and outsourcing rules

Official name: Standard of Sound Practice — Management of Cyber Risks · Issued under the Banking Services Act, 2014 · Statutory code of practice

In forceYes, with paperwork

Banks and other deposit-taking institutions must run a cyber risk programme. They must check cloud and other outside providers carefully. They must report a serious incident to the Bank of Jamaica within seventy-two hours. There is no requirement to keep the data in Jamaica.

In force since 29 November 2023

Enforced by Bank of Jamaica

Finance

Cloud and outsourcing rules (Finance)

Official name: Industry Guidance — Management of Cyber Risks · Issued to licensees under the Insurance Act, the Pensions Act and the Securities Act · Regulator guideline

In forceYes, with paperwork

Insurers, pension funds and investment firms must report a cyber incident or data breach to the Financial Services Commission within seventy-two hours. They must also give the Commission a yearly statement about their controls. Cloud providers are expected to hold independent security assurance. There is no requirement to keep the data in Jamaica.

In force since 1 October 2025

Enforced by Financial Services Commission

Government

Cloud and outsourcing rules (Government)

Official name: GoJ ICT Policies, Standards and Guidelines Manual — Guidelines for Cloud Computing · PSG Manual version 1.2, Office of the Chief Information Officer, February 2018; republished by the ICT Authority · Government policy document

In forceYes, with paperwork

Government ministries and agencies may use overseas cloud services. The provider's terms of service must first be cleared by the Attorney General's Office. The head of the body must also approve the use in writing. There is no ban on hosting government data abroad, and no list of approved countries.

In force since 26 February 2018

Enforced by Jamaica ICT Authority

Not fully verified — see “What we're not sure about” below.

Applies to every company3 rules

These bind you whatever business you are in, once the country's rules reach you.

General data protection law

Official name: The Data Protection Act, 2020 · Act No. 7 of 2020 · Act of parliament

In forceYes, with paperwork

Jamaica's general privacy law. It reaches foreign companies that serve or monitor people in Jamaica, and it makes them appoint a Jamaican representative. Data may leave the island only to countries you judge protect it well enough. There is no official list to rely on. Enforcement runs through the criminal courts. A company can be fined up to four percent of worldwide turnover. Public authorities cannot be prosecuted.

In force since 1 December 2021Enforced from 1 December 2023

Enforced by Office of the Information Commissioner — not yet operational

How this country controls where data goes: Approval each time (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision, Government sign-off needed, Explicit consent, Needed for a contract, Important public interest, Legal claims, To save someone’s life

Breach reporting rules

Official name: The Data Protection Regulations, 2024 (the Minister's Regulations) · Jamaica Gazette Supplement, Proclamations, Rules and Regulations, Vol. CXLVII No. 23A, 4 March 2024 · Directly binding regulation

In forceYes, with paperwork

The detailed rules under the Act. They set the breach forms. They give you a firm seventy-two hour deadline to tell affected individuals. They require a Jamaica-based stand-in if your data protection officer lives abroad. They let you charge a fee before answering a request for someone's own data.

In force since 1 March 2024

Enforced by Office of the Information Commissioner — not yet operational

General data protection law (2025)

Official name: The Data Protection (Disposal of Personal Data) Regulations, 2024 · Jamaica Gazette Supplement, Proclamations, Rules and Regulations, Vol. CXLVIII No. 339, 17 September 2025 · Directly binding regulation

In forceYes, with paperwork

The delete rule. You must regularly review all the personal data you hold. You must get rid of what you no longer need. You must destroy it in a way that cannot be undone, even by future technology. You must also write down your own minimum and maximum keeping periods. Data that other laws require you to keep is excluded.

In force since 17 September 2025

Enforced by Office of the Information Commissioner — not yet operational

On the books, but not enforceable1 rule

These rules are still printed in the law, but a court struck them down or the regulator has said it will not apply them. You do not have to comply today. They are here because text nobody deleted can come back without warning.

General data protection law (not enforced)

Official name: The Data Protection (Data Controller Registration) Regulations, 2024 · Jamaica Gazette Supplement, Proclamations, Rules and Regulations, 1 April 2024 · Directly binding regulation

SuspendedYes, with paperwork

Everyone who handles personal data must register with the regulator and pay a fee. You must renew each year by the first of December. You must also name the countries you send data to. The rule is still law. But the registration system has been switched off since March 2026, and the regulator has publicly promised not to impose liability while it is down. It can be switched back on without notice.

In force since 1 April 2024Enforced from 1 June 2024

Enforced by Office of the Information Commissioner — not yet operational

Who you would hear from

  • Office of the Information Commissioner (OIC)

    The national data protection regulator for all sectors under the Data Protection Act, 2020

    Staffed but not enforcing. Celia Barclay has been Information Commissioner since 1 December 2021. Ronald Frue is Deputy. The office answers complaints, runs a breach reporting form and keeps a public register of roughly five hundred organisations. But on 2 June 2026 the responsible Minister told Parliament the law is not being enforced. He said the office has a temporary structure, too few staff and key officers without training. The Data Protection Oversight Committee required by law has still not been appointed. The Reports page carries no annual report and no enforcement statistics. The registration portal has been offline since March 2026, with an express promise of no liability meanwhile. We found no published fine, prosecution or enforcement notice as at 19 August 2026.

  • Bank of Jamaica (BOJ)

    Banks, other deposit-taking institutions, financial holding companies, payment service providers, credit bureaux and money services

    Working and actively issuing standards. It published new anti-money-laundering guidance notes, gazetted 17 June 2026. It published a corporate governance standard in November 2025. It opened an outsourcing and third-party risk consultation in July 2026. That is an .org.jm address, but it is the official website of the central bank.

  • Financial Services Commission (FSC)

    Insurance, pensions, securities and unit trusts

    Working. It issued cyber risk guidance that took effect on 1 October 2025, and firms are expected to follow it. It requires incident reporting within 72 hours and a yearly statement on controls. The Commission itself was hit by a cyber attack in September 2023 and said so publicly. Its official website is fscjamaica.org, not a .gov.jm address.

  • Information and Communications Technology Authority (JAMICTA)

    Government ICT policy, standards and shared services for ministries, departments and agencies

    Set up under the Information and Communications Technology Authority Act, 2019. It marked its first anniversary in 2026 and launched the Jamaica Data Exchange Platform. It publishes the government's technology policies, standards and guidelines, and the Government of Jamaica Data Protection Act Compliance Framework. It sets policy for public bodies. It is not a data protection regulator and cannot fine anyone.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • That the whole of the Data Protection Act, 2020 is in force, rather than only part of it

    We could not confirm the exact date each part of the Act came into force. The regulator's mandate page names the sections that started on 1 December 2021. We could not see the commencement notices covering the registration, standards and offence sections. The regulator and the Minister both act as though those sections are in force, so we have recorded the Act as in force. If you need certainty about a specific section, ask the Commissioner in writing.

  • That no Ministerial order has been made naming countries with adequate protection under section 31(5)(c), and none designating 'specified processing' under section 19

    We found no such order. We checked the regulator's legislation pages and the government sites we could reach on 19 August 2026. We cannot prove that no order exists, because the Jamaica Gazette is not fully searchable online. If this matters to you, ask the Commissioner before you rely on it.

  • That the Office of the Information Commissioner has published no annual report and issued no enforcement decision

    The regulator's Reports page returns 'No available content', and none of its six press releases concerns an enforcement action. An annual report may have been given to Parliament without being posted online. So treat this as nothing published, rather than nothing happening. Ask the office directly if it matters.

  • Whether the data controller registration portal has reopened between 15 March 2026 and today

    The regulator's homepage on 19 August 2026 still says registration is temporarily paused, and no press release announcing a reopening has appeared. The advisory promises notice through the office's own channels but gives no date. Check the regulator's website before you rely on the pause.

  • Sector rules for health, education, telecoms, gambling, mapping and defence

    We found no rule in health, education, telecoms, gambling, mapping or defence that requires data to stay in Jamaica or limits sending it abroad. We could not confirm that against every regulator, because several of these government sites were unreachable. Coverage here is thinner than for finance. If you work in health or telecoms, check with your regulator before you rely on this.

  • The United States dollar approximations for Jamaican dollar penalties and fees

    We converted at roughly one hundred and sixty Jamaican dollars to the United States dollar. We could not read a live rate from the central bank. Treat every United States dollar figure here as rough, and use the Jamaican dollar figure for anything that matters.

  • Whether the Bank of Jamaica's draft outsourcing standard will contain any data location requirement in its final form

    The July 2026 text is a draft, and the consultation closes on 30 October 2026. As drafted it asks for supervisory access and a country risk assessment, not local storage. Drafts change. It has no legal effect today, so do not plan around it as binding.

Freshness and refresh

Freshness

Checked about 2 months ago, on 19 August 2026.

Re-checked every 60 days. Next check due 18 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.