Jamaica
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 19 August 2026.
If you collect data about people in Jamaica — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
You can send personal data out of Jamaica. It can only go to places that protect it well enough. You decide that yourself. The government has never published a list of approved countries. The written rules are heavy. You must register. You may need a data protection officer. Breaking the rules is a crime, not just a fine. Almost none of this is enforced today.
Data governance in Jamaica
The eight things that decide how you handle data about people in Jamaica. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. The law applies even if you have no office in Jamaica. It covers you if you offer products or services to people in Jamaica. It also covers you if you track what they do in Jamaica, or use equipment in Jamaica to handle the data. There is no size or revenue cut-off. A one-person business is covered the same as a bank. If you have no office or business base in Jamaica, you must appoint a representative who is based there.
- What you have to do here:
- Appoint a representative
Section 3(1) of the Data Protection Act, 2020 covers you if your company is based in Jamaica. It also covers you if you are not based in Jamaica but do one of two things. First, you use equipment in Jamaica for something other than just passing data through. Second, you handle data about someone who is in Jamaica. That applies if you offer them products or services, paid or free. It also applies if you watch what they do in Jamaica. Section 3(2) says that in the second case you must appoint a representative based in Jamaica. Section 3(3) says you count as based in Jamaica if you are a Jamaican company, a Jamaican partnership, or someone who normally lives there. You also count if you keep an office, branch, agency or regular practice in Jamaica. The Act sets no size or revenue threshold anywhere.
Sources
- Official sourceOffice of the Information Commissioner, JamaicaData Protection Act, 2020 (Act No. 7 of 2020), section 3
oic.gov.jm
“A data controller falling within subsection (1)(b) shall appoint for the purposes of this Act a representative established in Jamaica.”
Link checked 19 August 2026
Where the data is allowed to live
Yes, with conditions. Personal data can only go to a country that protects people's data well enough. The government has not published a list of which countries pass. So you make that judgement yourself and write down your reasoning. We found no industry that is banned from sending data abroad. We found no rule requiring a copy to stay on the island.
- Ways to send data out:
- Official 'this country is safe' decision
The rule is the eighth data protection standard, in section 31 of the Data Protection Act, 2020. You judge for yourself whether the destination protects data well enough. Older Commonwealth privacy laws use the same test. You must weigh eight things, looking at all the circumstances of the case. The type of data. Where it came from. Where it finally ends up. Why it is being used, and for how long. The law in force in that country. That country's international duties. Any binding codes of conduct. And the security measures used there. Section 31(4) lists ten situations where the test does not apply at all. They include the person's consent, a need to perform a contract, and substantial public interest. Also legal proceedings or legal advice, vital interests, and data taken from a public register. Also terms approved by the Commissioner, a transfer the Commissioner has authorised, and national security or crime prevention. Section 31(5)(c) lets the Minister publish an order naming countries treated as safe enough. We found no such order as at 19 August 2026. Section 31(6) limits any such order to what Jamaica needs to meet its international duties. Section 31(7) lets the Commissioner decide on a specific destination and issue a notice saying so. We checked twelve sectors on 19 August 2026: banking, payments, insurance, securities, pensions, health, telecoms, government cloud, education, gambling, mapping and defence. None of them requires data to stay in Jamaica or to be copied there. The strongest sector rules are about supervision, not location. The Bank of Jamaica's draft outsourcing standard would require that an offshore arrangement 'does not impair the ability of the licensee or the Supervisor to access, supervise, review, reconstruct' the information. It would also require records to be produced in English on request. That draft is still out for consultation. The Financial Services Commission requires a 72-hour incident report. Government bodies must get the Attorney General's Office to approve the terms of service of any overseas cloud service. Section 16(2)(g) makes you name the countries you send data to when you register. So the state can see the flows even though it does not block them.
Sources
- Official sourceOffice of the Information Commissioner, JamaicaData Protection Act, 2020, section 31 (the eighth standard) and section 16(2)(g)
oic.gov.jm
“The eighth standard is that personal data shall not be transferred to a State or territory outside of Jamaica unless that State or territory ensures an adequate level of protection for the rights and freedoms of data subjects in relation to the processing of personal data.”
Link checked 19 August 2026
- Official sourceOffice of the Information Commissioner, JamaicaThe Data Protection Standards — 8. Cross-border transfers
oic.gov.jm
“In determining what is considered an 'adequate level of protection', the Commissioner would consider, among other things: the nature of the data; the State or territory of final destination; the laws of the State or Territory; the international obligations of the State or Territory; and the security measures taken by the State or territory.”
Link checked 19 August 2026
- Official sourceBank of JamaicaConsultation Paper on Standards for Outsourcing Arrangements and Third-Party Risk Management (July 2026)
boj.org.jm
Link checked 19 August 2026
What to do: Get the paperwork for one of the routes below signed before any data leaves Jamaica.
Sending data out of the country
There is no form to file and no approval to wait for. Decide for yourself that the destination protects people's data well enough. Write down why. List that country when you register. If the destination does not pass, you can still send data under one of the exceptions in the law. Examples are the person's clear consent, or a real need to perform a contract. The government has published no list of approved countries and no standard contract you can sign. Nothing is pre-approved for you.
- What you have to do here:
- Put a transfer safeguard in place
- Ways to send data out:
- Official 'this country is safe' decision · Government sign-off needed · Explicit consent · Needed for a contract · Important public interest · Legal claims · To save someone’s life
You judge each destination yourself against the test in the law. There is no government permit. There is no published list of approved countries. The Minister can name safe countries under section 31(5)(c) but has not done so, as far as we could find. There is no power to ban countries at all. Two routes would give you certainty if they were live. Section 31(4)(h) covers a transfer 'made on terms (which may include contractual terms) that are of a kind approved by the Commissioner'. Section 31(4)(i) covers a transfer 'authorised by the Commissioner'. We found no approved terms and no published authorisations, so neither route works today. Section 31(7) lets you ask the Commissioner to decide whether a destination protects data well enough. The Commissioner must then issue a notice naming the relevant foreign regulator and stating the decision. So the paperwork that matters is your own. Keep a written assessment of each destination against the eight factors in the law. Make sure your supplier contract carries the security duty in the seventh standard. Section 16(2)(g) makes you list your destination countries when you register, so your assessment and your register entry must match.
Sources
- Official sourceOffice of the Information Commissioner, JamaicaData Protection Act, 2020, section 31(4)-(7)
oic.gov.jm
“the transfer is made on terms (which may include contractual terms) that are of a kind approved by the Commissioner as ensuring adequate safeguards for the rights and freedoms of data subjects”
Link checked 19 August 2026
- Official sourceOffice of the Information Commissioner, JamaicaData Protection (Data Controller Registration) Regulations, 2024 — Jamaica Gazette Supplement, 1 April 2024
oic.gov.jm
Link checked 19 August 2026
- Official sourceOffice of the Information Commissioner, JamaicaThe Data Protection Standards — cross-border transfers
oic.gov.jm
Link checked 19 August 2026
What to do: Budget months, not weeks: government sign-off has to be in hand before the data moves.
The regulator, and whether it actually acts
The Office of the Information Commissioner is the regulator. It exists, it has a Commissioner and a deputy, and it answers the phone. But it is not enforcing the law. In June 2026 the responsible Minister told Parliament that the law is not being enforced. He said the office was set up with a temporary structure and too few trained staff. Its website has published no annual reports. Its oversight committee page is blank. The registration system has been switched off since March 2026, with a promise that nobody will be penalised while it is down.
Here is the evidence for that rating. All of it comes from Jamaican government sources checked on 19 August 2026. 1. Minister without Portfolio Dr Andrew Wheatley spoke in Parliament on 2 June 2026. He said: 'We have the law. What we have not yet done is fully enforce it.' He described the office as having 'functional areas unprovided for, staffing below the required level, and key officers without the specialised technical training that compliance oversight demands'. He said the enforcement powers will be switched on only once the restructuring is finished. 2. The Data Protection Oversight Committee has still not been set up. The Minister blamed the legal requirement for a retired High Court judge, and said the point 'warrants legislative review'. The Commissioner's own oversight committee page lists no members. 3. The Commissioner's Reports page returns 'No available content'. There is no annual report, no casework statistics and no enforcement decisions. 4. On 15 March 2026 the office told the public that the registration portal was offline. It promised that it would not hold anyone liable for handling personal data without being registered while the portal is down. 5. There are signs of movement, but not of enforcement. A Data Protection Working Group was set up on 17 March 2026, after a public call in October 2025. The office's full budget request for 2026/27 was approved. Note section 72(3) of the Act as well. A public authority cannot be prosecuted at all. So the largest holder of Jamaican personal data faces no penalty. Real punishment under the Act runs through the criminal courts, the Parish Court and the Circuit Court. The Commissioner cannot issue fines.
Sources
- Official sourceJamaica Information ServiceEnforcement Provisions of Data Protection Act to Be Fully Activated (4 June 2026)
jis.gov.jm
“We have the law. What we have not yet done is fully enforce it. There is a structural reason for this. The OIC was established with an interim organisational structure that was not adequate for the full scope of its regulatory mandate.”
Link checked 19 August 2026
- Official sourceOffice of the Information Commissioner, JamaicaAdvisory re Registration of Data Controllers: No Adverse Implications While System Offline (15 March 2026)
oic.gov.jm
“no liability under the Act will be imposed by the Commissioner on data controllers for processing personal data without registration during the period the platform is offline”
Link checked 19 August 2026
- Official sourceOffice of the Information Commissioner, JamaicaReports page (returns 'No available content')
oic.gov.jm
Link checked 19 August 2026
- Official sourceOffice of the Information Commissioner, JamaicaThe Data Protection Oversight Committee (page lists no members)
oic.gov.jm
Link checked 19 August 2026
- Official sourceOffice of the Information Commissioner, JamaicaStrengthening Privacy in Jamaica: OIC Launches Data Protection Working Group (17 March 2026)
oic.gov.jm
Link checked 19 August 2026
How long you must keep it — and when to delete it
Jamaica sets no single number. You must get rid of personal data once you no longer need it. You must destroy it so thoroughly that it cannot be put back together or linked to anyone. You must also write down your own minimum and maximum keeping periods. Other laws set the floor. Banks and other financial firms must keep transaction records for at least seven years, and that beats the duty to delete.
- What you have to do here:
- Delete data after a period · Keep data for a minimum period · Keep records of how you use data
How long you may keep data. The fifth data protection standard, in section 28 of the Act, says you must not keep personal data longer than you need it. The Data Protection (Disposal of Personal Data) Regulations, 2024 add the detail. You must regularly review all the personal data you hold. You must get rid of anything you no longer need. You must also 'develop policies, and implement procedures consistent with those policies, governing the retention and disposal of data and specifying the minimum and maximum periods for which personal data shall be kept before being disposed of'. Once you dispose of data it must be unusable, and it must no longer identify the person or be linkable to them. The destruction must be permanent 'having regard to all reasonably foreseeable technological developments'. These rules were made on 4 March 2024. The Senate approved them on 19 July 2024 and the House on 17 June 2025. They were published in the Jamaica Gazette Supplement on 17 September 2025. How long you must keep data. The same rules leave out data you have to keep for other reasons. Those are another law, the Act's own record-keeping duties, a legal claim, or a real business purpose measured against your industry's standards. The clearest published minimum is anti-money-laundering. The Bank of Jamaica's Guidance Notes, gazetted 17 June 2026, require regulated financial institutions to 'make and retain for a period of not less than seven years or such other period specified in writing by the supervisory authority a record of all complex, unusual or large business transactions'. There is a second, smaller clock. Did you use someone's personal data to make a decision about them? Keep it long enough for them to ask to see it. There is a third. Your entry on the public register lapses after twelve months unless you pay the annual fee. Which rule wins. Keeping the data wins. The duty to dispose of data only applies to data you no longer need for any of the listed reasons. One of those reasons is that a law requires you to keep it.
Sources
- Official sourceOffice of the Information Commissioner, JamaicaData Protection (Disposal of Personal Data) Regulations, 2024 — Jamaica Gazette Supplement, 17 September 2025
oic.gov.jm
“develop policies, and implement procedures consistent with those policies, governing the retention and disposal of data and specifying the minimum and maximum periods for which personal data shall be kept before being disposed of”
Link checked 19 August 2026
- Official sourceBank of JamaicaGuidance Notes on the Prevention of Money Laundering and Countering the Financing of Terrorism and Proliferation (gazetted 17 June 2026)
boj.org.jm
“make and retain for a period of not less than seven years or such other period specified in writing by the supervisory authority a record of all complex, unusual or large business transactions”
Link checked 19 August 2026
- Official sourceOffice of the Information Commissioner, JamaicaData Protection Act, 2020, sections 17(3) and 28 (fifth standard)
oic.gov.jm
Link checked 19 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
If something goes wrong
You have seventy-two hours to tell the regulator. You also have seventy-two hours to tell the people affected. Most countries give you longer for the second one. Banks must also tell the Bank of Jamaica within seventy-two hours. Insurers, pension funds and investment firms must tell the Financial Services Commission within seventy-two hours. All these clocks start when you find out, and they run at the same time. Missing the first one is a crime.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents
Clock one. Section 21(3) of the Act. You must report to the Commissioner within seventy-two hours of finding out. This covers any security breach affecting personal data. It also covers any breach of any of the eight data protection standards, not just security incidents. Regulation 10 of the Data Protection Regulations, 2024 sets out Form 7, and you must send more information as it emerges. Not reporting is a crime under section 21(2). A magistrate can fine you up to two million Jamaican dollars (roughly twelve thousand United States dollars) or jail you for two years. A higher court can impose an unlimited fine or seven years. Clock two. Regulation 10(4). You must tell each affected person within seventy-two hours of finding out. This one is easy to miss, because it sits in the regulations and not in the Act itself. Section 21(4) lists what your report must contain. That includes the types and numbers of people and records affected, and the contact details of your data protection officer. Clock three. The Bank of Jamaica's Standard of Sound Practice on the Management of Cyber Risks. Deposit-taking institutions must report incidents 'promptly to the Bank of Jamaica and appropriate authorities within 72 hours'. They must also tell their own board within 72 hours. Clock four. The Financial Services Commission's Industry Guidance on the Management of Cyber Risks. It took effect on 1 October 2025 for insurance, pensions and securities licensees. It says 'FIs must report cyber incidents and data breaches promptly to the Financial Services Commission within 72 hours'. It also names other bodies you may need to tell. Those are the Bank of Jamaica, the Jamaica Cyber Incident Response Team and the Office of the Information Commissioner. Also the Major Organised Crime and Anti-Corruption Agency, the Financial Investigations Division and the Jamaica Constabulary Force. Clock five, informal. The Government of Jamaica's own compliance guidance tells public bodies to report to the Commissioner within 72 hours. It also tells them to alert the Jamaica Cyber Incident Response Team and the police for cyber incidents.
Sources
- Official sourceOffice of the Information Commissioner, JamaicaData Protection Act, 2020, section 21(2)-(5)
oic.gov.jm
“The data controller shall report to the Commissioner ... any security breach in respect of the data controller's operations which affects or may affect personal data, within seventy-two hours after becoming aware of the contravention or security breach”
Link checked 19 August 2026
- Official sourceOffice of the Information Commissioner, JamaicaData Protection Regulations, 2024 (Minister's), regulation 10(4) — Jamaica Gazette Supplement, 4 March 2024
oic.gov.jm
“The notification made by a data controller pursuant to section 21(5) of the Act to a data subject whose personal data is affected by a contravention of any data protection standard or a security breach, shall be made within seventy-two hours after the data controller becomes aware”
Link checked 19 August 2026
- Official sourceFinancial Services Commission, JamaicaIndustry Guidance — Management of Cyber Risks, sections 4.6.6 and 4.10.1 (effective 1 October 2025)
fscjamaica.org
“Incidents must be reported promptly to the Financial Services Commission and appropriate authorities within 72 hours.”
Link checked 19 August 2026
- Official sourceBank of JamaicaStandard of Sound Practice — Management of Cyber Risks
boj.org.jm
Link checked 19 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
Five things catch people out. Breaking this law is a crime, and a court can fine a company up to four percent of its worldwide turnover. Government bodies cannot be prosecuted at all. You must tell affected people within seventy-two hours, not just as soon as you reasonably can. If your data protection officer lives abroad, you must give that officer a stand-in who lives in Jamaica. And someone asking for a copy of their own data can be charged a fee, so you need a fee process at all.
- What you have to do here:
- Appoint a data protection officer · Appoint a representative · Get a parent's consent for children · Let people see their data
- What it costs if you get it wrong:
- Criminal liability · Percentage of global turnover
1. Crimes, not fines from the regulator. The Commissioner has no power to fine you. Cases go to the Parish Court or the Circuit Court. Using data in breach of a standard carries up to two million Jamaican dollars or two years in a magistrate's court. So does failing to report a breach. In a higher court it carries an unlimited fine and seven years. On top of that, section 68(1) says a company that commits any offence under the Act 'shall be liable to a fine not exceeding four percent of the annual gross worldwide turnover of that body corporate for the preceding year of assessment'. Directors and officers can be personally liable where the offence was committed with their consent or connivance. 2. Public authorities cannot be prosecuted. Section 72(3) says: 'A public authority shall not be liable to prosecution under this Act.' The Act binds the Crown, but the punishment does not reach it. If your risk analysis assumes government bodies face the same exposure as you, it is wrong. 3. The seventy-two hour clock to tell individuals. See question six. It sits in regulation 10(4), not in the Act, so anyone reading only the Act will miss it. 4. You need people in Jamaica. There are two separate requirements. If you have no office or business base in Jamaica, you must appoint a representative based in Jamaica. Separately, regulation 9(2) says that if your data protection officer lives outside Jamaica, that officer must have 'a representative who resides in Jamaica'. That stand-in has to make sure the officer's job gets done. An offshore group privacy officer is not enough on its own. 5. A copy of your own data is not free and not automatic. A person gets their data within thirty days. But the Minister's Regulations set fees, and regulation 5(4) says you are 'not obliged to provide information requested under section 6(2) of the Act until the applicable fees have been paid'. Public bodies may only waive the fee for hardship. 6. A pre-clearance system that is switched off. Section 19 lets the Minister name types of data use that are especially likely to cause serious damage or distress. Once named, you cannot start that work until you have filed your registration details. You must then wait thirty days, or wait for the Commissioner to issue an assessment notice. Doing it anyway carries five million Jamaican dollars or five years, or ten years in a higher court. No such order has been made, so the whole scheme sits idle. It can be switched on by a notice in the Gazette. 7. A child is anyone under eighteen. A parent or guardian exercises the child's rights, and must show proof of who they are and how they are related. 8. More organisations need a data protection officer than you would expect. Every public authority needs one. So does anyone handling sensitive personal data or criminal conviction data. So does anyone handling personal data 'on a large scale'. So does any group the Commissioner names in the Gazette.
Sources
- Official sourceOffice of the Information Commissioner, JamaicaData Protection Act, 2020, sections 19, 20, 21(2), 68 and 72(3)
oic.gov.jm
“where a body corporate commits an offence under this Act, the body corporate shall be liable to a fine not exceeding four percent of the annual gross worldwide turnover of that body corporate for the preceding year of assessment”
Link checked 19 August 2026
- Official sourceOffice of the Information Commissioner, JamaicaData Protection Regulations, 2024 (Minister's), regulations 5 and 9(2)
oic.gov.jm
“Where a data controller appoints a data protection officer who resides outside of Jamaica, the data controller shall ensure that the data protection officer has a representative who resides in Jamaica”
Link checked 19 August 2026
What's changing next
The main thing coming is enforcement itself. In June 2026 the responsible Minister told Parliament that the regulator's full budget was approved. A working group is running, and the oversight committee appointments are nearly done. After that the enforcement powers will be switched on. The Bank of Jamaica is consulting until 30 October 2026 on a new outsourcing and third-party risk standard for banks. A draft national artificial intelligence policy is due by November 2026. The Act itself falls due for its first five-yearly review from 1 December 2026.
Dated items in the next twelve months. • 30 October 2026. The Bank of Jamaica's consultation on Standards for Outsourcing Arrangements and Third-Party Risk Management closes. It would apply to every deposit-taking institution and financial holding company. It would require country risk assessments for offshore arrangements. It would require records to be produced in English on request. It would require 'timely and unrestricted' supervisory access to books, records, systems, data and personnel. It is a draft and has no legal effect yet. • November 2026. The National Artificial Intelligence Task Force is due to deliver a draft National AI Policy. It covers eight areas, including ethics and the law. The Minister announced this on 2 June 2026. • From 1 December 2026. Section 77 of the Act requires a review of the Act every five years from the first appointed day, which was 1 December 2021. The Minister has already flagged one target for that review. The Data Protection Oversight Committee has to include a retired High Court judge. He called that a bottleneck that warrants a change in the law. • No date. The reopening of the registration portal. The regulator says it will tell the public through its official channels. • Under consideration, no date. A 'data embassy', announced on 22 June 2026 as something the government is 'seriously going to start looking at'. It would store sovereign Jamaican data in another country under embassy-like protection. That is the opposite of keeping data at home. Powers the government already holds. Any of these could change the answer without consultation. • Section 31(5). The Minister may publish an order in the Gazette naming countries treated as safe enough. He may also set out what counts as substantial public interest. Never used. • Section 19 with section 74(3)(c). The Minister may name types of data use that need a thirty-day standstill and an assessment by the Commissioner before you can start. Never used. • Section 15(2). The Minister may exempt whole classes of business, or whole classes of data use, from having to register. Used only for the classes already in the Act. • Section 20(6)(d). The Commissioner may name in the Gazette classes of business that must appoint a data protection officer. • Section 33. The Minister responsible for national security may certify personal data as exempt from parts of the Act. • The Commissioner's March 2026 forbearance on registration is an advisory, not a legal amnesty. It can be withdrawn on the day the portal comes back. The underlying offence in section 18 never stopped existing. • Political direction. The Minister told Parliament on 2 June 2026 that 'data sovereignty — Jamaica's right to control, govern, and benefit from the data generated within our borders — is not a technical concept. It is a national security and national development imperative.' There is no rule today requiring data to stay in Jamaica. But that is the language that usually comes before one.
Sources
- Official sourceJamaica Information ServiceEnforcement Provisions of Data Protection Act to Be Fully Activated (4 June 2026)
jis.gov.jm
“Data sovereignty - Jamaica's right to control, govern, and benefit from the data generated within our borders - is not a technical concept. It is a national security and national development imperative.”
Link checked 19 August 2026
- Official sourceBank of JamaicaConsultation Paper on Standards for Outsourcing Arrangements and Third-Party Risk Management (July 2026), closing 30 October 2026
boj.org.jm
Link checked 19 August 2026
- Official sourceJamaica Information ServiceAI Task Force to Develop Draft Policy By November (4 June 2026)
jis.gov.jm
Link checked 19 August 2026
- Official sourceJamaica Information ServiceGov't Exploring Data Embassy to Safeguard Digital Assets (22 June 2026)
jis.gov.jm
“This is where we can take our sovereign data and store it in a different jurisdiction... in an embassy that rivals or is similar to sovereign ground in a different country, where [it] can't be tampered with.”
Link checked 19 August 2026
- Official sourceOffice of the Information Commissioner, JamaicaData Protection Act, 2020, sections 15(2), 19, 20(6), 31(5), 33 and 77
oic.gov.jm
Link checked 19 August 2026
What to do: Diarise 30 October 2026 — that is the date this changes.
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries3 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Cloud and outsourcing rules
Official name: Standard of Sound Practice — Management of Cyber Risks · Issued under the Banking Services Act, 2014 · Statutory code of practice
Banks and other deposit-taking institutions must run a cyber risk programme. They must check cloud and other outside providers carefully. They must report a serious incident to the Bank of Jamaica within seventy-two hours. There is no requirement to keep the data in Jamaica.
Enforced by Bank of Jamaica
What you have to do
- Report cyber incidents — within 72 hoursTo the Bank of Jamaica and other appropriate authorities.
- Secure the data
- Written vendor contractCheck your outside suppliers and cloud providers. This covers apps, data and equipment hosted in other people's data centres.
- Independent audit
Sources
- Official sourceBank of JamaicaStandard of Sound Practice — Management of Cyber Risks (final draft, 29 November 2023)
boj.org.jm
“reported promptly to the Bank of Jamaica and appropriate authorities within 72 hours”
Link checked 19 August 2026
- Official sourceBank of JamaicaConsultation Paper on Standards for Outsourcing Arrangements and Third-Party Risk Management (July 2026) — draft, consultation closes 30 October 2026
boj.org.jm
Link checked 19 August 2026
Cloud and outsourcing rules (Finance)
Official name: Industry Guidance — Management of Cyber Risks · Issued to licensees under the Insurance Act, the Pensions Act and the Securities Act · Regulator guideline
Insurers, pension funds and investment firms must report a cyber incident or data breach to the Financial Services Commission within seventy-two hours. They must also give the Commission a yearly statement about their controls. Cloud providers are expected to hold independent security assurance. There is no requirement to keep the data in Jamaica.
Enforced by Financial Services Commission
What you have to do
- Report cyber incidents — within 72 hoursTell the Financial Services Commission. At the same time tell the Bank of Jamaica, the Jamaica Cyber Incident Response Team and the Office of the Information Commissioner. Also tell the anti-corruption agency, the Financial Investigations Division and the police, where relevant.
- Secure the data
- Independent auditA yearly statement to the Commission. It alternates between your own statement and an independent one.
- Hold a security certificateOutside providers are expected to hold independent security assurance, such as a SOC 2 Type 2 report.
- Written vendor contract
Sources
- Official sourceFinancial Services Commission, JamaicaIndustry Guidance — Management of Cyber Risks
fscjamaica.org
“FIs must report cyber incidents and data breaches promptly to the Financial Services Commission within 72 hours along with relevant authorities”
Link checked 19 August 2026
- Official sourceFinancial Services Commission, JamaicaIndustry Guidance (Securities) — Management of Cyber Risks, date of effect 1 October 2025
fscjamaica.org
Link checked 19 August 2026
Cloud and outsourcing rules (Government)
Official name: GoJ ICT Policies, Standards and Guidelines Manual — Guidelines for Cloud Computing · PSG Manual version 1.2, Office of the Chief Information Officer, February 2018; republished by the ICT Authority · Government policy document
Government ministries and agencies may use overseas cloud services. The provider's terms of service must first be cleared by the Attorney General's Office. The head of the body must also approve the use in writing. There is no ban on hosting government data abroad, and no list of approved countries.
Enforced by Jamaica ICT Authority
What you have to do
- Written vendor contractTerms of service for an overseas cloud service must be approved by the Office of the Attorney General of Jamaica.
- Secure the dataSenior technology staff must confirm that security, privacy and technology management requirements are met before use is approved.
- Keep records of how you use dataKeep that confirmation with the investment paperwork.
- Report cyber incidents — within 72 hoursPublic bodies report to the Information Commissioner within 72 hours and alert the national cyber incident team and police for cyber incidents.
Sources
- Official sourceJamaica ICT Authority / Office of the Chief Information OfficerGoJ ICT Policies, Standards and Guidelines Manual, Guidelines for Cloud Computing
icta.gov.jm
“For external (over-seas) Cloud Computing services that require users to agree to terms of service agreements, such agreements must be approved by the Office of the Attorney General of Jamaica”
Link checked 19 August 2026
- Official sourceJamaica ICT AuthorityGovernment of Jamaica Data Protection Act Compliance Framework, version 1.2, June 2024
icta.gov.jm
Link checked 19 August 2026
- Official sourceJamaica ICT AuthorityTechnology Codes of Practice — policies, standards, guidelines and ICT legislation
icta.gov.jm
Link checked 19 August 2026
Applies to every company3 rules
These bind you whatever business you are in, once the country's rules reach you.
General data protection law
Official name: The Data Protection Act, 2020 · Act No. 7 of 2020 · Act of parliament
Jamaica's general privacy law. It reaches foreign companies that serve or monitor people in Jamaica, and it makes them appoint a Jamaican representative. Data may leave the island only to countries you judge protect it well enough. There is no official list to rely on. Enforcement runs through the criminal courts. A company can be fined up to four percent of worldwide turnover. Public authorities cannot be prosecuted.
Enforced by Office of the Information Commissioner — not yet operational
How this country controls where data goes: Approval each time (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision, Government sign-off needed, Explicit consent, Needed for a contract, Important public interest, Legal claims, To save someone’s life
What you have to do
- Register or notify — from 1 December 2023Using personal data without being on the register is a crime. You must renew every year.
- Appoint a representativeRequired if you have no office or business base in Jamaica.
- Appoint a data protection officer — applies at: Public authorities; anyone processing sensitive or criminal-conviction data; anyone processing personal data on a large scale; any class named by the Commissioner in the Gazette.
- Tell people what you do
- Get consent
- Secure the data
- Let people see their dataThirty days to respond. You may charge a fee, and you need not respond until it is paid.
- Let people correct their data
- Let people object
- Limit automated decisions
- Report breaches to the regulator — within 72 hours
- Tell affected people — within 72 hours
- Put a transfer safeguard in place
- Delete data after a period
- Get a parent's consent for children — applies at: under 18
What it costs if you get it wrong
- Percentage of global turnover: 4% of annual gross worldwide turnoverAny offence under the Act committed by a body corporate (section 68)
- Criminal liability: JMD 2,000,000 or 2 years (summary); unlimited fine or 7 years (indictment) — about $13 thousandProcessing in breach of a data protection standard, or failing to report a breach (section 21)
- Criminal liability: JMD 2,000,000 or 6 months — about $13 thousandProcessing personal data without being registered (section 18)
- Criminal liability: JMD 5,000,000 or 5 years (summary); 10 years (indictment) — about $31 thousandCarrying on designated 'specified processing' without clearance (section 19). No designation order has been made.
- Claims by individualsCompensation for damage or distress caused by a contravention (section 69)
Sources
- Official sourceOffice of the Information Commissioner, JamaicaThe Data Protection Act, 2020 (Act No. 7 of 2020)
oic.gov.jm
Link checked 19 August 2026
- Official sourceOffice of the Information Commissioner, JamaicaOur Mandate — Appointed Day Notice of 30 November 2021 and the two-year transitional period
oic.gov.jm
“By Appointed Day Notice published in the Jamaica Gazette on 30 November 2021, Sections 2, 4, 56, 57, 60, 66, 74 and 77, and the First Schedule of the Act were also brought into operation as of 1 December 2021.”
Link checked 19 August 2026
Breach reporting rules
Official name: The Data Protection Regulations, 2024 (the Minister's Regulations) · Jamaica Gazette Supplement, Proclamations, Rules and Regulations, Vol. CXLVII No. 23A, 4 March 2024 · Directly binding regulation
The detailed rules under the Act. They set the breach forms. They give you a firm seventy-two hour deadline to tell affected individuals. They require a Jamaica-based stand-in if your data protection officer lives abroad. They let you charge a fee before answering a request for someone's own data.
Enforced by Office of the Information Commissioner — not yet operational
What you have to do
- Report breaches to the regulator — within 72 hoursUse Form 7. Send more information as it emerges.
- Tell affected people — within 72 hoursRegulation 10(4). Most countries only ask you to do this without undue delay, so this deadline is much tighter.
- Appoint a data protection officerThe officer must report to senior or executive management, and may be an employee or a contractor.
- Appoint a representativeRegulation 9(2). If your data protection officer lives outside Jamaica, that officer must have a stand-in who lives in Jamaica.
- Let people see their data — 1 monthThirty days. Fees are set in the Second Schedule, and you need not answer until they are paid.
Sources
- Official sourceOffice of the Information Commissioner, JamaicaThe Data Protection Regulations, 2024 (Minister's) — Jamaica Gazette Supplement, 4 March 2024
oic.gov.jm
“These Regulations may be cited as the Data Protection Regulations, 2024, and shall come into operation on the 1st day of March, 2024.”
Link checked 19 August 2026
General data protection law (2025)
Official name: The Data Protection (Disposal of Personal Data) Regulations, 2024 · Jamaica Gazette Supplement, Proclamations, Rules and Regulations, Vol. CXLVIII No. 339, 17 September 2025 · Directly binding regulation
The delete rule. You must regularly review all the personal data you hold. You must get rid of what you no longer need. You must destroy it in a way that cannot be undone, even by future technology. You must also write down your own minimum and maximum keeping periods. Data that other laws require you to keep is excluded.
Enforced by Office of the Information Commissioner — not yet operational
What you have to do
- Delete data after a periodReview everything you hold regularly. Get rid of anything you no longer need.
- Keep records of how you use dataYou must have a written policy setting your minimum and maximum keeping periods.
- Secure the dataDestruction must be permanent. The data must no longer identify the person or be linkable to them.
Sources
- Official sourceOffice of the Information Commissioner, JamaicaThe Data Protection (Disposal of Personal Data) Regulations, 2024 — Jamaica Gazette Supplement, 17 September 2025
oic.gov.jm
“in a manner that ensures the permanence of the disposal, having regard to all reasonably foreseeable technological developments”
Link checked 19 August 2026
On the books, but not enforceable1 rule
These rules are still printed in the law, but a court struck them down or the regulator has said it will not apply them. You do not have to comply today. They are here because text nobody deleted can come back without warning.
General data protection law (not enforced)
Official name: The Data Protection (Data Controller Registration) Regulations, 2024 · Jamaica Gazette Supplement, Proclamations, Rules and Regulations, 1 April 2024 · Directly binding regulation
Everyone who handles personal data must register with the regulator and pay a fee. You must renew each year by the first of December. You must also name the countries you send data to. The rule is still law. But the registration system has been switched off since March 2026, and the regulator has publicly promised not to impose liability while it is down. It can be switched back on without notice.
Enforced by Office of the Information Commissioner — not yet operational
What you have to do
- Register or notify — 1 yearRegister once, then renew on or before 1 December each year. Tell the regulator about any change to your details within fourteen days.
- Keep records of how you use dataYou must name every country you send personal data to, directly or indirectly.
What it costs if you get it wrong
- Criminal liability: JMD 2,000,000 or 6 months — about $13 thousandProcessing personal data without registering (Act, section 18(1))
Sources
- Official sourceOffice of the Information Commissioner, JamaicaThe Data Protection (Data Controller Registration) Regulations, 2024, regulation 3(3) and Schedule of fees
oic.gov.jm
“thereafter, annually for so long as the entity concerned remains a data controller, on or before the 1st day of December in each year”
Link checked 19 August 2026
- Official sourceOffice of the Information Commissioner, JamaicaAdvisory re Registration of Data Controllers: No Adverse Implications While System Offline (15 March 2026)
oic.gov.jm
Link checked 19 August 2026
- Official sourceOffice of the Information Commissioner, JamaicaOffice of the Information Commissioner homepage — registration temporarily paused (checked 19 August 2026)
oic.gov.jm
Link checked 19 August 2026
- Official sourceOffice of the Information Commissioner, JamaicaRegister of Data Controllers for the 2023-2024 Registration Year Now Live (11 October 2024)
oic.gov.jm
Link checked 19 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
That the whole of the Data Protection Act, 2020 is in force, rather than only part of it
We could not confirm the exact date each part of the Act came into force. The regulator's mandate page names the sections that started on 1 December 2021. We could not see the commencement notices covering the registration, standards and offence sections. The regulator and the Minister both act as though those sections are in force, so we have recorded the Act as in force. If you need certainty about a specific section, ask the Commissioner in writing.
That no Ministerial order has been made naming countries with adequate protection under section 31(5)(c), and none designating 'specified processing' under section 19
We found no such order. We checked the regulator's legislation pages and the government sites we could reach on 19 August 2026. We cannot prove that no order exists, because the Jamaica Gazette is not fully searchable online. If this matters to you, ask the Commissioner before you rely on it.
That the Office of the Information Commissioner has published no annual report and issued no enforcement decision
The regulator's Reports page returns 'No available content', and none of its six press releases concerns an enforcement action. An annual report may have been given to Parliament without being posted online. So treat this as nothing published, rather than nothing happening. Ask the office directly if it matters.
Whether the data controller registration portal has reopened between 15 March 2026 and today
The regulator's homepage on 19 August 2026 still says registration is temporarily paused, and no press release announcing a reopening has appeared. The advisory promises notice through the office's own channels but gives no date. Check the regulator's website before you rely on the pause.
Sector rules for health, education, telecoms, gambling, mapping and defence
We found no rule in health, education, telecoms, gambling, mapping or defence that requires data to stay in Jamaica or limits sending it abroad. We could not confirm that against every regulator, because several of these government sites were unreachable. Coverage here is thinner than for finance. If you work in health or telecoms, check with your regulator before you rely on this.
The United States dollar approximations for Jamaican dollar penalties and fees
We converted at roughly one hundred and sixty Jamaican dollars to the United States dollar. We could not read a live rate from the central bank. Treat every United States dollar figure here as rough, and use the Jamaican dollar figure for anything that matters.
Whether the Bank of Jamaica's draft outsourcing standard will contain any data location requirement in its final form
The July 2026 text is a draft, and the consultation closes on 30 October 2026. As drafted it asks for supervisory access and a country risk assessment, not local storage. Drafts change. It has no legal effect today, so do not plan around it as binding.
Freshness and refresh
Freshness
Checked about 2 months ago, on 19 August 2026.
Re-checked every 60 days. Next check due 18 October 2026.