Trinidad and Tobago
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.
The answer
Trinidad and Tobago passed a privacy law in 2011 and then switched on only a small piece of it. The privacy principles apply on paper, but the parts that create duties for companies, duties for government bodies, and any punishment were never brought into force. No Information Commissioner has ever been appointed. The real rules come from the Central Bank, the telecoms regulator and money-laundering law.
Data governance in Trinidad and Tobago
The eight things that decide how you handle data about people in Trinidad and Tobago. Same eight on every country page, so you can compare.
Who has to follow these rules
Almost certainly not in any way you could be punished for. The privacy law does contain a clause that reaches anyone who collects personal information from people in Trinidad and Tobago, or who uses a local internet or phone company to do it, even with no office there. That clause has never been switched on. There is no size or revenue threshold and no requirement to appoint a local representative. If you are a bank, insurer, telephone company or gambling operator, you need a local licence anyway, and that licence is what actually binds you.
The extraterritorial hook is section 69 of the Data Protection Act, Chap. 22:04, sitting in Part IV (private sector). Part IV has never been proclaimed. The only provisions in force are Part I and sections 7 to 18, 22, 23, 25(1), 26 and 28 (from 6 January 2012, Legal Notice 2 of 2012) plus section 42(a) and (b) (from 23 August 2021, Legal Notice 220 of 2021). Section 6, which is in Part I and therefore in force, states that the General Privacy Principles are 'applicable to all persons who handle, store or process personal information belonging to another person' — a broad reach with no enforcement machinery behind it, because Parts III, IV and V are all dormant. Financial institutions face a separate, real localisation-adjacent hook: an electronic money issuer must be a body corporate with its registered office in Trinidad and Tobago.
Sources
- Official sourceDigital Legislative Library, Government of Trinidad and TobagoData Protection Act, Chap. 22:04 — consolidated text, sections 1(2), 6 and 69
laws.gov.tt
“A person who— (a) collects, retains, manages, uses, processes or stores personal information in Trinidad and Tobago; (b) collects personal information from individuals in Trinidad and Tobago; or (c) uses an intermediary or telecommunications service provider located in Trinidad and Tobago ... shall follow the General Privacy Principles set out in section 6”
Link checked 19 August 2026
- Official sourceGovernment Printer, Republic of Trinidad and TobagoLegal Notice No. 2 of 2012 — Proclamation bringing Part I and sections 7 to 18, 22, 23, 25(1), 26 and 28 into operation on 6 January 2012
laws.gov.tt
Link checked 19 August 2026
- Official sourceCentral Bank of Trinidad and TobagoE-Money Issuer Order, 2020 (Legal Notice 284 of 2020), clause 9(1)
central-bank.org.tt
“An EMI shall be a body corporate with its registered office in Trinidad and Tobago.”
Link checked 19 August 2026
Where the data is allowed to live
In general yes, and nobody will stop you. The one cross-border sentence that is actually in force says data sent abroad must go somewhere with protection comparable to Trinidad and Tobago's, and that an official list of approved countries must be published. That list has never been published, because the official who would publish it has never been appointed. So the rule is a locked door with nobody holding the key. Four industries are different and are set out below.
SECTOR OVERRIDES. Banking, insurance and payments: data can leave with paperwork. The Central Bank's Guideline for the Management of Outsourcing Risks (February 2022) tells regulated financial institutions to 'in principle, enter into arrangements only with service providers operating in jurisdictions with an equivalent (or higher) standard of data protection and privacy legislation, regulation or supervision as exists in Trinidad and Tobago', to obtain customer consent before transferring customer information to a service provider, and to notify the Central Bank if a foreign authority seeks access to customer data. Government and public bodies: data must stay in the country on paper, but not in force. Section 36 of the Data Protection Act would require a public body to store personal information only in Trinidad and Tobago and to allow access only from Trinidad and Tobago, unless the individual consents in the prescribed manner or the destination has comparable safeguards. 'Public body' includes ministries, municipal corporations, service commissions, the Tobago House of Assembly and state-owned companies. Section 36 sits in Part III and has never been proclaimed. Gambling: data must stay in the country on paper, not in force. Schedule 3 to the Gambling (Gaming and Betting) Control Act, 2021 makes it a licence condition that all books, records and documents relating to the licensed activity are 'kept at the licensed premises' and retained at least seven years. Only Parts I, II and X and Schedule 1 were proclaimed, on 11 August 2021; the licensing Part III, which carries Schedule 3, is not in force. Telecoms: data can leave with paperwork in substance. A concession holder must keep user information confidential and may use it only to run the network, bill, protect its property and a few other listed purposes; and it must be able to give prompt help with interception warrants, which in practice means keeping the capability inside the country. Border and travel: data can leave with paperwork, enacted but not in force. Health, education, securities, defence and mapping: no cross-border storage rule found, checked 19 August 2026, confidence medium.
Sources
- Official sourceDigital Legislative Library, Government of Trinidad and TobagoData Protection Act, Chap. 22:04 — section 6(l) (in force), section 28 (in force), section 36 (not in force)
laws.gov.tt
“personal information which is requested to be disclosed outside of Trinidad and Tobago shall be regulated and comparable safeguards to those under this Act shall exist in the jurisdiction receiving the personal information.”
Link checked 19 August 2026
- Official sourceCentral Bank of Trinidad and TobagoGuideline for the Management of Outsourcing Risks (February 2022), paragraph 9.2.1
central-bank.org.tt
“In principle, enter into arrangements only with service providers operating in jurisdictions with an equivalent (or higher) standard of data protection and privacy legislation, regulation or supervision as exists in Trinidad and Tobago”
Link checked 19 August 2026
- Official sourceParliament of the Republic of Trinidad and TobagoGambling (Gaming and Betting) Control Act, 2021 (Act No. 8 of 2021), Schedule 3 paragraph 6
ttparliament.org
“It shall be a condition of a licence that the licensee shall ensure that all books, records and documents relating to the licensed activity are— (a) kept at the licensed premises; and (b) retained for not less than seven years”
Link checked 19 August 2026
- Official sourceDigital Legislative Library, Government of Trinidad and TobagoTelecommunications Act, Chap. 47:31, section 24(1)(j)
laws.gov.tt
Link checked 19 August 2026
Sending data out of the country
On paper the model is an approved-country list, which normally means you cannot send data anywhere until the government names the destination. In practice the list has never been published, and there is no regulator to publish it or to complain to, so the model is unenforced. If you are supervised by the Central Bank, the practical test is different and real: you must satisfy yourself the destination protects data at least as well as Trinidad and Tobago does, get your customer's consent, and write the right terms into the contract.
Section 28 of the Data Protection Act requires the Information Commissioner to publish, in the Gazette and in two daily newspapers, 'a list of countries which have comparable safeguards for personal information as provided by this Act'. Section 28 is in force. No such list has ever been published, because no Commissioner has been appointed. The list is therefore empty and, unusually, cannot currently be populated by anyone. This is an allowlist model that behaves like an unrestricted one. For public bodies, section 46 would set up a case-by-case route where the body must inform the individual, obtain consent, and refer doubtful destinations to the Commissioner for a comparable-safeguards determination — section 46 is not in force. For Central Bank licensees the mechanisms that actually matter are the outsourcing guideline's equivalence test, customer consent under paragraph 5.7.3, contract terms preserving the Central Bank's access to books and records, and a duty to notify the Central Bank if any overseas authority seeks access to customer information. Existing material outsourcing contracts had to be notified to the Inspector of Financial Institutions within six months of the guideline's issuance.
Sources
- Official sourceDigital Legislative Library, Government of Trinidad and TobagoData Protection Act, Chap. 22:04, sections 28 and 46
laws.gov.tt
“The Commissioner shall by Order publish in the Gazette and at least two newspapers in daily circulation in Trinidad and Tobago a list of countries which have comparable safeguards for personal information as provided by this Act.”
Link checked 19 August 2026
- Official sourceCentral Bank of Trinidad and TobagoGuideline for the Management of Outsourcing Risks (February 2022), paragraphs 5.7.3, 9.2.1, 9.2.4 and 12.1.2
central-bank.org.tt
“Any transfer of customer information from the RFI to a third party service provider under the terms of an outsourcing contract should be with the customer's consent.”
Link checked 19 August 2026
- Official sourceParliament of the Republic of Trinidad and TobagoSenate Hansard, 31 January 2023 — debate on the Data Protection Act 2011
ttparliament.org
Link checked 19 August 2026
The regulator, and whether it actually acts
Nobody, for general privacy. The law creates an Office of the Information Commissioner and that office has legally existed since January 2012, but no Commissioner has ever been appointed and the office has never been staffed. In January 2023 the responsible government minister told the Senate he regretted that the office 'has not yet been fully operationalized'. Nothing has changed since. The bodies that do enforce data-adjacent rules are the Central Bank for financial firms, the telecoms authority for phone and internet companies, and the money-laundering unit for record-keeping.
Sections 7 to 18 of the Data Protection Act — establishing the Office, providing for appointment of the Commissioner and Deputy, and for staff — were proclaimed on 6 January 2012. Section 19 (inspectors and their powers), section 20 and 21 (audits and enquiries), section 24 (privileged information), section 27 (annual report to Parliament), and all of Parts III, IV and V were not proclaimed and remain unproclaimed as at 19 August 2026. A Senate motion calling on the Government to proclaim the remaining sections was debated on 31 January, 28 February and 28 March 2023 and passed as amended; no proclamation followed. We reviewed the official register of Legal Notices for 2022, 2023, 2024, 2025 and 2026 and found no further proclamation of any part of the Data Protection Act. The office has no website and does not appear in the national government services directory. Enforcement rating: dormant. By contrast the Central Bank of Trinidad and Tobago issues circulars and requires annual cybersecurity self-assessments; the Trinidad and Tobago Securities and Exchange Commission publishes administrative sanctions orders; the Telecommunications Authority publishes current market statistics and decisions; and the national cyber incident response team publishes incident statistics updated to 23 July 2026. None of those is a privacy regulator.
Sources
- Official sourceParliament of the Republic of Trinidad and TobagoSenate Hansard, 31 January 2023 — statement of the Minister of Digital Transformation on the Office of the Information Commissioner
ttparliament.org
“I have my regrets of the fact that the Office of the Information Commissioner has not yet been fully operationalized and that has spanned several administrations.”
Link checked 19 August 2026
- Official sourceParliament of the Republic of Trinidad and TobagoSenate motion: Proclaim the remaining sections of the Data Protection Act (debated 31 January, 28 February and 28 March 2023)
ttparliament.org
Link checked 19 August 2026
- Official sourceDigital Legislative Library, Government of Trinidad and TobagoChronological register of Legal Notices, 1838 to 2026 — reviewed for 2022 to 2026, no further Data Protection Act proclamation
laws.gov.tt
Link checked 19 August 2026
- Official sourceCentral Bank of Trinidad and TobagoCybersecurity — supervisory expectations for regulated institutions
central-bank.org.tt
Link checked 19 August 2026
How long you must keep it — and when to delete it
The floors are real and the ceiling is not. If you handle money you must keep transaction records, customer identity records, account files and correspondence for six years, and investment firms must keep their books for at least six years too. Electronic money issuers must keep customer and transaction files for seven years. Gambling licensees will have to keep records seven years once that part of the law starts. The only delete-by rule says personal information should be kept no longer than needed for the purpose it was collected for, and nobody enforces it, so when a keep-it rule and a delete-it rule clash, the keep-it rule wins in practice.
FLOORS. Anti-money-laundering: six years for all domestic and international transactions, customer due diligence identification data, account files and business correspondence, and the results of analysis of an account transaction. Securities: section 87(4) of the Securities Act, Chap. 83:02 requires any book, record or document kept under that Act to be kept for at least six years. Electronic money: clause 22 of the E-Money Issuer Order, 2020 requires record-keeping systems that retain customer and transaction files for a minimum of seven years. Gambling: seven years from completion of the transaction, on the licensed premises, once Part III is proclaimed. Passenger data: seven years under the Advance Passenger Information and Passenger Name Record Act, 2026, once proclaimed, with passenger name record data depersonalised after six months. CEILING. Principle (e) of section 6 of the Data Protection Act — in force — says personal information 'shall only be retained for as long as is necessary for the purpose collected'. There is no regulator, no penalty in force, and no published guidance, so the ceiling is unenforced. CONFLICT. Trinidad and Tobago's statutes do not contain an express conflict rule. In practice the specific statutory retention floors are enforceable and the general privacy ceiling is not, so the floor governs.
Sources
- Official sourceFinancial Intelligence Unit of Trinidad and TobagoAML/CFT Obligations for Registered Supervised Entities — record retention
fiu.gov.tt
“Financial institutions and listed businesses must retain the following records in electronic or written form for a period of six (6) years”
Link checked 19 August 2026
- Official sourceDigital Legislative Library, Government of Trinidad and TobagoSecurities Act, Chap. 83:02, section 87(4)
laws.gov.tt
“Any book, record or other document required to be kept under this Act shall be kept for a period of at least six years or as otherwise prescribed.”
Link checked 19 August 2026
- Official sourceCentral Bank of Trinidad and TobagoE-Money Issuer Order, 2020, clause 22 (record retention)
central-bank.org.tt
“An EMI shall have record keeping systems that retain customer and transaction files for a minimum period of seven years”
Link checked 19 August 2026
- Official sourceDigital Legislative Library, Government of Trinidad and TobagoData Protection Act, Chap. 22:04, section 6(e)
laws.gov.tt
Link checked 19 August 2026
If something goes wrong
There is no general duty to report a data breach to anyone, and no duty to tell the people affected. That is the single biggest gap in the country's rules. If the Central Bank regulates you, there is a hard clock: alert the Central Bank within 24 hours of becoming aware of a cyber incident, and file the full report within 72 hours. The national cyber team accepts reports from anyone but cannot compel them. So most organisations have zero clocks and financial firms have two.
CLOCK 1 — Central Bank, 24 hours. The Cybersecurity Best Practices Guideline (September 2023), issued under section 10(b) of the Financial Institutions Act, 2008 and section 278(1) of the Insurance Act, 2018: 'As soon as possible but within 24 hours of becoming aware of a cyber-incident, the company shall alert the Central Bank, that a cyber-incident has occurred.' CLOCK 2 — Central Bank, 72 hours: the Cyber Incident Reporting Template must be submitted within 72 hours of the incident, followed by regular (for example daily) updates until resolution and a post-incident review. Failure to report may lead to enhanced supervisory reporting or compliance directions. A separate duty in the outsourcing guideline requires notifying the Central Bank of any unauthorised access or breach of confidentiality by a service provider or sub-contractor. CLOCK 3 — none for everyone else. The Data Protection Act contains no breach notification obligation at all, in force or otherwise. The Trinidad and Tobago Cyber Security Incident Response Team runs a reporting portal and publishes incident statistics, most recently updated 23 July 2026, but we found no statute making a report to it mandatory. FUTURE CLOCK: the Advance Passenger Information and Passenger Name Record Act, 2026 requires a high-risk personal data breach to be communicated to the individual and to a Data Protection Officer 'without undue delay' — that Act is not yet in force.
Sources
- Official sourceCentral Bank of Trinidad and TobagoCybersecurity Best Practices Guideline (September 2023), Appendix II — Cybersecurity Incident Reporting
central-bank.org.tt
“As soon as possible but within 24 hours of becoming aware of a cyber-incident, the company shall alert the Central Bank, that a cyber-incident has occurred.”
Link checked 19 August 2026
- Official sourceTrinidad and Tobago Cyber Security Incident Response TeamReport an Incident — national cyber security incident reporting portal
ttcsirt.gov.tt
Link checked 19 August 2026
- Official sourceParliament of the Republic of Trinidad and TobagoAdvance Passenger Information and Passenger Name Record Act, 2026 (Act No. 7 of 2026), section 28(12)
ttparliament.org
Link checked 19 August 2026
What catches people out
Five things bite people here. A law that looks binding is mostly asleep. A second law you would assume protects online consumers is also asleep. Phone and internet companies can be ordered to go and collect data they do not even hold, and are forbidden from telling anyone. The country has been under a state of emergency, and emergency orders can authorise the searching of seized computers and phones. And the punishment written into the privacy law includes prison and a fine of up to a tenth of company turnover, which would be severe if it were ever switched on.
TRAP 1 — the law reads binding and is not. A plain text search of the Data Protection Act returns detailed duties on public bodies, private companies, directors and officers. Parts III, IV and V have never been proclaimed. A compliance programme built from the statute text alone will be built on sections that do not exist in operation. TRAP 2 — the Electronic Transactions Act, Chap. 22:05 is also only partly in force. Parts I to IV and Part VII commenced in January 2012. Part V (electronic authentication service providers), Part VI (liability of intermediaries and telecommunications service providers), Part VIII (consumer protection and unwanted commercial messages), Part IX (offences) and Part X have not commenced. There is therefore no in-force anti-spam rule and no in-force safe harbour for online intermediaries. TRAP 3 — compelled collection plus a gag. Under section 18 of the Interception of Communications Act, Chap. 15:08, an authorised officer holding a warrant may require a telecommunications provider not only to hand over communications data it holds but, 'if the provider is not already in possession of the data, to obtain the data and so disclose it', and the provider must not reveal the notice's existence to anyone other than its own staff and its lawyers. Section 13 makes failure to provide prompt interception assistance an offence carrying a fine of one million Trinidad and Tobago dollars, roughly one hundred and fifty thousand United States dollars. TRAP 4 — emergency powers. Emergency Powers Regulations made under section 7 of the Constitution and published on 3 March 2026 allow the Minister responsible for internal security to make Orders 'authorising the interrogation of computers and electronic devices seized'. Detention orders under those Regulations were still being gazetted through 2026. TRAP 5 — the sleeping penalty is unusually harsh. Section 95 of the Data Protection Act provides for imprisonment of up to five years on indictment, and section 96 allows a court to fine a corporation up to ten per cent of the annual turnover of the enterprise. Directors and officers who directed or assented to an offence commit the offence personally. None of Part V is in force, so this is a risk that could appear overnight rather than one that exists today.
Sources
- Official sourceDigital Legislative Library, Government of Trinidad and TobagoElectronic Transactions Act, Chap. 22:05, section 1(2) — only Parts I to IV and Part VII commenced
laws.gov.tt
“Parts I, II, III and IV of this Act came into operation on 6th January 2012. Part VII of this Act came into operation on 18th January 2012.”
Link checked 19 August 2026
- Official sourceDigital Legislative Library, Government of Trinidad and TobagoInterception of Communications Act, Chap. 15:08, sections 13 and 18
laws.gov.tt
“if the provider is not already in possession of the data, to obtain the data and so disclose it.”
Link checked 19 August 2026
- Official sourceGovernment Printer, Republic of Trinidad and TobagoLegal Notice No. 40 of 2026 — The Emergency Powers Regulations, 2026, regulation 3(g)
laws.gov.tt
“authorising the interrogation of computers and electronic devices seized under paragraph (f)”
Link checked 19 August 2026
- Official sourceDigital Legislative Library, Government of Trinidad and TobagoData Protection Act, Chap. 22:04, sections 94, 95 and 96 (Part V, not in force)
laws.gov.tt
“Where a corporation contravenes any of the provisions of this Act, the Court may impose a fine of up to ten per cent of the annual turnover of the enterprise.”
Link checked 19 August 2026
What's changing next
One new law is signed and waiting. In May 2026 Parliament passed a law on airline and ship passenger data that sets seven-year retention, six-month anonymisation of booking data, and conditions on sending that data to other countries. It has been signed by the President but not switched on. No bill to fix or replace the 2011 privacy law has been introduced. The bigger risk is not new legislation at all: the President can switch on the sleeping parts of the existing privacy law at any moment, with no consultation and no notice.
COMING. The Advance Passenger Information and Passenger Name Record Act, 2026 (Act No. 7 of 2026) was assented to on 15 May 2026 and gazetted on 21 May 2026. Its section 2 says it comes into operation on a date fixed by the President by Proclamation. Parliament's own bill tracker records its status as 'Assent: Awaiting Proclamation'. It repeals and replaces the Immigration (Advance Passenger Information) Act and operationalises the CARICOM Advance Passenger Information System. NOT COMING, so far. We checked Parliament's bills index on 19 August 2026: no Data Protection (Amendment) Bill has been introduced. In January 2023 the responsible minister told the Senate that modernising amendments were being developed with international consultants and Inter-American Development Bank support; more than three years later no bill has been laid. DORMANT SWITCHES. First and largest: section 1(2) of the Data Protection Act lets the President by Proclamation bring any remaining section into force on any chosen day. That single act would switch on the public sector storage-and-access-only-in-Trinidad-and-Tobago rule in section 36, all private sector duties in Part IV, and the criminal and turnover-percentage penalties in Part V. Second: section 100 lets the Minister make Regulations under the Act. Third: section 71 lets the Information Commissioner, once appointed, order any industry to develop a mandatory code of conduct, and section 74 makes such a code binding. Fourth: Part III of the Gambling (Gaming and Betting) Control Act, 2021 can be proclaimed at any time, switching on the keep-records-on-the-premises licence condition. Fifth: Emergency Powers Regulations can be revived or amended under a state of public emergency. None of these requires consultation.
Sources
- Official sourceParliament of the Republic of Trinidad and TobagoThe Advance Passenger Information and Passenger Name Record Bill, 2026 — status: Assent, Awaiting Proclamation
ttparliament.org
Link checked 19 August 2026
- Official sourceParliament of the Republic of Trinidad and TobagoBills before Parliament — index reviewed 19 August 2026, no Data Protection amendment bill
ttparliament.org
Link checked 19 August 2026
- Official sourceGovernment Printer, Republic of Trinidad and TobagoLegal Notice No. 205 of 2021 — Proclamation bringing only Parts I, II and X and Schedule 1 of the Gambling (Gaming and Betting) Control Act, 2021 into operation
laws.gov.tt
“And whereas it is expedient that Parts I, II and X and Schedule 1 of the Act come into operation”
Link checked 19 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries5 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Data Protection Act, Chap. 22:04, Part III (Protection of Personal Data by Public Bodies)
Act of parliament · Act No. 13 of 2011, sections 29 to 68, in particular section 36
The strictest data residency rule in Trinidad and Tobago law would force ministries, municipal corporations, service commissions, the Tobago House of Assembly and state-owned companies to store and access personal information only inside the country. It has sat unproclaimed since 2011 and is the single provision most likely to be switched on without notice.
Enforced by Office of the Information Commissioner — not yet operational
Transfer model: Approval each time (the list is currently empty) · Accepted routes: Explicit consent, Official 'this country is safe' decision, Government sign-off needed
What it makes you do
- Keep the data in the countrySection 36: personal information must be stored only in Trinidad and Tobago and accessed only in Trinidad and Tobago, unless the individual consents in the prescribed manner or the other jurisdiction has comparable safeguards. NOT IN FORCE.
- Put a transfer safeguard in placeSection 46: inform the individual, obtain consent, and refer doubtful destinations to the Information Commissioner for a comparable-safeguards determination. NOT IN FORCE.
- Assess high-risk projectsSection 47: privacy impact assessment and mitigation. NOT IN FORCE.
- Keep records of processingSections 48 and 51: personal information banks and a personal information index. NOT IN FORCE.
- Let people see their dataSection 52. NOT IN FORCE.
- Let people correct their dataSection 57. NOT IN FORCE.
Sources
- Official sourceDigital Legislative Library, Government of Trinidad and TobagoData Protection Act, Chap. 22:04, sections 2 ('public body'), 36, 46, 47
laws.gov.tt
“A public body shall ensure or take steps to ensure that personal information in its custody or under its control is stored only in Trinidad and Tobago and accessed only in Trinidad and Tobago unless— (a) the individual to whom the information relates has identified the information and has consented in the prescribed manner to its being stored in or accessed from another jurisdiction; or (b) the information is stored in or accessed from another jurisdiction that has comparable safeguards as provided by this Act.”
Link checked 19 August 2026
- Official sourceParliament of the Republic of Trinidad and TobagoSenate Hansard, 31 January 2023 — list of Data Protection Act provisions never proclaimed
ttparliament.org
Link checked 19 August 2026
Guideline for the Management of Outsourcing Risks (February 2022), read with the Cybersecurity Best Practices Guideline (September 2023)
Regulator guideline · Issued under section 10(b) of the Financial Institutions Act, 2008 and section 278(1) of the Insurance Act, 2018
The rules that actually bind banks, insurers, payment firms and e-money issuers. Send data abroad only to countries protecting it at least as well as Trinidad and Tobago, get customer consent, keep the Central Bank's access rights in the contract, and report cyber incidents within 24 hours.
Enforced by Central Bank of Trinidad and Tobago
Transfer model: Allowlist (the list is currently empty) · Accepted routes: Official 'this country is safe' decision, Explicit consent
What it makes you do
- Put a transfer safeguard in placeUse cross-border service providers only in jurisdictions with an equivalent or higher standard of data protection than Trinidad and Tobago.
- Get consentCustomer consent is required before customer information moves to a third party service provider; it may be taken up front as a term of the customer agreement.
- Written vendor contractThe contract must let the Central Bank access all information, books and records relating to the outsourced activity on request.
- Do not hand data to foreign authorities on demandNotify the Central Bank if an overseas authority seeks access to customer information, or if the institution's or the Central Bank's rights of access are restricted or denied.
- Register or notify — 6 monthsExisting material outsourcing contracts had to be notified to the Inspector of Financial Institutions within six months of issuance.
- Report cyber incidents — within 24 hours, from 13 September 2023Alert the Central Bank within 24 hours of becoming aware of a cyber incident.
- Report breaches to the regulator — within 72 hours, from 13 September 2023Submit the Cyber Incident Reporting Template within 72 hours, then regular updates until closure.
- Independent audit — 1 yearAnnual cybersecurity self-assessment submitted to the Central Bank by 31 March of the following calendar year.
- Secure the dataTwenty requirements across governance, risk management, awareness and training, business continuity, testing, and incident management.
What it costs if you get it wrong
- Order to stopFailure to report a cyber incident may result in enhanced supervisory reporting and the issuance of compliance directions.
Sources
- Official sourceCentral Bank of Trinidad and TobagoGuideline for the Management of Outsourcing Risks (February 2022)
central-bank.org.tt
“RFIs should therefore take special care when entering into and managing outsourcing agreements undertaken outside Trinidad and Tobago because of possible data protection risks and risks to effective supervision by the Central Bank.”
Link checked 19 August 2026
- Official sourceCentral Bank of Trinidad and TobagoCybersecurity Best Practices Guideline (September 2023)
central-bank.org.tt
“Each year companies should conduct annual self-assessments against the Guideline and submit these to the Central Bank by March 31st of the next calendar year.”
Link checked 19 August 2026
- Official sourceCentral Bank of Trinidad and TobagoCircular Letter — Cybersecurity Best Practices Guideline for Financial Institutions (re-issued July 2025)
central-bank.org.tt
Link checked 19 August 2026
Telecommunications Act, Chap. 47:31, section 24(1)(j), read with the Interception of Communications Act, Chap. 15:08, sections 13 and 18
Licence condition · Act No. 4 of 2001; Act No. 11 of 2010
Because the general privacy law's private sector part is dormant, the real privacy duty for telephone and internet companies is a condition of their operating licence: keep user information confidential and use it only for running and billing the service. Separately, providers must be able to assist interception warrants promptly and can be gagged from disclosing a data demand.
Enforced by Telecommunications Authority of Trinidad and Tobago
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Secure the dataConcession condition: maintain the confidentiality of users' confidential, personal and proprietary information.
- Delete data after a periodPurpose limitation: user information may only be used to operate the network or service, to bill and collect charges, to protect the concessionaire's rights or property, and a small number of other listed purposes.
- Keep logsNo general retention mandate found, but a provider can be ordered to obtain communications data it does not already hold.
- Keep the data in the countryNot a storage rule, but section 13 requires every telecommunications provider to take all steps necessary to ensure prompt assistance with interception warrants, which in practice requires in-country technical capability.
What it costs if you get it wrong
- Criminal liability: TTD 1,000,000 — about $148 thousandFailure to provide prompt interception assistance, on summary conviction (Interception of Communications Act, section 13(3)).
- Loss of your licenceBreach of concession conditions under the Telecommunications Act.
Sources
- Official sourceDigital Legislative Library, Government of Trinidad and TobagoTelecommunications Act, Chap. 47:31, section 24(1)(j)
laws.gov.tt
“refrain from using, and maintain the confidentiality of any confidential, personal and proprietary information of any user, other operator of a public telecommunications network or other provider of a telecommunications service”
Link checked 19 August 2026
- Official sourceDigital Legislative Library, Government of Trinidad and TobagoInterception of Communications Act, Chap. 15:08, sections 13 and 18
laws.gov.tt
“Every person or entity who provides a telecommunications service ... shall take all steps that are necessary to ensure that prompt assistance can be provided where necessary to comply with interception warrants granted under this Act.”
Link checked 19 August 2026
- Official sourceTelecommunications Authority of Trinidad and TobagoTelecommunications Authority of Trinidad and Tobago — market statistics current to 30 June 2026
tatt.org.tt
Link checked 19 August 2026
Gambling (Gaming and Betting) Control Act, 2021, Part III and Schedule 3
Act of parliament · Act No. 8 of 2021; Legal Notice 205 of 2021 (partial proclamation)
The tightest data-location rule on the statute book: gambling licensees must keep every record of the licensed activity physically at the licensed premises for seven years, which rules out remote-only cloud storage. Only the preliminary parts and the Commission itself were switched on in August 2021; the licensing part carrying this condition has never been proclaimed.
Enforced by Gambling (Gaming and Betting) Control Commission — not yet operational
Transfer model: Not allowed
What it makes you do
- Keep the data in the countrySchedule 3 paragraph 6: books, records and documents relating to the licensed activity must be kept AT the licensed premises. Not in force — Part III was not proclaimed.
- Keep data for a minimum period — 7 yearsSeven years after completion of the transaction to which the records relate. Not in force.
- Keep logsClosed-circuit television footage of the interior and exterior of licensed premises must be kept for fourteen days, or another period the Commission prescribes. Not in force.
- Register or notifyLicence required to own or operate a gaming establishment. Part III not in force.
Sources
- Official sourceParliament of the Republic of Trinidad and TobagoGambling (Gaming and Betting) Control Act, 2021 (Act No. 8 of 2021), Schedule 3 (to section 52(2))
ttparliament.org
“the keeping of books and other records which shall be kept at the gaming premises and retained for no less than seven years after the completion of the transaction to which such books and records relate”
Link checked 19 August 2026
- Official sourceGovernment Printer, Republic of Trinidad and TobagoLegal Notice No. 205 of 2021 — Proclamation of 11 August 2021 (Parts I, II and X and Schedule 1 only)
laws.gov.tt
Link checked 19 August 2026
Advance Passenger Information and Passenger Name Record Act, 2026
Act of parliament · Act No. 7 of 2026; gazetted Legal Supplement Part A, Vol. 65 No. 89, 21 May 2026
A signed but not yet switched-on law covering airline and ship passenger data. It sets a seven-year retention limit, strips identifying fields from booking records after six months, bans processing of sensitive data, and creates the country's first statutory data protection officer role.
Transfer model: Approval each time (the list is currently empty) · Accepted routes: Government sign-off needed, Official 'this country is safe' decision, Approved code of conduct
What it makes you do
- Delete data after a period — 7 yearsAdvance passenger information: not more than seven years from the date of travel, then deleted from every database. Passenger name records: deleted permanently seven years after transfer.
- Keep data for a minimum period — 7 yearsProcessing records kept for seven years for audit and self-monitoring.
- Put a transfer safeguard in placeData may go to another country's competent authority only if that country intends to use it consistently with the Act; where the destination's protection is lower, conflicts must be resolved before transfer using a legally binding instrument, binding rules conferring enforceable individual rights, or an agreed code of conduct.
- Tell affected peopleA high-risk personal data breach must be communicated to the individual and to the Data Protection Officer without undue delay.
- Keep records of processingThe Passenger Information Unit must log collection, consultation, disclosure and erasure operations.
- Appoint a data protection officerA Data Protection Officer and a Regional Data Protection Officer oversee compliance — the first statutory data protection officer role in Trinidad and Tobago law.
- Secure the dataTechnical and organisational measures appropriate to the risk.
What it costs if you get it wrong
- Criminal liability: Fines plus imprisonment for six months on several offencesVarious offences under the Act, none in force until proclamation.
Sources
- Official sourceParliament of the Republic of Trinidad and TobagoAdvance Passenger Information and Passenger Name Record Act, 2026 (Act No. 7 of 2026), sections 2, 16, 21, 29 and 30
ttparliament.org
“This Act comes into operation on such date as is fixed by the President by Proclamation.”
Link checked 19 August 2026
- Official sourceParliament of the Republic of Trinidad and TobagoParliament bill record — Assent: Awaiting Proclamation
ttparliament.org
Link checked 19 August 2026
Applies to every company1 rule
These bind you whatever business you are in, once the country's rules reach you.
Data Protection Act, Chap. 22:04
Act of parliament · Act No. 13 of 2011; Legal Notice 2 of 2012; Legal Notice 220 of 2021
Trinidad and Tobago's general privacy law. Only Part I (including the privacy principles), the sections creating the Office of the Information Commissioner, and one disclosure sub-section are in force. Everything that would create enforceable duties, rights procedures or penalties remains unproclaimed, and no Commissioner has ever been appointed.
Enforced by Office of the Information Commissioner — not yet operational
Transfer model: Allowlist (the list is currently empty) · Accepted routes: Official 'this country is safe' decision
What it makes you do
- Get consent — from 6 January 2012Principle (c) of section 6. In force but with no enforcement body.
- Tell people what you do — from 6 January 2012Principle (b): purpose must be identified before or at the time of collection.
- Secure the data — from 6 January 2012Principle (g): safeguards proportionate to sensitivity.
- Delete data after a period — from 6 January 2012Principle (e): keep only as long as necessary for the purpose collected.
- Let people see their data — from 6 January 2012Principle (j). The access procedure itself sits in Part IV and is not in force.
- Put a transfer safeguard in place — from 6 January 2012Principle (l): comparable safeguards must exist in the receiving jurisdiction. No list of comparable jurisdictions has ever been published.
- Appoint a data protection officerNot required. There is no data protection officer obligation anywhere in the Act.
What it costs if you get it wrong
- Criminal liability: TTD 100,000 and 5 years imprisonment (on indictment); TTD 50,000 and 3 years (summary) — about $15 thousandAny offence under the Act. Section 95 sits in Part V, which has NOT been brought into force as at 19 August 2026.
- Fixed maximum fine: TTD 500,000 (body corporate, on indictment) — about $74 thousandOffence committed by a body corporate. Section 95(2), Part V not in force.
- Percentage of global turnover: 10% of annual turnover of the enterpriseContravention of any provision by a corporation. Section 96, Part V not in force.
Sources
- Official sourceDigital Legislative Library, Government of Trinidad and TobagoData Protection Act, Chap. 22:04 — consolidated text
laws.gov.tt
“Part I and Sections 7–18, 22, 23, 25(1), 26 and 28 came into operation on the 6th January 2012.”
Link checked 19 August 2026
- Official sourceDigital Legislative Library, Government of Trinidad and TobagoDigital Legislative Library record for Data Protection Chap. 22:04 — 'This Act has only been partially proclaimed'
laws.gov.tt
Link checked 19 August 2026
- Official sourceGovernment Printer, Republic of Trinidad and TobagoLegal Notice No. 220 of 2021 — section 42(a) and (b) into operation on 23 August 2021
laws.gov.tt
Link checked 19 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
That no Information Commissioner has been appointed at any point between 1 January 2024 and 19 August 2026
We can evidence non-appointment directly from a ministerial statement in the Senate on 31 January 2023, from the absence of any Data Protection Act proclamation in the official Legal Notice register for 2022 to 2026, and from the absence of the office from the national government services directory. None of that proves a negative for every day since. Any appointment would ordinarily be gazetted, and we found none.
Whether the Gambling (Gaming and Betting) Control Commission is staffed and functioning
Two plausible official web addresses for the Commission did not resolve, and our search environment could not reach the Ministry of Digital Transformation site either. We rely on the proclamation record and the absence of published decisions. Rated 'not operational' with low confidence.
Whether any published government cloud, data hosting or data classification policy applies to ministries and state agencies
The Ministry of Digital Transformation website was unreachable from our environment throughout this run, so we could not check for a public sector cloud policy. The only statutory rule we could verify is section 36 of the Data Protection Act, which is not in force. There may be a procurement-level or Cabinet-level policy we did not see.
That reporting a cyber incident to the national cyber incident response team is voluntary rather than mandatory
The team's own site presents reporting as a service rather than a duty and cites no empowering statute. We found no legislation imposing a reporting obligation. Stated as 'no mandatory reporting rule found, checked 19 August 2026', not as a certainty.
Current sectoral guidance issued by the Telecommunications Authority on subscriber data and privacy
The Authority's regulatory framework and policy pages sit behind an automated bot challenge that our tooling could not clear. We verified the statutory concession condition directly from the Telecommunications Act instead, and could reach the Authority's home page only.
Whether the state of public emergency declared in 2025 and re-declared in 2026 is still in effect on 19 August 2026
The official Legal Notice register for 2026 shows Emergency Powers Regulations gazetted on 3 March 2026, a prohibition on public protests, and hundreds of individual detention orders, alongside revocation orders. We could not determine from notice titles alone whether the emergency itself was still running on the verification date. Treat the emergency powers as live until confirmed otherwise.
Whether any Trinidad and Tobago court has decided a case under the Data Protection Act
We did not complete a search of the Judiciary's judgment database within this run. Given that Parts III, IV and V are unproclaimed, a decision under the Act is unlikely but not impossible.
Health sector, education sector and mapping or geospatial data rules
No sector-specific data storage or transfer rule found for these areas, checked 19 August 2026, confidence medium. Health confidentiality in Trinidad and Tobago rests mainly on professional codes and common law rather than a data statute, and we did not verify those codes against an official source in this run.
Freshness and refresh
Freshness
Checked today — on 19 August 2026.
Re-checked every 60 days. Next check due 18 October 2026.
Put this next to another country
Trinidad and Tobago versus
Compare