Skip to the content
Global Data RulesData governance rules, country by country

Trinidad and Tobago

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.

The answer

Depends on your industryWork: MediumEnforcement: Dormant

Trinidad and Tobago passed a privacy law in 2011 and then switched on only a small piece of it. The privacy principles apply on paper, but the parts that create duties for companies, duties for government bodies, and any punishment were never brought into force. No Information Commissioner has ever been appointed. The real rules come from the Central Bank, the telecoms regulator and money-laundering law.

Data governance in Trinidad and Tobago

The eight things that decide how you handle data about people in Trinidad and Tobago. Same eight on every country page, so you can compare.

Who has to follow these rules

Almost certainly not in any way you could be punished for. The privacy law does contain a clause that reaches anyone who collects personal information from people in Trinidad and Tobago, or who uses a local internet or phone company to do it, even with no office there. That clause has never been switched on. There is no size or revenue threshold and no requirement to appoint a local representative. If you are a bank, insurer, telephone company or gambling operator, you need a local licence anyway, and that licence is what actually binds you.

High confidenceNational rulesPartly in force

Where the data is allowed to live

In general yes, and nobody will stop you. The one cross-border sentence that is actually in force says data sent abroad must go somewhere with protection comparable to Trinidad and Tobago's, and that an official list of approved countries must be published. That list has never been published, because the official who would publish it has never been appointed. So the rule is a locked door with nobody holding the key. Four industries are different and are set out below.

High confidenceDepends on your industryAllowlistOfficial 'this country is safe' decision

Sending data out of the country

On paper the model is an approved-country list, which normally means you cannot send data anywhere until the government names the destination. In practice the list has never been published, and there is no regulator to publish it or to complain to, so the model is unenforced. If you are supervised by the Central Bank, the practical test is different and real: you must satisfy yourself the destination protects data at least as well as Trinidad and Tobago does, get your customer's consent, and write the right terms into the contract.

High confidenceAllowlistOfficial 'this country is safe' decisionExplicit consentPut a transfer safeguard in place

The regulator, and whether it actually acts

Nobody, for general privacy. The law creates an Office of the Information Commissioner and that office has legally existed since January 2012, but no Commissioner has ever been appointed and the office has never been staffed. In January 2023 the responsible government minister told the Senate he regretted that the office 'has not yet been fully operationalized'. Nothing has changed since. The bodies that do enforce data-adjacent rules are the Central Bank for financial firms, the telecoms authority for phone and internet companies, and the money-laundering unit for record-keeping.

High confidenceDormantPartly in force

How long you must keep it — and when to delete it

The floors are real and the ceiling is not. If you handle money you must keep transaction records, customer identity records, account files and correspondence for six years, and investment firms must keep their books for at least six years too. Electronic money issuers must keep customer and transaction files for seven years. Gambling licensees will have to keep records seven years once that part of the law starts. The only delete-by rule says personal information should be kept no longer than needed for the purpose it was collected for, and nobody enforces it, so when a keep-it rule and a delete-it rule clash, the keep-it rule wins in practice.

High confidenceKeep data for a minimum periodDelete data after a periodKeep records of processing

If something goes wrong

There is no general duty to report a data breach to anyone, and no duty to tell the people affected. That is the single biggest gap in the country's rules. If the Central Bank regulates you, there is a hard clock: alert the Central Bank within 24 hours of becoming aware of a cyber incident, and file the full report within 72 hours. The national cyber team accepts reports from anyone but cannot compel them. So most organisations have zero clocks and financial firms have two.

High confidenceReport breaches to the regulatorReport cyber incidentsSecure the data

What catches people out

Five things bite people here. A law that looks binding is mostly asleep. A second law you would assume protects online consumers is also asleep. Phone and internet companies can be ordered to go and collect data they do not even hold, and are forbidden from telling anyone. The country has been under a state of emergency, and emergency orders can authorise the searching of seized computers and phones. And the punishment written into the privacy law includes prison and a fine of up to a tenth of company turnover, which would be severe if it were ever switched on.

High confidenceCriminal liabilityPercentage of global turnoverPartly in forceDo not hand data to foreign authorities on demand

What's changing next

One new law is signed and waiting. In May 2026 Parliament passed a law on airline and ship passenger data that sets seven-year retention, six-month anonymisation of booking data, and conditions on sending that data to other countries. It has been signed by the President but not switched on. No bill to fix or replace the 2011 privacy law has been introduced. The bigger risk is not new legislation at all: the President can switch on the sleeping parts of the existing privacy law at any moment, with no consultation and no notice.

High confidencePassed, not yet fully in forceAct of parliament

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries5 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Government

Data Protection Act, Chap. 22:04, Part III (Protection of Personal Data by Public Bodies)

Act of parliament · Act No. 13 of 2011, sections 29 to 68, in particular section 36

Passed, not yet fully in forceYes, with paperwork

The strictest data residency rule in Trinidad and Tobago law would force ministries, municipal corporations, service commissions, the Tobago House of Assembly and state-owned companies to store and access personal information only inside the country. It has sat unproclaimed since 2011 and is the single provision most likely to be switched on without notice.

Enforced by Office of the Information Commissioner — not yet operational

Transfer model: Approval each time (the list is currently empty) · Accepted routes: Explicit consent, Official 'this country is safe' decision, Government sign-off needed

High confidence
Finance

Guideline for the Management of Outsourcing Risks (February 2022), read with the Cybersecurity Best Practices Guideline (September 2023)

Regulator guideline · Issued under section 10(b) of the Financial Institutions Act, 2008 and section 278(1) of the Insurance Act, 2018

In forceYes, with paperwork

The rules that actually bind banks, insurers, payment firms and e-money issuers. Send data abroad only to countries protecting it at least as well as Trinidad and Tobago, get customer consent, keep the Central Bank's access rights in the contract, and report cyber incidents within 24 hours.

In force since 1 February 2022But only enforceable from 13 September 2023

Enforced by Central Bank of Trinidad and Tobago

Transfer model: Allowlist (the list is currently empty) · Accepted routes: Official 'this country is safe' decision, Explicit consent

High confidence
Telecoms

Telecommunications Act, Chap. 47:31, section 24(1)(j), read with the Interception of Communications Act, Chap. 15:08, sections 13 and 18

Licence condition · Act No. 4 of 2001; Act No. 11 of 2010

In forceYes, with paperwork

Because the general privacy law's private sector part is dormant, the real privacy duty for telephone and internet companies is a condition of their operating licence: keep user information confidential and use it only for running and billing the service. Separately, providers must be able to assist interception warrants promptly and can be gagged from disclosing a data demand.

In force since 5 July 2001

Enforced by Telecommunications Authority of Trinidad and Tobago

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Applies to every company1 rule

These bind you whatever business you are in, once the country's rules reach you.

Data Protection Act, Chap. 22:04

Act of parliament · Act No. 13 of 2011; Legal Notice 2 of 2012; Legal Notice 220 of 2021

Partly in forceYes, with paperwork

Trinidad and Tobago's general privacy law. Only Part I (including the privacy principles), the sections creating the Office of the Information Commissioner, and one disclosure sub-section are in force. Everything that would create enforceable duties, rights procedures or penalties remains unproclaimed, and no Commissioner has ever been appointed.

In force since 6 January 2012

Enforced by Office of the Information Commissioner — not yet operational

Transfer model: Allowlist (the list is currently empty) · Accepted routes: Official 'this country is safe' decision

High confidence

Who you would hear from

  • Office of the Information Commissioner

    General data protection and privacy under the Data Protection Act, Chap. 22:04

    Established in law on 6 January 2012 when sections 7 to 18 were proclaimed. No Information Commissioner and no Deputy have ever been appointed, the office has never been staffed, and it has no website of its own. The Minister of Digital Transformation told the Senate on 31 January 2023 that the office 'has not yet been fully operationalized' and that recruitment had still to be arranged. No proclamation, appointment or decision has been recorded since. Its powers to conduct audits and enquiries (sections 19 to 21) and to report to Parliament (section 27) are not in force. Enforcement is dormant.

  • Central Bank of Trinidad and Tobago

    Banks, non-bank financial institutions, insurers, pension plans, payment service providers, e-money issuers and payment system operators. In practice the only body in the country actively supervising data handling, outsourcing and cyber incident reporting.

    Issuing circulars and guidelines continuously; published an approved list of payment service providers, e-money issuers and payment system operators as at 1 August 2026 and a thematic review of commercial banks' fees in August 2026. Requires annual cybersecurity self-assessments by 31 March.

  • Telecommunications Authority of Trinidad and Tobago

    Concessions and licences for telecommunications and broadcasting, including the user confidentiality condition in section 24(1)(j) of the Telecommunications Act

    Active: publishes market statistics current to 30 June 2026, consultations, determinations and decisions. We found no published enforcement decision specifically about the confidentiality condition.

  • Financial Intelligence Unit of Trinidad and Tobago (FIUTT)

    Anti-money-laundering record-keeping and reporting obligations for financial institutions and listed businesses

    Operational, registering supervised entities and publishing compliance guidance and sector-specific guidance.

  • TT-CSIRT

    National cyber incident coordination and voluntary incident reporting

    Operational since November 2015; published incident statistics last updated 23 July 2026. We found no statute making reporting to it mandatory, so it coordinates rather than enforces.

  • Trinidad and Tobago Securities and Exchange Commission

    Securities market actors, including the six-year record-keeping duty in section 87 of the Securities Act

    Active: publishes administrative sanctions orders, circulars and guidelines. We found no securities-sector data localisation or cross-border data guideline.

  • Gambling (Gaming and Betting) Control Commission

    Licensing and control of gaming and betting, including the keep-records-on-the-premises licence condition in Schedule 3

    Established in law on 11 August 2021 when Part II was proclaimed. We could not reach any official website for the Commission and found no published licensing decisions. The licensing regime it would administer, Part III of the Act, has never been proclaimed, so its central function cannot yet be exercised. Treat 'not operational' as our best assessment rather than a confirmed fact.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • That no Information Commissioner has been appointed at any point between 1 January 2024 and 19 August 2026

    We can evidence non-appointment directly from a ministerial statement in the Senate on 31 January 2023, from the absence of any Data Protection Act proclamation in the official Legal Notice register for 2022 to 2026, and from the absence of the office from the national government services directory. None of that proves a negative for every day since. Any appointment would ordinarily be gazetted, and we found none.

  • Whether the Gambling (Gaming and Betting) Control Commission is staffed and functioning

    Two plausible official web addresses for the Commission did not resolve, and our search environment could not reach the Ministry of Digital Transformation site either. We rely on the proclamation record and the absence of published decisions. Rated 'not operational' with low confidence.

  • Whether any published government cloud, data hosting or data classification policy applies to ministries and state agencies

    The Ministry of Digital Transformation website was unreachable from our environment throughout this run, so we could not check for a public sector cloud policy. The only statutory rule we could verify is section 36 of the Data Protection Act, which is not in force. There may be a procurement-level or Cabinet-level policy we did not see.

  • That reporting a cyber incident to the national cyber incident response team is voluntary rather than mandatory

    The team's own site presents reporting as a service rather than a duty and cites no empowering statute. We found no legislation imposing a reporting obligation. Stated as 'no mandatory reporting rule found, checked 19 August 2026', not as a certainty.

  • Current sectoral guidance issued by the Telecommunications Authority on subscriber data and privacy

    The Authority's regulatory framework and policy pages sit behind an automated bot challenge that our tooling could not clear. We verified the statutory concession condition directly from the Telecommunications Act instead, and could reach the Authority's home page only.

  • Whether the state of public emergency declared in 2025 and re-declared in 2026 is still in effect on 19 August 2026

    The official Legal Notice register for 2026 shows Emergency Powers Regulations gazetted on 3 March 2026, a prohibition on public protests, and hundreds of individual detention orders, alongside revocation orders. We could not determine from notice titles alone whether the emergency itself was still running on the verification date. Treat the emergency powers as live until confirmed otherwise.

  • Whether any Trinidad and Tobago court has decided a case under the Data Protection Act

    We did not complete a search of the Judiciary's judgment database within this run. Given that Parts III, IV and V are unproclaimed, a decision under the Act is unlikely but not impossible.

  • Health sector, education sector and mapping or geospatial data rules

    No sector-specific data storage or transfer rule found for these areas, checked 19 August 2026, confidence medium. Health confidentiality in Trinidad and Tobago rests mainly on professional codes and common law rather than a data statute, and we did not verify those codes against an official source in this run.

Freshness and refresh

Freshness

Checked today — on 19 August 2026.

Re-checked every 60 days. Next check due 18 October 2026.

Read the exact prompt used to research this page

Put this next to another country

Trinidad and Tobago versus

Compare

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.