Skip to the content
Global Data RulesData governance rules, country by country

Trinidad and Tobago

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 19 August 2026.

If you collect data about people in Trinidad and Tobago — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Depends on your industryWork: MediumEnforcement: Dormant

Trinidad and Tobago has a privacy law, but most of it is switched off. Parliament passed it in 2011. Only a small part was ever brought into force. The privacy principles apply on paper. The parts that create duties for companies and for government bodies were never started. Neither were any penalties. No Information Commissioner has ever been appointed. The rules that really bind you come from the Central Bank, the phone and internet regulator, and money-laundering law.

Data governance in Trinidad and Tobago

The eight things that decide how you handle data about people in Trinidad and Tobago. Same eight on every country page, so you can compare.

Who has to follow these rules

Almost certainly not, in any way you could be punished for. The privacy law does have a clause that applies even if you have no office there. It covers anyone who collects personal information from people in Trinidad and Tobago. It also covers anyone who uses a local internet or phone company to do it. That clause has never been switched on. There is no size or revenue cut-off. You do not need a local representative. Banks, insurers, phone companies and gambling operators need a local licence anyway. That licence is what actually binds you.

Where the data is allowed to live

In general yes, and nobody will stop you. One cross-border sentence is in force. It says data sent abroad must go somewhere that protects it as well as Trinidad and Tobago. It also says an official list of approved countries must be published. That list has never been published. The official who would publish it has never been appointed. So the rule cannot be used against you. Four industries are different, and they are set out below.

Ways to send data out:
Official 'this country is safe' decision

What to do: Check your own industry against the restricted list before you pick a hosting region.

Sending data out of the country

On paper, you can only send data to approved countries. The government would have to name each destination first. But the list has never been published. There is no regulator to publish it, and nobody to complain to. So the rule is not enforced. If the Central Bank supervises you, a different and real test applies. You must satisfy yourself that the destination protects data at least as well as Trinidad and Tobago does. You must get your customer's consent. And you must put the right terms in the contract.

What you have to do here:
Put a transfer safeguard in place
Ways to send data out:
Official 'this country is safe' decision · Explicit consent

The regulator, and whether it actually acts

Nobody enforces general privacy. The law creates an Office of the Information Commissioner. That office has existed in law since January 2012. No Commissioner has ever been appointed, and the office has never been staffed. In January 2023 the responsible government minister told the Senate he regretted that the office 'has not yet been fully operationalized'. Nothing has changed since. Other bodies do enforce related rules. The Central Bank covers financial firms. The Telecommunications Authority covers phone and internet companies. The money-laundering unit covers record-keeping.

How long you must keep it — and when to delete it

Minimum keep times are real. The maximum keep time is not enforced. If you handle money, you must keep transaction records, customer identity records, account files and correspondence for six years. Investment firms must keep their books for at least six years too. Electronic money issuers must keep customer and transaction files for seven years. Gambling licensees will have to keep records for seven years once that part of the law starts. The only delete-by rule says you should keep personal information no longer than you need it. Nobody enforces that rule. So when a keep rule and a delete rule clash, the keep rule wins.

What you have to do here:
Keep data for a minimum period · Delete data after a period · Keep records of how you use data

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

There is no general duty to report a data breach to anyone. There is no duty to tell the people affected either. That is the biggest gap in the country's rules. If the Central Bank regulates you, two deadlines apply. Alert the Central Bank within 24 hours of learning about a cyber incident. File the full report within 72 hours. The national cyber team accepts reports from anyone but cannot force you to file one. So most organisations have no deadline, and financial firms have two.

What you have to do here:
Report breaches to the regulator · Report cyber incidents · Secure the data

What to do: Your breach process has to reach Trinidad and Tobago's regulator inside the deadline above.

What catches people out

Five things catch people out here. First, a law that reads as binding is mostly switched off. Second, a law you would expect to protect online consumers is also switched off. Third, phone and internet companies can be ordered to go and collect data they do not even hold. They are banned from telling anyone about it. Fourth, the country has been under a state of emergency. Emergency orders can allow seized computers and phones to be searched. Fifth, the punishment written into the privacy law includes prison and a fine of up to a tenth of company turnover. That would be severe if it were ever switched on.

What you have to do here:
Do not hand data to foreign authorities on demand
What it costs if you get it wrong:
Criminal liability · Percentage of global turnover

What's changing next

One new law is signed and waiting to start. In May 2026 Parliament passed a law on airline and ship passenger data. It sets seven-year retention. It requires booking data to have identifying details stripped out after six months. It also sets conditions on sending that data to other countries. The President has signed it, but it has not been switched on. No bill to fix or replace the 2011 privacy law has been introduced. The bigger risk is not a new law. The President can switch on the sleeping parts of the existing privacy law at any time, with no consultation and no notice.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries5 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Government

Government data must stay in the country

Official name: Data Protection Act, Chap. 22:04, Part III (Protection of Personal Data by Public Bodies) · Act No. 13 of 2011, sections 29 to 68, in particular section 36 · Act of parliament

Passed, not yet fully in forceYes, with paperwork

This is the strictest data location rule in Trinidad and Tobago law. It would force ministries, municipal corporations, service commissions, the Tobago House of Assembly and state-owned companies to store and use personal information only inside the country. It has sat switched off since 2011. It is the single rule most likely to be turned on without notice.

Enforced by Office of the Information Commissioner — not yet operational

How this country controls where data goes: Approval each time (no country is on the approved list yet) · Accepted routes: Explicit consent, Official 'this country is safe' decision, Government sign-off needed

Finance

Cyber security rules

Official name: Guideline for the Management of Outsourcing Risks (February 2022), read with the Cybersecurity Best Practices Guideline (September 2023) · Issued under section 10(b) of the Financial Institutions Act, 2008 and section 278(1) of the Insurance Act, 2018 · Regulator guideline

In forceYes, with paperwork

These are the rules that actually bind banks, insurers, payment firms and electronic money issuers. Send data abroad only to countries that protect it at least as well as Trinidad and Tobago. Get customer consent. Keep the Central Bank's access rights in the contract. Report cyber incidents within 24 hours.

In force since 1 February 2022Enforced from 13 September 2023

Enforced by Central Bank of Trinidad and Tobago

How this country controls where data goes: Only approved countries (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision, Explicit consent

Telecoms

Telecoms rules

Official name: Telecommunications Act, Chap. 47:31, section 24(1)(j), read with the Interception of Communications Act, Chap. 15:08, sections 13 and 18 · Act No. 4 of 2001; Act No. 11 of 2010 · Licence condition

In forceYes, with paperwork

The private sector part of the general privacy law is switched off. So the real privacy duty for phone and internet companies is a condition of their operating licence. Keep user information confidential. Use it only to run and bill the service. Separately, providers must be able to help with interception warrants promptly. They can also be banned from telling anyone about a data demand.

In force since 5 July 2001

Enforced by Telecommunications Authority of Trinidad and Tobago

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Applies to every company1 rule

These bind you whatever business you are in, once the country's rules reach you.

General data protection law

Official name: Data Protection Act, Chap. 22:04 · Act No. 13 of 2011; Legal Notice 2 of 2012; Legal Notice 220 of 2021 · Act of parliament

Partly in forceYes, with paperwork

This is Trinidad and Tobago's general privacy law. Only part of it is in force. That part is Part I, which includes the privacy principles, plus the sections creating the Office of the Information Commissioner and one disclosure sub-section. Everything that would create enforceable duties, rights or penalties is still switched off. No Commissioner has ever been appointed.

In force since 6 January 2012

Enforced by Office of the Information Commissioner — not yet operational

How this country controls where data goes: Only approved countries (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision

Who you would hear from

  • Office of the Information Commissioner

    General data protection and privacy under the Data Protection Act, Chap. 22:04

    The office was created in law on 6 January 2012, when sections 7 to 18 started. No Information Commissioner and no Deputy have ever been appointed. The office has never been staffed and has no website of its own. On 31 January 2023 the Minister of Digital Transformation spoke to the Senate. He said the office 'has not yet been fully operationalized' and that recruitment still had to be arranged. No proclamation, appointment or decision has been recorded since. Its powers to run audits and enquiries (sections 19 to 21) and to report to Parliament (section 27) are not in force. Enforcement is dormant.

  • Central Bank of Trinidad and Tobago

    Banks, non-bank financial institutions, insurers, pension plans, payment service providers, e-money issuers and payment system operators. In practice the only body in the country actively supervising data handling, outsourcing and cyber incident reporting.

    Active. It issues circulars and guidelines continuously. It publishes an approved list of payment service providers, electronic money issuers and payment system operators, current as at 1 August 2026. It published a review of commercial banks' fees in August 2026. It requires annual cybersecurity self-assessments by 31 March.

  • Telecommunications Authority of Trinidad and Tobago

    Concessions and licences for telecommunications and broadcasting, including the user confidentiality condition in section 24(1)(j) of the Telecommunications Act

    Active. It publishes market statistics current to 30 June 2026, plus consultations, determinations and decisions. We found no published enforcement decision about the confidentiality condition.

  • Financial Intelligence Unit of Trinidad and Tobago (FIUTT)

    Anti-money-laundering record-keeping and reporting obligations for financial institutions and listed businesses

    Operational. It registers the firms it supervises and publishes compliance guidance, including guidance for particular industries.

  • TT-CSIRT

    National cyber incident coordination and voluntary incident reporting

    Operational since November 2015. Its incident statistics were last updated 23 July 2026. We found no law making reports to it compulsory. It coordinates rather than enforces.

  • Trinidad and Tobago Securities and Exchange Commission

    Securities market actors, including the six-year record-keeping duty in section 87 of the Securities Act

    Active. It publishes administrative sanctions orders, circulars and guidelines. We found no guidance for the securities industry on where data must be stored or on sending data abroad.

  • Gambling (Gaming and Betting) Control Commission

    Licensing and control of gaming and betting, including the keep-records-on-the-premises licence condition in Schedule 3

    Created in law on 11 August 2021, when Part II started. We could not reach any official website for the Commission, and found no published licensing decisions. The licensing rules it would run sit in Part III of the Act, which has never started. So it cannot yet do its main job. Treat 'not operational' as our best assessment, not a confirmed fact.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • That no Information Commissioner has been appointed at any point between 1 January 2024 and 19 August 2026

    We could not fully confirm that no Commissioner has been appointed. A minister said so in the Senate on 31 January 2023. The official Legal Notice register for 2022 to 2026 shows no proclamation of the Data Protection Act. The office does not appear in the national government services directory. None of that proves the position on every single day since. An appointment would normally be gazetted, and we found none.

  • Whether the Gambling (Gaming and Betting) Control Commission is staffed and functioning

    We could not confirm whether the Gambling Control Commission is staffed and working. We could not reach an official website for it, or the Ministry of Digital Transformation site. We rely on the proclamation record and on the lack of published decisions. We rate it 'not operational' with low confidence. Ask the Commission directly before you rely on this.

  • Whether any published government cloud, data hosting or data classification policy applies to ministries and state agencies

    We could not confirm whether the government has a published cloud or data hosting policy. The Ministry of Digital Transformation website was unreachable for us. The only rule we could verify is section 36 of the Data Protection Act, which is not in force. There may be a purchasing or Cabinet policy we did not see. If you sell to government, ask before you rely on this.

  • That reporting a cyber incident to the national cyber incident response team is voluntary rather than mandatory

    We could not confirm that reporting a cyber incident to the national cyber team is voluntary. Its own site presents reporting as a service rather than a duty, and names no law behind it. We found no law requiring a report. Checked 19 August 2026. Treat this as a rule we could not find, not a certainty.

  • Current sectoral guidance issued by the Telecommunications Authority on subscriber data and privacy

    We could not read the Telecommunications Authority's rules and policy pages. They sit behind an automated bot check that our tools could not pass. We confirmed the licence confidentiality condition directly from the Telecommunications Act instead. We could only reach the Authority's home page.

  • Whether the state of public emergency declared in 2025 and re-declared in 2026 is still in effect on 19 August 2026

    We could not confirm whether the state of emergency was still running on the date we checked. The official Legal Notice register for 2026 shows Emergency Powers Regulations gazetted on 3 March 2026. It also lists a ban on public protests, hundreds of individual detention orders, and some revocation orders. The notice titles alone do not tell us the current position. Treat the emergency powers as live until you confirm otherwise.

  • Whether any Trinidad and Tobago court has decided a case under the Data Protection Act

    We could not search the Judiciary's judgment database, so we cannot say whether any court has decided a case under the Act. Parts III, IV and V are not in force, so a decision is unlikely but possible. Check the court records if this matters to you.

  • Health sector, education sector and mapping or geospatial data rules

    We found no rule for these industries about where data must be stored or how it may be sent abroad. Checked 19 August 2026, confidence medium. Health confidentiality in Trinidad and Tobago rests mainly on professional codes and common law, not on a data law. We did not check those codes against a government source. If you work in these industries, check before you rely on this.

Freshness and refresh

Freshness

Checked about 2 months ago, on 19 August 2026.

Re-checked every 60 days. Next check due 18 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.