Trinidad and Tobago
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 19 August 2026.
If you collect data about people in Trinidad and Tobago — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
Trinidad and Tobago has a privacy law, but most of it is switched off. Parliament passed it in 2011. Only a small part was ever brought into force. The privacy principles apply on paper. The parts that create duties for companies and for government bodies were never started. Neither were any penalties. No Information Commissioner has ever been appointed. The rules that really bind you come from the Central Bank, the phone and internet regulator, and money-laundering law.
Data governance in Trinidad and Tobago
The eight things that decide how you handle data about people in Trinidad and Tobago. Same eight on every country page, so you can compare.
Who has to follow these rules
Almost certainly not, in any way you could be punished for. The privacy law does have a clause that applies even if you have no office there. It covers anyone who collects personal information from people in Trinidad and Tobago. It also covers anyone who uses a local internet or phone company to do it. That clause has never been switched on. There is no size or revenue cut-off. You do not need a local representative. Banks, insurers, phone companies and gambling operators need a local licence anyway. That licence is what actually binds you.
Section 69 of the Data Protection Act, Chap. 22:04 is the clause that reaches companies with no office in the country. It sits in Part IV, which covers the private sector. Part IV has never been brought into force. Only these parts are in force. Part I, and sections 7 to 18, 22, 23, 25(1), 26 and 28, from 6 January 2012 under Legal Notice 2 of 2012. Also section 42(a) and (b), from 23 August 2021 under Legal Notice 220 of 2021. Section 6 sits in Part I, so it is in force. It says the General Privacy Principles apply to everyone who handles, stores or uses personal information belonging to another person. That is a very wide reach. Nothing sits behind it, because Parts III, IV and V are all switched off. Financial firms face one real location rule. An electronic money issuer must be a company with its registered office in Trinidad and Tobago.
Sources
- Official sourceDigital Legislative Library, Government of Trinidad and TobagoData Protection Act, Chap. 22:04 — consolidated text, sections 1(2), 6 and 69
laws.gov.tt
“A person who— (a) collects, retains, manages, uses, processes or stores personal information in Trinidad and Tobago; (b) collects personal information from individuals in Trinidad and Tobago; or (c) uses an intermediary or telecommunications service provider located in Trinidad and Tobago ... shall follow the General Privacy Principles set out in section 6”
Link checked 19 August 2026
- Official sourceGovernment Printer, Republic of Trinidad and TobagoLegal Notice No. 2 of 2012 — Proclamation bringing Part I and sections 7 to 18, 22, 23, 25(1), 26 and 28 into operation on 6 January 2012
laws.gov.tt
Link checked 19 August 2026
- Official sourceCentral Bank of Trinidad and TobagoE-Money Issuer Order, 2020 (Legal Notice 284 of 2020), clause 9(1)
central-bank.org.tt
“An EMI shall be a body corporate with its registered office in Trinidad and Tobago.”
Link checked 19 August 2026
Where the data is allowed to live
In general yes, and nobody will stop you. One cross-border sentence is in force. It says data sent abroad must go somewhere that protects it as well as Trinidad and Tobago. It also says an official list of approved countries must be published. That list has never been published. The official who would publish it has never been appointed. So the rule cannot be used against you. Four industries are different, and they are set out below.
- Ways to send data out:
- Official 'this country is safe' decision
Industry by industry. BANKING, INSURANCE AND PAYMENTS: data can leave only if conditions are met The Central Bank's Guideline for the Management of Outsourcing Risks (February 2022) applies to regulated financial firms. It tells them to use service providers only in certain countries. The country's data protection and privacy law, regulation or supervision must be equal to Trinidad and Tobago's, or better. You must get customer consent before sending customer information to a service provider. You must also tell the Central Bank if a foreign authority asks for access to customer data. GOVERNMENT AND PUBLIC BODIES: data must stay in the country on paper, but not in force. Section 36 of the Data Protection Act would make a public body store personal information only in Trinidad and Tobago. It could also be reached only from Trinidad and Tobago. There are two exceptions. The person consents in the way the law sets out, or the destination has comparable safeguards. 'Public body' covers ministries, municipal corporations, service commissions, the Tobago House of Assembly and state-owned companies. Section 36 sits in Part III, which has never been brought into force. GAMBLING: data must stay in the country on paper, not in force. Schedule 3 to the Gambling (Gaming and Betting) Control Act, 2021 sets a licence condition. You must keep all books, records and documents about the licensed activity at the licensed premises. They must be kept at least seven years. Only Parts I, II and X and Schedule 1 started, on 11 August 2021. Part III covers licensing and carries Schedule 3. It is not in force. TELECOMS: data can leave only if conditions are met in substance. A concession holder must keep user information confidential. It may use that information only to run the network, to bill, to protect its property, and for a few other listed purposes. It must also be able to give prompt help with interception warrants. That normally means keeping the technical ability inside the country. BORDER AND TRAVEL: data can leave only if conditions are met The law is passed but not in force. HEALTH, EDUCATION, SECURITIES, DEFENCE AND MAPPING: we found no rule about sending data abroad. Checked 19 August 2026, confidence medium.
Sources
- Official sourceDigital Legislative Library, Government of Trinidad and TobagoData Protection Act, Chap. 22:04 — section 6(l) (in force), section 28 (in force), section 36 (not in force)
laws.gov.tt
“personal information which is requested to be disclosed outside of Trinidad and Tobago shall be regulated and comparable safeguards to those under this Act shall exist in the jurisdiction receiving the personal information.”
Link checked 19 August 2026
- Official sourceCentral Bank of Trinidad and TobagoGuideline for the Management of Outsourcing Risks (February 2022), paragraph 9.2.1
central-bank.org.tt
“In principle, enter into arrangements only with service providers operating in jurisdictions with an equivalent (or higher) standard of data protection and privacy legislation, regulation or supervision as exists in Trinidad and Tobago”
Link checked 19 August 2026
- Official sourceParliament of the Republic of Trinidad and TobagoGambling (Gaming and Betting) Control Act, 2021 (Act No. 8 of 2021), Schedule 3 paragraph 6
ttparliament.org
“It shall be a condition of a licence that the licensee shall ensure that all books, records and documents relating to the licensed activity are— (a) kept at the licensed premises; and (b) retained for not less than seven years”
Link checked 19 August 2026
- Official sourceDigital Legislative Library, Government of Trinidad and TobagoTelecommunications Act, Chap. 47:31, section 24(1)(j)
laws.gov.tt
Link checked 19 August 2026
What to do: Check your own industry against the restricted list before you pick a hosting region.
Sending data out of the country
On paper, you can only send data to approved countries. The government would have to name each destination first. But the list has never been published. There is no regulator to publish it, and nobody to complain to. So the rule is not enforced. If the Central Bank supervises you, a different and real test applies. You must satisfy yourself that the destination protects data at least as well as Trinidad and Tobago does. You must get your customer's consent. And you must put the right terms in the contract.
- What you have to do here:
- Put a transfer safeguard in place
- Ways to send data out:
- Official 'this country is safe' decision · Explicit consent
Section 28 of the Data Protection Act is in force. It requires the Information Commissioner to publish a list of countries with comparable safeguards for personal information. The list must appear in the Gazette and in two daily newspapers. No such list has ever been published, because no Commissioner has been appointed. The list is empty, and right now nobody can add to it. So a rule that allows only approved countries behaves like no rule at all. For public bodies, section 46 would set up a case-by-case route. The body would have to tell the person, get consent, and send doubtful destinations to the Commissioner to decide whether safeguards are comparable. Section 46 is not in force. For Central Bank licensees, four things actually matter. The equivalence test in the outsourcing guideline. Customer consent under paragraph 5.7.3. Contract terms that keep the Central Bank's access to books and records. And a duty to tell the Central Bank if any overseas authority asks for access to customer information. Existing major outsourcing contracts had to be reported to the Inspector of Financial Institutions within six months of the guideline being issued.
Sources
- Official sourceDigital Legislative Library, Government of Trinidad and TobagoData Protection Act, Chap. 22:04, sections 28 and 46
laws.gov.tt
“The Commissioner shall by Order publish in the Gazette and at least two newspapers in daily circulation in Trinidad and Tobago a list of countries which have comparable safeguards for personal information as provided by this Act.”
Link checked 19 August 2026
- Official sourceCentral Bank of Trinidad and TobagoGuideline for the Management of Outsourcing Risks (February 2022), paragraphs 5.7.3, 9.2.1, 9.2.4 and 12.1.2
central-bank.org.tt
“Any transfer of customer information from the RFI to a third party service provider under the terms of an outsourcing contract should be with the customer's consent.”
Link checked 19 August 2026
- Official sourceParliament of the Republic of Trinidad and TobagoSenate Hansard, 31 January 2023 — debate on the Data Protection Act 2011
ttparliament.org
Link checked 19 August 2026
The regulator, and whether it actually acts
Nobody enforces general privacy. The law creates an Office of the Information Commissioner. That office has existed in law since January 2012. No Commissioner has ever been appointed, and the office has never been staffed. In January 2023 the responsible government minister told the Senate he regretted that the office 'has not yet been fully operationalized'. Nothing has changed since. Other bodies do enforce related rules. The Central Bank covers financial firms. The Telecommunications Authority covers phone and internet companies. The money-laundering unit covers record-keeping.
Sections 7 to 18 of the Data Protection Act came into force on 6 January 2012. They set up the Office and provide for appointing the Commissioner, the Deputy and staff. Other sections were never started and are still not in force as at 19 August 2026. Section 19 covers inspectors and their powers. Sections 20 and 21 cover audits and enquiries. Section 24 covers privileged information. Section 27 covers the annual report to Parliament. All of Parts III, IV and V are switched off too. A Senate motion asked the Government to bring the remaining sections into force. It was debated on 31 January, 28 February and 28 March 2023 and passed as amended. No proclamation followed. We reviewed the official register of Legal Notices for 2022, 2023, 2024, 2025 and 2026. We found no further proclamation of any part of the Data Protection Act. The office has no website and does not appear in the national government services directory. Enforcement rating: dormant. Other regulators are active. The Central Bank of Trinidad and Tobago issues circulars and requires annual cybersecurity self-assessments. The Trinidad and Tobago Securities and Exchange Commission publishes administrative sanctions orders. The Telecommunications Authority publishes current market statistics and decisions. The national cyber incident response team publishes incident statistics, updated to 23 July 2026. None of these is a privacy regulator.
Sources
- Official sourceParliament of the Republic of Trinidad and TobagoSenate Hansard, 31 January 2023 — statement of the Minister of Digital Transformation on the Office of the Information Commissioner
ttparliament.org
“I have my regrets of the fact that the Office of the Information Commissioner has not yet been fully operationalized and that has spanned several administrations.”
Link checked 19 August 2026
- Official sourceParliament of the Republic of Trinidad and TobagoSenate motion: Proclaim the remaining sections of the Data Protection Act (debated 31 January, 28 February and 28 March 2023)
ttparliament.org
Link checked 19 August 2026
- Official sourceDigital Legislative Library, Government of Trinidad and TobagoChronological register of Legal Notices, 1838 to 2026 — reviewed for 2022 to 2026, no further Data Protection Act proclamation
laws.gov.tt
Link checked 19 August 2026
- Official sourceCentral Bank of Trinidad and TobagoCybersecurity — supervisory expectations for regulated institutions
central-bank.org.tt
Link checked 19 August 2026
How long you must keep it — and when to delete it
Minimum keep times are real. The maximum keep time is not enforced. If you handle money, you must keep transaction records, customer identity records, account files and correspondence for six years. Investment firms must keep their books for at least six years too. Electronic money issuers must keep customer and transaction files for seven years. Gambling licensees will have to keep records for seven years once that part of the law starts. The only delete-by rule says you should keep personal information no longer than you need it. Nobody enforces that rule. So when a keep rule and a delete rule clash, the keep rule wins.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period · Keep records of how you use data
MINIMUM KEEP TIMES. Money laundering: six years. That covers all local and international transactions, customer identity checks, account files, business correspondence, and the results of analysis of an account transaction. Securities: section 87(4) of the Securities Act, Chap. 83:02 requires any book, record or document kept under that Act to be kept for at least six years. Electronic money: clause 22 of the E-Money Issuer Order, 2020 requires record systems that keep customer and transaction files for a minimum of seven years. Gambling: seven years from the end of the transaction the records relate to, at the licensed premises, once Part III starts. Passenger data: seven years under the Advance Passenger Information and Passenger Name Record Act, 2026, once it starts. Booking record data must have identifying details stripped out after six months. MAXIMUM KEEP TIME. Principle (e) of section 6 of the Data Protection Act is in force. It says personal information 'shall only be retained for as long as is necessary for the purpose collected'. There is no regulator, no penalty in force and no published guidance. So this limit is not enforced. CONFLICT. Trinidad and Tobago's laws have no express conflict rule. The specific minimum keep times can be enforced and the general privacy limit cannot. So the minimum keep time wins.
Sources
- Official sourceFinancial Intelligence Unit of Trinidad and TobagoAML/CFT Obligations for Registered Supervised Entities — record retention
fiu.gov.tt
“Financial institutions and listed businesses must retain the following records in electronic or written form for a period of six (6) years”
Link checked 19 August 2026
- Official sourceDigital Legislative Library, Government of Trinidad and TobagoSecurities Act, Chap. 83:02, section 87(4)
laws.gov.tt
“Any book, record or other document required to be kept under this Act shall be kept for a period of at least six years or as otherwise prescribed.”
Link checked 19 August 2026
- Official sourceCentral Bank of Trinidad and TobagoE-Money Issuer Order, 2020, clause 22 (record retention)
central-bank.org.tt
“An EMI shall have record keeping systems that retain customer and transaction files for a minimum period of seven years”
Link checked 19 August 2026
- Official sourceDigital Legislative Library, Government of Trinidad and TobagoData Protection Act, Chap. 22:04, section 6(e)
laws.gov.tt
Link checked 19 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
If something goes wrong
There is no general duty to report a data breach to anyone. There is no duty to tell the people affected either. That is the biggest gap in the country's rules. If the Central Bank regulates you, two deadlines apply. Alert the Central Bank within 24 hours of learning about a cyber incident. File the full report within 72 hours. The national cyber team accepts reports from anyone but cannot force you to file one. So most organisations have no deadline, and financial firms have two.
- What you have to do here:
- Report breaches to the regulator · Report cyber incidents · Secure the data
DEADLINE 1: Central Bank, 24 hours. The Cybersecurity Best Practices Guideline (September 2023) was issued under section 10(b) of the Financial Institutions Act, 2008 and section 278(1) of the Insurance Act, 2018. It says you must alert the Central Bank as soon as possible. The limit is 24 hours from becoming aware of a cyber incident. DEADLINE 2: Central Bank, 72 hours. You must send the Cyber Incident Reporting Template within 72 hours of the incident. Then you send regular updates, for example daily, until it is resolved. You also do a post-incident review. If you fail to report, the Central Bank may impose extra supervisory reporting or compliance directions. The outsourcing guideline adds a separate duty. You must tell the Central Bank about any unauthorised access or breach of confidentiality by a service provider or sub-contractor. DEADLINE 3: none for everyone else. The Data Protection Act has no breach reporting rule at all, in force or otherwise. The Trinidad and Tobago Cyber Security Incident Response Team runs a reporting portal and publishes incident statistics, last updated 23 July 2026. We found no law that makes a report to it compulsory. FUTURE DEADLINE. The Advance Passenger Information and Passenger Name Record Act, 2026 covers high-risk personal data breaches. You must tell the person affected and a Data Protection Officer without undue delay. That Act is not yet in force.
Sources
- Official sourceCentral Bank of Trinidad and TobagoCybersecurity Best Practices Guideline (September 2023), Appendix II — Cybersecurity Incident Reporting
central-bank.org.tt
“As soon as possible but within 24 hours of becoming aware of a cyber-incident, the company shall alert the Central Bank, that a cyber-incident has occurred.”
Link checked 19 August 2026
- Official sourceTrinidad and Tobago Cyber Security Incident Response TeamReport an Incident — national cyber security incident reporting portal
ttcsirt.gov.tt
Link checked 19 August 2026
- Official sourceParliament of the Republic of Trinidad and TobagoAdvance Passenger Information and Passenger Name Record Act, 2026 (Act No. 7 of 2026), section 28(12)
ttparliament.org
Link checked 19 August 2026
What to do: Your breach process has to reach Trinidad and Tobago's regulator inside the deadline above.
What catches people out
Five things catch people out here. First, a law that reads as binding is mostly switched off. Second, a law you would expect to protect online consumers is also switched off. Third, phone and internet companies can be ordered to go and collect data they do not even hold. They are banned from telling anyone about it. Fourth, the country has been under a state of emergency. Emergency orders can allow seized computers and phones to be searched. Fifth, the punishment written into the privacy law includes prison and a fine of up to a tenth of company turnover. That would be severe if it were ever switched on.
- What you have to do here:
- Do not hand data to foreign authorities on demand
- What it costs if you get it wrong:
- Criminal liability · Percentage of global turnover
TRAP 1: the law reads as binding but is not. Read the Data Protection Act and you find detailed duties on public bodies, private companies, directors and officers. Parts III, IV and V have never been brought into force. A compliance programme built from the statute text alone rests on sections that do not operate. TRAP 2: the Electronic Transactions Act, Chap. 22:05 is also only partly in force. Parts I to IV and Part VII started in January 2012. Part V covers electronic authentication service providers. Part VI covers liability of intermediaries and telecoms service providers. Part VIII covers consumer protection and unwanted commercial messages. Part IX covers offences. Parts V, VI, VIII, IX and X have not started. So there is no anti-spam rule in force, and no legal shelter in force for online intermediaries. TRAP 3: forced collection plus a gag. Section 18 of the Interception of Communications Act, Chap. 15:08 lets an authorised officer with a warrant demand communications data from a telecoms provider. If the provider does not already hold the data, it can be required 'to obtain the data and so disclose it'. The provider must not tell anyone the notice exists, except its own staff and its lawyers. Section 13 makes it an offence to fail to give prompt interception help. The fine is one million Trinidad and Tobago dollars, roughly one hundred and fifty thousand United States dollars. TRAP 4: emergency powers. Emergency Powers Regulations were made under section 7 of the Constitution and published on 3 March 2026. They let the Minister responsible for internal security make Orders 'authorising the interrogation of computers and electronic devices seized'. Detention orders under those Regulations were still being gazetted through 2026. TRAP 5: the sleeping penalty is unusually harsh. Section 95 of the Data Protection Act allows prison of up to five years on indictment. Section 96 lets a court fine a company up to ten per cent of the annual turnover of the enterprise. Directors and officers who directed or agreed to an offence commit the offence themselves. None of Part V is in force. So this risk could appear overnight rather than existing today.
Sources
- Official sourceDigital Legislative Library, Government of Trinidad and TobagoElectronic Transactions Act, Chap. 22:05, section 1(2) — only Parts I to IV and Part VII commenced
laws.gov.tt
“Parts I, II, III and IV of this Act came into operation on 6th January 2012. Part VII of this Act came into operation on 18th January 2012.”
Link checked 19 August 2026
- Official sourceDigital Legislative Library, Government of Trinidad and TobagoInterception of Communications Act, Chap. 15:08, sections 13 and 18
laws.gov.tt
“if the provider is not already in possession of the data, to obtain the data and so disclose it.”
Link checked 19 August 2026
- Official sourceGovernment Printer, Republic of Trinidad and TobagoLegal Notice No. 40 of 2026 — The Emergency Powers Regulations, 2026, regulation 3(g)
laws.gov.tt
“authorising the interrogation of computers and electronic devices seized under paragraph (f)”
Link checked 19 August 2026
- Official sourceDigital Legislative Library, Government of Trinidad and TobagoData Protection Act, Chap. 22:04, sections 94, 95 and 96 (Part V, not in force)
laws.gov.tt
“Where a corporation contravenes any of the provisions of this Act, the Court may impose a fine of up to ten per cent of the annual turnover of the enterprise.”
Link checked 19 August 2026
What's changing next
One new law is signed and waiting to start. In May 2026 Parliament passed a law on airline and ship passenger data. It sets seven-year retention. It requires booking data to have identifying details stripped out after six months. It also sets conditions on sending that data to other countries. The President has signed it, but it has not been switched on. No bill to fix or replace the 2011 privacy law has been introduced. The bigger risk is not a new law. The President can switch on the sleeping parts of the existing privacy law at any time, with no consultation and no notice.
COMING. The Advance Passenger Information and Passenger Name Record Act, 2026 (Act No. 7 of 2026) was signed on 15 May 2026 and gazetted on 21 May 2026. Its section 2 says it starts on a date the President fixes by Proclamation. Parliament's own bill tracker records its status as 'Assent: Awaiting Proclamation'. It repeals and replaces the Immigration (Advance Passenger Information) Act. It also puts the CARICOM Advance Passenger Information System into operation. NOT COMING, so far. We checked Parliament's bills index on 19 August 2026. No Data Protection (Amendment) Bill has been introduced. In January 2023 the responsible minister told the Senate that updates were being developed with international consultants and Inter-American Development Bank support. More than three years later, no bill has been laid. SWITCHES THAT COULD BE FLIPPED. First and largest: section 1(2) of the Data Protection Act lets the President bring any remaining section into force on any chosen day, by Proclamation. That single act would switch on section 36, which keeps public sector data stored and reachable only in Trinidad and Tobago. It would also switch on all private sector duties in Part IV, and the prison and turnover-percentage penalties in Part V. Second: section 100 lets the Minister make Regulations under the Act. Third: section 71 lets the Information Commissioner, once appointed, order any industry to write a compulsory code of conduct. Section 74 makes such a code binding. Fourth: Part III of the Gambling (Gaming and Betting) Control Act, 2021 can start at any time. That would switch on the licence condition to keep records on the premises. Fifth: Emergency Powers Regulations can be revived or amended during a state of public emergency. None of these needs consultation.
Sources
- Official sourceParliament of the Republic of Trinidad and TobagoThe Advance Passenger Information and Passenger Name Record Bill, 2026 — status: Assent, Awaiting Proclamation
ttparliament.org
Link checked 19 August 2026
- Official sourceParliament of the Republic of Trinidad and TobagoBills before Parliament — index reviewed 19 August 2026, no Data Protection amendment bill
ttparliament.org
Link checked 19 August 2026
- Official sourceGovernment Printer, Republic of Trinidad and TobagoLegal Notice No. 205 of 2021 — Proclamation bringing only Parts I, II and X and Schedule 1 of the Gambling (Gaming and Betting) Control Act, 2021 into operation
laws.gov.tt
“And whereas it is expedient that Parts I, II and X and Schedule 1 of the Act come into operation”
Link checked 19 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries5 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Government data must stay in the country
Official name: Data Protection Act, Chap. 22:04, Part III (Protection of Personal Data by Public Bodies) · Act No. 13 of 2011, sections 29 to 68, in particular section 36 · Act of parliament
This is the strictest data location rule in Trinidad and Tobago law. It would force ministries, municipal corporations, service commissions, the Tobago House of Assembly and state-owned companies to store and use personal information only inside the country. It has sat switched off since 2011. It is the single rule most likely to be turned on without notice.
Enforced by Office of the Information Commissioner — not yet operational
How this country controls where data goes: Approval each time (no country is on the approved list yet) · Accepted routes: Explicit consent, Official 'this country is safe' decision, Government sign-off needed
What you have to do
- Keep the data in the countrySection 36: personal information must be stored only in Trinidad and Tobago. It may be reached only from Trinidad and Tobago. Two exceptions: the person consents in the way the law sets out, or the other country has comparable safeguards. NOT IN FORCE.
- Put a transfer safeguard in placeSection 46: tell the person, get consent, and send doubtful destinations to the Information Commissioner to decide whether safeguards are comparable. NOT IN FORCE.
- Assess high-risk projectsSection 47: privacy impact assessment and mitigation. NOT IN FORCE.
- Keep records of how you use dataSections 48 and 51: personal information banks and a personal information index. NOT IN FORCE.
- Let people see their dataSection 52. NOT IN FORCE.
- Let people correct their dataSection 57. NOT IN FORCE.
Sources
- Official sourceDigital Legislative Library, Government of Trinidad and TobagoData Protection Act, Chap. 22:04, sections 2 ('public body'), 36, 46, 47
laws.gov.tt
“A public body shall ensure or take steps to ensure that personal information in its custody or under its control is stored only in Trinidad and Tobago and accessed only in Trinidad and Tobago unless— (a) the individual to whom the information relates has identified the information and has consented in the prescribed manner to its being stored in or accessed from another jurisdiction; or (b) the information is stored in or accessed from another jurisdiction that has comparable safeguards as provided by this Act.”
Link checked 19 August 2026
- Official sourceParliament of the Republic of Trinidad and TobagoSenate Hansard, 31 January 2023 — list of Data Protection Act provisions never proclaimed
ttparliament.org
Link checked 19 August 2026
Cyber security rules
Official name: Guideline for the Management of Outsourcing Risks (February 2022), read with the Cybersecurity Best Practices Guideline (September 2023) · Issued under section 10(b) of the Financial Institutions Act, 2008 and section 278(1) of the Insurance Act, 2018 · Regulator guideline
These are the rules that actually bind banks, insurers, payment firms and electronic money issuers. Send data abroad only to countries that protect it at least as well as Trinidad and Tobago. Get customer consent. Keep the Central Bank's access rights in the contract. Report cyber incidents within 24 hours.
Enforced by Central Bank of Trinidad and Tobago
How this country controls where data goes: Only approved countries (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision, Explicit consent
What you have to do
- Put a transfer safeguard in placeUse service providers abroad only in countries whose data protection standard is equal to Trinidad and Tobago's, or higher.
- Get consentYou need customer consent before customer information goes to an outside service provider. You can take that consent up front, as a term of the customer agreement.
- Written vendor contractThe contract must let the Central Bank access all information, books and records relating to the outsourced activity on request.
- Do not hand data to foreign authorities on demandTell the Central Bank if an overseas authority asks for access to customer information. Also tell it if your access rights, or the Central Bank's, are restricted or denied.
- Register or notify — 6 monthsYou had to report existing major outsourcing contracts to the Inspector of Financial Institutions within six months of the guideline being issued.
- Report cyber incidents — within 24 hours, from 13 September 2023Alert the Central Bank within 24 hours of becoming aware of a cyber incident.
- Report breaches to the regulator — within 72 hours, from 13 September 2023Submit the Cyber Incident Reporting Template within 72 hours, then regular updates until closure.
- Independent audit — 1 yearAnnual cybersecurity self-assessment submitted to the Central Bank by 31 March of the following calendar year.
- Secure the dataTwenty requirements across governance, risk management, awareness and training, business continuity, testing, and incident management.
What it costs if you get it wrong
- Order to stopFailure to report a cyber incident may result in enhanced supervisory reporting and the issuance of compliance directions.
Sources
- Official sourceCentral Bank of Trinidad and TobagoGuideline for the Management of Outsourcing Risks (February 2022)
central-bank.org.tt
“RFIs should therefore take special care when entering into and managing outsourcing agreements undertaken outside Trinidad and Tobago because of possible data protection risks and risks to effective supervision by the Central Bank.”
Link checked 19 August 2026
- Official sourceCentral Bank of Trinidad and TobagoCybersecurity Best Practices Guideline (September 2023)
central-bank.org.tt
“Each year companies should conduct annual self-assessments against the Guideline and submit these to the Central Bank by March 31st of the next calendar year.”
Link checked 19 August 2026
- Official sourceCentral Bank of Trinidad and TobagoCircular Letter — Cybersecurity Best Practices Guideline for Financial Institutions (re-issued July 2025)
central-bank.org.tt
Link checked 19 August 2026
Telecoms rules
Official name: Telecommunications Act, Chap. 47:31, section 24(1)(j), read with the Interception of Communications Act, Chap. 15:08, sections 13 and 18 · Act No. 4 of 2001; Act No. 11 of 2010 · Licence condition
The private sector part of the general privacy law is switched off. So the real privacy duty for phone and internet companies is a condition of their operating licence. Keep user information confidential. Use it only to run and bill the service. Separately, providers must be able to help with interception warrants promptly. They can also be banned from telling anyone about a data demand.
Enforced by Telecommunications Authority of Trinidad and Tobago
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Secure the dataConcession condition: maintain the confidentiality of users' confidential, personal and proprietary information.
- Delete data after a periodUser information may only be used for set purposes. Those are running the network or service, billing and collecting charges, protecting the licence holder's rights or property, and a few other listed purposes.
- Keep logsNo general retention mandate found, but a provider can be ordered to obtain communications data it does not already hold.
- Keep the data in the countryThis is not a storage rule. Section 13 requires every telecoms provider to take all steps needed to give prompt help with interception warrants. That normally requires technical capability inside the country.
What it costs if you get it wrong
- Criminal liability: TTD 1,000,000 — about $148 thousandFailure to provide prompt interception assistance, on summary conviction (Interception of Communications Act, section 13(3)).
- Loss of your licenceBreach of concession conditions under the Telecommunications Act.
Sources
- Official sourceDigital Legislative Library, Government of Trinidad and TobagoTelecommunications Act, Chap. 47:31, section 24(1)(j)
laws.gov.tt
“refrain from using, and maintain the confidentiality of any confidential, personal and proprietary information of any user, other operator of a public telecommunications network or other provider of a telecommunications service”
Link checked 19 August 2026
- Official sourceDigital Legislative Library, Government of Trinidad and TobagoInterception of Communications Act, Chap. 15:08, sections 13 and 18
laws.gov.tt
“Every person or entity who provides a telecommunications service ... shall take all steps that are necessary to ensure that prompt assistance can be provided where necessary to comply with interception warrants granted under this Act.”
Link checked 19 August 2026
- Official sourceTelecommunications Authority of Trinidad and TobagoTelecommunications Authority of Trinidad and Tobago — market statistics current to 30 June 2026
tatt.org.tt
Link checked 19 August 2026
Online gaming data must stay in the country
Official name: Gambling (Gaming and Betting) Control Act, 2021, Part III and Schedule 3 · Act No. 8 of 2021; Legal Notice 205 of 2021 (partial proclamation) · Act of parliament
This is the tightest data location rule on the statute book. Gambling licensees must keep every record of the licensed activity physically at the licensed premises for seven years. That rules out cloud-only storage. Only the opening parts and the Commission itself were switched on in August 2021. The licensing part that carries this condition has never been brought into force.
Enforced by Gambling (Gaming and Betting) Control Commission — not yet operational
How this country controls where data goes: Not allowed
What you have to do
- Keep the data in the countrySchedule 3 paragraph 6: books, records and documents relating to the licensed activity must be kept AT the licensed premises. Not in force — Part III was not proclaimed.
- Keep data for a minimum period — 7 yearsSeven years after completion of the transaction to which the records relate. Not in force.
- Keep logsClosed-circuit television footage of the interior and exterior of licensed premises must be kept for fourteen days, or another period the Commission prescribes. Not in force.
- Register or notifyLicence required to own or operate a gaming establishment. Part III not in force.
Sources
- Official sourceParliament of the Republic of Trinidad and TobagoGambling (Gaming and Betting) Control Act, 2021 (Act No. 8 of 2021), Schedule 3 (to section 52(2))
ttparliament.org
“the keeping of books and other records which shall be kept at the gaming premises and retained for no less than seven years after the completion of the transaction to which such books and records relate”
Link checked 19 August 2026
- Official sourceGovernment Printer, Republic of Trinidad and TobagoLegal Notice No. 205 of 2021 — Proclamation of 11 August 2021 (Parts I, II and X and Schedule 1 only)
laws.gov.tt
Link checked 19 August 2026
General data protection law (Government)
Official name: Advance Passenger Information and Passenger Name Record Act, 2026 · Act No. 7 of 2026; gazetted Legal Supplement Part A, Vol. 65 No. 89, 21 May 2026 · Act of parliament
This law covers airline and ship passenger data. It is signed but has not started yet. It sets a seven-year keep limit. It strips identifying fields from booking records after six months. It bans the use of sensitive data. It creates the country's first data protection officer role set by law.
How this country controls where data goes: Approval each time (no country is on the approved list yet) · Accepted routes: Government sign-off needed, Official 'this country is safe' decision, Approved code of conduct
What you have to do
- Delete data after a period — 7 yearsAdvance passenger information: not more than seven years from the date of travel, then deleted from every database. Passenger name records: deleted permanently seven years after transfer.
- Keep data for a minimum period — 7 yearsRecords of how data is used must be kept for seven years, for audit and self-checking.
- Put a transfer safeguard in placeYou may send data to another country's competent authority only if that country intends to use it in line with the Act. If the destination protects data less well, the conflict must be resolved before you send it. You do that with a legally binding agreement, with binding rules that give people enforceable rights, or with an agreed code of conduct.
- Tell affected peopleA high-risk personal data breach must be communicated to the individual and to the Data Protection Officer without undue delay.
- Keep records of how you use dataThe Passenger Information Unit must log collection, consultation, disclosure and erasure operations.
- Appoint a data protection officerA Data Protection Officer and a Regional Data Protection Officer oversee compliance. This is the first data protection officer role set by law in Trinidad and Tobago.
- Secure the dataTechnical and organisational measures appropriate to the risk.
What it costs if you get it wrong
- Criminal liability: Fines plus imprisonment for six months on several offencesVarious offences under the Act, none in force until proclamation.
Sources
- Official sourceParliament of the Republic of Trinidad and TobagoAdvance Passenger Information and Passenger Name Record Act, 2026 (Act No. 7 of 2026), sections 2, 16, 21, 29 and 30
ttparliament.org
“This Act comes into operation on such date as is fixed by the President by Proclamation.”
Link checked 19 August 2026
- Official sourceParliament of the Republic of Trinidad and TobagoParliament bill record — Assent: Awaiting Proclamation
ttparliament.org
Link checked 19 August 2026
Applies to every company1 rule
These bind you whatever business you are in, once the country's rules reach you.
General data protection law
Official name: Data Protection Act, Chap. 22:04 · Act No. 13 of 2011; Legal Notice 2 of 2012; Legal Notice 220 of 2021 · Act of parliament
This is Trinidad and Tobago's general privacy law. Only part of it is in force. That part is Part I, which includes the privacy principles, plus the sections creating the Office of the Information Commissioner and one disclosure sub-section. Everything that would create enforceable duties, rights or penalties is still switched off. No Commissioner has ever been appointed.
Enforced by Office of the Information Commissioner — not yet operational
How this country controls where data goes: Only approved countries (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision
What you have to do
- Get consent — from 6 January 2012Principle (c) of section 6. In force but with no enforcement body.
- Tell people what you do — from 6 January 2012Principle (b): purpose must be identified before or at the time of collection.
- Secure the data — from 6 January 2012Principle (g): your safeguards must match how sensitive the data is.
- Delete data after a period — from 6 January 2012Principle (e): keep only as long as necessary for the purpose collected.
- Let people see their data — from 6 January 2012Principle (j). The access procedure itself sits in Part IV and is not in force.
- Put a transfer safeguard in place — from 6 January 2012Principle (l): the country receiving the data must have comparable safeguards. No list of such countries has ever been published.
- Appoint a data protection officerNot required. The Act never asks you to appoint a data protection officer.
What it costs if you get it wrong
- Criminal liability: TTD 100,000 and 5 years imprisonment (on indictment); TTD 50,000 and 3 years (summary) — about $15 thousandAny offence under the Act. Section 95 sits in Part V, which has NOT been brought into force as at 19 August 2026.
- Fixed maximum fine: TTD 500,000 (body corporate, on indictment) — about $74 thousandOffence committed by a body corporate. Section 95(2), Part V not in force.
- Percentage of global turnover: 10% of annual turnover of the enterpriseContravention of any provision by a corporation. Section 96, Part V not in force.
Sources
- Official sourceDigital Legislative Library, Government of Trinidad and TobagoData Protection Act, Chap. 22:04 — consolidated text
laws.gov.tt
“Part I and Sections 7–18, 22, 23, 25(1), 26 and 28 came into operation on the 6th January 2012.”
Link checked 19 August 2026
- Official sourceDigital Legislative Library, Government of Trinidad and TobagoDigital Legislative Library record for Data Protection Chap. 22:04 — 'This Act has only been partially proclaimed'
laws.gov.tt
Link checked 19 August 2026
- Official sourceGovernment Printer, Republic of Trinidad and TobagoLegal Notice No. 220 of 2021 — section 42(a) and (b) into operation on 23 August 2021
laws.gov.tt
Link checked 19 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
That no Information Commissioner has been appointed at any point between 1 January 2024 and 19 August 2026
We could not fully confirm that no Commissioner has been appointed. A minister said so in the Senate on 31 January 2023. The official Legal Notice register for 2022 to 2026 shows no proclamation of the Data Protection Act. The office does not appear in the national government services directory. None of that proves the position on every single day since. An appointment would normally be gazetted, and we found none.
Whether the Gambling (Gaming and Betting) Control Commission is staffed and functioning
We could not confirm whether the Gambling Control Commission is staffed and working. We could not reach an official website for it, or the Ministry of Digital Transformation site. We rely on the proclamation record and on the lack of published decisions. We rate it 'not operational' with low confidence. Ask the Commission directly before you rely on this.
Whether any published government cloud, data hosting or data classification policy applies to ministries and state agencies
We could not confirm whether the government has a published cloud or data hosting policy. The Ministry of Digital Transformation website was unreachable for us. The only rule we could verify is section 36 of the Data Protection Act, which is not in force. There may be a purchasing or Cabinet policy we did not see. If you sell to government, ask before you rely on this.
That reporting a cyber incident to the national cyber incident response team is voluntary rather than mandatory
We could not confirm that reporting a cyber incident to the national cyber team is voluntary. Its own site presents reporting as a service rather than a duty, and names no law behind it. We found no law requiring a report. Checked 19 August 2026. Treat this as a rule we could not find, not a certainty.
Current sectoral guidance issued by the Telecommunications Authority on subscriber data and privacy
We could not read the Telecommunications Authority's rules and policy pages. They sit behind an automated bot check that our tools could not pass. We confirmed the licence confidentiality condition directly from the Telecommunications Act instead. We could only reach the Authority's home page.
Whether the state of public emergency declared in 2025 and re-declared in 2026 is still in effect on 19 August 2026
We could not confirm whether the state of emergency was still running on the date we checked. The official Legal Notice register for 2026 shows Emergency Powers Regulations gazetted on 3 March 2026. It also lists a ban on public protests, hundreds of individual detention orders, and some revocation orders. The notice titles alone do not tell us the current position. Treat the emergency powers as live until you confirm otherwise.
Whether any Trinidad and Tobago court has decided a case under the Data Protection Act
We could not search the Judiciary's judgment database, so we cannot say whether any court has decided a case under the Act. Parts III, IV and V are not in force, so a decision is unlikely but possible. Check the court records if this matters to you.
Health sector, education sector and mapping or geospatial data rules
We found no rule for these industries about where data must be stored or how it may be sent abroad. Checked 19 August 2026, confidence medium. Health confidentiality in Trinidad and Tobago rests mainly on professional codes and common law, not on a data law. We did not check those codes against a government source. If you work in these industries, check before you rely on this.
Freshness and refresh
Freshness
Checked about 2 months ago, on 19 August 2026.
Re-checked every 60 days. Next check due 18 October 2026.