Data Protection Act, 2013
Data Protection Act, 2013 (No. 10 of 2013), ss. 5-23
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force.
A comprehensive regime rule binding public and private bodies.
As of 5 September 2026.
What it requires
- Obtain a data subject's consent before processing their personal data arising from a commercial transaction, unless a listed alternative ground such as contract performance or legal obligation applies.
- On request, tell a data subject the purposes of collecting their personal data, its source, the classes of third parties it may be disclosed to, and whether supplying it is obligatory.
- Do not disclose personal data for a purpose other than the one notified at collection without the data subject's consent or a listed exception.
- Take practical security steps against loss, misuse, unauthorised access or disclosure of personal data, including when a data processor handles it on your behalf.
- Do not keep personal data longer than necessary, and keep it accurate and up to date.
- Give a data subject access to their personal data within thirty days of a written request, and correct it on a substantiated claim that it is inaccurate, incomplete, misleading or irrelevant.
- Before processing sensitive personal data such as health, sexual orientation, political opinion or religious belief, obtain the data subject's explicit consent or rely on a listed ground such as employment law, vital interests or legal proceedings.
If you get it wrong
Criminal exposureYes
Private right of actionNo
Criminal exposure note
Unlawfully processing sensitive personal data is an offence under s. 18(3) carrying a fine of up to two hundred thousand dollars or imprisonment of up to three years, or both. A contravention for which no other penalty is specified is an offence under the s. 23 general penalty: for an individual, a fine of up to fifty thousand dollars or imprisonment of up to three years on summary conviction, or a fine of up to one hundred thousand dollars or imprisonment of up to five years on indictment; for a body corporate, a fine of up to two hundred thousand dollars on summary conviction or five hundred thousand dollars on indictment.
Penalty structure
Five hundred thousand dollars is the ceiling the Act itself states, for a body corporate convicted on indictment under s. 23(2)(b). An individual's general-penalty ceiling is lower (one hundred thousand dollars on indictment, fifty thousand on summary conviction, under s. 23(1)), and unlawfully processing sensitive personal data carries its own, separate penalty of up to two hundred thousand dollars or three years imprisonment under s. 18(3).
- Rule
- Fixed only
- As of
- 5 September 2026
- Currency
- XCD
- Fixed cap
- 500,000
Who enforces it
Enforcement body
Information Commissioner (appointed under the Freedom of Information Act 2004)
What it reaches
Obligation class
Consent, Disclosure, Data subject rights, Security, Retention
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Section 5 requires a data user to obtain a data subject's consent before processing personal data other than sensitive personal data, subject to alternative grounds including contract performance, legal obligation, vital interests and the administration of justice. Section 6 requires a data user, on request, to tell a data subject the purposes of collection, the source of the data, the classes of third party recipients, and whether supplying the data is obligatory.
Section 7 bars disclosure of personal data for a purpose other than the one notified at collection, absent consent or a listed exception, and section 8 requires practical security steps against loss, misuse or unauthorised access, extending to a data processor engaged by the data user. Section 9 bars retaining personal data longer than necessary and section 10 requires a data user to keep personal data accurate and up to date.
Sections 11 through 17 give a data subject the right to access personal data held about them within thirty days of a written request, subject to listed exemptions and extensions, and the right to have inaccurate, incomplete, misleading or irrelevant personal data rectified.
Section 18 bars processing sensitive personal data (health, sexual orientation, political opinion, religious belief, or an alleged offence) except on the data subject's explicit consent or a listed ground such as employment law, vital interests, medical purposes or legal proceedings, and makes an unlawful processing of sensitive personal data an offence carrying a fine of up to two hundred thousand dollars or imprisonment of up to three years, or both.
Section 19 exempts personal, family or household processing, and processing for crime prevention, court orders, statistics and research, regulatory functions, and journalistic, literary or artistic purposes, from some or all of the principles above.
Section 21 assigns the Information Commissioner appointed under the Freedom of Information Act 2004 the powers, functions and duties needed to enforce this Act, and section 23 makes a contravention of the Act for which no other penalty is specified an offence carrying, for an individual, a fine of up to fifty thousand dollars or imprisonment of up to three years on summary conviction, or a fine of up to one hundred thousand dollars or imprisonment of up to five years on conviction on indictment, and for a body corporate, a fine of up to two hundred thousand dollars on summary conviction or five hundred thousand dollars on indictment.
When LexLint raises it
automated_outreach