Data Protection Act, 2019
Data Protection Act, 2019 (Act 2019-29)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 26 March 2021.
A comprehensive regime rule binding public and private bodies.
As of 5 September 2026.
What it requires
- Before processing personal data, establish a lawful basis and confine processing to the stated purpose.
- Do not process sensitive personal data, including biometric data, unless the data subject consents or a specific statutory ground applies.
- When collecting personal data, or promptly after obtaining it from another source, give the data subject the required notice, including of any automated decision-making and meaningful information about its logic.
- Honour a data subject's rights to access, rectification, erasure, restriction, portability, and objection to automated decision-making or direct marketing.
- Before transferring personal data outside Barbados, confirm the destination provides an adequate level of protection or rely on an appropriate safeguard such as standard clauses or binding corporate rules.
- Notify the Data Protection Commissioner of a personal data breach without undue delay, and within 72 hours where feasible, and notify affected data subjects where the breach is likely to put them at high risk.
- Register with the Data Protection Commissioner as a data controller or data processor before processing personal data.
If you get it wrong
Criminal exposureYes
Private right of actionYes
Criminal exposure note
A person who contravenes the data-processing principles in section 4 is guilty of an offence and is liable on summary conviction to a fine of $500,000 or to imprisonment for three years, or to both; the same fine and term apply to a contravention of the cross-border-transfer duties in sections 22 to 24.
Penalty structure
Fine for contravening the data-processing principles (s. 4) or the cross-border-transfer duties (ss. 22-24); the Act sets separate, lower fixed fines for narrower failures such as operating as an unregistered data controller or processor, ranging from $10,000 to $100,000, each with an alternative or concurrent prison term.
- Rule
- Fixed only
- As of
- 5 September 2026
- Currency
- BBD
- Fixed cap
- 500,000
Who enforces it
Enforcement body
Data Protection Commissioner
What it reaches
Obligation class
Consent, Disclosure, Data subject rights, Transfer, Breach notice, Security, Biometric, DPIA
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
The Act requires a lawful basis before processing personal data (consent, contract, legal obligation, vital interest, or a public or legitimate-interest ground) and confines processing to a stated purpose. It prohibits processing sensitive personal data, a category that includes biometric and genetic data, unless the data subject consents or a narrow statutory ground applies.
Data subjects have rights of access, rectification, erasure, restriction, portability, and objection to automated decision-making or direct marketing, and section 18 gives a right not to be subject to a decision based solely on automated processing, including profiling, that produces a legal or similarly significant effect, subject to contract, statutory, and consent exceptions.
A data controller or processor must notify the Data Protection Commissioner of a personal data breach without undue delay, and within 72 hours where feasible. Transferring personal data outside Barbados requires an adequate level of protection in the destination or an appropriate safeguard such as standard clauses or binding corporate rules.
Data controllers and processors must register with the Commissioner, and an individual who suffers damage or distress from a contravention is entitled to compensation from the controller or processor.
When LexLint raises it
automated_outreachcrawls_webdeploys_chatbothigh_risk_decisionsprocesses_biometricstrains_models