Law / Barbados

Data Protection Act, 2019, reach over scraped personal data

Data Protection Act, 2019 (Act 2019-29)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 26 March 2021.

A personal data rule binding public and private bodies.

As of 5 September 2026.

What it requires

  • Establish a lawful basis before collecting or processing personal data scraped from a public Barbadian website; public availability is not itself an exemption.
  • Do not scrape or otherwise process a biometric identifier unless the data subject consents or a specific statutory ground applies.
  • Before moving scraped personal data outside Barbados, confirm an adequate level of protection or an appropriate safeguard.

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

The Act applies to processing personal data by a controller or processor established in Barbados, or targeting data subjects in Barbados, and carries no general exemption for personal data that is already publicly accessible; the only public-data exemption is narrow, covering information a controller is itself obliged by another enactment to publish.

A scraper collecting personal data, including a face or other biometric identifier, from a public Barbadian website remains subject to the Act's lawful-basis and purpose-limitation duties, and biometric data is sensitive personal data whose processing is prohibited unless a specific ground applies. Moving scraped personal data outside Barbados requires an adequate level of protection in the destination country or an appropriate safeguard.

When LexLint raises it

  • crawls_web
  • processes_biometrics
  • trains_models

Read the law

Official text of the Data Protection Act, 2019 (Act 2019-29), Office of the Attorney General of Barbados

Back to the example  ·  Lint your app