Data Protection Act, 2019, transfers of personal data outside of Barbados
Data Protection Act, 2019, ss. 22-28 (transfers of personal data outside of Barbados)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 26 March 2021.
A cross border transfer rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Before transferring personal data outside Barbados, confirm the destination provides an adequate level of protection or rely on an appropriate safeguard such as standard clauses or binding corporate rules.
- Assess adequacy on all the circumstances before the transfer, weighing the nature of the data, the countries of origin and final destination, the purposes and period of the intended processing, the law in force and international obligations there, any enforceable codes of conduct, and the security measures taken in that country or territory.
- Submit any binding corporate rules you rely on to the Commissioner for authorisation, and make them specify what section 25 requires, including the data subjects' rights and how to exercise them, the acceptance of liability, the complaint procedures and the compliance-verification mechanisms.
- Where you rely on a derogation in section 26 instead, make sure it is one the section lists, such as the data subject's consent, contractual necessity, substantial public interest, legal proceedings, vital interests, a public register, or terms approved or a transfer authorised by the Commissioner.
What it reaches
Obligation class
Transfer
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Section 22 bars the transfer of personal data to a country or territory outside Barbados unless that country or territory provides an adequate level of protection for the rights and freedoms of data subjects and appropriate safeguards, on condition that the data subject's rights are enforceable and effective legal remedies are available.
Section 23 makes adequacy a question of all the circumstances, weighing the nature of the data, the country of origin and of final destination, the purposes and period of the intended processing, the law in force and international obligations of that country, any enforceable codes of conduct and the security measures taken there.
Section 24 lists the appropriate safeguards: a legally binding and enforceable instrument between public authorities, binding corporate rules under section 25, standard data protection clauses prescribed by the Commissioner with the Minister's approval, contractual clauses the Commissioner authorises, and authorised provisions in administrative arrangements between public authorities.
Section 25 sets out what binding corporate rules must specify and requires them to be submitted to the Commissioner for authorisation. Section 26 lists the derogations that displace sections 22 to 24, including the data subject's consent, contractual necessity, substantial public interest, legal proceedings or advice, vital interests, a public register, and terms approved or a transfer authorised by the Commissioner.
Section 27 makes contravening sections 22, 23 or 24 an offence carrying, on summary conviction, a fine of $500,000 or three years' imprisonment or both, and section 28 lets the Minister specify by order when a transfer is to be treated as necessary for reasons of substantial public interest. Section 100 leaves commencement to a proclamation.
The Official Gazette of 26 March 2021 carries Statutory Instrument 2021 No. 24, the Proclamation re Data Protection Act, 2019, which is the day these provisions began to bind.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotprocesses_biometrics
Read the law
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.