Law / Barbados

Data Protection Act, 2019, personal data breach notification

Data Protection Act, 2019, ss. 63-64 (personal data breach notification)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 26 March 2021.

A breach notification rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Notify a personal data breach to the Data Protection Commissioner without undue delay and, where feasible, not later than 72 hours after becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of an individual, and give reasons for the delay if you notify later.
  • Communicate a personal data breach likely to result in a high risk to the rights and freedoms of individuals to the affected data subject, in clear and plain language, without undue delay and, where feasible, not later than 72 hours after becoming aware of it.
  • As a data processor, notify the data controller without undue delay after becoming aware of a personal data breach.
  • Describe in the notification the nature of the breach, including where possible the categories and approximate number of data subjects and of personal data records concerned, the contact point for more information, the likely consequences and the measures taken, supplying the information in phases without undue further delay where it cannot all be given at once.
  • Document every personal data breach, its facts, its effects and the remedial action taken, so the Commissioner can assess compliance.

What it reaches

Obligation class

Breach notice, Reporting

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Section 63(1) requires a data controller, where there is a personal data breach, to notify it to the Commissioner without undue delay and, where feasible, not later than 72 hours after having become aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of an individual, and section 63(2) requires a notification made outside that period to be accompanied by reasons for the delay.

Section 63(3) requires a data processor to notify the data controller without undue delay after becoming aware of a personal data breach.

Section 63(4) fixes what the notification must describe: the nature of the breach including, where possible, the categories and approximate number of data subjects and of personal data records concerned, the name and contact details of the data privacy officer or other contact point, the likely consequences, and the measures taken or proposed to address the breach and mitigate its adverse effects, with information given in phases without undue further delay where it cannot all be supplied at once.

Section 63(6) requires the controller to document every personal data breach, its facts, effects and remedial action, so the Commissioner can assess compliance.

Section 64(1) requires the controller to communicate a breach likely to result in a high risk to the rights and freedoms of individuals to the data subject without undue delay and, where feasible, not later than 72 hours after having become aware of it, in clear and plain language, and section 64(3) excuses that communication only where protective measures such as encryption render the affected data unintelligible, where subsequent measures have made the high risk no longer likely to materialise, or where it would involve disproportionate effort and a public communication of equal effect is made instead.

Section 100 leaves commencement to a proclamation. The Official Gazette of 26 March 2021 carries Statutory Instrument 2021 No. 24, the Proclamation re Data Protection Act, 2019, which is the day these provisions began to bind.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • processes_biometrics
  • operates_essential_service

Read the law

Official text of the Data Protection Act, 2019 (Act 2019-29), Office of the Attorney General of Barbados

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app