Data Protection Act, 2020, reporting a contravention or security breach
Data Protection Act, 2020 (Act 7 of 2020), ss. 21(2)-(5), 30(1)(b), (4)-(5)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force.
A breach notification rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Report any security breach in respect of your operations which affects or may affect personal data, and any contravention of the data protection standards, to the Information Commissioner within 72 hours of becoming aware of the breach or contravention, in the prescribed form and manner.
- Notify the Information Commissioner without undue delay of any breach of your security measures which affects or may affect personal data.
- Notify each data subject whose personal data is affected by the breach, upon becoming aware of the breach or having reason to become aware of it, of the nature of the breach, of the measures taken or proposed to address it, and of your data protection officer's contact information, in the form, manner and time prescribed.
- Set out in the report to the Information Commissioner the facts of the breach, its nature including the categories and number of data subjects and the type and number of personal data concerned, the measures taken or proposed to mitigate it, its consequences, and your data protection officer's contact information.
- Engage a data processor only where it gives sufficient guarantees as to the reporting of security breaches to you, under a written contract binding it to obligations equivalent to your own.
- Expect the Information Commissioner, on receiving your report, to serve an enforcement notice or to direct you to tell affected data subjects what the Commissioner thinks fit about the breach and the measures addressing it.
If you get it wrong
Criminal exposureYes
Criminal exposure note
Failing to make a report required by section 21(3) or a notification required by section 21(5) is an offence under section 21(2), liable on summary conviction in a Parish Court to a fine not exceeding JMD 2,000,000 or imprisonment not exceeding two years, and on conviction on indictment in a Circuit Court to a fine or imprisonment not exceeding seven years. It is a defence under section 21(7) to show, on the balance of probabilities, that the person exercised all due diligence to prevent the commission of the offence. Section 62 lets the Information Commissioner offer a data controller a fixed penalty notice for a section 21(2) offence instead of prosecution where the contravention was of a kind likely to cause substantial damage or distress and was deliberate or negligent.
Penalty structure
Section 21(2) states the scale for failing to make the report or notification: on summary conviction in a Parish Court a fine not exceeding JMD 2,000,000 or imprisonment not exceeding two years, and on conviction on indictment in a Circuit Court an unspecified fine or imprisonment not exceeding seven years. Section 68(1) applies notwithstanding any other penalty specified in the Act, so where the data controller is a body corporate the fine for that offence is capped instead at four percent of its annual gross worldwide turnover for the preceding year of assessment.
- Rule
- Turnover pct only
- As of
- 19 September 2026
- Turnover percentage cap
- 4
What it reaches
Obligation class
Breach notice, Reporting
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Section 21(3) requires a data controller to report to the Commissioner, in such form and manner as shall be prescribed, any contravention of the data protection standards and any security breach in respect of the data controller's operations which affects or may affect personal data, within seventy-two hours after becoming aware of the contravention or security breach.
The report must set out the facts surrounding it, a description of its nature including the categories and number of data subjects concerned and the type and number of personal data concerned, the measures taken or proposed to mitigate or address its possible adverse effects, its consequences, and the name, address and contact information of the data controller's data protection officer.
Section 21(5) requires the data controller, upon becoming aware of or having reason to become aware of the contravention or breach, to notify each data subject whose personal data is affected of its nature, of the measures taken or proposed to mitigate or address its possible adverse effects, and of the data protection officer's contact information.
That notification is to be given in such form and manner, and within such time, as shall be prescribed, and the Act states no period of its own for it. The seventh standard separately requires appropriate measures to ensure that the Commissioner is notified, without any undue delay, of any breach of the data controller's security measures which affect or may affect any personal data.
The same standard requires a data controller using a data processor to choose one that gives sufficient guarantees as to the reporting of security breaches to the data controller, and to bind it by written contract to obligations equivalent to the controller's own. On receiving a report the Commissioner may serve an enforcement notice or direct the data controller to give affected data subjects such information about the contravention or breach as the Commissioner thinks fit.
Failing to make a report or notification required by section 21(3) or (5) is an offence under section 21(2). The Act is in force: it reached its appointed day under the Appointed Day Notice gazetted in 2023, the mechanism its own commencement clause leaves to a notice published in the Gazette, and no notice stating the day itself has been located.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbot
Read the law
Text of the Data Protection Act, 2020 as published by the Houses of Parliament of Jamaica
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.