Law / Kiribati

Data Protection Act 2025, processing and transfers outside Kiribati

Data Protection Act 2025, ss. 23-25 (processing and transfers outside Kiribati)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

Commencement not set.

A cross border transfer rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • This Act is enacted but not in force: section 2 leaves commencement to a ministerial notice, and none was located as of this review, so no cross-border restriction binds anyone yet.
  • On commencement, before processing personal data outside Kiribati or transferring it to a person outside Kiribati, take reasonable steps to verify that the recipient jurisdiction affords adequate protection, meaning restrictions and obligations substantially similar to Parts III and V, rights substantially similar to Part IV, and that those restrictions, obligations and rights are substantially enforceable.
  • On commencement, where adequate protection cannot be verified, transfer or process personal data outside Kiribati only on another listed basis, such as the data subject's informed consent to the transfer, contractual necessity, a medical emergency, a transfer for the data subject's benefit where consent is impracticable but would likely be given, or a transfer under an international agreement such as a mutual legal assistance treaty.
  • On commencement, comply with any prohibition, designation or guideline the Digital Transformation Office issues on whether a jurisdiction, organisation, law or measure affords adequate protection, and with any Office prohibition on transferring personal data to a specified jurisdiction, organisation or under specified measures for want of adequate protection or for reasons of national security.
  • On commencement, keep a written record of the reasonable steps taken to verify adequate protection or the alternative basis relied on for processing or transferring personal data outside Kiribati, and make that record available to the Office on request.

What it reaches

Obligation class

Transfer, Governance

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Section 23(1) requires a person that processes personal data outside Kiribati or transfers it to a person outside Kiribati to take reasonable steps to verify or ensure that there is adequate protection with respect to the personal data.

Section 23(2) defines adequate protection as restrictions and obligations substantially similar to Parts III and V, rights substantially similar to Part IV, and enforceability of those restrictions, obligations and rights, and section 23(3) lets that protection rest on the destination jurisdiction's laws, on binding corporate rules, contractual clauses, a code of conduct or a certification mechanism, or on an international organisation's own policies and measures.

Section 23(4) lets the Office issue guidelines on assessing adequate protection and designate a jurisdiction, organisation, law, or measure as affording or not affording it, and section 23(6) lets the Office prohibit a transfer to a specified jurisdiction, organisation or under specified measures for want of adequate protection or for reasons of national security.

Section 24 lets a person process or transfer personal data outside Kiribati without adequate protection where the data subject has given informed consent to the transfer, the transfer is necessary to a contract with the data subject or to a medical emergency, the transfer is for the data subject's benefit and consent is impracticable but would likely be given, or the transfer follows a court or administrative order under an international agreement such as a mutual legal assistance treaty.

Section 25 requires a person processing or transferring personal data outside Kiribati to keep a written record of the reasonable steps taken under section 23(1) or the basis relied on under section 24, and to make that record available to the Office on request.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach

Read the law

Act text as published by the Ministry of Information, Communications and Transport (Data Protection Act 2025).

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app