Law / Saint Kitts and Nevis

Data Protection Act, 2018, Information Commissioner, enforcement and offences

Data Protection Act, 2018, ss. 23-38 (Information Commissioner, enforcement and offences)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

Commencement not set.

An enforcement supervision rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • This law was passed and gazetted in 2018 but, on its own terms, does not take effect until a Ministerial commencement order is published in the Gazette; no such order has been located, so whether it currently binds has to be confirmed before relying on what follows.
  • Furnish the Information Commissioner with access to personal data, documentation of its processing, or information about its security, in writing within the time an information notice specifies.
  • Comply with an enforcement notice the Information Commissioner serves within the time it states, and notify the data subject and anyone the data was disclosed to in the twelve months before the notice, within thirty days of complying, if compliance materially modifies the data.
  • Expect a data subject to bring civil proceedings against you for damage caused by your contravention of the Act, unless you can prove you took reasonable care to comply.
  • Do not obstruct the Information Commissioner or an authorised officer in the conduct of their duties.
  • Do not dismiss, suspend, demote, discipline, harass, or otherwise disadvantage an employee for reporting or refusing to participate in a contravention of the Act in good faith.
  • Do not wilfully disclose personal information in contravention of the Act, or collect, store, or dispose of personal information in a manner that contravenes the Act.

If you get it wrong

Criminal exposureYes

Criminal exposure note

Unlawful processing of sensitive personal data without a permitted ground carries a fine not exceeding two hundred thousand dollars or imprisonment not exceeding two years, or both (s. 20(3)). Wilfully disclosing personal information in contravention of the Act, collecting, storing or disposing of personal information in a manner that contravenes the Act, or breaching the whistleblower confidentiality obligation, is an offence (ss. 35, 36). Obstructing the Information Commissioner or an authorised officer carries a fine not exceeding five thousand dollars or imprisonment not exceeding six months (s. 33(2)). Where a corporation commits an offence under the Act, an officer, director, or agent who directed, authorised, assented to, or participated in it is also liable (s. 37). Any other offence under the Act for which no specific penalty is provided carries, for an individual, a fine not exceeding fifty thousand dollars or imprisonment not exceeding three years on summary conviction, or a fine not exceeding one hundred thousand dollars or imprisonment not exceeding five years on conviction on indictment, and for a body corporate a fine of two hundred and fifty thousand dollars on summary conviction or five hundred thousand dollars on conviction on indictment (s. 38).

Penalty structure

Residual penalty (s. 38) for an offence with no specific penalty: individual, up to XCD 50,000 or 3 years on summary conviction, up to XCD 100,000 or 5 years on indictment; body corporate, XCD 250,000 on summary conviction or XCD 500,000 (the figure recorded here) on indictment. A separate, lower specific penalty attaches to unlawfully processing sensitive personal data (s. 20(3)): a fine not exceeding XCD 200,000 or imprisonment not exceeding 2 years, or both, and to obstruction (s. 33(2)): a fine not exceeding XCD 5,000 or imprisonment not exceeding 6 months.

Rule
Fixed only
As of
19 September 2026
Currency
XCD
Fixed cap
500,000

Who enforces it

Enforcement body

Information Commissioner

What it reaches

Obligation class

Governance, Reporting, Prohibition

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Sections 23 and 24 make the Information Commissioner the officer appointed under section 35 of the Freedom of Information Act, and give the Information Commissioner functions including monitoring compliance, advising public and private bodies, receiving and investigating complaints, and conducting research and education.

Section 25 lets the Information Commissioner investigate, on a data subject's complaint or on the Commissioner's own initiative, whether a public body or private body has contravened the Act, and requires the Commissioner to notify the data subject of the decision and their right of appeal to the Court. Section 28 lets the Information Commissioner serve an information notice requiring a person to furnish access to personal data, documentation of its processing, or information about its security.

Section 30 lets the Information Commissioner serve an enforcement notice on a body that has contravened or is contravening a provision of the Act whose contravention is an offence, specifying the steps required and the time to take them, including rectifying or erasing personal data, and requires the body to notify the data subject and, where reasonably practicable, anyone the data was disclosed to in the twelve months before the notice, within thirty days of complying if compliance materially modifies the data.

Section 31 lets the Information Commissioner assess a body's processing on request or at the Commissioner's own discretion, and report non-compliance to the body with recommendations. Section 32 lets a data subject who suffers damage from a body's contravention of the Act bring civil proceedings in the Court, subject to a defence that the body took reasonable care to comply.

Section 33 makes it an offence, carrying a fine not exceeding five thousand dollars or imprisonment not exceeding six months, to obstruct the Information Commissioner or an authorised officer. Section 34 bars an employer from dismissing, suspending, demoting, disciplining, harassing, disadvantaging, or denying a benefit to an employee for reporting or refusing to participate in a contravention of the Act in good faith.

Section 35 makes it an offence to wilfully disclose personal information in contravention of the Act, or to collect, store, or dispose of personal information in a manner that contravenes the Act, and section 36 makes it an offence to breach the whistleblower confidentiality obligation section 34 establishes. Section 37 makes an officer, director, or agent of a corporation who directed, authorised, assented to, or participated in an offence the corporation committed a party to that offence.

Section 38 sets the residual penalty for an offence with no penalty otherwise specified at, for an individual, a fine of not more than fifty thousand dollars or imprisonment of three years on summary conviction, or one hundred thousand dollars or five years on indictment, and for a body corporate, two hundred and fifty thousand dollars on summary conviction or five hundred thousand dollars on indictment.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • is_listed_company

Read the law

Data Protection Act, 2018 (No. 5 of 2018), Saint Kitts and Nevis Law Commission text, preserved on archive.org

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived July 25, 2024. Publisher's page: https://lawcommission.gov.kn/wp-content/documents/Annual-Laws/2018/ACTs/Act-5-of-2018-Data-Protection-Act-2018.pdf

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app