Data Protection Act, 2018, Information Commissioner, enforcement and offences
Data Protection Act, 2018, ss. 23-38 (Information Commissioner, enforcement and offences)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
Commencement not set.
An enforcement supervision rule binding public and private bodies.
As of 19 September 2026.
What it requires
- This law was passed and gazetted in 2018 but, on its own terms, does not take effect until a Ministerial commencement order is published in the Gazette; no such order has been located, so whether it currently binds has to be confirmed before relying on what follows.
- Furnish the Information Commissioner with access to personal data, documentation of its processing, or information about its security, in writing within the time an information notice specifies.
- Comply with an enforcement notice the Information Commissioner serves within the time it states, and notify the data subject and anyone the data was disclosed to in the twelve months before the notice, within thirty days of complying, if compliance materially modifies the data.
- Expect a data subject to bring civil proceedings against you for damage caused by your contravention of the Act, unless you can prove you took reasonable care to comply.
- Do not obstruct the Information Commissioner or an authorised officer in the conduct of their duties.
- Do not dismiss, suspend, demote, discipline, harass, or otherwise disadvantage an employee for reporting or refusing to participate in a contravention of the Act in good faith.
- Do not wilfully disclose personal information in contravention of the Act, or collect, store, or dispose of personal information in a manner that contravenes the Act.
If you get it wrong
Criminal exposureYes
Criminal exposure note
Unlawful processing of sensitive personal data without a permitted ground carries a fine not exceeding two hundred thousand dollars or imprisonment not exceeding two years, or both (s. 20(3)). Wilfully disclosing personal information in contravention of the Act, collecting, storing or disposing of personal information in a manner that contravenes the Act, or breaching the whistleblower confidentiality obligation, is an offence (ss. 35, 36). Obstructing the Information Commissioner or an authorised officer carries a fine not exceeding five thousand dollars or imprisonment not exceeding six months (s. 33(2)). Where a corporation commits an offence under the Act, an officer, director, or agent who directed, authorised, assented to, or participated in it is also liable (s. 37). Any other offence under the Act for which no specific penalty is provided carries, for an individual, a fine not exceeding fifty thousand dollars or imprisonment not exceeding three years on summary conviction, or a fine not exceeding one hundred thousand dollars or imprisonment not exceeding five years on conviction on indictment, and for a body corporate a fine of two hundred and fifty thousand dollars on summary conviction or five hundred thousand dollars on conviction on indictment (s. 38).
Penalty structure
Residual penalty (s. 38) for an offence with no specific penalty: individual, up to XCD 50,000 or 3 years on summary conviction, up to XCD 100,000 or 5 years on indictment; body corporate, XCD 250,000 on summary conviction or XCD 500,000 (the figure recorded here) on indictment. A separate, lower specific penalty attaches to unlawfully processing sensitive personal data (s. 20(3)): a fine not exceeding XCD 200,000 or imprisonment not exceeding 2 years, or both, and to obstruction (s. 33(2)): a fine not exceeding XCD 5,000 or imprisonment not exceeding 6 months.
- Rule
- Fixed only
- As of
- 19 September 2026
- Currency
- XCD
- Fixed cap
- 500,000
Who enforces it
Enforcement body
Information Commissioner
What it reaches
Obligation class
Governance, Reporting, Prohibition
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Sections 23 and 24 make the Information Commissioner the officer appointed under section 35 of the Freedom of Information Act, and give the Information Commissioner functions including monitoring compliance, advising public and private bodies, receiving and investigating complaints, and conducting research and education.
Section 25 lets the Information Commissioner investigate, on a data subject's complaint or on the Commissioner's own initiative, whether a public body or private body has contravened the Act, and requires the Commissioner to notify the data subject of the decision and their right of appeal to the Court. Section 28 lets the Information Commissioner serve an information notice requiring a person to furnish access to personal data, documentation of its processing, or information about its security.
Section 30 lets the Information Commissioner serve an enforcement notice on a body that has contravened or is contravening a provision of the Act whose contravention is an offence, specifying the steps required and the time to take them, including rectifying or erasing personal data, and requires the body to notify the data subject and, where reasonably practicable, anyone the data was disclosed to in the twelve months before the notice, within thirty days of complying if compliance materially modifies the data.
Section 31 lets the Information Commissioner assess a body's processing on request or at the Commissioner's own discretion, and report non-compliance to the body with recommendations. Section 32 lets a data subject who suffers damage from a body's contravention of the Act bring civil proceedings in the Court, subject to a defence that the body took reasonable care to comply.
Section 33 makes it an offence, carrying a fine not exceeding five thousand dollars or imprisonment not exceeding six months, to obstruct the Information Commissioner or an authorised officer. Section 34 bars an employer from dismissing, suspending, demoting, disciplining, harassing, disadvantaging, or denying a benefit to an employee for reporting or refusing to participate in a contravention of the Act in good faith.
Section 35 makes it an offence to wilfully disclose personal information in contravention of the Act, or to collect, store, or dispose of personal information in a manner that contravenes the Act, and section 36 makes it an offence to breach the whistleblower confidentiality obligation section 34 establishes. Section 37 makes an officer, director, or agent of a corporation who directed, authorised, assented to, or participated in an offence the corporation committed a party to that offence.
Section 38 sets the residual penalty for an offence with no penalty otherwise specified at, for an individual, a fine of not more than fifty thousand dollars or imprisonment of three years on summary conviction, or one hundred thousand dollars or five years on indictment, and for a body corporate, two hundred and fifty thousand dollars on summary conviction or five hundred thousand dollars on indictment.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotis_listed_company
Read the law
archived copy
Read from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived July 25, 2024. Publisher's page: https://lawcommission.gov.kn/wp-content/documents/Annual-Laws/2018/ACTs/Act-5-of-2018-Data-Protection-Act-2018.pdfEvery line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.