Data Protection Act, 2018
Saint Christopher and Nevis Data Protection Act, 2018 (No. 5 of 2018)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
Commencement not set.
A comprehensive regime rule binding public and private bodies.
As of 7 September 2026.
What it requires
- This law was passed and gazetted in 2018 but, on its own terms, does not take effect until a Ministerial commencement order is published in the Gazette; no such order has been located, so whether it currently binds has to be confirmed before relying on what follows.
- Obtain a data subject's consent before processing their personal data, or rely on one of the specific lawful grounds this Act lists.
- Before collecting personal data, tell the data subject the purpose of collection, the classes of third party it may be disclosed to, and how to request access or correction.
- Do not disclose personal data for a new purpose without the data subject's consent, subject to the exceptions this Act lists.
- Take practical steps to protect personal data from loss, misuse or unauthorised access, and keep it no longer than the purpose requires.
- Give a data subject access to their personal data on request, and correct it where it is inaccurate, incomplete, misleading or out of date.
If you get it wrong
Criminal exposureYes
Criminal exposure note
Unlawful processing of sensitive personal data without a permitted ground carries a fine not exceeding two hundred thousand dollars or imprisonment not exceeding two years, or both (s. 20(3)). Any other offence under the Act for which no specific penalty is provided carries, for an individual, a fine not exceeding fifty thousand dollars or imprisonment not exceeding three years on summary conviction, or a fine not exceeding one hundred thousand dollars or imprisonment not exceeding five years on conviction on indictment, and for a body corporate a fine of two hundred and fifty thousand dollars on summary conviction or five hundred thousand dollars on conviction on indictment (s. 38).
Penalty structure
Residual penalty (s. 38) for an offence with no specific penalty: individual, up to XCD 50,000 or 3 years on summary conviction, up to XCD 100,000 or 5 years on indictment; body corporate, XCD 250,000 on summary conviction or XCD 500,000 (the figure recorded here) on indictment. A separate, lower specific penalty attaches to unlawfully processing sensitive personal data (s. 20(3)): a fine not exceeding XCD 200,000 or imprisonment not exceeding 2 years, or both.
- Rule
- Fixed only
- As of
- 7 September 2026
- Currency
- XCD
- Fixed cap
- 500,000
Who enforces it
Enforcement body
Information Commissioner
What it reaches
Obligation class
Consent, Disclosure, Data subject rights, Retention, Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Section 4 applies the Act to a private body processing personal data in respect of commercial transactions and, subject to a territorial-nexus test, to any other person, and section 6 binds the State. Section 7 requires a data user to obtain a data subject's consent before processing personal data, or to process sensitive personal data only on one of the specific grounds in section 20.
Sections 8 to 13 set notice-and-choice, disclosure, security, retention, data-integrity and access duties, and Part III gives a data subject a right to access and to seek rectification of their personal data, exercised through the body and appealable to the Information Commissioner and then the Court.
Section 1(2) provides that the Act comes into force on a day fixed by the Minister by Order published in the Gazette; no commencement order has been located, so the Act's substantive duties are not yet confirmed to be in operation.
When LexLint raises it
automated_outreachdeploys_chatbotcrawls_webtrains_models