Draft Law on the Protection of Privacy and Personal Data, Commissioner, remedies and fines
Arts. 23-42 Wet Bescherming Privacy en Persoonsgegevens
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
Proposed: draft date not recorded.
An enforcement supervision rule binding public and private bodies.
As of 19 September 2026.
What it requires
- This measure is a draft bill; it binds nobody yet. What follows is what it would require if it is enacted in this form.
- Cooperate with the Commissioner for Personal Data Protection, an independent authority the bill would establish, including by giving access to the records, information, and premises the Commissioner needs to investigate a complaint.
- Let a data subject or their representative lodge a complaint with the Commissioner about your processing, and give reasonable assistance to a person who wants to put a complaint in writing.
- Pay compensation to a person who suffers material or non-material damage because you processed their personal data in violation of this law, unless you show you were not in any way responsible for the event that caused the damage.
- Do not dismiss, suspend, demote, discipline, fine, intimidate, or otherwise disadvantage an employee for reporting in good faith that you have or will violate this law.
- Expect an administrative fine of up to SRD 5,000 or 2 percent of worldwide annual turnover, whichever is higher, for violating the chapter V obligations on controllers and processors, and up to SRD 10,000 or 4 percent of worldwide annual turnover, whichever is higher, for violating the principles, data subject rights, or cross border transfer chapters, or for failing to comply with a Commissioner decision or order.
- Let a data subject authorise a nonprofit organisation active in privacy protection to lodge a complaint or exercise their judicial and compensation rights on their behalf.
If you get it wrong
Criminal exposureNo
Private right of actionYes
Penalty structure
This is the higher of the bill's two fine tiers (art. 35(6)(b)): SRD 10,000 or 4 percent of worldwide annual turnover, whichever is higher, for a violation of the principles, rights, or cross border transfer chapters, or non-compliance with a Commissioner order. A lower tier applies to a chapter V (controller and processor obligations) violation: SRD 5,000 or 2 percent of worldwide annual turnover, whichever is higher (art. 35(6)(a)). Both are administrative fines; the bill sets no criminal penalty.
- Rule
- Higher of
- As of
- 19 September 2026
- Currency
- SRD
- Fixed cap
- 10,000
- Turnover percentage cap
- 4
Who enforces it
Enforcement body
Proposed: Commissioner for Personal Data Protection (Commissaris voor persoonsgegevensbescherming), an independent authority the bill would create
What it reaches
Obligation class
Governance
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
This measure is a draft bill; it binds nobody yet, and what follows describes what it would require if enacted in the form read. Article 23 establishes an independent Commissioner for Personal Data Protection (Commissaris voor Persoonsgegevensbescherming), responsible for supervising and enforcing this law, accountable to De Nationale Assemblee.
Article 33 gives every data subject or their legal representative the right to lodge a complaint with the Commissioner, and articles 34 and 37 set the complaint procedure, including a decision within three months, extendable by three months for complex cases, and the factors the Commissioner weighs before imposing a fine.
Article 35 lets the Commissioner fine a controller or processor for a violation: up to SRD 5,000 or 2 percent of worldwide annual turnover, whichever is higher, for violating the chapter V obligations on controllers and processors, and up to SRD 10,000 or 4 percent of worldwide annual turnover, whichever is higher, for violating the principles, rights, or cross border transfer chapters, or for failing to comply with a Commissioner decision, order, or notice or to grant access needed for a complaint investigation.
Articles 38 and 39 give a person effective judicial remedies against the Commissioner and against a controller or processor respectively, before the kantonrechter, and article 40 gives every person who suffers material or non-material damage from a violation of this law the right to compensation from the controller or processor responsible, with joint and several liability where more than one is involved.
Article 41 bars an employer from dismissing, suspending, demoting, disciplining, fining, intimidating or otherwise disadvantaging an employee for reporting in good faith that the employer or another person has violated or will violate this law. Article 42 lets a data subject authorise a nonprofit organisation active in privacy protection to lodge a complaint or exercise their judicial and compensation rights on their behalf.
The bill contains no criminal penalty for a violation; its sanctions are the administrative fine, the compensation claim, and the Commissioner's other decisions and orders. The bill remains under consideration before De Nationale Assemblee, with no enactment timeline.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreach
Read the law
Draft text of the Ontwerpwet Bescherming Privacy en Persoonsgegevens
as republished by SRiS (Stichting voor de Rechtsorde in Suriname), a Surinamese legal-information foundation, not an official government gazette page the bill's current pendency before De Nationale Assemblee is confirmed on the National Assembly's own list of bills under consideration
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.