Privacy Act 2025, comprehensive personal information protection regime
Privacy Act 2025 (Act 34 of 2025)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
Commencement not set.
A comprehensive regime rule binding public and private bodies.
As of 6 September 2026.
What it requires
- This law is recorded as enacted, but the Cabinet proclamation that would fix its commencement date under section 1(2) has not been located, so whether it is yet in force has to be established before relying on what follows.
- Do not process personal information unless the data subject has given specific, informed, unambiguous consent, or another lawful basis in section 27 applies, such as contract performance, a legal obligation, or a legitimate interest that does not override the data subject's rights.
- Do not process sensitive personal information, including biometric data such as a voiceprint or facial image, racial or ethnic origin, political opinions, religious belief, health, sexual orientation, criminal or financial record, or genetic information, unless a section 27 basis is met together with one of the heightened conditions in section 28, such as explicit consent or a substantial-public-interest law.
- Before processing a child's personal information, obtain the consent of a parent or legal guardian and apply appropriate age and consent verification mechanisms, including government-approved identification, unless the processing is necessary to protect the child's vital interests or is medical or social care under a duty of confidentiality.
- At the time personal information is collected, tell the data subject the identity of the data controller, the purpose of collection, whether sensitive personal information will be collected, the intended recipients, whether disclosure to an overseas recipient is likely, and the data subject's rights of access, correction, deletion, and objection to direct marketing.
- Do not retain personal information longer than necessary for the purpose it was collected; once retention is no longer necessary, return, destroy, permanently de-identify, or render the information permanently inaccessible.
- Implement appropriate technical and organisational security measures to prevent accidental or unlawful loss, misuse, destruction, or unauthorised access to personal information.
- Notify the Privacy Commission of a personal information breach likely to result in a risk to a data subject's rights and freedoms within seventy-two hours of becoming aware of it, and notify the affected data subject directly, without undue delay, where the breach is likely to result in a high risk to them; this duty does not begin until the second anniversary of the Act's commencement date.
- Do not transfer personal information outside Tonga unless the Privacy Commission has consented in writing to the transfer, the recipient is bound by a law, binding corporate rules, contractual clauses, or a certification mechanism affording adequate protection, or a specific exception such as the data subject's informed consent applies.
- Give a data subject access to their personal information, and correct or delete it on request, without unreasonable delay or expense; on request, stop processing their information for direct marketing purposes; and do not subject a data subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects, unless a statutory exception applies.
- A first contravention by an organisation can draw a civil pecuniary penalty of up to TOP 30,000, rising to TOP 100,000 for a subsequent contravention, and a data subject who suffers loss or damage from a contravention may sue for it directly.
If you get it wrong
Criminal exposureNo
Private right of actionYes
Penalty structure
Section 54(4) sets four separate caps rather than one: an individual's first contravention is capped at TOP 5,000, an individual's subsequent contravention at the greater of TOP 30,000 or three times the value of the benefit obtained from the contravention, an organisation's or public authority's first contravention at TOP 30,000, and a subsequent contravention by an organisation or public authority at TOP 100,000. The court fixes the actual amount within the applicable cap having regard to the nature and extent of the contravention and any prior findings against the same data controller or data processor. The Act states these figures in dollars, understood here as Tongan pa'anga.
- Rule
- Fixed only
- As of
- 6 September 2026
- Currency
- TOP
- Fixed cap
- 30,000
Who enforces it
Enforcement body
Privacy Commission
Settledness
- As of
- 6 September 2026
- Open questions
- Has Cabinet proclaimed a commencement date for the Act under section 1(2), and if so, on what date does the Act take effect?
- Does the "generally available publication" exemption in section 48(1)(a) reach personal information an organisation posts on an ordinary public website, or only material with the media-style character the term's own definition lists (a magazine, book, article, newspaper)?
What it reaches
Obligation class
Consent, Disclosure, Data subject rights, Transfer, Breach notice, Security, Governance, Biometric, Age verification, DPIA, Retention
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Section 4 binds the State, and section 5 applies the Act to a data controller or data processor established in Tonga, processing within Tonga, or targeting or monitoring a Tongan data subject.
Section 27 requires a lawful basis, ordinarily the data subject's specific and informed consent, before personal information may be processed, and section 28 requires a heightened basis, such as explicit consent or a proportionate substantial-public-interest law, before sensitive personal information (including biometric data, racial or ethnic origin, political opinions, religious belief, health, sexual orientation, criminal or financial record, or genetic information) may be processed.
Section 29 requires a parent's or guardian's consent and government-approved age and consent verification before processing a child's personal information, subject to vital-interest and medical-care exceptions. Section 33 requires notice to a data subject at collection of the controller's identity, the purpose of collection, whether sensitive personal information or overseas disclosure is involved, and the data subject's rights; section 34 limits retention to what is necessary for that purpose.
Section 36 requires appropriate technical and organisational security measures, and section 37 requires notifying the Privacy Commission of a personal information breach likely to risk a data subject's rights within seventy-two hours of becoming aware of it, and notifying the affected data subject directly where the risk is high; section 37(11) states that the breach-notification duty does not apply until the second anniversary of the Act's commencement date.
Sections 39 and 40 bar transferring personal information outside Tonga unless the Privacy Commission has given written consent, the recipient is bound by a law, binding corporate rules, contractual clauses, a code of conduct, or a certification mechanism affording adequate protection, or a specific exception (such as the data subject's informed consent) applies.
Part IV gives a data subject the right to access, correct, and delete their personal information, to stop its use for direct marketing, to object to certain processing, to withdraw consent, and not to be subject to a decision based solely on automated processing, including profiling, that produces a legal or similarly significant effect, subject to stated exceptions; section 47 makes a right to data portability available only once the Minister makes regulations creating it.
Section 48 exempts information already published in a generally available publication or permanently de-identified, though section 48(2) keeps information collected before that publication within the Act; sections 49 and 50 exempt purely personal or household processing, defined public-authority purposes such as national security and criminal investigation, journalism under a published privacy code, and processing connected with legal proceedings or professional privilege.
A new Privacy Commission, established by section 7 and headed by a Privacy Commissioner, investigates complaints, issues enforcement notices and information notices, accepts enforceable undertakings, and may bring civil proceedings under section 54 for a pecuniary penalty; section 57 separately lets a data subject who suffers loss or damage from a contravention sue for it directly.
Section 1(2) states that the Act comes into force on a date proclaimed by Cabinet rather than automatically upon assent; press reporting (Tonga Independent News, 6 January 2026) states the Act was gazetted into force alongside a package of other 2025 governance-reform statutes, but the Cabinet proclamation itself, which would fix the exact commencement date, is not confirmed in the primary text, so the Act's status is recorded here as enacted rather than as confirmed in force.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometricsserves_minors