Data Protection Act, 2011, cross border disclosure of personal information
Act 13 of 2011, ss. 6(l), 46 and 72 (cross border disclosure)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 6 January 2012.
A cross border transfer rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Section 6(l)'s general principle already binds everyone who handles personal information: before disclosing personal information outside Trinidad and Tobago, make sure the disclosure is regulated and that comparable safeguards to those under this Act exist in the receiving jurisdiction.
- Once Part III is in force, before a public body discloses personal information to a party in another jurisdiction, tell the individual the purpose of the disclosure and the identity of the requester and the receiving jurisdiction's data protection body, and obtain the individual's consent.
- Once Part IV is in force, follow the same disclosure, consent and Commissioner-referral process before an organisation covered by a mandatory code of conduct discloses personal information to another jurisdiction.
What it reaches
Obligation class
Transfer
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Section 6(l) of the General Privacy Principles already requires that personal information requested to be disclosed outside of Trinidad and Tobago be regulated, and that comparable safeguards to those under this Act exist in the receiving jurisdiction, binding every person who handles personal information regardless of whether Part III or Part IV has been proclaimed.
Section 46 would require a public body disclosing personal information to a party in another jurisdiction to tell the individual the purpose of the disclosure and the identity of the requester and the receiving jurisdiction's data protection body, and to obtain consent; where the individual withholds consent the public body would not disclose, and where the receiving jurisdiction's safeguards are in doubt the public body would refer the question to the Commissioner for a determination.
Section 72 would impose the equivalent duty on an organisation disclosing personal information under a mandatory code of conduct, again with a Commissioner referral where the organisation is not satisfied the receiving jurisdiction has comparable safeguards.
Section 28 already lets the Commissioner publish a list of countries the Commissioner considers to have comparable safeguards for personal information, which operationalises the section 6(l) principle even before sections 46 and 72 take effect.
Sections 46 and 72 are not shown as commenced: they sit in Part III and Part IV, which section 1(2) does not name among the provisions brought into force on 6 January 2012, so the detailed consent-and-referral mechanism awaits proclamation while the general section 6(l) principle already binds.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachdistributes_software_productships_mobile_app
Read the law
Consolidated text of the Data Protection Act
Chap. 22:04, Ministry of the Attorney General and Legal Affairs, mirrored by the Trinidad and Tobago Cyber Security Incident Response Team
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.