Law / Trinidad and Tobago

Data Protection Act, 2011, Commissioner, contravention and enforcement

Act 13 of 2011, ss. 7-28 and 87-96 (Commissioner, contravention and enforcement)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 6 January 2012.

An enforcement supervision rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • The Office of the Information Commissioner is established and operating, with powers to audit and investigate compliance, order a body to stop a contravening practice, authorise data matching, and publish compliance guidelines; the Commissioner's power to audit or enquire specifically under Part III or Part IV (sections 20 and 21) is not yet in force, since neither Part currently binds.
  • The Commissioner and anyone acting under the Commissioner's direction must not disclose information obtained in performing their duties under the Act.
  • Part V's offences and penalties (sections 87 to 96) have not been proclaimed, so a contravention of the General Privacy Principles or of the Commissioner's own confidentiality obligation currently carries no criminal exposure under this Act; once proclaimed, an individual offender would face a fine of up to $50,000 or three years' imprisonment on summary conviction, or up to $100,000 or five years on indictment, and a body corporate a fine of $250,000 on summary conviction or $500,000 on indictment, with the Court able to separately impose a fine of up to ten percent of annual turnover.
  • Once Part IV is in force, every director and officer of a corporation must take reasonable care to ensure the corporation complies with the Act, the Regulations, and any Commissioner order.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

Part V, sections 87 to 96, which would make it an offence to contravene the General Privacy Principles, obstruct the Commissioner, breach a mandatory code of conduct, or breach the Commissioner's own confidentiality obligation under section 25, has not been proclaimed: section 1(2) names only Part I and specified sections of Part II as in force. No criminal exposure currently exists under the Act. Once proclaimed, section 95 would fine an individual up to $50,000 or three years' imprisonment on summary conviction, or up to $100,000 or five years on indictment, and section 95(2) would fine a body corporate $250,000 on summary conviction or $500,000 on indictment, with section 96 letting the Court separately impose a fine of up to ten percent of the corporation's annual turnover.

Penalty structure

Individual offender: summary conviction fine of up to $50,000 or imprisonment for three years; conviction on indictment, fine of up to $100,000 or imprisonment for five years (s. 95(1)). A body corporate is liable to a fine of $250,000 on summary conviction or $500,000 on indictment (s. 95(2)), and the Court may separately impose a fine of up to ten percent of the corporation's annual turnover for a contravention (s. 96(1)). Part V, which states these offences, is enacted but has not been proclaimed and is not in force; the figures above are the enacted, not-yet-commenced penalty.

Rule
Fixed only
As of
19 September 2026
Currency
TTD
Fixed cap
100,000

Who enforces it

Enforcement body

Office of the Information Commissioner

What it reaches

Obligation class

Governance, Reporting

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Sections 7 to 18 establish the Office of the Information Commissioner as a body corporate, provide for the appointment, tenure, removal, remuneration and oath of the Commissioner and up to two Deputy Commissioners, and give the Commissioner powers to audit and investigate compliance, order a public body or organisation to cease a contravening practice, authorise data matching, make orders on fee reasonableness and compliance with the General Privacy Principles, and publish compliance guidelines.

Section 10 gives the Commissioner functions including promoting codes of conduct, disseminating information about the Act, monitoring compliance, cooperating with counterparts in other jurisdictions, researching privacy issues, flagging a body's failure to meet the Principles or Part III or Part IV, publishing compliance reports, and reviewing privacy impact assessments.

Section 25(1) bars the Commissioner and anyone acting under the Commissioner's direction from disclosing information obtained in performing their duties, and section 28 requires the Commissioner to publish a list of countries with comparable safeguards for personal information.

All of these provisions, together with the rest of Part I, came into force on 6 January 2012, so Trinidad and Tobago currently has an operating Information Commissioner with these powers and functions, even though the Parts the Commissioner would chiefly enforce, Part III and Part IV, are not yet proclaimed.

Not commenced within Part II are the designation of inspectors (section 19), the Commissioner's power to audit or enquire pursuant to Part III (section 20) or Part IV (section 21), privileged information (section 24), the exceptions to the Commissioner's confidentiality obligation (section 25(2) and (3)), and the Commissioner's annual report to Parliament (section 27).

Part V, sections 87 to 96, would make it an offence to obstruct the Commissioner, make a false statement, fail to comply with a Commissioner order, violate the whistle-blowing protection, breach a mandatory code of conduct, wilfully disclose or unlawfully collect personal information in contravention of the Act, or breach the Commissioner's own confidentiality obligation under section 25, and would penalise an individual offender with a fine of up to $100,000 or five years' imprisonment on indictment and a body corporate with a fine of up to $500,000 on indictment or up to ten percent of annual turnover.

Part V is not shown as commenced: section 1(2) does not name it among the provisions brought into force on 6 January 2012, so none of the Act's offences or penalties currently apply, and a contravention of the General Privacy Principles, including the confidentiality obligation in section 25(1) that already binds the Commissioner's own office, cannot presently be prosecuted under this Act.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach

Read the law

Consolidated text of the Data Protection Act
Chap. 22:04, Ministry of the Attorney General and Legal Affairs, mirrored by the Trinidad and Tobago Cyber Security Incident Response Team

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app