Law / Barbados

Barbados

All 5 named instruments researched to a stage, across three of the six areas of law we track: 5 in force. As of 5 September 2026.

When they take effect5 of 5 carry a date. Earlier is before 2014.
Before 2014: 3 instruments (3 in force) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 0 instruments 2019: 0 instruments 2020: 0 instruments ’20 2021: 2 instruments (2 in force) 2022: 0 instruments 2023: 0 instruments 2024: 0 instruments 2025: 0 instruments 2026: 0 instruments ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law none researched
  2. Privacy law 1
  3. Scraping law 3
  4. Cybersecurity law none researched
  5. Age gating law none researched
  6. News aggregation law 1

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law1 instrument, 1 in force

Research summary (151 words)

Barbados's comprehensive data-protection regime is the Data Protection Act, 2019 (Act 2019-29), closely modelled on the EU General Data Protection Regulation and enforced by the Data Protection Commissioner. The Act received the Governor-General's assent on 12 August 2019 and, by its own terms, comes into operation on a date fixed by proclamation; the Government gazetted that proclamation, S.I. 2021 No. 24, on 26 March 2021.

The Act covers processing of personal data by a data controller or data processor established in Barbados, or targeting data subjects in Barbados, without a general carve-out for publicly accessible personal data; only data a controller is itself obliged by another enactment to publish is exempt.

Biometric and genetic data are included in the Act's definition of sensitive personal data, whose processing is prohibited unless a specific ground applies, and an individual who suffers damage or distress from a contravention has a private right to compensation.

Comprehensive regime

Data Protection Act, 2019

Data Protection Act, 2019 (Act 2019-29)Official text of the Data Protection Act, 2019 (Act 2019-29), Office of the Attorney General of Barbados

In force since 26 March 2021. Binds public and private bodies.

What this law does

The Act requires a lawful basis before processing personal data (consent, contract, legal obligation, vital interest, or a public or legitimate-interest ground) and confines processing to a stated purpose. It prohibits processing sensitive personal data, a category that includes biometric and genetic data, unless the data subject consents or a narrow statutory ground applies.

Data subjects have rights of access, rectification, erasure, restriction, portability, and objection to automated decision-making or direct marketing, and section 18 gives a right not to be subject to a decision based solely on automated processing, including profiling, that produces a legal or similarly significant effect, subject to contract, statutory, and consent exceptions.

A data controller or processor must notify the Data Protection Commissioner of a personal data breach without undue delay, and within 72 hours where feasible. Transferring personal data outside Barbados requires an adequate level of protection in the destination or an appropriate safeguard such as standard clauses or binding corporate rules.

Data controllers and processors must register with the Commissioner, and an individual who suffers damage or distress from a contravention is entitled to compensation from the controller or processor.

What it requires

Scraping law3 instruments, 3 in force

Research summary (276 words)

Barbados has no scraping-specific statute, so general law governs each dimension separately.

The Computer Misuse Act, Cap. 124B criminalises gaining access to a computer system knowingly or recklessly and without lawful excuse or justification; unlike some Caribbean neighbours' computer-misuse statutes, section 4 does not require defeating a security measure, but the Act separately defines access as unauthorised only where the person is not entitled to it or lacks permission, so whether reading a public, unauthenticated page (which the site operator has made available to any visitor) falls within the offence is a genuine textual question no reported Barbadian case has answered.

No Barbadian court has ruled on the enforceability of a browsewrap or clickwrap terms-of-service against a scraper. The Copyright Act, Cap. 300 permits fair dealing for research or private study and, separately, for criticism, review, or reporting current events with sufficient acknowledgment, but Barbados has not enacted a text-and-data-mining exception, so training a model on scraped copyrighted text rests only on the research-or-private-study ground if it can be so characterised.

The Copyright Act protects a compilation only as a literary work under ordinary copyright, conferring no sui generis database right.

The Data Protection Act, 2019 applies to personal data without a general carve-out for information that is publicly accessible, so scraping personal data from a public Barbadian website remains subject to the Act's lawful-basis, purpose-limitation, and cross-border-transfer duties, and biometric data scraped from public images is sensitive personal data whose processing is prohibited absent a specific ground.

No Barbadian statute or reported case establishes a scraping-specific unfair-competition, misappropriation, or trespass doctrine, and none assigns legal weight to a robots.txt directive or imposes an AI-training-specific rule.

Computer misuse

Computer Misuse Act, illegal access

Computer Misuse Act, Cap. 124B, s. 4 (Illegal Access)Official consolidated text of the Computer Misuse Act, Cap. 124B, reproduced by the Organization of American States

In force since 18 July 2005. Binds public and private bodies.

What this law does

Section 4 prohibits a person, knowingly or recklessly and without lawful excuse or justification, from gaining access to the whole or any part of a computer system, causing a programme to be executed, using a programme to gain access to data, copying or moving data, or altering or erasing it. The offence carries a fine of $25,000 or imprisonment of up to two years, or both.

Section 3(2) separately defines access as unauthorised only where the person is not entitled to it, lacks permission, or exceeds the permission granted; because section 4 does not itself require defeating a security measure, whether a person reading a public, unauthenticated page (which the site operator has made generally available) acts without lawful excuse is an open textual question that no reported Barbadian decision has settled.

What it requires

Personal data

Data Protection Act, 2019, reach over scraped personal data

Data Protection Act, 2019 (Act 2019-29)Official text of the Data Protection Act, 2019 (Act 2019-29), Office of the Attorney General of Barbados

In force since 26 March 2021. Binds public and private bodies.

What this law does

The Act applies to processing personal data by a controller or processor established in Barbados, or targeting data subjects in Barbados, and carries no general exemption for personal data that is already publicly accessible; the only public-data exemption is narrow, covering information a controller is itself obliged by another enactment to publish.

A scraper collecting personal data, including a face or other biometric identifier, from a public Barbadian website remains subject to the Act's lawful-basis and purpose-limitation duties, and biometric data is sensitive personal data whose processing is prohibited unless a specific ground applies. Moving scraped personal data outside Barbados requires an adequate level of protection in the destination country or an appropriate safeguard.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (185 words)

Barbados has no press-publisher neighbouring right, no mandatory platform-to-publisher bargaining code, no recognised hot-news misappropriation doctrine distinct from ordinary copyright law, and no located statute or case law addressing hyperlinking or framing liability specifically; each of those dimensions is a sourced absence rather than an unresolved question.

Unlike some Francophone copyright statutes in the region, the Copyright Act, Cap. 300 contains no provision excluding the news of the day or mere facts from protection, and no general quotation exception letting one work reproduce extracts of another.

The only exception reaching a news aggregator's reproduction of headlines and snippets is section 52(1)(b), which excuses fair dealing with a protected work, other than a photograph, for the purpose of reporting current events, if accompanied by sufficient acknowledgment, subject to the section 53 fairness factors.

That exception carries no headline-length or short-extract cap and is not confined to the press industry, and no reported Barbadian decision applies it to a systematic aggregator as opposed to a traditional news report. The Act predates the concept of a machine-readable text-and-data-mining reservation, so no opt-out mechanism of that kind exists either.

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.