Comprehensive regime
Data Protection Act, 2019
Data Protection Act, 2019 (Act 2019-29)Official text of the Data Protection Act, 2019 (Act 2019-29), Office of the Attorney General of Barbados
In force since 26 March 2021. Binds public and private bodies.
What this law does
The Act requires a lawful basis before processing personal data (consent, contract, legal obligation, vital interest, or a public or legitimate-interest ground) and confines processing to a stated purpose. It prohibits processing sensitive personal data, a category that includes biometric and genetic data, unless the data subject consents or a narrow statutory ground applies.
Data subjects have rights of access, rectification, erasure, restriction, portability, and objection to automated decision-making or direct marketing, and section 18 gives a right not to be subject to a decision based solely on automated processing, including profiling, that produces a legal or similarly significant effect, subject to contract, statutory, and consent exceptions.
A data controller or processor must notify the Data Protection Commissioner of a personal data breach without undue delay, and within 72 hours where feasible. Transferring personal data outside Barbados requires an adequate level of protection in the destination or an appropriate safeguard such as standard clauses or binding corporate rules.
Data controllers and processors must register with the Commissioner, and an individual who suffers damage or distress from a contravention is entitled to compensation from the controller or processor.
What it requires