Law / Vanuatu

Vanuatu

4 of 7 named instruments researched to a stage, across four of the six areas of law we track: 4 in force. As of 6 September 2026.

  1. AI law 1
  2. Privacy law 1
  3. Scraping law 1
  4. Cybersecurity law none researched
  5. Age gating law none researched
  6. News aggregation law 1

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law1 instrument, 1 in force

Research summary (110 words)

Vanuatu's Digital Transformation Act No. 42 of 2025 names artificial intelligence (AI) and AI-related data services as one of thirteen classes of ICT service in section 13, so a person carrying on business providing AI or AI-related data services in Vanuatu must hold an ICT service permit from the Director of the Department of Communications and Digital Transformation, renewed annually, subject to conditions, suspension, and cancellation.

The Act does not further define what counts as an AI or AI-related data service, and it imposes no separate transparency, risk-assessment, training-data, or prohibited-practices duty specific to AI beyond the general permit and enforcement scheme that applies to every ICT service class alike.

AI governance

Digital Transformation Act 2025, ICT service permit for AI and AI-related data services

Digital Transformation Act No. 42 of 2025 (Vanuatu), s. 13(l)Official text of the Digital Transformation Act No. 42 of 2025, Vanuatu Department of Communications and Digital Transformation

In force 9 months, effective 17 December 2025. Binds public and private bodies.

What this law does

Section 13 lists an "artificial intelligence (AI) and AI-related data services permit" as one of thirteen classes of ICT service permit, alongside classes such as cloud and data services, e-commerce, and cybersecurity governance.

Section 14 requires a person who intends to carry on business as an ICT service provider, including one offering AI or AI-related data services, to apply to the Director for the corresponding permit, which section 17 makes valid for one year and renewable, and section 18 requires an annual permit fee.

The Director may impose, vary, suspend, or cancel a permit's conditions under sections 16, 19, and 20 for breach of a condition or of the Act or its Regulations, and section 31(1) makes carrying out an ICT activity, including providing AI or AI-related data services, without a valid permit an offence punishable on conviction by a fine of up to VT3,000,000 or up to 3 years' imprisonment for an individual, or a fine of up to VT20,000,000 for a body corporate.

What it requires

Privacy law1 instrument, 1 in force

Research summary (145 words)

Vanuatu's Data Protection and Privacy Act No. 13 of 2024 is the country's first comprehensive personal-data statute, assented on 5 December 2024 and commenced on 2 January 2025. It binds public and private data controllers and processors alike, requiring a lawful basis for ordinary processing, a heightened basis for special categories including biometric data, and parental consent with age-verification mechanisms before processing a child's personal data.

It grants data subjects rights of access, rectification, erasure, restriction, objection, and protection from a decision based solely on automated processing, restricts transferring personal data outside Vanuatu absent ministerial authorisation or an approved-country listing, and enforces its duties through a Deputy Commissioner of Data Protection and Privacy backed by criminal fines rather than a stated civil damages right.

Several duties the Act names, including breach notification to data subjects, are left to Regulations the Minister has not yet made.

Comprehensive regime

Data Protection and Privacy Act 2024, comprehensive personal data protection regime

Data Protection and Privacy Act No. 13 of 2024 (Vanuatu)Official text of the Data Protection and Privacy Act No. 13 of 2024, Vanuatu Department of Communications and Digital Transformation

In force since 2 January 2025. Binds public and private bodies.

What this law does

Section 2 applies the Act to processing of personal data in the private and public sectors, wherever the data subject resides, where the processing takes place in Vanuatu, involves data generated or collected in Vanuatu, or targets or monitors a person in Vanuatu, but excludes purely personal or household processing.

Section 4 requires personal data to be processed fairly, transparently, for explicit and legitimate purposes, adequately and proportionately, accurately, for no longer than necessary, and with appropriate security, and section 5 lists the lawful bases for processing, including consent, contract necessity, legal obligation, public interest, and a legitimate interest that does not override the data subject's rights.

Section 6 prohibits processing special categories of personal data, defined in section 1 to include genetic data, biometric data uniquely identifying a person, and data revealing racial or ethnic origin, political opinions, trade-union membership, religious belief, health or sexual life, unless a listed exception applies, such as consent, an employment or social-security purpose, medical care, public health, or a safeguarded charitable-body purpose.

Section 7 prohibits processing a child's personal data unless a parent, carer or legal representative has consented, the processing is in the child's legitimate interest, meets a legal obligation, serves the public interest, or is necessary for preventive or counselling services offered directly to the child, and requires that communication addressed to a child use clear, plain language with appropriate mechanisms for age verification in place.

Section 8 requires that consent be demonstrable, freely given, presented separately from other matters in plain language, and withdrawable at any time free of charge.

Sections 9 to 14 give a data subject the right to access their personal data and related information within one month and free of charge, to restrict processing in specified circumstances, to have inaccurate or unlawfully processed data rectified or erased, to object to processing, and not to be subject to a decision based solely on automated processing, including profiling, that significantly affects them, unless the decision is authorised by law, necessary for a contract, or consented to with safeguards including human intervention.

Sections 15 to 17 bar transferring personal data generated or collected in Vanuatu outside the country without the Minister's prior authorisation, unless the recipient country or organisation is on a Minister-published list of jurisdictions providing an appropriate level of protection, or a specific exception such as the data subject's informed consent applies.

Part 5 gives the Deputy Commissioner powers to compel disclosure of documents or information within 14 days and to obtain a Court-issued search warrant to access, seize or secure a data centre or data server, and Part 6 makes non-compliance with the Act, unlawful obtaining or disclosure of personal data, altering data to defeat a disclosure request, obstructing a search warrant, and destroying or falsifying information sought by the Deputy Commissioner each an offence punishable by a fine of up to VT10,000,000, with lesser fines of VT1,000,000 for hindering the Deputy Commissioner's powers and VT2,000,000 for unlawfully disclosing information obtained under a request or warrant.

Section 31 lets the Minister make Regulations on matters including joint-controller obligations, processor obligations, security of processing, records of processing, and personal-data-breach obligations and notification, none of which the Act itself yet states as a standing duty, and section 32 commenced the Act on the day of its Gazette publication.

What it requires

Scraping law1 instrument, 1 in force

Research summary (159 words)

Vanuatu's Cybercrime Act No. 22 of 2021 criminalises accessing a computer system by infringing a security measure, so open-web crawling of a public unauthenticated page carries no offence under it absent a technical circumvention.

The Act separately criminalises unauthorised interference with a computer system, program or data, and misuse of devices intended for unauthorised access or interception, each with escalating fines and imprisonment terms for an individual and a separate fine scale for a body corporate; section 63 confirms the general posture by letting a police officer access publicly available stored computer data without authorisation.

Personal data that a scraper collects from Vanuatu falls within the Data Protection and Privacy Act No. 13 of 2024, researched under the privacy topic. Vanuatu's Electronic Transactions Act No. 24 of 2000 recognises electronic contract formation generally, without a provision distinguishing browsewrap from clickwrap acceptance, and its own voluntary personal-data standard at section 25 has been superseded in substance by the 2024 Act.

Computer misuse

Cybercrime Act 2021, computer-access and interference offences

Cybercrime Act No. 22 of 2021 (Vanuatu)Text of the Cybercrime Act No. 22 of 2021, PacLII, archived copy

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived December 22, 2024. Publisher's page: https://www.paclii.org/vu/legis/num_act/ca2021112.pdf

In force since 22 September 2021. Binds public and private bodies.

What this law does

Section 3 makes it an offence to intentionally and without lawful excuse access the whole or part of a computer system by infringing a security measure, punishable by a fine of up to VT2,000,000 or up to 5 years' imprisonment for an individual, or a fine of up to VT4,000,000 for a body corporate; a person is not liable if entitled to access the program or data or has consent to it. Section 4 similarly bars intercepting a non-public transmission of computer data without lawful excuse.

Section 5 makes unauthorised interference with a computer system, program or data an offence carrying a fine of up to VT7,000,000 or up to 40 years' imprisonment for an individual (up to VT100,000,000 for a body corporate), rising to a fine of up to VT50,000,000 or up to 50 years' imprisonment where the interference causes serious harm such as a financial loss over VT1,000,000, a threat to national security, physical injury or death, or a threat to public health or safety, and a lesser fine of up to VT10,000,000 or up to 40 years' imprisonment for reckless interference.

Section 6 makes it an offence, carrying a fine of up to VT1,000,000 or up to 3 years' imprisonment for an individual (up to VT3,000,000 for a body corporate), to produce, sell, procure, import, export, distribute or make available software, a device, or an access code for the purpose of unauthorised interception or interference, unless the act is for authorised training, testing or protection of a computer system.

Section 63, in the Act's mutual-assistance part, confirms that a police officer may access publicly available stored computer data without authorisation regardless of where it is geographically located, consistent with section 3's security-measure-based test for what counts as unauthorised access.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (83 words)

Vanuatu's Electronic Transactions Act No. 24 of 2000 gives an intermediary that carries or links to third-party electronic content a general liability limitation: an intermediary that did not originate the content and has no actual knowledge, or reasonable awareness of facts, giving rise to civil or criminal liability faces no liability for it, and is under no duty to monitor content it carries.

The limitation is general to any electronic intermediary and is not framed around journalism, headline reproduction, or a compelled-payment scheme.

Linking and framing

Electronic Transactions Act 2000, intermediary liability limitation

Electronic Transactions Act No. 24 of 2000 (Vanuatu), Cap 263Text of the Electronic Transactions Act No. 24 of 2000, Telecommunications, Radiocommunications and Broadcasting Regulator of Vanuatu

In force since 6 November 2000. Binds public and private bodies.

What this law does

Section 26 provides that an intermediary, defined as a person who on behalf of another sends, receives, stores, or provides other services with respect to an electronic record, is not subject to civil or criminal liability for information in a record it carries if it was not the originator, has no actual knowledge that the information gives rise to liability, and is not aware of facts or circumstances from which the likelihood of liability ought reasonably to have been known; section 26(2) states the intermediary is under no duty to monitor the information it carries to establish such knowledge.

Section 27 requires an intermediary that acquires actual knowledge that carried information gives rise to civil or criminal liability to remove it as soon as practicable and notify the Minister or the appropriate law enforcement agency, and requires an intermediary that becomes aware of facts suggesting a likelihood of liability to follow an approved code of conduct or notify the Minister, who may then direct removal.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.