What national laws regulate the processing of personal data in your jurisdiction?
The Data Protection Act, 2018, The Data Protection Regulations, 2024
The Data Protection (Data Controller Registration) Regulations, 2024
Data protection continues to be a top issue for companies around the globe. With the ever-changing technology and responding legislation, it is important that businesses be prepared to handle a patchwork of data protection regulations. This guide, prepared by TerraLex members from around the globe, provides initial guidance on some of the key aspects to consider.
How to Use: You can use the tools below to create bespoke reports for the jurisdiction(s) and topic(s) covered. Click into single jurisdiction for one location or use the compare tool to compare multiple jurisdictions. Select the jurisdictions and topics of interest to create your unique report. You also have the option to print or download using the ellipsis button in the top right corner.
The Data Protection Act, 2018, The Data Protection Regulations, 2024
The Data Protection (Data Controller Registration) Regulations, 2024
The laws apply to the following:
The law covers both personal data and sensitive personal data.
Personal Data is any information from which a living individual can be identified and includes an individual's name, date of birth, email address, telephone address, residential address, online identifiers, account numbers etc.
Sensitive Personal Data includes genetic data, biometric data, racial or ethnic origin, political opinions, philosophical beliefs, religious beliefs or other beliefs of a similar nature, physical or mental health or condition, sex life or criminal convictions.
There are certain circumstances in which the processing of personal data would be exempted under local laws. These circumstances include where the personal data is being processed:
The data owners have the following rights under local laws:
In order to process personal data, the data controller must be able to satisfy or prove that one of the following legal grounds exist:
The main obligations imposed upon data controllers are:
The law does not establish a data retention period but merely states that the data must not be kept for longer than it is reasonably required.
Yes.
Yes. The Office of the Information Commissioner is the regulatory authority and its main role is to monitor compliance with the Data Protection Act and its attendant regulations.
Yes, there are certain categories of data controllers who must appoint a DPO. These categories include:
a) public authorities; b) entities who process sensitive personal data or data relating to criminal convictions; or c) entities who process personal data on a large scale.
The main roles of the DPO are to ensure that the data controller processes personal data in compliance with the data protection standards and in compliance with local laws and good practice and to assist data subjects with exercising their rights.
Local law stipulates that personal data shall not be transferred to a state or territory outside of Jamaica unless that state or territory ensures an adequate level of protection for the rights and freedoms of data subjects. This rule, however, would not be applicable in specified circumstances such as where the data subject has consented to the transfer, the transfer is necessary for reasons of substantial public interest or where the transfer is necessary for the performance of a contract.
No.
Yes, local laws stipulate that all data controllers must implement certain technical and organisational measures to prevent any unauthorised or unlawful processing of personal data as well as any accidental loss or destruction of, or damage to, personal data. These measures include a) pseudonymisation and encryption of personal data; (b) the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services; (c) the ability to restore the availability of, and access to, personal data in a timely manner in the event of a physical or technical incident; and (d) a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing.
Yes, all data controllers are required to report any security breach to both the Information Commissioner and affected data subject within 72 hours of becoming aware of the breach.
An entity can be liable to a fine not exceeding 4% of its annual gross worldwide income.
A director, manager, secretary, or senior officer can also be held personally liable if it can be proven that they were negligent or consented to the entity's non-compliance.
An entity may also be liable to pay compensation to any person who can prove that they have sufferred some sort of loss as a result ot the entity's non-compliance.
Disclaimer: This guide contains summaries of general principles of law. It is not a substitute for specific legal advice and should not be relied upon in relation to the application of the law or subject matter covered.