TerraLex Guide to Data Protection

Welcome to the Terralex cross-border guide to data protection

Data protection continues to be a top issue for companies around the globe. With the ever-changing technology and responding legislation, it is important that businesses be prepared to handle a patchwork of data protection regulations. This guide, prepared by TerraLex members from around the globe, provides initial guidance on some of the key aspects to consider.

How to Use: You can use the tools below to create bespoke reports for the jurisdiction(s) and topic(s) covered. Click into single jurisdiction for one location or use the compare tool to compare multiple jurisdictions. Select the jurisdictions and topics of interest to create your unique report. You also have the option to print or download using the ellipsis button in the top right corner.

Jamaica TerraLex Guide to Data Protection Guide

Date posted:
16/08/2024
Last update:
05/09/2024

Legislation and regulations

What national laws regulate the processing of personal data in your jurisdiction?

The Data Protection Act, 2018, The Data Protection Regulations, 2024

The Data Protection (Data Controller Registration) Regulations, 2024

To whom do the laws apply?

The laws apply to the following:

  • An entity that is established in Jamaica or in any place where Jamaican law applies by virtue of international public law, and the personal data are processed in the context of that establishment; or
  • An entity that is not established in Jamaica but- (i) uses equipment in Jamaica for processing the personal data otherwise than for the purpose of transit through Jamaica; or (ii) processes personal data, of an individual who is located in Jamaica, and the processing activities are related to- (A) the offering of products or services to individuals in Jamaica, irrespective of whether a payment is required; or (B) the monitoring of the behaviour of individuals as far as their behaviour takes place within Jamaica.

Scope of protection

What type of data is covered by the law?

The law covers both personal data and sensitive personal data.

Personal Data is any information from which a living individual can be identified and includes an individual's name, date of birth, email address, telephone address, residential address, online identifiers, account numbers etc.

Sensitive Personal Data includes genetic data, biometric data, racial or ethnic origin, political opinions, philosophical beliefs, religious beliefs or other beliefs of a similar nature, physical or mental health or condition, sex life or criminal convictions.

What are the main exemptions (if any)?

There are certain circumstances in which the processing of personal data would be exempted under local laws. These circumstances include where the personal data is being processed:

  • for the purposes of safeguarding national security;
  • for the prevention, detection, or investigation of crime;
  • to exercise or discharge a legal function;
  • for journalism, research, historical or statistical purposes; or
  • for domestic purposes.

What rights do the laws grant to the data owners?

The data owners have the following rights under local laws:

  • the right to access the data;
  • the right to prevent/object to processing of his/her personal data in specified circumstances;
  • the right to request rectification of the data i.e. to modify, amend or delete the data;
  • the right to object to processing of his/her personal data for marketing purposes; and
  • the right to withdraw consent to processing.

Processing requirement and main obligations

What are the lawful grounds for processing personal data or sensitive personal data (if different)?

In order to process personal data, the data controller must be able to satisfy or prove that one of the following legal grounds exist:

  • the data subject consented;
  • the processing is necessary for the performance of a contract;
  • the processing is necessary to comply with a legal obligation;
  • the processing is necessary to protect the vital interests of the data subject;
  • the processing is necessary for the administration of justice or for the exercise of a legal function; or
  • the processing is necessary for the purposes of legitimate interests pursued by the data controller.

What are the main obligations imposed by the law?

The main obligations imposed upon data controllers are:

  • registration with the Information Commissioner and payment of registration fee;
  • compliance with the eight (8) data protection international standards;
  • appointment of a data protection officer;
  • annually conduct a data protection impact assessment; and
  • reporting of data breaches to both the Information Commissioner and affected data subject within 72 hours of becoming aware of the breach.

Do the laws establish a data retention period to be observed?

The law does not establish a data retention period but merely states that the data must not be kept for longer than it is reasonably required.

Must the data processing activities be recorded under the law?

Yes.

National authority and DPO

Is there a Data Protection National Authority? If so, what is the National Authority main role?

Yes. The Office of the Information Commissioner is the regulatory authority and its main role is to monitor compliance with the Data Protection Act and its attendant regulations.

Does the law impose the obligation of designating a data protection officer (DPO)? If so, what is the role of the DPO under the law?

Yes, there are certain categories of data controllers who must appoint a DPO. These categories include:

a) public authorities; b) entities who process sensitive personal data or data relating to criminal convictions; or c) entities who process personal data on a large scale.

The main roles of the DPO are to ensure that the data controller processes personal data in compliance with the data protection standards and in compliance with local laws and good practice and to assist data subjects with exercising their rights.

Cross-border transfers

What rules regulate the transfer of data outside your jurisdiction?

Local law stipulates that personal data shall not be transferred to a state or territory outside of Jamaica unless that state or territory ensures an adequate level of protection for the rights and freedoms of data subjects. This rule, however, would not be applicable in specified circumstances such as where the data subject has consented to the transfer, the transfer is necessary for reasons of substantial public interest or where the transfer is necessary for the performance of a contract.

Is it necessary to notify the National Authority prior to the international transfer?

No.

Security standards, data breaches, and sanctions

Do the laws impose any information security standards and/or requirements?

Yes, local laws stipulate that all data controllers must implement certain technical and organisational measures to prevent any unauthorised or unlawful processing of personal data as well as any accidental loss or destruction of, or damage to, personal data. These measures include a) pseudonymisation and encryption of personal data; (b) the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services; (c) the ability to restore the availability of, and access to, personal data in a timely manner in the event of a physical or technical incident; and (d) a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing.

Do the laws establish any kind of mandatory notification duty?

Yes, all data controllers are required to report any security breach to both the Information Commissioner and affected data subject within 72 hours of becoming aware of the breach.

What are the sanctions for noncompliance with data protection laws?

An entity can be liable to a fine not exceeding 4% of its annual gross worldwide income.

A director, manager, secretary, or senior officer can also be held personally liable if it can be proven that they were negligent or consented to the entity's non-compliance.

An entity may also be liable to pay compensation to any person who can prove that they have sufferred some sort of loss as a result ot the entity's non-compliance.

Other comments

Other comments

Disclaimer: This guide contains summaries of general principles of law. It is not a substitute for specific legal advice and should not be relied upon in relation to the application of the law or subject matter covered.