Where things stand
Jamaica’s Data Protection Act, 2020 established how personal data is to be collected, used, and protected, and created the Office of the Information Commissioner (OIC) as the national regulator. The Act’s substantive obligations took effect on 1 December 2023, and data controllers have since been required to register with the OIC. Registration runs in yearly cycles, with renewal due at the start of each registration year.
The position has hardened since then. The Government has signalled that the OIC is being resourced and restructured to become an enforcement-ready authority, and the regulator has been clear that failure to register as a data controller is an offense under the Act. In short, the period of awareness-building is giving way to compliance expectations that carry consequences.
What the Act requires of a data controller
If your organization decides why and how personal data is processed — about customers, employees, or the directors and officers of the entities you deal with — you are very likely a data controller. The core obligations are these:
- Register with the OIC and keep that registration current each year.
- Apply the data protection standards set out in the Act when processing personal data — lawful and fair handling, purpose limitation, accuracy, retention discipline, and security among them.
- Appoint a data protection officer where required, with the standing to do the job.
- Keep records of your processing — what data you hold, why, and who it is shared with.
- Assess higher-risk processing through a data protection impact assessment before it begins.
- Honor the rights of data subjects, including access to their data, within the time the Act allows.
- Be ready for a breach — to detect it, contain it, and notify within the required timelines.
For institutions regulated by the Financial Services Commission, none of this stands apart from existing supervisory expectations around outsourcing, operational risk, and the safeguarding of client information. Data protection sits alongside that work rather than competing with it.
Where organizations get stuck
The obligations are rarely the hard part. The friction is practical: no single owner for data protection; processing that has never been written down; privacy notices and consent that were never put in place; service providers handling personal data without documented terms; and a data protection officer named on paper but unsupported in practice. Each gap is manageable on its own. Left together until a complaint or an audit, they become a scramble.
A practical path to readiness
The work is best sequenced rather than attempted all at once: assess the gap against the Act; map what personal data you hold and why; put the policy, notices, and processing records in place; register with the OIC; stand up the data protection officer function and the procedures behind it; brief leadership and train staff; then review at least once a year. Driven properly, with senior leadership engaged from the start, this is a program of weeks and months, not years.
A readiness checklist
Use the following to gauge where your organization stands today. The same checklist is available as a one-page download.
- You have determined whether your organization is a data controller under the Act.
- You have registered, or begun registering, with the Office of the Information Commissioner.
- You know what personal data you hold, where it lives, and why you process it.
- You have a written data protection policy and current privacy notices.
- A data protection officer has been appointed, or the responsibility clearly assigned where one is required.
- Higher-risk processing has been assessed through a data protection impact assessment.
- Service providers that handle personal data are documented and engaged under appropriate terms.
- You can recognize, log, and answer a data subject’s request within the time the Act allows.
- You have a breach-response procedure that can detect, contain, and notify on time.
- Staff and leadership understand their responsibilities, and the program is reviewed at least annually.
Download the checklist (PDF) ↓
How we help
Data protection and compliance is one of the firm’s practice areas. We built and now operate our own data-protection framework — registration particulars, impact assessment, processing records, and policy — before offering to build anyone else’s, and we drive these programs end to end alongside your senior leadership. Where a formal legal opinion is required, we coordinate with your counsel.
Where does your organization stand?
If the checklist surfaced gaps — or you would rather not work through them alone — we drive data-protection programs end to end, alongside your leadership.
Begin a conversation →This article is general information, not legal advice. Requirements under the Data Protection Act, 2020 and the OIC’s processes may change; confirm the current position with the OIC or your advisers before acting.