Guiding organizations through Jamaica's Data Protection Act, 2020 — from first assessment to a working compliance program. Most organizations know the Act applies to them; far fewer have done the work it requires: registration with the Office of the Information Commissioner, a named data protection officer, documented processing, and a credible answer when a regulator or the board asks how personal data is protected. We built and operate our own framework before offering to build anyone else's, and we drive these programs end to end alongside your senior leadership.
Engagements in this practice typically include:
- Compliance gap assessment — measuring current practice against the Act and identifying exactly what must change
- OIC registration — preparing the data controller registration particulars and guiding the submission through to completion
- Impact assessments (DPIAs) — evaluating higher-risk processing and documenting the safeguards that make it defensible
- Processing records and policies — establishing the data processor register, retention schedule, internal policy, and external privacy notices the Act expects
- Data protection officer support — standing up the DPO function, or supporting an appointed officer with the procedures and reporting lines the role requires
- Requests, breaches, and training — data-subject-request and breach-response procedures, and briefing leadership and staff on their accountabilities
- AI and vendor data governance — reviewing where AI tools and vendors touch customer data, and holding contracts to the Act before they are signed
- Shadow IT and processor discovery — identifying the unapproved applications and third parties that hold institutional data, and bringing them under contract, register, and control
Where does your organization stand on the Act?
If you know the Data Protection Act applies but haven't yet done what it requires, that gap is exactly what we close.
Begin a conversation →