Barbados Data Protection Act 2019
Evidence request list. 23 controls, 23 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Part I: Preliminary
Citation as the Data Protection Act, 2019
- Scope analysis memo
- Definitions crosswalk to internal policy
- Applicability assessment
- Effective date and transition tracker
- Exemption inventory
- Scope assessment never refreshed
- Internal terms not aligned to statute
- Exemptions claimed without documentation
- Effective dates missed
Defines key terms including personal data, data controller, data processor, data subject, and processing
- Scope analysis memo
- Definitions crosswalk to internal policy
- Applicability assessment
- Effective date and transition tracker
- Exemption inventory
- Scope assessment never refreshed
- Internal terms not aligned to statute
- Exemptions claimed without documentation
- Effective dates missed
Scope of the Act covering processing of personal data in Barbados
- Scope analysis memo
- Definitions crosswalk to internal policy
- Applicability assessment
- Effective date and transition tracker
- Exemption inventory
- Scope assessment never refreshed
- Internal terms not aligned to statute
- Exemptions claimed without documentation
- Effective dates missed
Part II: Data Protection Principles
Core data protection principles including lawfulness, fairness, transparency, and purpose limitation
- Lawful basis assessment register
- Privacy notice versions
- Purpose limitation evidence per processing
- Data minimisation review reports
- Accuracy maintenance procedures
- Lawful basis not documented per activity
- Privacy notices outdated
- Purposes broaden silently over time
- Data hoarded beyond schedule
Requirements for fair processing of personal data
- Lawful basis assessment register
- Privacy notice versions
- Purpose limitation evidence per processing
- Data minimisation review reports
- Accuracy maintenance procedures
- Lawful basis not documented per activity
- Privacy notices outdated
- Purposes broaden silently over time
- Data hoarded beyond schedule
Conditions under which processing is considered lawful
- Lawful basis assessment register
- Privacy notice versions
- Purpose limitation evidence per processing
- Data minimisation review reports
- Accuracy maintenance procedures
- Lawful basis not documented per activity
- Privacy notices outdated
- Purposes broaden silently over time
- Data hoarded beyond schedule
Requirements for obtaining valid consent from data subjects
- Data subject request intake form and workflow
- DSR fulfillment log with SLAs
- Consent capture records
- Identity verification procedure for requesters
- Automated decision-making register
- No single intake channel for requests
- SLA breaches on access or erasure requests
- Consent receipts not retained
- Verification too weak or too burdensome
Conditions applicable to a child's consent for processing
- Data subject request intake form and workflow
- DSR fulfillment log with SLAs
- Consent capture records
- Identity verification procedure for requesters
- Automated decision-making register
- No single intake channel for requests
- SLA breaches on access or erasure requests
- Consent receipts not retained
- Verification too weak or too burdensome
Additional conditions for processing sensitive personal data
- Lawful basis assessment register
- Privacy notice versions
- Purpose limitation evidence per processing
- Data minimisation review reports
- Accuracy maintenance procedures
- Lawful basis not documented per activity
- Privacy notices outdated
- Purposes broaden silently over time
- Data hoarded beyond schedule
Part III: Rights of a Data Subject
Data subjects may request access to their personal data
- Data subject request intake form and workflow
- DSR fulfillment log with SLAs
- Consent capture records
- Identity verification procedure for requesters
- Automated decision-making register
- No single intake channel for requests
- SLA breaches on access or erasure requests
- Consent receipts not retained
- Verification too weak or too burdensome
Right to have inaccurate personal data corrected
- Data subject request intake form and workflow
- DSR fulfillment log with SLAs
- Consent capture records
- Identity verification procedure for requesters
- Automated decision-making register
- No single intake channel for requests
- SLA breaches on access or erasure requests
- Consent receipts not retained
- Verification too weak or too burdensome
Right to have personal data erased under specified conditions
- Data subject request intake form and workflow
- DSR fulfillment log with SLAs
- Consent capture records
- Identity verification procedure for requesters
- Automated decision-making register
- No single intake channel for requests
- SLA breaches on access or erasure requests
- Consent receipts not retained
- Verification too weak or too burdensome
Right to restrict the processing of personal data
- Data subject request intake form and workflow
- DSR fulfillment log with SLAs
- Consent capture records
- Identity verification procedure for requesters
- Automated decision-making register
- No single intake channel for requests
- SLA breaches on access or erasure requests
- Consent receipts not retained
- Verification too weak or too burdensome
Right to receive personal data in a structured, machine-readable format
- Data subject request intake form and workflow
- DSR fulfillment log with SLAs
- Consent capture records
- Identity verification procedure for requesters
- Automated decision-making register
- No single intake channel for requests
- SLA breaches on access or erasure requests
- Consent receipts not retained
- Verification too weak or too burdensome
Rights regarding automated individual decision-making and profiling
- Data subject request intake form and workflow
- DSR fulfillment log with SLAs
- Consent capture records
- Identity verification procedure for requesters
- Automated decision-making register
- No single intake channel for requests
- SLA breaches on access or erasure requests
- Consent receipts not retained
- Verification too weak or too burdensome
Part IV: Transfers of Personal Data Outside Barbados
Personal data may only be transferred where recipient country ensures adequate protection
- Transfer impact assessment documents
- Standard contractual clauses register
- Binding corporate rules approval
- Adequacy decision references
- Vendor transfer mapping
- No transfer impact assessment performed
- SCCs not updated to current versions
- Sub-processor transfers untracked
- Reliance on adequacy without supplementary measures
Safeguards required for international transfers including binding corporate rules and standard clauses
- Transfer impact assessment documents
- Standard contractual clauses register
- Binding corporate rules approval
- Adequacy decision references
- Vendor transfer mapping
- No transfer impact assessment performed
- SCCs not updated to current versions
- Sub-processor transfers untracked
- Reliance on adequacy without supplementary measures
Requirements for binding corporate rules as a transfer mechanism
- Transfer impact assessment documents
- Standard contractual clauses register
- Binding corporate rules approval
- Adequacy decision references
- Vendor transfer mapping
- No transfer impact assessment performed
- SCCs not updated to current versions
- Sub-processor transfers untracked
- Reliance on adequacy without supplementary measures
Part V: Exemptions
Exemptions for national security, crime prevention, taxation, health, education, journalism, and research
- Policy referencing the control
- Documented procedure
- Evidence of operating effectiveness
- Monitoring or review reports
- Roles and responsibilities mapping
- Policy not aligned to control statement
- Procedure undocumented
- No periodic monitoring
- Evidence not retained
Part VI: Data Controller and Data Processor
Registration requirements, security obligations, breach notification, and impact assessments
- Approved information security policy
- Policy review and approval history
- Roles and responsibilities matrix
- Management commitment statement
- Policy communication evidence
- Policies outdated or unsigned
- No defined review cadence
- Roles unclear or duplicated
- Management commitment not visible
Appointment and functions of data privacy officers
- Policy referencing the control
- Documented procedure
- Evidence of operating effectiveness
- Monitoring or review reports
- Roles and responsibilities mapping
- Policy not aligned to control statement
- Procedure undocumented
- No periodic monitoring
- Evidence not retained
Part VII: Data Protection Commissioner
Appointment, functions, staff, confidentiality, and annual reporting of the Commissioner
- Regulator contact list
- Inspection readiness pack
- Authority engagement log
- Notification submission records
- Regulator guidance subscription
- No nominated regulator liaison
- Inspection pack outdated
- Notifications not tracked
- Authority guidance not monitored
Part VIII: Enforcement
Guidelines, codes of practice, penalties, prosecutions, and liability provisions
- Complaints register and resolution log
- Regulator correspondence file
- Penalty exposure tracker
- Cooperation procedure with authorities
- Remediation action plans
- Complaints not centrally tracked
- No defined regulator response owner
- Remediation actions not closed out
- Penalty risk not on enterprise risk register
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Barbados Data Protection Act 2019 framework page.