Skip to content

Evidence request lists

Barbados Data Protection Act 2019

Evidence request list. 23 controls, 23 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Part I: Preliminary

BB-DPA-1
Section 1 - Short Title

Citation as the Data Protection Act, 2019

Artefacts an auditor will ask for
  • Scope analysis memo
  • Definitions crosswalk to internal policy
  • Applicability assessment
  • Effective date and transition tracker
  • Exemption inventory
Where this commonly fails
  • Scope assessment never refreshed
  • Internal terms not aligned to statute
  • Exemptions claimed without documentation
  • Effective dates missed
BB-DPA-2
Section 2 - Interpretation

Defines key terms including personal data, data controller, data processor, data subject, and processing

Artefacts an auditor will ask for
  • Scope analysis memo
  • Definitions crosswalk to internal policy
  • Applicability assessment
  • Effective date and transition tracker
  • Exemption inventory
Where this commonly fails
  • Scope assessment never refreshed
  • Internal terms not aligned to statute
  • Exemptions claimed without documentation
  • Effective dates missed
BB-DPA-3
Section 3 - Application of Act

Scope of the Act covering processing of personal data in Barbados

Artefacts an auditor will ask for
  • Scope analysis memo
  • Definitions crosswalk to internal policy
  • Applicability assessment
  • Effective date and transition tracker
  • Exemption inventory
Where this commonly fails
  • Scope assessment never refreshed
  • Internal terms not aligned to statute
  • Exemptions claimed without documentation
  • Effective dates missed

Part II: Data Protection Principles

BB-DPA-4
Section 4 - Principles Relating to Processing

Core data protection principles including lawfulness, fairness, transparency, and purpose limitation

Artefacts an auditor will ask for
  • Lawful basis assessment register
  • Privacy notice versions
  • Purpose limitation evidence per processing
  • Data minimisation review reports
  • Accuracy maintenance procedures
Where this commonly fails
  • Lawful basis not documented per activity
  • Privacy notices outdated
  • Purposes broaden silently over time
  • Data hoarded beyond schedule
BB-DPA-5
Section 5 - Fairness of Processing

Requirements for fair processing of personal data

Artefacts an auditor will ask for
  • Lawful basis assessment register
  • Privacy notice versions
  • Purpose limitation evidence per processing
  • Data minimisation review reports
  • Accuracy maintenance procedures
Where this commonly fails
  • Lawful basis not documented per activity
  • Privacy notices outdated
  • Purposes broaden silently over time
  • Data hoarded beyond schedule
BB-DPA-6
Section 6 - Lawfulness of Processing

Conditions under which processing is considered lawful

Artefacts an auditor will ask for
  • Lawful basis assessment register
  • Privacy notice versions
  • Purpose limitation evidence per processing
  • Data minimisation review reports
  • Accuracy maintenance procedures
Where this commonly fails
  • Lawful basis not documented per activity
  • Privacy notices outdated
  • Purposes broaden silently over time
  • Data hoarded beyond schedule
BB-DPA-7
Section 7 - Conditions for Consent

Requirements for obtaining valid consent from data subjects

Artefacts an auditor will ask for
  • Data subject request intake form and workflow
  • DSR fulfillment log with SLAs
  • Consent capture records
  • Identity verification procedure for requesters
  • Automated decision-making register
Where this commonly fails
  • No single intake channel for requests
  • SLA breaches on access or erasure requests
  • Consent receipts not retained
  • Verification too weak or too burdensome
BB-DPA-8
Section 8 - Child's Consent

Conditions applicable to a child's consent for processing

Artefacts an auditor will ask for
  • Data subject request intake form and workflow
  • DSR fulfillment log with SLAs
  • Consent capture records
  • Identity verification procedure for requesters
  • Automated decision-making register
Where this commonly fails
  • No single intake channel for requests
  • SLA breaches on access or erasure requests
  • Consent receipts not retained
  • Verification too weak or too burdensome
BB-DPA-9
Section 9 - Sensitive Personal Data

Additional conditions for processing sensitive personal data

Artefacts an auditor will ask for
  • Lawful basis assessment register
  • Privacy notice versions
  • Purpose limitation evidence per processing
  • Data minimisation review reports
  • Accuracy maintenance procedures
Where this commonly fails
  • Lawful basis not documented per activity
  • Privacy notices outdated
  • Purposes broaden silently over time
  • Data hoarded beyond schedule

Part III: Rights of a Data Subject

BB-DPA-10
Section 10 - Right of Access

Data subjects may request access to their personal data

Artefacts an auditor will ask for
  • Data subject request intake form and workflow
  • DSR fulfillment log with SLAs
  • Consent capture records
  • Identity verification procedure for requesters
  • Automated decision-making register
Where this commonly fails
  • No single intake channel for requests
  • SLA breaches on access or erasure requests
  • Consent receipts not retained
  • Verification too weak or too burdensome
BB-DPA-11
Section 11 - Right to Rectification

Right to have inaccurate personal data corrected

Artefacts an auditor will ask for
  • Data subject request intake form and workflow
  • DSR fulfillment log with SLAs
  • Consent capture records
  • Identity verification procedure for requesters
  • Automated decision-making register
Where this commonly fails
  • No single intake channel for requests
  • SLA breaches on access or erasure requests
  • Consent receipts not retained
  • Verification too weak or too burdensome
BB-DPA-12
Section 12 - Right to Erasure

Right to have personal data erased under specified conditions

Artefacts an auditor will ask for
  • Data subject request intake form and workflow
  • DSR fulfillment log with SLAs
  • Consent capture records
  • Identity verification procedure for requesters
  • Automated decision-making register
Where this commonly fails
  • No single intake channel for requests
  • SLA breaches on access or erasure requests
  • Consent receipts not retained
  • Verification too weak or too burdensome
BB-DPA-13
Section 13 - Right to Restriction of Processing

Right to restrict the processing of personal data

Artefacts an auditor will ask for
  • Data subject request intake form and workflow
  • DSR fulfillment log with SLAs
  • Consent capture records
  • Identity verification procedure for requesters
  • Automated decision-making register
Where this commonly fails
  • No single intake channel for requests
  • SLA breaches on access or erasure requests
  • Consent receipts not retained
  • Verification too weak or too burdensome
BB-DPA-14
Section 15 - Right to Data Portability

Right to receive personal data in a structured, machine-readable format

Artefacts an auditor will ask for
  • Data subject request intake form and workflow
  • DSR fulfillment log with SLAs
  • Consent capture records
  • Identity verification procedure for requesters
  • Automated decision-making register
Where this commonly fails
  • No single intake channel for requests
  • SLA breaches on access or erasure requests
  • Consent receipts not retained
  • Verification too weak or too burdensome
BB-DPA-15
Section 18 - Automated Decision-Making Including Profiling

Rights regarding automated individual decision-making and profiling

Artefacts an auditor will ask for
  • Data subject request intake form and workflow
  • DSR fulfillment log with SLAs
  • Consent capture records
  • Identity verification procedure for requesters
  • Automated decision-making register
Where this commonly fails
  • No single intake channel for requests
  • SLA breaches on access or erasure requests
  • Consent receipts not retained
  • Verification too weak or too burdensome

Part IV: Transfers of Personal Data Outside Barbados

BB-DPA-16
Section 22 - General Principle for Transfers

Personal data may only be transferred where recipient country ensures adequate protection

Artefacts an auditor will ask for
  • Transfer impact assessment documents
  • Standard contractual clauses register
  • Binding corporate rules approval
  • Adequacy decision references
  • Vendor transfer mapping
Where this commonly fails
  • No transfer impact assessment performed
  • SCCs not updated to current versions
  • Sub-processor transfers untracked
  • Reliance on adequacy without supplementary measures
BB-DPA-17
Section 24 - Appropriate Safeguards

Safeguards required for international transfers including binding corporate rules and standard clauses

Artefacts an auditor will ask for
  • Transfer impact assessment documents
  • Standard contractual clauses register
  • Binding corporate rules approval
  • Adequacy decision references
  • Vendor transfer mapping
Where this commonly fails
  • No transfer impact assessment performed
  • SCCs not updated to current versions
  • Sub-processor transfers untracked
  • Reliance on adequacy without supplementary measures
BB-DPA-18
Section 25 - Binding Corporate Rules

Requirements for binding corporate rules as a transfer mechanism

Artefacts an auditor will ask for
  • Transfer impact assessment documents
  • Standard contractual clauses register
  • Binding corporate rules approval
  • Adequacy decision references
  • Vendor transfer mapping
Where this commonly fails
  • No transfer impact assessment performed
  • SCCs not updated to current versions
  • Sub-processor transfers untracked
  • Reliance on adequacy without supplementary measures

Part V: Exemptions

BB-DPA-19
Sections 29-49 - General Exemptions

Exemptions for national security, crime prevention, taxation, health, education, journalism, and research

Artefacts an auditor will ask for
  • Policy referencing the control
  • Documented procedure
  • Evidence of operating effectiveness
  • Monitoring or review reports
  • Roles and responsibilities mapping
Where this commonly fails
  • Policy not aligned to control statement
  • Procedure undocumented
  • No periodic monitoring
  • Evidence not retained

Part VI: Data Controller and Data Processor

BB-DPA-20
Sections 50-60 - Registration and Responsibilities

Registration requirements, security obligations, breach notification, and impact assessments

Artefacts an auditor will ask for
  • Approved information security policy
  • Policy review and approval history
  • Roles and responsibilities matrix
  • Management commitment statement
  • Policy communication evidence
Where this commonly fails
  • Policies outdated or unsigned
  • No defined review cadence
  • Roles unclear or duplicated
  • Management commitment not visible
BB-DPA-21
Sections 61-69 - Data Privacy Officer

Appointment and functions of data privacy officers

Artefacts an auditor will ask for
  • Policy referencing the control
  • Documented procedure
  • Evidence of operating effectiveness
  • Monitoring or review reports
  • Roles and responsibilities mapping
Where this commonly fails
  • Policy not aligned to control statement
  • Procedure undocumented
  • No periodic monitoring
  • Evidence not retained

Part VII: Data Protection Commissioner

BB-DPA-22
Sections 70-75 - Commissioner Functions

Appointment, functions, staff, confidentiality, and annual reporting of the Commissioner

Artefacts an auditor will ask for
  • Regulator contact list
  • Inspection readiness pack
  • Authority engagement log
  • Notification submission records
  • Regulator guidance subscription
Where this commonly fails
  • No nominated regulator liaison
  • Inspection pack outdated
  • Notifications not tracked
  • Authority guidance not monitored

Part VIII: Enforcement

BB-DPA-23
Sections 76-89 - Enforcement Provisions

Guidelines, codes of practice, penalties, prosecutions, and liability provisions

Artefacts an auditor will ask for
  • Complaints register and resolution log
  • Regulator correspondence file
  • Penalty exposure tracker
  • Cooperation procedure with authorities
  • Remediation action plans
Where this commonly fails
  • Complaints not centrally tracked
  • No defined regulator response owner
  • Remediation actions not closed out
  • Penalty risk not on enterprise risk register
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Barbados Data Protection Act 2019 framework page.