Jamaica Data Protection Act 2020
Evidence request list. 17 controls, 17 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
JM DPA 2020 Breach Notification
Sections 28-30 of the Jamaica Data Protection Act 2020 establish the Personal Data Breach Notification framework. (1) Section 28 Personal Data Breach Definition: (a) breach of security leading to accidental or unlawful (i) destruction; (ii) loss; (iii) alteration; (iv) unauthorised disclosure; (v) access to personal data; (b) covers all data states - at rest + in transit + in use; (c) covers both technical (cyber) + human (insider + negligence) + physical (theft + loss); (d) covers controller + processor breaches. (2) Section 28(2) Duty to Notify Commissioner: (a) NOTIFICATION REQUIRED to OIC without undue delay + WHERE FEASIBLE within 72 HOURS of becoming aware; (b) if delayed beyond 72 hours - reasons must accompany notification; (c) phased notification allowed if full information not available; (d) ongoing updates as investigation progresses. (3) Section 29 Notification Information Re
- Breach detection + SIEM/DLP/EDR/insider + records + per incident + audit trail
- OIC notification + 72-hour + Section 28-29 + records + per breach + phased updates
- Subject notification + high-risk + Section 30 + records + per breach + clear language
- Breach documentation + ALL breaches + Section 28(5) + records + audit-ready
- Processor notification + Section 26 + records + per sub-processor + escalation
- Breach detection passive (manual reports only)
- OIC notification beyond 72 hours without explanation
- Subject notification skipped (high-risk underestimated)
- Documentation only for notified breaches (Section 28(5) failure)
- Processor notification absent in contracts
JM DPA 2020 Complaints + Enforcement
Sections 45-50 of the Jamaica Data Protection Act 2020 establish the complaints and enforcement framework. (1) Section 45 Right to Complain: (a) data subject may complain to OIC against controller or processor; (b) anonymous complaints accepted at OIC discretion; (c) other stakeholders + civil society may file complaints (with subject consent); (d) Commissioner may initiate investigation on own motion. (2) Section 46 Investigation Procedure: (a) preliminary review + admissibility; (b) controller/processor invited to respond; (c) formal investigation with information gathering; (d) interim orders if urgent; (e) interview of witnesses; (f) production of documents; (g) inspection of premises (with warrant or in emergency); (h) cooperation requirement; (i) Privacy of investigation balanced with transparency. (3) Section 47 Hearing: (a) formal hearing where complaint cannot be resolved inform
- Complaint handling + Section 45 + records + per complaint + audit trail
- Investigation cooperation + Section 46 + records + per investigation + document production
- Compliance Notice response + Section 49 + records + per Notice + remediation
- Administrative penalty defence + Section 50 + mitigation evidence + records
- Appeal Tribunal + Section 48 + High Court + records + per case + counsel
- Complaint handling reactive (no proactive procedure)
- Investigation cooperation reluctant (defensive)
- Compliance Notice ignored + escalating penalties
- Administrative penalty defence unprepared
- Appeal Tribunal route unknown (no counsel)
JM DPA 2020 Information Commissioner + OIC
The Office of the Information Commissioner (OIC) established by the Jamaica Data Protection Act 2020 Sections 6-15 + Schedule serves as Jamaica's independent supervisory authority for data protection. (1) Section 6 Establishment of the Office: (a) Office of the Information Commissioner established as independent body corporate; (b) located in Jamaica; (c) reports annually to Parliament; (d) has perpetual succession + common seal; (e) may sue and be sued in own name. (2) Section 12-13 Independence + Appointment: (a) Commissioner appointed by Governor-General on advice of Prime Minister after consultation with Leader of Opposition; (b) Term 5 years renewable once; (c) Independence guaranteed - no direction from Minister on operational matters; (d) Removal only for cause + Parliament approval; (e) Salary determined by Parliament; (f) supported by Deputy Commissioner + staff. (3) Section 8 F
- OIC registration + Section 16 + Certificate + records + annual renewal
- DPO appointment + Section 14 + qualifications + independence + records + protected
- Investigation cooperation + Section 10 + records + per inquiry + audit trail
- OIC engagement + Codes + Guidance + records + per consultation + Council participation
- Material change notification + 30 days + records + per change + amendment
- OIC registration absent or expired
- DPO appointed but not independent (reporting line wrong)
- Investigation cooperation reactive (no proactive engagement)
- OIC Codes of Conduct not consulted
- Material changes not notified within 30 days
JM DPA 2020 Joint Controller + Processor
Sections 24-26 of the Jamaica DPA 2020 establish the framework for Joint Controllers + Processors + Sub-Processors + and Records of Processing Activities. (1) Section 24 Joint Controllers: (a) two or more controllers jointly determine purposes and means of processing; (b) MUST agree in TRANSPARENT MANNER respective responsibilities for compliance + particularly regarding (i) exercise of data subject rights; (ii) Privacy Notice information; (c) arrangement made available to data subjects; (d) data subjects may exercise rights against either controller. (2) Section 25 Records of Processing Activities (ROPA): (a) MANDATORY for controllers + processors; (b) Section 25(2) Controller ROPA contents - (i) controller identity + contact details + DPO; (ii) purposes; (iii) categories of data subjects; (iv) categories of personal data; (v) categories of recipients; (vi) transfers + adequacy mechanis
- Joint controller arrangement + Section 24 + allocation + records + transparent to subjects
- ROPA + Section 25 + controller/processor + records + audit-ready + OIC
- Processor contract + Section 26 + mandatory terms + records + per processor
- Sub-processor authorisation + flow-down + records + per sub-processor + chain
- Vendor DD + DPIA + records + per engagement + periodic review
- Joint controller status unrecognised
- ROPA absent or incomplete
- Processor contracts missing Section 26 mandatory terms
- Sub-processor chain undisclosed
- Vendor DD weak (questionnaire only, no audit)
JM DPA 2020 Penalties + Risk
The Jamaica Data Protection Act 2020 establishes a comprehensive penalty regime spanning criminal + civil + and administrative penalties. (1) Section 50 Administrative Penalties: (a) imposed by Commissioner; (b) UP TO JMD 10 MILLION per violation; (c) considerations - nature/gravity/duration + intentional/negligent + mitigation measures + responsibility level + previous infringements + cooperation + categories of data + manner came to attention + effect + other factors; (d) Per-violation cumulation possible; (e) tiered approach typical; (f) issued by Penalty Notice per Section 49; (g) Appeal to Tribunal + High Court. (2) Section 31 Unauthorised Disclosure + Use - Criminal Offence: (a) knowingly or recklessly without consent of controller (i) obtains + discloses + procures disclosure; (ii) sells + offers for sale; (b) UP TO JMD 4 MILLION FINE + 4 YEARS IMPRISONMENT; (c) on summary convict
- Penalty risk assessment + per processing + records + quarterly + Board reporting
- Reasonable care defence evidence + Section 31(2) + records + per control + audit trail
- D and O liability + Section 31(3) + insurance + records + per director/officer + Board
- Civil class action preparedness + Section 52 + records + per risk class + counsel
- Board reporting + privacy risk statement + records + per quarter + Audit Committee
- Penalty risk not quantified (Board unaware)
- Reasonable care defence undocumented
- D and O insurance excludes privacy claims
- Class action exposure unmanaged
- Board reporting infrequent or absent
JM DPA 2020 Privacy by Design + DPIA
Section 34 of the Jamaica Data Protection Act 2020 establishes Privacy by Design + Privacy by Default + and Data Protection Impact Assessment (DPIA) requirements. (1) Section 34 Privacy by Design (Article 25 GDPR equivalent): (a) at time of determining means of processing + at time of processing itself; (b) implement appropriate technical and organisational measures designed to implement data protection principles; (c) integrate necessary safeguards into processing; (d) consideration includes (i) state of the art; (ii) cost of implementation; (iii) nature + scope + context + purposes of processing; (iv) risks to rights and freedoms. (2) Privacy by Default (Section 34 + Schedule): (a) only personal data necessary for each specific purpose processed by default; (b) applies to (i) amount of data; (ii) extent of processing; (iii) period of storage; (iv) accessibility; (c) data not made acces
- Privacy by Design + Default + Section 34 + records + per system + per phase
- DPIA + Section 34 + high-risk + records + per processing + DPO advice
- Prior consultation + OIC + 8-week + records + per high-risk processing
- Privacy engineering + pseudonymisation/encryption/minimisation + records + per pattern
- Lifecycle integration + DPIA trigger + records + per material change + audit trail
- Privacy by Design retrofitted (privacy at deployment)
- DPIA absent for high-risk processing
- Prior consultation skipped + processing proceeds
- Privacy engineering ad-hoc (no patterns)
- DPIA not re-triggered on material change
JM DPA 2020 Public Authority + Exemptions
Sections 4 + 44 + 46 of the Jamaica Data Protection Act 2020 establish the framework for public authority processing + exemptions + and data subject rights limitations. (1) Section 4 General Exemptions: (a) Personal/Household Activity - processing by individuals in course of personal or household activities; (b) Journalism + Literary + Artistic Purposes - subject to specific conditions + public interest test; (c) National Security - protection of national security; (d) Defence + Armed Forces; (e) Prevention + Detection + Prosecution of Crime + Apprehension of Offenders; (f) Tax Administration + Revenue Collection; (g) Public Sector Health + Social Welfare; (h) Legal Privilege + Judicial Proceedings; (i) Research + Statistics + Archival Purposes (subject to safeguards). (2) Section 44 Intelligence Services Processing: (a) limited exemption for intelligence agencies (Jamaica Defence Force
- Section 4 exemption reliance + per category + records + audit trail + necessity test
- Section 44 intelligence services + oversight + records + per decision + Parliamentary Committee
- Section 46 limitations + proportionality + records + per limitation + safeguards
- Section 41 research + statistics + safeguards + records + per project + anonymisation
- Public authority + Section 50 + ATI compliance + records + transparency
- Exemption claimed without necessity test
- Intelligence services without Parliamentary oversight
- Rights limitations disproportionate
- Research data not anonymised + Section 41 misapplied
- Public authority opacity (no ATI engagement)
JM DPA 2020 Scope + Application
The Jamaica Data Protection Act 2020 (Act No. 7 of 2020) is Jamaica's first comprehensive data protection legislation passed by the Jamaican Parliament 16 June 2020 + assented to by the Governor-General 30 June 2020 + published in the Gazette 1 July 2020. The Act establishes a comprehensive framework for the processing of personal data + creates the Office of the Information Commissioner (OIC) + and aligns Jamaica with international data protection standards modelled significantly on the EU GDPR + UK DPA 2018 + Caribbean Community CARICOM model. (1) Section 1 Short Title and Commencement: (a) the Act is cited as the Data Protection Act 2020; (b) commencement in phases - Partial Commencement 1 December 2021 (registration provisions + functions of the Commission) + 1 December 2022 (limited transition for data processing); (c) MANDATORY COMPLIANCE DATE 1 December 2023 - all data controllers
- Scope assessment + per processing operation + records + per business unit
- Territorial application + per data subject + Jamaica + records + per market
- Definitions mapping + per system + per category + records + per data flow
- Compliance status + 1 Dec 2023 mandatory + records + per controller/processor
- Exemption reliance + Section 4 + records + per derogation + audit trail
- Scope misjudged (only paper records covered)
- Extraterritorial application unrecognised (foreign processors uncontrolled)
- Definitions not mapped (sensitive personal data unflagged)
- Compliance status pre-1 Dec 2023 (enforcement risk)
- Exemption reliance undocumented (lawful basis weak)
JM DPA 2020 Sensitive Data + Children
Section 5 of the Jamaica Data Protection Act 2020 establishes special protections for Sensitive Personal Data + Section 7 establishes additional protections for children's data. (1) Section 5 Sensitive Personal Data Categories: (a) race or ethnic origin; (b) political opinion; (c) religious beliefs or other beliefs of a similar nature; (d) trade union membership or activities; (e) physical or mental health condition; (f) sexual orientation or sex life; (g) commission or alleged commission of any offence; (h) any proceedings + dispositions + sentences related to offences; (i) genetic data; (j) biometric data; (k) any other category Commissioner specifies. (2) Section 5(2) Lawful Basis for Sensitive Data Processing: processing PROHIBITED unless one of these conditions applies (a) Explicit Consent of data subject (specific to the sensitive data + informed); (b) Employment Law + labour law o
- Sensitive data inventory + Section 5 + 11 categories + records + per system + per data class
- Lawful basis sensitive + Section 5(2) + records + per processing + per condition
- Explicit consent sensitive + Section 5(3) + records + per subject + per category
- Children age verification + Section 7 + records + per service + per touchpoint
- Parental consent + under 16 + Section 7(2) + records + per child + verification
- Sensitive data uncategorised (treated as general)
- Lawful basis sensitive same as general (Section 5(2) not applied)
- Explicit consent same as general consent
- Children age not verified (adult treatment by default)
- Parental consent absent for under-16
JM DPA 2020 Standard 1 - Fair + Lawful + Transparent
Standard 1 per Section 19 + the Schedule of the Jamaica Data Protection Act 2020: Personal data shall be processed fairly + lawfully + transparently. The first of 8 Data Protection Standards establishes the foundational requirement that ALL processing must have a lawful basis + be carried out fairly toward data subjects + and be transparent in its purposes + means + and consequences. (1) Lawful Basis (Section 19) - at least one of the following must apply: (a) the data subject has given consent (subject to specific consent requirements per Sections 11 + 16 + Schedule); (b) the processing is necessary for performance of a contract to which the data subject is a party + or for steps requested by the data subject prior to entering a contract; (c) the processing is necessary for compliance with a legal obligation other than a contractual obligation to which the controller is subject; (d) the
- Lawful basis register + per processing + Section 19 + records + per activity
- Consent records + Section 11 + audit trail + withdrawal mechanism + records + per data subject
- Privacy notice + Section 22 + identity/DPO/purposes/rights + records + per touchpoint + versioned
- Direct marketing consent + Section 9 + opt-in/opt-out + records + per campaign + penalty awareness
- Sensitive data conditions + Section 5 + explicit consent + records + per category + per processing
- Lawful basis selected after processing (consent bias)
- Consent records weak (bundled + pre-ticked)
- Privacy notices generic (no Jamaica DPA references)
- Direct marketing without specific opt-in
- Sensitive data without Section 5 explicit conditions
JM DPA 2020 Standard 2 - Purpose Limitation
Standard 2 per Section 20 + the Schedule of the Jamaica Data Protection Act 2020: Personal data shall be collected only for specified + explicit + and legitimate purposes + and shall not be further processed in any manner incompatible with those purposes. (1) Purpose Specification at Collection: (a) purposes must be defined at the point of collection NOT retrospectively justified; (b) purposes documented in Records of Processing Activities (ROPA); (c) Privacy Notice (Section 22) must clearly state purposes; (d) purposes specific to processing activity not vague aggregate; (e) primary + secondary purposes distinguished. (2) Explicit Purposes: (a) NOT implicit or assumed; (b) plain language understandable to data subject; (c) NOT buried in lengthy terms of service; (d) machine-readable purpose taxonomy emerging best practice. (3) Legitimate Purposes: (a) purposes must be lawful + ethical +
- Purpose specification + per processing + ROPA + records + per activity
- Compatibility test + per secondary use + records + per assessment
- ROPA + Section 25 + entries + records + audit ready
- Re-consent procedure + materially new purpose + records + per change
- DPIA on purpose drift + records + per material change + Commissioner consultation if high-risk
- Purposes vague at collection ('improving services')
- Compatibility test never run (purpose drift unchecked)
- ROPA absent or out-of-date
- Re-consent not sought for new purposes
- DPIA not triggered on material scope change
JM DPA 2020 Standard 3 - Data Minimisation
Standard 3 per Section 21 + the Schedule of the Jamaica Data Protection Act 2020: Personal data shall be adequate + relevant + and necessary in relation to the purposes for which they are processed (Data Minimisation Principle). The third Data Protection Standard requires the LEAST amount of personal data that achieves the legitimate purpose - no more + no less + no longer. (1) Adequate: data must be sufficient to achieve the purpose - not so little that purpose cannot be properly served; (a) operational completeness; (b) decision-quality data; (c) avoid scenarios where insufficient data leads to harmful outcomes (e.g. credit denial based on incomplete record). (2) Relevant: data must relate directly to the purpose; (a) NOT collected because it might be useful later; (b) NOT collected because the form has an empty field; (c) NOT collected to enable future expansion. (3) Necessary: data m
- Field-level justification + per data point + records + per collection form/API
- Data inventory + minimisation review + annual + records + per change
- Privacy by Default + Section 34 + opt-in defaults + records + per system
- Children minimisation + Section 7 + records + per data subject under 18
- Sensitive data minimisation + Section 5 + records + per category + per processing
- Forms collect 'might be useful' fields
- Data inventory absent or out-of-date
- Privacy by Default opt-out rather than opt-in
- Children's data uncategorised + over-collected
- Sensitive data collected with weak justification
JM DPA 2020 Standard 4 - Accuracy
Standard 4 per Section 22 + the Schedule of the Jamaica Data Protection Act 2020: Personal data shall be accurate and + where necessary + kept up to date. The fourth Data Protection Standard requires data quality + accuracy + currency + and provides data subjects with the right to seek rectification. (1) Accuracy Definition: (a) factually correct + complete; (b) up-to-date as needed by the purpose; (c) NOT misleading by omission; (d) traceable to authoritative sources where available; (e) free from systematic bias. (2) Reasonable Steps Standard: (a) controller must take reasonable steps to ensure accuracy; (b) reasonableness depends on (i) purpose (high-stakes decisions require higher accuracy); (ii) nature of data; (iii) cost of accuracy measures; (iv) consequences of inaccuracy. (3) Source Verification: (a) data from trustworthy sources; (b) primary source preferred over secondary; (c)
- Accuracy reasonable steps + source verification + records + per data class
- Rectification right + Section 38 + 30 days + extension + records + per request
- Erasure right + Section 39 + 30 days + grounds + records + per request
- Quality assurance + metrics + DQ profiling + records + per data class + periodic
- Downstream propagation + recipients notification + records + per correction + audit trail
- Reasonable steps undocumented (defence to accuracy challenge weak)
- Rectification SLA missed (>30 days)
- Erasure refused without reasoned response
- Quality assurance absent (no metrics + no cleansing)
- Corrections siloed (downstream systems out of date)
JM DPA 2020 Standard 5 - Retention
Standard 5 per Section 23 + the Schedule of the Jamaica Data Protection Act 2020: Personal data shall be kept for no longer than is necessary for the purposes for which they are processed. The fifth Data Protection Standard requires Storage Limitation - retention only as long as necessary + then erasure or anonymisation. (1) Retention Period Setting: (a) by purpose - different purposes may have different retention; (b) by lawful basis - consent withdrawal triggers earlier deletion; (c) by data category - sensitive data requires shorter retention; (d) by legal requirement - statutory minimums (tax: 7 years; banking: 5-7 years; employment: 5-7 years post-departure; medical: lifetime + 25 years; certain children's records: 25 years; AML/KYC: 7 years post-relationship); (e) by jurisdiction - if data subject in multiple countries take strictest. (2) Retention Schedule per Section 25 ROPA: (a)
- Retention schedule + per processing + Section 25 + records + per data category
- Erasure methods + logical/physical/anonymisation + records + per deletion + audit trail
- Backup retention + crypto-shredding + records + per system + per backup class
- Legal hold + litigation hold + records + per hold + release
- Periodic review + annual retention audit + records + per cycle + DPO oversight
- Retention indefinite by default
- Deletion not actually executed (soft delete only)
- Backups retain deleted data perpetually
- Legal holds undocumented or never released
- No annual retention audit
JM DPA 2020 Standard 6 - Data Subject Rights
Standard 6 per Sections 37-43 + the Schedule of the Jamaica Data Protection Act 2020: Personal data shall be processed in accordance with the rights of data subjects under this Act. The sixth Data Protection Standard establishes comprehensive data subject rights closely modelled on EU GDPR + UK DPA 2018 + Convention 108+. (1) Section 37 Right of Access (Subject Access Request - SAR): (a) right to confirmation whether personal data being processed; (b) right to copy of personal data; (c) right to supplementary information (purposes + categories + recipients + retention + rights + sources + automated decision-making); (d) response within 30 calendar days + extension up to 60 days for complex requests; (e) free for first request per year - reasonable fee for additional or excessive; (f) Section 37(8) refusal grounds limited - manifestly unfounded + excessive + frequency disproportionate. (2
- SAR portal + Section 37 + 30-day SLA + records + per request + audit trail
- Rights implementation + Section 38-43 + 7 rights + records + per type
- DPO oversight + escalation + records + per request + decisions
- Identity verification + proportionate + records + per SAR + per access level
- Downstream propagation + recipients + records + per action + audit trail
- SAR portal absent (email-only handling)
- 30-day SLA frequently missed
- Rights implementation incomplete (portability + restriction)
- Identity verification weak (impersonation risk)
- Downstream propagation absent (siloed responses)
JM DPA 2020 Standard 7 - Security
Standard 7 per Section 35 + the Schedule of the Jamaica Data Protection Act 2020: Personal data shall be processed in a manner that ensures appropriate security including protection against unauthorised or unlawful processing + accidental loss + destruction or damage using appropriate technical and organisational measures. (1) Risk-Based Security per Section 35: (a) security measures appropriate to the risk; (b) state of the art consideration; (c) cost of implementation; (d) nature + scope + context + purposes; (e) risk of varying likelihood and severity for data subject rights and freedoms; (f) particular consideration for risks of accidental + unlawful destruction + loss + alteration + unauthorised disclosure or access. (2) Technical Measures: (a) Encryption per Section 35(1)(a) - at-rest + in-transit + in-use; (b) Pseudonymisation - personal data cannot be attributed to specific data
- Technical measures + encryption/pseudonymisation/access + records + per system + per data class
- Organisational measures + policies/training + records + per role + per quarter
- Risk-based security + risk assessment + records + per material change + per data class
- Regular testing + pen test + vuln + records + per quarter + per service
- Vendor/processor security + Section 26 + DPA + records + per contract + per sub-processor
- Technical measures point-in-time (not continuous)
- Organisational measures policy-only (no enforcement)
- Risk assessments stale (>annual)
- Pen testing annual only (no continuous vuln)
- Vendor security accepted (no due diligence)
JM DPA 2020 Standard 8 - International Transfers
Standard 8 per Section 27 + the Schedule of the Jamaica Data Protection Act 2020: Personal data shall not be transferred outside Jamaica unless adequate protection is provided. The eighth Data Protection Standard governs international data transfers + closely modelled on EU GDPR Chapter V. (1) Section 27 General Prohibition: transfer outside Jamaica prohibited UNLESS one of the following grounds applies (a) Adequacy Decision; (b) Appropriate Safeguards; (c) Specific Derogations; (d) Compelling Legitimate Interests (narrow). (2) Adequacy Decisions: (a) Commissioner determines third country provides adequate level of protection; (b) consideration includes (i) rule of law + respect for human rights; (ii) data protection legislation + enforcement; (iii) supervisory authority independence; (iv) international commitments; (v) Convention 108+ accession; (c) Commissioner has discretion + may iss
- Transfer map + per destination + records + per data flow + per category
- Lawful mechanism + Adequacy/SCC/BCR + records + per transfer + per recipient
- TIA + per transfer + records + per destination + periodic review
- Supplementary measures + encryption/pseudonymisation + records + per transfer
- Section 22 disclosure + transfer destinations + records + per touchpoint
- Transfers without mapping (cloud sprawl)
- Lawful mechanism not chosen per transfer
- TIA absent (Schrems II ignored)
- Supplementary measures not implemented
- Privacy Notice silent on transfers
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Jamaica Data Protection Act 2020 framework page.