Skip to content

Evidence request lists

Jamaica Data Protection Act 2020

Evidence request list. 17 controls, 17 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

JM DPA 2020 Breach Notification

JM-DPA2020-Breach-Notification-Sec28-30-Duty-Notify-Commissioner-Affected-Subjects-72-Hours-Severe
Jamaica DPA 2020 Personal Data Breach Notification + Sections 28-30 + Duty to Notify Commissioner + Affected Subjects + 72-Hour Reporting + High Risk + Severe + Mitigation + Documentation

Sections 28-30 of the Jamaica Data Protection Act 2020 establish the Personal Data Breach Notification framework. (1) Section 28 Personal Data Breach Definition: (a) breach of security leading to accidental or unlawful (i) destruction; (ii) loss; (iii) alteration; (iv) unauthorised disclosure; (v) access to personal data; (b) covers all data states - at rest + in transit + in use; (c) covers both technical (cyber) + human (insider + negligence) + physical (theft + loss); (d) covers controller + processor breaches. (2) Section 28(2) Duty to Notify Commissioner: (a) NOTIFICATION REQUIRED to OIC without undue delay + WHERE FEASIBLE within 72 HOURS of becoming aware; (b) if delayed beyond 72 hours - reasons must accompany notification; (c) phased notification allowed if full information not available; (d) ongoing updates as investigation progresses. (3) Section 29 Notification Information Re

Artefacts an auditor will ask for
  • Breach detection + SIEM/DLP/EDR/insider + records + per incident + audit trail
  • OIC notification + 72-hour + Section 28-29 + records + per breach + phased updates
  • Subject notification + high-risk + Section 30 + records + per breach + clear language
  • Breach documentation + ALL breaches + Section 28(5) + records + audit-ready
  • Processor notification + Section 26 + records + per sub-processor + escalation
Where this commonly fails
  • Breach detection passive (manual reports only)
  • OIC notification beyond 72 hours without explanation
  • Subject notification skipped (high-risk underestimated)
  • Documentation only for notified breaches (Section 28(5) failure)
  • Processor notification absent in contracts

JM DPA 2020 Complaints + Enforcement

JM-DPA2020-Complaints-Enforcement-Sec45-50-Investigation-Hearing-Determination-Appeal-Tribunal
Jamaica DPA 2020 Complaints + Enforcement + Sections 45-50 + Complaint Procedure + Investigation + Hearing + Determination + Compliance Orders + Administrative Penalties + Data Protection Tribunal + High Court Appeals

Sections 45-50 of the Jamaica Data Protection Act 2020 establish the complaints and enforcement framework. (1) Section 45 Right to Complain: (a) data subject may complain to OIC against controller or processor; (b) anonymous complaints accepted at OIC discretion; (c) other stakeholders + civil society may file complaints (with subject consent); (d) Commissioner may initiate investigation on own motion. (2) Section 46 Investigation Procedure: (a) preliminary review + admissibility; (b) controller/processor invited to respond; (c) formal investigation with information gathering; (d) interim orders if urgent; (e) interview of witnesses; (f) production of documents; (g) inspection of premises (with warrant or in emergency); (h) cooperation requirement; (i) Privacy of investigation balanced with transparency. (3) Section 47 Hearing: (a) formal hearing where complaint cannot be resolved inform

Artefacts an auditor will ask for
  • Complaint handling + Section 45 + records + per complaint + audit trail
  • Investigation cooperation + Section 46 + records + per investigation + document production
  • Compliance Notice response + Section 49 + records + per Notice + remediation
  • Administrative penalty defence + Section 50 + mitigation evidence + records
  • Appeal Tribunal + Section 48 + High Court + records + per case + counsel
Where this commonly fails
  • Complaint handling reactive (no proactive procedure)
  • Investigation cooperation reluctant (defensive)
  • Compliance Notice ignored + escalating penalties
  • Administrative penalty defence unprepared
  • Appeal Tribunal route unknown (no counsel)

JM DPA 2020 Information Commissioner + OIC

JM-DPA2020-Information-Commissioner-Sec6-15-OIC-Office-Information-Commissioner-Establishment-Independence-Functions
Jamaica DPA 2020 Office of the Information Commissioner (OIC) + Sections 6-15 + Establishment + Independence + Functions + Powers + Registration Requirements + Investigation + Enforcement + Data Protection Council

The Office of the Information Commissioner (OIC) established by the Jamaica Data Protection Act 2020 Sections 6-15 + Schedule serves as Jamaica's independent supervisory authority for data protection. (1) Section 6 Establishment of the Office: (a) Office of the Information Commissioner established as independent body corporate; (b) located in Jamaica; (c) reports annually to Parliament; (d) has perpetual succession + common seal; (e) may sue and be sued in own name. (2) Section 12-13 Independence + Appointment: (a) Commissioner appointed by Governor-General on advice of Prime Minister after consultation with Leader of Opposition; (b) Term 5 years renewable once; (c) Independence guaranteed - no direction from Minister on operational matters; (d) Removal only for cause + Parliament approval; (e) Salary determined by Parliament; (f) supported by Deputy Commissioner + staff. (3) Section 8 F

Artefacts an auditor will ask for
  • OIC registration + Section 16 + Certificate + records + annual renewal
  • DPO appointment + Section 14 + qualifications + independence + records + protected
  • Investigation cooperation + Section 10 + records + per inquiry + audit trail
  • OIC engagement + Codes + Guidance + records + per consultation + Council participation
  • Material change notification + 30 days + records + per change + amendment
Where this commonly fails
  • OIC registration absent or expired
  • DPO appointed but not independent (reporting line wrong)
  • Investigation cooperation reactive (no proactive engagement)
  • OIC Codes of Conduct not consulted
  • Material changes not notified within 30 days

JM DPA 2020 Joint Controller + Processor

JM-DPA2020-Joint-Controller-Processor-Sec24-25-26-Arrangements-Allocation-Responsibilities-Contracts
Jamaica DPA 2020 Joint Controllers + Processors + Sections 24-26 + Arrangements + Allocation of Responsibilities + Contracts + Records of Processing Activities (ROPA) + Sub-Processors + Vendor Management

Sections 24-26 of the Jamaica DPA 2020 establish the framework for Joint Controllers + Processors + Sub-Processors + and Records of Processing Activities. (1) Section 24 Joint Controllers: (a) two or more controllers jointly determine purposes and means of processing; (b) MUST agree in TRANSPARENT MANNER respective responsibilities for compliance + particularly regarding (i) exercise of data subject rights; (ii) Privacy Notice information; (c) arrangement made available to data subjects; (d) data subjects may exercise rights against either controller. (2) Section 25 Records of Processing Activities (ROPA): (a) MANDATORY for controllers + processors; (b) Section 25(2) Controller ROPA contents - (i) controller identity + contact details + DPO; (ii) purposes; (iii) categories of data subjects; (iv) categories of personal data; (v) categories of recipients; (vi) transfers + adequacy mechanis

Artefacts an auditor will ask for
  • Joint controller arrangement + Section 24 + allocation + records + transparent to subjects
  • ROPA + Section 25 + controller/processor + records + audit-ready + OIC
  • Processor contract + Section 26 + mandatory terms + records + per processor
  • Sub-processor authorisation + flow-down + records + per sub-processor + chain
  • Vendor DD + DPIA + records + per engagement + periodic review
Where this commonly fails
  • Joint controller status unrecognised
  • ROPA absent or incomplete
  • Processor contracts missing Section 26 mandatory terms
  • Sub-processor chain undisclosed
  • Vendor DD weak (questionnaire only, no audit)

JM DPA 2020 Penalties + Risk

JM-DPA2020-Penalty-Risk-Sec31-33-50-52-Criminal-Civil-Administrative-Up-to-10M-JMD-Compensation-Imprisonment
Jamaica DPA 2020 Penalty Risk Management + Sections 31-33 + 50 + 52 + Criminal Offences + Civil Compensation + Administrative Penalties + Up to JMD 10 Million + Imprisonment + Director/Officer Liability + Reasonable Care Defence

The Jamaica Data Protection Act 2020 establishes a comprehensive penalty regime spanning criminal + civil + and administrative penalties. (1) Section 50 Administrative Penalties: (a) imposed by Commissioner; (b) UP TO JMD 10 MILLION per violation; (c) considerations - nature/gravity/duration + intentional/negligent + mitigation measures + responsibility level + previous infringements + cooperation + categories of data + manner came to attention + effect + other factors; (d) Per-violation cumulation possible; (e) tiered approach typical; (f) issued by Penalty Notice per Section 49; (g) Appeal to Tribunal + High Court. (2) Section 31 Unauthorised Disclosure + Use - Criminal Offence: (a) knowingly or recklessly without consent of controller (i) obtains + discloses + procures disclosure; (ii) sells + offers for sale; (b) UP TO JMD 4 MILLION FINE + 4 YEARS IMPRISONMENT; (c) on summary convict

Artefacts an auditor will ask for
  • Penalty risk assessment + per processing + records + quarterly + Board reporting
  • Reasonable care defence evidence + Section 31(2) + records + per control + audit trail
  • D and O liability + Section 31(3) + insurance + records + per director/officer + Board
  • Civil class action preparedness + Section 52 + records + per risk class + counsel
  • Board reporting + privacy risk statement + records + per quarter + Audit Committee
Where this commonly fails
  • Penalty risk not quantified (Board unaware)
  • Reasonable care defence undocumented
  • D and O insurance excludes privacy claims
  • Class action exposure unmanaged
  • Board reporting infrequent or absent

JM DPA 2020 Privacy by Design + DPIA

JM-DPA2020-Privacy-by-Design-Default-Sec34-Engineering-Data-Protection-Impact-Assessment-DPIA-Risk-Based
Jamaica DPA 2020 Privacy by Design + Privacy by Default + Section 34 + Data Protection Impact Assessment (DPIA) + Risk-Based + High-Risk Processing + Prior Consultation + Privacy Engineering

Section 34 of the Jamaica Data Protection Act 2020 establishes Privacy by Design + Privacy by Default + and Data Protection Impact Assessment (DPIA) requirements. (1) Section 34 Privacy by Design (Article 25 GDPR equivalent): (a) at time of determining means of processing + at time of processing itself; (b) implement appropriate technical and organisational measures designed to implement data protection principles; (c) integrate necessary safeguards into processing; (d) consideration includes (i) state of the art; (ii) cost of implementation; (iii) nature + scope + context + purposes of processing; (iv) risks to rights and freedoms. (2) Privacy by Default (Section 34 + Schedule): (a) only personal data necessary for each specific purpose processed by default; (b) applies to (i) amount of data; (ii) extent of processing; (iii) period of storage; (iv) accessibility; (c) data not made acces

Artefacts an auditor will ask for
  • Privacy by Design + Default + Section 34 + records + per system + per phase
  • DPIA + Section 34 + high-risk + records + per processing + DPO advice
  • Prior consultation + OIC + 8-week + records + per high-risk processing
  • Privacy engineering + pseudonymisation/encryption/minimisation + records + per pattern
  • Lifecycle integration + DPIA trigger + records + per material change + audit trail
Where this commonly fails
  • Privacy by Design retrofitted (privacy at deployment)
  • DPIA absent for high-risk processing
  • Prior consultation skipped + processing proceeds
  • Privacy engineering ad-hoc (no patterns)
  • DPIA not re-triggered on material change

JM DPA 2020 Public Authority + Exemptions

JM-DPA2020-Public-Authority-Exemptions-Sec4-44-46-National-Security-Intelligence-Crime-Tax-Defence-Limitations
Jamaica DPA 2020 Public Authority Exemptions + Sections 4 + 44 + 46 + National Security + Intelligence Services + Crime Prevention + Tax + Defence + Research + Journalism + Data Subject Rights Limitations

Sections 4 + 44 + 46 of the Jamaica Data Protection Act 2020 establish the framework for public authority processing + exemptions + and data subject rights limitations. (1) Section 4 General Exemptions: (a) Personal/Household Activity - processing by individuals in course of personal or household activities; (b) Journalism + Literary + Artistic Purposes - subject to specific conditions + public interest test; (c) National Security - protection of national security; (d) Defence + Armed Forces; (e) Prevention + Detection + Prosecution of Crime + Apprehension of Offenders; (f) Tax Administration + Revenue Collection; (g) Public Sector Health + Social Welfare; (h) Legal Privilege + Judicial Proceedings; (i) Research + Statistics + Archival Purposes (subject to safeguards). (2) Section 44 Intelligence Services Processing: (a) limited exemption for intelligence agencies (Jamaica Defence Force

Artefacts an auditor will ask for
  • Section 4 exemption reliance + per category + records + audit trail + necessity test
  • Section 44 intelligence services + oversight + records + per decision + Parliamentary Committee
  • Section 46 limitations + proportionality + records + per limitation + safeguards
  • Section 41 research + statistics + safeguards + records + per project + anonymisation
  • Public authority + Section 50 + ATI compliance + records + transparency
Where this commonly fails
  • Exemption claimed without necessity test
  • Intelligence services without Parliamentary oversight
  • Rights limitations disproportionate
  • Research data not anonymised + Section 41 misapplied
  • Public authority opacity (no ATI engagement)

JM DPA 2020 Scope + Application

JM-DPA2020-Scope-Application-Sec1-3-31Dec2021-PartialEffective-1Dec2023-MandatoryCompliance-Territorial-Extraterritorial
Jamaica Data Protection Act 2020 - Scope + Application + Sections 1-3 + Commencement 1 December 2021 Partial + 1 December 2023 Mandatory Compliance + Territorial + Extraterritorial Application + Definitions

The Jamaica Data Protection Act 2020 (Act No. 7 of 2020) is Jamaica's first comprehensive data protection legislation passed by the Jamaican Parliament 16 June 2020 + assented to by the Governor-General 30 June 2020 + published in the Gazette 1 July 2020. The Act establishes a comprehensive framework for the processing of personal data + creates the Office of the Information Commissioner (OIC) + and aligns Jamaica with international data protection standards modelled significantly on the EU GDPR + UK DPA 2018 + Caribbean Community CARICOM model. (1) Section 1 Short Title and Commencement: (a) the Act is cited as the Data Protection Act 2020; (b) commencement in phases - Partial Commencement 1 December 2021 (registration provisions + functions of the Commission) + 1 December 2022 (limited transition for data processing); (c) MANDATORY COMPLIANCE DATE 1 December 2023 - all data controllers

Artefacts an auditor will ask for
  • Scope assessment + per processing operation + records + per business unit
  • Territorial application + per data subject + Jamaica + records + per market
  • Definitions mapping + per system + per category + records + per data flow
  • Compliance status + 1 Dec 2023 mandatory + records + per controller/processor
  • Exemption reliance + Section 4 + records + per derogation + audit trail
Where this commonly fails
  • Scope misjudged (only paper records covered)
  • Extraterritorial application unrecognised (foreign processors uncontrolled)
  • Definitions not mapped (sensitive personal data unflagged)
  • Compliance status pre-1 Dec 2023 (enforcement risk)
  • Exemption reliance undocumented (lawful basis weak)

JM DPA 2020 Sensitive Data + Children

JM-DPA2020-Childrens-Data-Special-Categories-Sensitive-Sec5-Genetic-Biometric-Health-Race-Political-Religious
Jamaica DPA 2020 Section 5 Sensitive Personal Data + Special Categories + Genetic + Biometric + Health + Race + Ethnicity + Political + Religious + Philosophical + Trade Union + Sex Life + Sexual Orientation + Section 7 Children's Data + Enhanced Protections

Section 5 of the Jamaica Data Protection Act 2020 establishes special protections for Sensitive Personal Data + Section 7 establishes additional protections for children's data. (1) Section 5 Sensitive Personal Data Categories: (a) race or ethnic origin; (b) political opinion; (c) religious beliefs or other beliefs of a similar nature; (d) trade union membership or activities; (e) physical or mental health condition; (f) sexual orientation or sex life; (g) commission or alleged commission of any offence; (h) any proceedings + dispositions + sentences related to offences; (i) genetic data; (j) biometric data; (k) any other category Commissioner specifies. (2) Section 5(2) Lawful Basis for Sensitive Data Processing: processing PROHIBITED unless one of these conditions applies (a) Explicit Consent of data subject (specific to the sensitive data + informed); (b) Employment Law + labour law o

Artefacts an auditor will ask for
  • Sensitive data inventory + Section 5 + 11 categories + records + per system + per data class
  • Lawful basis sensitive + Section 5(2) + records + per processing + per condition
  • Explicit consent sensitive + Section 5(3) + records + per subject + per category
  • Children age verification + Section 7 + records + per service + per touchpoint
  • Parental consent + under 16 + Section 7(2) + records + per child + verification
Where this commonly fails
  • Sensitive data uncategorised (treated as general)
  • Lawful basis sensitive same as general (Section 5(2) not applied)
  • Explicit consent same as general consent
  • Children age not verified (adult treatment by default)
  • Parental consent absent for under-16

JM DPA 2020 Standard 1 - Fair + Lawful + Transparent

JM-DPA2020-Standard1-Fair-Lawful-Transparent-Sec19-Lawful-Basis-Consent-Contract-Legal-Vital-Public-Interest-Legitimate
Jamaica DPA 2020 Standard 1 - Fair + Lawful + Transparent Processing + Section 19 + Lawful Basis + Consent + Contract Performance + Legal Obligation + Vital Interests + Public Interest + Legitimate Interests + Privacy Notices

Standard 1 per Section 19 + the Schedule of the Jamaica Data Protection Act 2020: Personal data shall be processed fairly + lawfully + transparently. The first of 8 Data Protection Standards establishes the foundational requirement that ALL processing must have a lawful basis + be carried out fairly toward data subjects + and be transparent in its purposes + means + and consequences. (1) Lawful Basis (Section 19) - at least one of the following must apply: (a) the data subject has given consent (subject to specific consent requirements per Sections 11 + 16 + Schedule); (b) the processing is necessary for performance of a contract to which the data subject is a party + or for steps requested by the data subject prior to entering a contract; (c) the processing is necessary for compliance with a legal obligation other than a contractual obligation to which the controller is subject; (d) the

Artefacts an auditor will ask for
  • Lawful basis register + per processing + Section 19 + records + per activity
  • Consent records + Section 11 + audit trail + withdrawal mechanism + records + per data subject
  • Privacy notice + Section 22 + identity/DPO/purposes/rights + records + per touchpoint + versioned
  • Direct marketing consent + Section 9 + opt-in/opt-out + records + per campaign + penalty awareness
  • Sensitive data conditions + Section 5 + explicit consent + records + per category + per processing
Where this commonly fails
  • Lawful basis selected after processing (consent bias)
  • Consent records weak (bundled + pre-ticked)
  • Privacy notices generic (no Jamaica DPA references)
  • Direct marketing without specific opt-in
  • Sensitive data without Section 5 explicit conditions

JM DPA 2020 Standard 2 - Purpose Limitation

JM-DPA2020-Standard2-Purpose-Limitation-Sec20-Specified-Explicit-Legitimate-No-Further-Processing-Incompatible
Jamaica DPA 2020 Standard 2 - Purpose Limitation + Section 20 + Specified + Explicit + Legitimate Purposes + No Further Processing Incompatible + Purpose Compatibility Test + Secondary Use Restrictions

Standard 2 per Section 20 + the Schedule of the Jamaica Data Protection Act 2020: Personal data shall be collected only for specified + explicit + and legitimate purposes + and shall not be further processed in any manner incompatible with those purposes. (1) Purpose Specification at Collection: (a) purposes must be defined at the point of collection NOT retrospectively justified; (b) purposes documented in Records of Processing Activities (ROPA); (c) Privacy Notice (Section 22) must clearly state purposes; (d) purposes specific to processing activity not vague aggregate; (e) primary + secondary purposes distinguished. (2) Explicit Purposes: (a) NOT implicit or assumed; (b) plain language understandable to data subject; (c) NOT buried in lengthy terms of service; (d) machine-readable purpose taxonomy emerging best practice. (3) Legitimate Purposes: (a) purposes must be lawful + ethical +

Artefacts an auditor will ask for
  • Purpose specification + per processing + ROPA + records + per activity
  • Compatibility test + per secondary use + records + per assessment
  • ROPA + Section 25 + entries + records + audit ready
  • Re-consent procedure + materially new purpose + records + per change
  • DPIA on purpose drift + records + per material change + Commissioner consultation if high-risk
Where this commonly fails
  • Purposes vague at collection ('improving services')
  • Compatibility test never run (purpose drift unchecked)
  • ROPA absent or out-of-date
  • Re-consent not sought for new purposes
  • DPIA not triggered on material scope change

JM DPA 2020 Standard 3 - Data Minimisation

JM-DPA2020-Standard3-Adequacy-Relevance-Necessity-Sec21-Data-Minimisation-No-Excess-Processing
Jamaica DPA 2020 Standard 3 - Adequacy + Relevance + Necessity + Section 21 + Data Minimisation + No Excess Processing + Proportionality + Privacy by Default + Field-Level Restraint + Granular Permissions

Standard 3 per Section 21 + the Schedule of the Jamaica Data Protection Act 2020: Personal data shall be adequate + relevant + and necessary in relation to the purposes for which they are processed (Data Minimisation Principle). The third Data Protection Standard requires the LEAST amount of personal data that achieves the legitimate purpose - no more + no less + no longer. (1) Adequate: data must be sufficient to achieve the purpose - not so little that purpose cannot be properly served; (a) operational completeness; (b) decision-quality data; (c) avoid scenarios where insufficient data leads to harmful outcomes (e.g. credit denial based on incomplete record). (2) Relevant: data must relate directly to the purpose; (a) NOT collected because it might be useful later; (b) NOT collected because the form has an empty field; (c) NOT collected to enable future expansion. (3) Necessary: data m

Artefacts an auditor will ask for
  • Field-level justification + per data point + records + per collection form/API
  • Data inventory + minimisation review + annual + records + per change
  • Privacy by Default + Section 34 + opt-in defaults + records + per system
  • Children minimisation + Section 7 + records + per data subject under 18
  • Sensitive data minimisation + Section 5 + records + per category + per processing
Where this commonly fails
  • Forms collect 'might be useful' fields
  • Data inventory absent or out-of-date
  • Privacy by Default opt-out rather than opt-in
  • Children's data uncategorised + over-collected
  • Sensitive data collected with weak justification

JM DPA 2020 Standard 4 - Accuracy

JM-DPA2020-Standard4-Accuracy-Sec22-Up-to-Date-Rectification-Erasure-Correction-Right
Jamaica DPA 2020 Standard 4 - Accuracy + Section 22 + Up-to-Date + Rectification Right + Erasure Right + Correction Procedures + Quality Assurance + Sources Verification

Standard 4 per Section 22 + the Schedule of the Jamaica Data Protection Act 2020: Personal data shall be accurate and + where necessary + kept up to date. The fourth Data Protection Standard requires data quality + accuracy + currency + and provides data subjects with the right to seek rectification. (1) Accuracy Definition: (a) factually correct + complete; (b) up-to-date as needed by the purpose; (c) NOT misleading by omission; (d) traceable to authoritative sources where available; (e) free from systematic bias. (2) Reasonable Steps Standard: (a) controller must take reasonable steps to ensure accuracy; (b) reasonableness depends on (i) purpose (high-stakes decisions require higher accuracy); (ii) nature of data; (iii) cost of accuracy measures; (iv) consequences of inaccuracy. (3) Source Verification: (a) data from trustworthy sources; (b) primary source preferred over secondary; (c)

Artefacts an auditor will ask for
  • Accuracy reasonable steps + source verification + records + per data class
  • Rectification right + Section 38 + 30 days + extension + records + per request
  • Erasure right + Section 39 + 30 days + grounds + records + per request
  • Quality assurance + metrics + DQ profiling + records + per data class + periodic
  • Downstream propagation + recipients notification + records + per correction + audit trail
Where this commonly fails
  • Reasonable steps undocumented (defence to accuracy challenge weak)
  • Rectification SLA missed (>30 days)
  • Erasure refused without reasoned response
  • Quality assurance absent (no metrics + no cleansing)
  • Corrections siloed (downstream systems out of date)

JM DPA 2020 Standard 5 - Retention

JM-DPA2020-Standard5-Retention-Sec23-Time-Limit-No-Longer-Than-Necessary-Erasure-Deletion-Anonymisation
Jamaica DPA 2020 Standard 5 - Retention + Section 23 + Time Limit + No Longer Than Necessary + Erasure + Deletion + Anonymisation + Retention Schedule + Legal Hold + Backup Considerations + Storage Limitation

Standard 5 per Section 23 + the Schedule of the Jamaica Data Protection Act 2020: Personal data shall be kept for no longer than is necessary for the purposes for which they are processed. The fifth Data Protection Standard requires Storage Limitation - retention only as long as necessary + then erasure or anonymisation. (1) Retention Period Setting: (a) by purpose - different purposes may have different retention; (b) by lawful basis - consent withdrawal triggers earlier deletion; (c) by data category - sensitive data requires shorter retention; (d) by legal requirement - statutory minimums (tax: 7 years; banking: 5-7 years; employment: 5-7 years post-departure; medical: lifetime + 25 years; certain children's records: 25 years; AML/KYC: 7 years post-relationship); (e) by jurisdiction - if data subject in multiple countries take strictest. (2) Retention Schedule per Section 25 ROPA: (a)

Artefacts an auditor will ask for
  • Retention schedule + per processing + Section 25 + records + per data category
  • Erasure methods + logical/physical/anonymisation + records + per deletion + audit trail
  • Backup retention + crypto-shredding + records + per system + per backup class
  • Legal hold + litigation hold + records + per hold + release
  • Periodic review + annual retention audit + records + per cycle + DPO oversight
Where this commonly fails
  • Retention indefinite by default
  • Deletion not actually executed (soft delete only)
  • Backups retain deleted data perpetually
  • Legal holds undocumented or never released
  • No annual retention audit

JM DPA 2020 Standard 6 - Data Subject Rights

JM-DPA2020-Standard6-Subject-Rights-Sec37-43-Access-Correction-Erasure-Portability-Objection-Profiling-Restriction
Jamaica DPA 2020 Standard 6 - Data Subject Rights Enablement + Section 37-43 + Access Right + Correction Right + Erasure Right + Portability Right + Objection Right + Automated Decision-Making Restrictions + Profiling + Restriction Right

Standard 6 per Sections 37-43 + the Schedule of the Jamaica Data Protection Act 2020: Personal data shall be processed in accordance with the rights of data subjects under this Act. The sixth Data Protection Standard establishes comprehensive data subject rights closely modelled on EU GDPR + UK DPA 2018 + Convention 108+. (1) Section 37 Right of Access (Subject Access Request - SAR): (a) right to confirmation whether personal data being processed; (b) right to copy of personal data; (c) right to supplementary information (purposes + categories + recipients + retention + rights + sources + automated decision-making); (d) response within 30 calendar days + extension up to 60 days for complex requests; (e) free for first request per year - reasonable fee for additional or excessive; (f) Section 37(8) refusal grounds limited - manifestly unfounded + excessive + frequency disproportionate. (2

Artefacts an auditor will ask for
  • SAR portal + Section 37 + 30-day SLA + records + per request + audit trail
  • Rights implementation + Section 38-43 + 7 rights + records + per type
  • DPO oversight + escalation + records + per request + decisions
  • Identity verification + proportionate + records + per SAR + per access level
  • Downstream propagation + recipients + records + per action + audit trail
Where this commonly fails
  • SAR portal absent (email-only handling)
  • 30-day SLA frequently missed
  • Rights implementation incomplete (portability + restriction)
  • Identity verification weak (impersonation risk)
  • Downstream propagation absent (siloed responses)

JM DPA 2020 Standard 7 - Security

JM-DPA2020-Standard7-Security-Sec35-Appropriate-Technical-Organisational-Confidentiality-Integrity-Availability-Resilience
Jamaica DPA 2020 Standard 7 - Security + Section 35 + Appropriate Technical and Organisational Measures + Confidentiality + Integrity + Availability + Resilience + Encryption + Pseudonymisation + Risk-Based Security

Standard 7 per Section 35 + the Schedule of the Jamaica Data Protection Act 2020: Personal data shall be processed in a manner that ensures appropriate security including protection against unauthorised or unlawful processing + accidental loss + destruction or damage using appropriate technical and organisational measures. (1) Risk-Based Security per Section 35: (a) security measures appropriate to the risk; (b) state of the art consideration; (c) cost of implementation; (d) nature + scope + context + purposes; (e) risk of varying likelihood and severity for data subject rights and freedoms; (f) particular consideration for risks of accidental + unlawful destruction + loss + alteration + unauthorised disclosure or access. (2) Technical Measures: (a) Encryption per Section 35(1)(a) - at-rest + in-transit + in-use; (b) Pseudonymisation - personal data cannot be attributed to specific data

Artefacts an auditor will ask for
  • Technical measures + encryption/pseudonymisation/access + records + per system + per data class
  • Organisational measures + policies/training + records + per role + per quarter
  • Risk-based security + risk assessment + records + per material change + per data class
  • Regular testing + pen test + vuln + records + per quarter + per service
  • Vendor/processor security + Section 26 + DPA + records + per contract + per sub-processor
Where this commonly fails
  • Technical measures point-in-time (not continuous)
  • Organisational measures policy-only (no enforcement)
  • Risk assessments stale (>annual)
  • Pen testing annual only (no continuous vuln)
  • Vendor security accepted (no due diligence)

JM DPA 2020 Standard 8 - International Transfers

JM-DPA2020-Standard8-Transfers-Outside-Jamaica-Sec27-Adequacy-Decisions-Standard-Contractual-Clauses-BCR-Derogations
Jamaica DPA 2020 Standard 8 - Transfers Outside Jamaica + Section 27 + Adequacy Decisions + Standard Contractual Clauses + Binding Corporate Rules + Derogations + Cross-Border Data Flows + Caribbean Community + International Data Privacy

Standard 8 per Section 27 + the Schedule of the Jamaica Data Protection Act 2020: Personal data shall not be transferred outside Jamaica unless adequate protection is provided. The eighth Data Protection Standard governs international data transfers + closely modelled on EU GDPR Chapter V. (1) Section 27 General Prohibition: transfer outside Jamaica prohibited UNLESS one of the following grounds applies (a) Adequacy Decision; (b) Appropriate Safeguards; (c) Specific Derogations; (d) Compelling Legitimate Interests (narrow). (2) Adequacy Decisions: (a) Commissioner determines third country provides adequate level of protection; (b) consideration includes (i) rule of law + respect for human rights; (ii) data protection legislation + enforcement; (iii) supervisory authority independence; (iv) international commitments; (v) Convention 108+ accession; (c) Commissioner has discretion + may iss

Artefacts an auditor will ask for
  • Transfer map + per destination + records + per data flow + per category
  • Lawful mechanism + Adequacy/SCC/BCR + records + per transfer + per recipient
  • TIA + per transfer + records + per destination + periodic review
  • Supplementary measures + encryption/pseudonymisation + records + per transfer
  • Section 22 disclosure + transfer destinations + records + per touchpoint
Where this commonly fails
  • Transfers without mapping (cloud sprawl)
  • Lawful mechanism not chosen per transfer
  • TIA absent (Schrems II ignored)
  • Supplementary measures not implemented
  • Privacy Notice silent on transfers
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Jamaica Data Protection Act 2020 framework page.