Law / Kiribati

Data Protection Act 2025

Data Protection Act 2025 ss. 1-11, 14, 18, 21-22, 32-33 (lawful basis, purpose limitation, controller and processor duties, security measures, data protection impact assessments)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

Commencement not set.

A comprehensive regime rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • This Act is enacted but not in force: section 2 leaves commencement to a ministerial notice, and none was located as of this review, so nothing that follows binds anyone yet.
  • On commencement, process personal data only on one of the Act's lawful bases, such as consent, contract necessity, legal obligation, or legitimate interests, and only for a purpose that is explicit and not prohibited by law.
  • On commencement, further process personal data only for a purpose compatible with the original purpose, and do not retain personal data longer than necessary to achieve that purpose unless retention is required or authorised by law, necessary for a legitimate business purpose, or the data subject has consented to it.
  • On commencement, implement appropriate technical and organisational measures against accidental or unlawful destruction, loss, misuse or alteration and unauthorised disclosure or access, taking into account the amount of personal data, the likelihood of harm, the extent of processing, the retention period, and the availability and cost of measures.
  • On commencement, put a written agreement in place with any person who processes personal data on your behalf, requiring that person to give you the notifications and assistance you need to comply with the Act and to impose the same written-agreement requirement on anyone it engages for downstream processing.
  • On commencement, if you are a controller of major importance, carry out a data protection impact assessment and submit the report to the Digital Transformation Office before processing likely to expose 10,000 or more data subjects to a high risk of significant harm, and proceed only with the Office's approval if the risk remains high after mitigation; this duty does not apply until the second anniversary of commencement.
  • A person who is not a controller of major importance has a further two years from commencement before the Act applies to them (s. 6(2)).

What it reaches

Obligation class

Consent, Retention, Security, Governance, DPIA

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Section 5 applies the Act to processing personal data within Kiribati and, outside Kiribati, to processing that offers goods or services to, or monitors the behaviour of, data subjects in Kiribati. Section 5(3) states that the Act binds the Republic.

Section 6 exempts personal, household or recreational processing and excludes processing by legally authorised authorities for criminal law enforcement, public health emergencies or national security, processing necessary to a legal claim, and processing for journalistic, educational, artistic or literary expression. Section 6(2) defers the Act for two years after commencement for a person who is not a controller of major importance.

Section 10 requires a controller to process personal data only for an explicit purpose compatible with the purpose of collection, to limit processing to what that purpose requires, to keep the data accurate and current, and not to retain it longer than necessary unless retention is authorised by law, needed for a legitimate business purpose, or consented to.

Section 11 lists twelve lawful bases for processing, including consent, voluntary provision, contractual necessity, a legal obligation, a public authority's lawful function, a medical or public health emergency, legitimate interests that do not override the data subject's fundamental rights, archiving or research, and data the data subject has intentionally made public.

Section 14 requires a controller to take reasonable measures, including a written agreement, to bind any person processing personal data on its behalf to the Act, and to pass the same written-agreement duty down to further processors. Section 18 requires appropriate technical and organisational security measures against accidental or unlawful destruction, loss, misuse, alteration, or unauthorised disclosure or access.

Section 21 requires a controller of major importance to carry out a data protection impact assessment and submit it to the Digital Transformation Office before processing likely to expose 10,000 or more data subjects to a high risk of significant harm, a duty that does not apply until the second anniversary of commencement. Sections 32 and 33 give the Minister power to make regulations and state that the Act does not limit any other obligation or right under Kiribati law.

Section 2 leaves commencement to a notice the Minister may appoint, and none was located, so nothing in this Act binds anyone yet.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach

Read the law

Act text as published by the Ministry of Information, Communications and Transport (Data Protection Act 2025).

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app