Data Protection Act, 2018
Saint Christopher and Nevis Data Protection Act, 2018 (No. 5 of 2018), ss. 1-12, 19 and 21-22
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
Commencement not set.
A comprehensive regime rule binding public and private bodies.
As of 19 September 2026.
What it requires
- This law was passed and gazetted in 2018 but, on its own terms, does not take effect until a Ministerial commencement order is published in the Gazette; no such order has been located, so whether it currently binds has to be confirmed before relying on what follows.
- Obtain a data subject's consent before processing their personal data other than sensitive personal data, unless a listed exception applies.
- Before collecting personal data, tell the data subject the purpose of collection, the source of the data where available, the classes of third party it may be disclosed to, whether supplying the data is obligatory or voluntary, and how to request access or correction.
- Do not disclose personal data for a new purpose without the data subject's consent, except where crime prevention or detection, legal authorisation, a reasonable belief in a right or in the data subject's consent, or the public interest applies.
- Take practical steps to protect personal data from loss, misuse, unauthorised access, alteration or destruction, having regard to the nature of the data, its storage, and the personnel with access to it, and require a data processor you engage to give sufficient security guarantees and comply with them.
- Do not keep personal data longer than the purpose requires, and take reasonable steps to destroy or permanently delete it once no longer needed.
- Take reasonable steps to keep personal data accurate, complete, not misleading and up to date.
What it reaches
Obligation class
Consent, Disclosure, Security, Retention
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Section 4 applies the Act to a private body processing personal data in respect of commercial transactions, and to any other person meeting a territorial nexus test tied to establishment in Saint Christopher and Nevis or use of equipment there. Section 6 binds the State. Section 7(1) requires a data user to obtain a data subject's consent before processing personal data other than sensitive personal data, or to process sensitive personal data only in accordance with section 20.
Section 7(2) lets a data user process personal data without consent where necessary for a contract, a legal obligation other than a contractual one, the vital interests of the data subject, the administration of justice, or a function conferred by law, and section 7(3) requires the processing to be for a lawful purpose directly related to the data user's activity, necessary for or directly related to that purpose, and adequate but not excessive.
Section 8 requires a data user, on a request for personal data, to tell the data subject the purposes of collection, the source of the data where available, the right to request access and correction, the classes of third party to whom it may be disclosed, and whether supplying the data is obligatory or voluntary.
Section 9 bars disclosure of personal data without the data subject's consent for a purpose other than the one it was collected for or a directly related purpose, or to a class of third party not specified under section 8(d). Section 19 lists the circumstances, including the data subject's consent, crime prevention or detection, legal authorisation, and the public interest, in which such a further disclosure is permitted.
Section 10 requires a data user to take practical steps to protect personal data from loss, misuse, unauthorised access, alteration or destruction, and requires a data processor engaged by the data user to give sufficient security guarantees and to comply with them. Section 11 bars keeping personal data longer than the purpose requires and requires a data user to take reasonable steps to destroy or permanently delete personal data no longer needed.
Section 12 requires a data user to take reasonable steps to keep personal data accurate, complete, not misleading and up to date.
Section 21 exempts personal data processed for an individual's own personal, family or household affairs from the Act entirely, and, subject to listed conditions, exempts data processed for crime prevention or detection, taxation, statistics or research, a court order or judgment, regulatory functions, or journalistic, literary or artistic purposes from some or all of the Act's other principles.
Section 1(2) provides that the Act comes into force on a day fixed by the Minister by Order published in the Gazette, and no commencement order has been located, so the Act's substantive duties are not yet confirmed to be in operation.
When LexLint raises it
automated_outreachdeploys_chatbotcrawls_webtrains_models
Read the law
archived copy
Read from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived July 25, 2024. Publisher's page: https://lawcommission.gov.kn/wp-content/documents/Annual-Laws/2018/ACTs/Act-5-of-2018-Data-Protection-Act-2018.pdfEvery line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.