Data Protection Act
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 31 January 2023.
A comprehensive regime rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Before collecting personal data directly from a person, tell them what is being collected, why, who will receive it, whether providing it is mandatory, the consequences of not providing it, and their rights to access, correct, and have it destroyed.
- Collect personal data only for a lawful purpose connected with your function or activity, and only where the collection is necessary for that purpose.
- Obtain a person's express consent before processing their personal data, unless a specific ground applies such as performing a contract with them, complying with a legal obligation, or a legitimate interest that does not override their privacy rights, and let them object to processing done on public interest or legitimate interest grounds and revoke consent at any time.
- Keep personal data only for the specified purpose it was collected for, do not use or disclose it in a way incompatible with that purpose, keep it adequate and relevant and not excessive, and keep it accurate and up to date.
- Take security measures appropriate to the risk of unauthorized access, alteration, or loss of personal data, taking the state of technology and the cost of the measures into account, and make sure staff know and follow them.
- Destroy personal data as soon as reasonably practicable once the purpose for holding it has lapsed.
- Part 4's registration scheme (sections 46 to 51) is enacted and not in force, so a data controller currently has no statutory duty under this Act to register with the Commissioner.
What it reaches
Obligation class
Consent, Disclosure, Retention, Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Part 1 states the Act's preliminary provisions: section 3 applies it to a data controller established in Saint Lucia, or established elsewhere but using equipment in Saint Lucia to process data otherwise than in transit, and section 4 binds the State as well as private actors.
Section 33 bars a data controller from collecting personal data except for a lawful purpose connected with its function or activity where the collection is necessary for that purpose, and requires it to tell the data subject, at the point of collection, what is being collected, why, who will receive it, whether providing it is mandatory, the consequences of not providing it, and the subject's rights of access, correction and destruction.
Section 34 bars processing personal data without the data subject's express consent unless a listed ground applies, such as performing a contract with the subject, complying with a legal obligation, or a legitimate interest that does not override the subject's privacy rights, and lets the subject object to processing done on the public interest or legitimate interest grounds and revoke consent at any time.
Section 39 confines processing of data relating to offences, criminal convictions or security measures to the control of a public authority. Section 40 requires a data controller to keep personal data accurate and up to date. Section 41 requires personal data to be kept only for specified lawful purposes, not used or disclosed incompatibly with those purposes, kept adequate and relevant, and not retained longer than necessary.
Section 42 requires the data controller to take security measures appropriate to the risk of unauthorized access, alteration, or loss, having regard to the state of technology and the cost of the measures. Section 43 requires the data controller to destroy personal data once the purpose for holding it has lapsed. Schedule 2 restates these duties as eight Data Protection Principles.
Part 4, sections 46 to 51, would require a data controller to register with the Commissioner, maintain that registration, and hold a certificate the Commissioner issues, and it is enacted and not in force, as are Part 2 and Part 5.
Part 6 exempts a data controller from specified Principles and sections in listed cases, including national security, crime and taxation, health and social work, regulatory activities, journalism, research, information already public under another enactment, legal proceedings, legal professional privilege, domestic purposes, and Commissioner authorization, such as the section 64 exemption applying where the data controller is itself obliged under another enactment to make the information public.
The 2015 Act reworked four of these provisions: it replaced section 1(2) and added section 1(3) so the Minister may fix different dates for different Parts or sections, substituted the definition of data controller in section 2 and added a definition of privacy impact assessment, cut the penalty in section 34(5) to a fine alone by deleting the alternative of imprisonment, and replaced the domestic-purposes exemption in section 67.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachprocesses_biometrics
Read the law
Data Protection Act No. 11 of 2011, Saint Lucia, full text of the Act as enacted
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.