Law / Suriname

Draft Law on the Protection of Privacy and Personal Data (Ontwerpwet Bescherming Privacy en Persoonsgegevens)

Wet Bescherming Privacy en Persoonsgegevens, arts. 1-6, 12, 14-19, 21 (general obligations)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

Proposed: draft date not recorded.

A comprehensive regime rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • This measure is a draft bill; it binds nobody yet. What follows is what it would require if it is enacted in this form.
  • Have a lawful basis, such as a contract, a legal obligation, vital interests, a public interest task, official authority, a legitimate interest that does not override the data subject's rights, or the data subject's consent, before processing personal data.
  • Where processing rests on consent, present the request separately from other matters, in clear and simple language, and let the data subject withdraw consent as easily as it was given.
  • Process personal data lawfully and fairly, only for specified, explicit and legitimate purposes, and keep it adequate, relevant, accurate, and limited to what those purposes need.
  • Do not keep personal data in a form that identifies a data subject for longer than the processing purposes require.
  • Take appropriate technical and organizational measures so you can demonstrate compliance with this law on request, and require anyone with access to personal data under your authority to keep it confidential or be bound by a legal duty of confidentiality.
  • Implement data protection by design and by default, taking into account the state of the art, the cost of implementation, and the risks the processing poses to data subjects' rights and freedoms.
  • Keep a written or electronic register of your processing activities, covering the categories of data, recipients, retention periods, and security measures, and notify it to the Commissioner for Personal Data Protection, updating the notification whenever needed and at least once a year.
  • Take appropriate technical and organizational security measures against accidental or unauthorized access, destruction, loss, use, alteration, or disclosure of personal data, matched to the risk.
  • Appoint a data protection officer to advise you and your staff on this law's duties, liaise with the Commissioner, and act as the contact point for data subjects exercising their rights.

What it reaches

Obligation class

Consent, Governance, Security, Retention

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

This measure is a draft bill; it binds nobody yet, and what follows describes what it would require if enacted in the form read.

The bill defines privacy as the right to protection of all information about an identified or identifiable living natural person, and defines personal data the same way, an identifiable natural person being one who can be identified directly or indirectly by reference to an identifier such as a name, an identification number, location data, an online identifier, or one or more factors specific to that person's physical, physiological, genetic, mental, economic, cultural or social identity.

Article 5 sets out the processing principles: lawfulness and fairness, openness and transparency, purpose limitation and data minimization, data quality, storage limitation, security safeguards, data-subject participation, ethical processing, and accountability.

Article 6 requires a lawful basis before processing, running from contractual necessity, a legal obligation, vital interests, a public-interest task, and official authority through to a legitimate interest that does not override the data subject's rights, or the data subject's own specific, informed consent presented separately from other matters and withdrawable at any time.

Article 12 lets specific laws narrow the rights and obligations in article 5, chapter III, and article 20(5) for purposes including national security, defence, public safety, and the prevention, investigation, detection or prosecution of criminal offences. Article 14 requires a controller and, where applicable, a processor to take appropriate technical and organizational measures able to demonstrate compliance on request, and to bind anyone with access to personal data to confidentiality.

Article 15 requires data protection by design and by default under article 17, a written processor contract, and cooperation between joint controllers. Article 18 requires a controller and processor to keep a register of processing activities and notify it to the Commissioner for Personal Data Protection, updated whenever needed and at least once a year. Article 19 requires appropriate technical and organizational security measures matched to the risk.

Article 21 requires a controller and a processor each to appoint a data protection officer to advise on this law's duties, liaise with the Commissioner, and act as the contact point for a data subject exercising their rights. The bill remains under consideration before De Nationale Assemblee, with no enactment timeline.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach

Read the law

Draft text of the Ontwerpwet Bescherming Privacy en Persoonsgegevens
as republished by SRiS (Stichting voor de Rechtsorde in Suriname), a Surinamese legal-information foundation, not an official government gazette page the bill's current pendency before De Nationale Assemblee is confirmed on the National Assembly's own list of bills under consideration

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app