Data Protection Act, 2011
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 6 January 2012.
A comprehensive regime rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Part I of the Act, including the General Privacy Principles in section 6, and sections 7 to 18, 22, 23, 25(1), 26 and 28 of Part II, are in force; Part III (public-body duties), Part IV (private-sector duties) and Part V (offences and penalties) are enacted but have not been proclaimed.
- Whether or not Part III or Part IV binds you yet, be responsible for the personal information under your control, identify the purpose of collection before or at the time of collection, and get the individual's knowledge and consent for its collection, use or disclosure.
- Limit collection of personal information to what is legally undertaken and necessary for the identified purpose, retain it only as long as necessary for that purpose, and do not disclose it for another purpose without the individual's prior consent.
- Keep personal information accurate, complete and up to date as necessary for the purpose of collection, and protect it with safeguards appropriate to its sensitivity.
- Make available to individuals your policies and practices for managing personal information, and give an individual the ability to challenge your compliance with these Principles and a timely, appropriate response.
What it reaches
Obligation class
Consent, Disclosure, Retention, Governance
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Section 1(2) brought Part I into force on 6 January 2012, together with sections 7 to 18, 22, 23, 25(1), 26 and 28 of Part II, while Part III, Part IV and Part V remain enacted but not proclaimed. Section 3 binds the State, and section 4 states the Act's object as protecting an individual's right to privacy and the right to keep sensitive personal information private and personal.
Section 5 keeps the Act from limiting information a party may obtain by law in a proceeding, a Court's power to compel testimony or production, or a judicial officer's own working notes. Section 6 states the General Privacy Principles, applicable to all persons who handle, store or process personal information belonging to another person, independent of whether Part III or Part IV has been brought into force for the body or organisation concerned.
Those Principles make an organisation responsible for the personal information under its control, require it to identify the collection purpose before or at collection, require the individual's knowledge and consent for collection, use or disclosure, limit collection to what is legally undertaken and necessary, limit retention and further disclosure to the purpose of collection, require the information to be accurate, complete and up to date, require appropriate safeguards, require organisations to make their information-handling policies available to individuals, and give the individual a right to challenge an organisation's compliance and receive a timely response.
Two further Principles are researched separately as their own families: paragraph (h) restricts processing sensitive personal information and paragraph (l) restricts disclosing personal information outside Trinidad and Tobago.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreach
Read the law
Consolidated text of the Data Protection Act
Chap. 22:04, Ministry of the Attorney General and Legal Affairs, mirrored by the Trinidad and Tobago Cyber Security Incident Response Team
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.