Law / Barbados

Barbados

All 10 named instruments researched to a stage, across three of the six areas of law we track: 10 in force. As of 19 September 2026.

When they take effect10 of 10 carry a date. Earlier is before 2014.
Before 2014: 3 instruments (3 in force) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 0 instruments 2019: 0 instruments 2020: 0 instruments ’20 2021: 7 instruments (7 in force) 2022: 0 instruments 2023: 0 instruments 2024: 0 instruments 2025: 0 instruments 2026: 0 instruments ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law none researched
  2. Privacy law 6
  3. Scraping law 3
  4. Cybersecurity law none researched
  5. Age gating law none researched
  6. News aggregation law 1

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law6 instruments, 6 in force

Research summary (151 words)

Barbados's comprehensive data-protection regime is the Data Protection Act, 2019 (Act 2019-29), closely modelled on the EU General Data Protection Regulation and enforced by the Data Protection Commissioner. The Act received the Governor-General's assent on 12 August 2019 and, by its own terms, comes into operation on a date fixed by proclamation; the Government gazetted that proclamation, S.I. 2021 No. 24, on 26 March 2021.

The Act covers processing of personal data by a data controller or data processor established in Barbados, or targeting data subjects in Barbados, without a general carve-out for publicly accessible personal data; only data a controller is itself obliged by another enactment to publish is exempt.

Biometric and genetic data are included in the Act's definition of sensitive personal data, whose processing is prohibited unless a specific ground applies, and an individual who suffers damage or distress from a contravention has a private right to compensation.

Breach notification

Data Protection Act, 2019, personal data breach notification

Data Protection Act, 2019, ss. 63-64 (personal data breach notification)Official text of the Data Protection Act, 2019 (Act 2019-29), Office of the Attorney General of Barbados

In force since 26 March 2021. Binds public and private bodies.

What this law does

Section 63(1) requires a data controller, where there is a personal data breach, to notify it to the Commissioner without undue delay and, where feasible, not later than 72 hours after having become aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of an individual, and section 63(2) requires a notification made outside that period to be accompanied by reasons for the delay.

Section 63(3) requires a data processor to notify the data controller without undue delay after becoming aware of a personal data breach.

Section 63(4) fixes what the notification must describe: the nature of the breach including, where possible, the categories and approximate number of data subjects and of personal data records concerned, the name and contact details of the data privacy officer or other contact point, the likely consequences, and the measures taken or proposed to address the breach and mitigate its adverse effects, with information given in phases without undue further delay where it cannot all be supplied at once.

Section 63(6) requires the controller to document every personal data breach, its facts, effects and remedial action, so the Commissioner can assess compliance.

Section 64(1) requires the controller to communicate a breach likely to result in a high risk to the rights and freedoms of individuals to the data subject without undue delay and, where feasible, not later than 72 hours after having become aware of it, in clear and plain language, and section 64(3) excuses that communication only where protective measures such as encryption render the affected data unintelligible, where subsequent measures have made the high risk no longer likely to materialise, or where it would involve disproportionate effort and a public communication of equal effect is made instead.

Section 100 leaves commencement to a proclamation. The Official Gazette of 26 March 2021 carries Statutory Instrument 2021 No. 24, the Proclamation re Data Protection Act, 2019, which is the day these provisions began to bind.

What it requires

Comprehensive regime

Data Protection Act, 2019

Data Protection Act, 2019 (Act 2019-29), ss. 1-7, 29-62, 65-69 and 96-100Official text of the Data Protection Act, 2019 (Act 2019-29), Office of the Attorney General of Barbados

In force since 26 March 2021. Binds public and private bodies.

What this law does

Section 3 applies the Act to processing personal data in the context of the activities of a data controller or data processor established in Barbados, and to processing the personal data of data subjects in Barbados by a controller or processor not established there where the activities relate to offering goods or services to them.

Section 4 sets the processing principles, requiring personal data to be processed lawfully, fairly and transparently, collected for specified, explicit and legitimate purposes, adequate, relevant and limited to what those purposes need, accurate and kept up to date, kept in identifiable form no longer than the purpose requires, and processed with appropriate security using technical or organisational measures. Sections 5 to 7 govern fairness, lawfulness and the conditions for valid consent.

Sections 29 to 49 carry the exemptions, from national security and crime through journalism, research, legal privilege and examinations. Section 50 bars operating as a data controller without registration in the Register of Data Controllers and requires a controller not established in Barbados to nominate a representative there; section 55 imposes the same on a data processor.

Section 54 requires data protection by design and by default, section 60 requires records of processing activities, section 62 requires technical and organisational measures giving a level of security appropriate to the risk, including pseudonymisation and encryption, the ability to restore availability and access after a physical or technical incident, and a process for regularly testing their effectiveness.

Section 65 requires a data protection impact assessment before processing likely to result in a high risk, section 66 requires prior consultation with the Commissioner, and sections 67 to 69 govern the designation, position and duties of the data privacy officer. Section 100 leaves commencement to a proclamation. The Official Gazette of 26 March 2021 carries Statutory Instrument 2021 No. 24, the Proclamation re Data Protection Act, 2019, which is the day these provisions began to bind.

What it requires

Cross border transfer

Data Protection Act, 2019, transfers of personal data outside of Barbados

Data Protection Act, 2019, ss. 22-28 (transfers of personal data outside of Barbados)Official text of the Data Protection Act, 2019 (Act 2019-29), Office of the Attorney General of Barbados

In force since 26 March 2021. Binds public and private bodies.

What this law does

Section 22 bars the transfer of personal data to a country or territory outside Barbados unless that country or territory provides an adequate level of protection for the rights and freedoms of data subjects and appropriate safeguards, on condition that the data subject's rights are enforceable and effective legal remedies are available.

Section 23 makes adequacy a question of all the circumstances, weighing the nature of the data, the country of origin and of final destination, the purposes and period of the intended processing, the law in force and international obligations of that country, any enforceable codes of conduct and the security measures taken there.

Section 24 lists the appropriate safeguards: a legally binding and enforceable instrument between public authorities, binding corporate rules under section 25, standard data protection clauses prescribed by the Commissioner with the Minister's approval, contractual clauses the Commissioner authorises, and authorised provisions in administrative arrangements between public authorities.

Section 25 sets out what binding corporate rules must specify and requires them to be submitted to the Commissioner for authorisation. Section 26 lists the derogations that displace sections 22 to 24, including the data subject's consent, contractual necessity, substantial public interest, legal proceedings or advice, vital interests, a public register, and terms approved or a transfer authorised by the Commissioner.

Section 27 makes contravening sections 22, 23 or 24 an offence carrying, on summary conviction, a fine of $500,000 or three years' imprisonment or both, and section 28 lets the Minister specify by order when a transfer is to be treated as necessary for reasons of substantial public interest. Section 100 leaves commencement to a proclamation.

The Official Gazette of 26 March 2021 carries Statutory Instrument 2021 No. 24, the Proclamation re Data Protection Act, 2019, which is the day these provisions began to bind.

What it requires

Data subject rights

Data Protection Act, 2019, rights of a data subject

Data Protection Act, 2019, ss. 10-21 (rights of a data subject)Official text of the Data Protection Act, 2019 (Act 2019-29), Office of the Attorney General of Barbados

In force since 26 March 2021. Binds public and private bodies.

What this law does

Section 10 gives a data subject the right to be told by a data controller whether personal data about them is being processed and to obtain a copy of it, section 11 a right to rectification, section 12 a right to erasure, section 13 a right to restriction of processing and section 14 a duty on the controller to notify recipients of a rectification, erasure or restriction.

Section 15 gives a right to data portability, section 16 a right to prevent processing likely to cause damage or distress, and section 17 an unqualified right to prevent processing for the purposes of direct marketing.

Section 18 gives the data subject the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them, except where the processing is necessary for entering into or performing a contract with them, authorised by an enactment that lays down suitable safeguards, or based on their consent; where a contract or consent is relied on the controller must implement suitable measures to safeguard their rights, freedoms and legitimate interests, and the exceptions do not reach sensitive personal data unless the processing is in the public interest and those safeguards are in place.

Sections 19 and 20 fix the information a controller must give when it collects personal data from the data subject and when it obtains the data elsewhere, and section 21 requires that information and every communication about these rights to be transparent and to be provided in a form that lets the data subject exercise them. Section 100 leaves commencement to a proclamation.

The Official Gazette of 26 March 2021 carries Statutory Instrument 2021 No. 24, the Proclamation re Data Protection Act, 2019, which is the day these provisions began to bind.

What it requires

Enforcement supervision

Data Protection Act, 2019, the Commissioner, enforcement and penalties

Data Protection Act, 2019, ss. 70-95 (Commissioner, enforcement, tribunal and penalties)Official text of the Data Protection Act, 2019 (Act 2019-29), Office of the Attorney General of Barbados

In force since 26 March 2021. Binds public and private bodies.

What this law does

Sections 70 to 75 establish the Data Protection Commissioner and set the Commissioner's functions, staff, duties of confidence, indemnity and reporting.

Section 76 lets the Commissioner, on being satisfied that a data controller or data processor has contravened or is contravening the Act, serve an enforcement notice requiring steps to be taken or refrained from within a specified time, or requiring processing to stop, having considered whether the contravention has caused or is likely to cause damage or distress; sections 77 to 82 govern cancellation of a notice, requests for assessment, information notices, special information notices and the journalism restriction.

Section 83 makes failure to comply with a notice an offence, and sections 84 to 89 govern service, warrants, their execution and return, matters exempt from inspection and seizure, and obstruction. Sections 90 to 92 establish the Data Protection Tribunal and the right of appeal against the Commissioner's notices and its determination.

Section 93 entitles an individual who suffers damage or distress from any contravention of the Act to compensation from the data controller or data processor, subject to the defence of having taken all measures reasonably required to comply.

Section 94 makes it an offence to obtain, disclose or procure the disclosure of personal data knowingly or recklessly without the data controller's consent, carrying a fine of $10,000 or six months' imprisonment or both, rising to $100,000 or three years where the personal data so obtained is sold or offered for sale.

Section 95 lets the Commissioner, after a hearing and where the public interest calls for it, order a person who has contravened section 52(1), section 57(1) or sections 60 to 67 to pay the Crown a penalty of up to $50,000. Section 100 leaves commencement to a proclamation. The Official Gazette of 26 March 2021 carries Statutory Instrument 2021 No. 24, the Proclamation re Data Protection Act, 2019, which is the day these provisions began to bind.

What it requires

Scraping law3 instruments, 3 in force

Research summary (276 words)

Barbados has no scraping-specific statute, so general law governs each dimension separately.

The Computer Misuse Act, Cap. 124B criminalises gaining access to a computer system knowingly or recklessly and without lawful excuse or justification; unlike some Caribbean neighbours' computer-misuse statutes, section 4 does not require defeating a security measure, but the Act separately defines access as unauthorised only where the person is not entitled to it or lacks permission, so whether reading a public, unauthenticated page (which the site operator has made available to any visitor) falls within the offence is a genuine textual question no reported Barbadian case has answered.

No Barbadian court has ruled on the enforceability of a browsewrap or clickwrap terms-of-service against a scraper. The Copyright Act, Cap. 300 permits fair dealing for research or private study and, separately, for criticism, review, or reporting current events with sufficient acknowledgment, but Barbados has not enacted a text-and-data-mining exception, so training a model on scraped copyrighted text rests only on the research-or-private-study ground if it can be so characterised.

The Copyright Act protects a compilation only as a literary work under ordinary copyright, conferring no sui generis database right.

The Data Protection Act, 2019 applies to personal data without a general carve-out for information that is publicly accessible, so scraping personal data from a public Barbadian website remains subject to the Act's lawful-basis, purpose-limitation, and cross-border-transfer duties, and biometric data scraped from public images is sensitive personal data whose processing is prohibited absent a specific ground.

No Barbadian statute or reported case establishes a scraping-specific unfair-competition, misappropriation, or trespass doctrine, and none assigns legal weight to a robots.txt directive or imposes an AI-training-specific rule.

Computer misuse

Computer Misuse Act, illegal access

Computer Misuse Act, Cap. 124B, s. 4 (Illegal Access)Official consolidated text of the Computer Misuse Act, Cap. 124B, reproduced by the Organization of American States

In force since 18 July 2005. Binds public and private bodies.

What this law does

Section 4 prohibits a person, knowingly or recklessly and without lawful excuse or justification, from gaining access to the whole or any part of a computer system, causing a programme to be executed, using a programme to gain access to data, copying or moving data, or altering or erasing it. The offence carries a fine of $25,000 or imprisonment of up to two years, or both.

Section 3(2) separately defines access as unauthorised only where the person is not entitled to it, lacks permission, or exceeds the permission granted; because section 4 does not itself require defeating a security measure, whether a person reading a public, unauthenticated page (which the site operator has made generally available) acts without lawful excuse is an open textual question that no reported Barbadian decision has settled.

What it requires

Personal data

Data Protection Act, 2019, reach over scraped personal data

Data Protection Act, 2019 (Act 2019-29)Official text of the Data Protection Act, 2019 (Act 2019-29), Office of the Attorney General of Barbados

In force since 26 March 2021. Binds public and private bodies.

What this law does

The Act applies to processing personal data by a controller or processor established in Barbados, or targeting data subjects in Barbados, and carries no general exemption for personal data that is already publicly accessible; the only public-data exemption is narrow, covering information a controller is itself obliged by another enactment to publish.

A scraper collecting personal data, including a face or other biometric identifier, from a public Barbadian website remains subject to the Act's lawful-basis and purpose-limitation duties, and biometric data is sensitive personal data whose processing is prohibited unless a specific ground applies. Moving scraped personal data outside Barbados requires an adequate level of protection in the destination country or an appropriate safeguard.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (185 words)

Barbados has no press-publisher neighbouring right, no mandatory platform-to-publisher bargaining code, no recognised hot-news misappropriation doctrine distinct from ordinary copyright law, and no located statute or case law addressing hyperlinking or framing liability specifically; each of those dimensions is a sourced absence rather than an unresolved question.

Unlike some Francophone copyright statutes in the region, the Copyright Act, Cap. 300 contains no provision excluding the news of the day or mere facts from protection, and no general quotation exception letting one work reproduce extracts of another.

The only exception reaching a news aggregator's reproduction of headlines and snippets is section 52(1)(b), which excuses fair dealing with a protected work, other than a photograph, for the purpose of reporting current events, if accompanied by sufficient acknowledgment, subject to the section 53 fairness factors.

That exception carries no headline-length or short-extract cap and is not confined to the press industry, and no reported Barbadian decision applies it to a systematic aggregator as opposed to a traditional news report. The Act predates the concept of a machine-readable text-and-data-mining reservation, so no opt-out mechanism of that kind exists either.

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.