Law / Kiribati

Kiribati

10 of 12 named instruments researched to a stage, across four of the six areas of law we track: 10 enacted but not yet in force. As of 19 September 2026.

  1. AI law none researched
  2. Privacy law 6
  3. Scraping law 1
  4. Cybersecurity law 2
  5. Age gating law none researched
  6. News aggregation law 1

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law6 instruments, 6 enacted but not yet in force

Research summary (150 words)

Kiribati's first comprehensive data-protection statute, the Data Protection Act 2025, has been made by the Maneaba ni Maungatabu and assented to by the Beretitenti, and is not yet in force: section 2 provides that it commences on a date the Minister may appoint by notice, and no appointing notice was located as of this review.

It creates lawful-basis, purpose-limitation, data-subject-rights, breach-notification, cross-border-transfer and enforcement duties administered by the Digital Transformation Office, modelled on the privacy laws of Australia and New Zealand. None of those duties binds anyone until commencement, and section 6(2) then defers application for a further two years for a person who is not a controller of major importance.

The Digital Government Act 2023, which does bind Kiribati's public bodies and their digital infrastructure, defines no personal-data duties of its own; section 34 of the new Act amends it to cross-reference the new rules, on the same commencement.

Breach notification

Data Protection Act 2025, personal data breaches

Data Protection Act 2025, ss. 19-20 (personal data breaches)Act text as published by the Ministry of Information, Communications and Transport (Data Protection Act 2025).

Commencement not set. Binds public and private bodies.

What this law does

Section 19(1) requires a person processing personal data on another person's behalf to inform that other person as soon as practicable after becoming aware of any personal data breach, whether or not it meets the harm threshold in section 20, and section 19(3) requires every person to keep a record of any personal data breach, including its facts, effects and remedial action, whether or not that threshold is met.

Section 19(4) requires a controller to determine whether a breach meets the section 20(1) threshold, keep a written record of that analysis, and make it available to the Office on request.

Section 20 applies to a personal data breach that has resulted in, or is likely to result in, significant harm to affected data subjects, assessed against factors including encryption or other security measures, the nature of the likely harm, mitigating action taken, and whether lost or altered data has been recovered.

When a harmful personal data breach has occurred, section 20(2) requires the relevant controller, as soon as practicable after becoming aware of the breach, to notify the Office and each affected data subject, or to notify data subjects by public notification through widely used media where direct notification would involve disproportionate effort or expense or is otherwise not feasible.

Section 20(5) requires the notification to set out the nature of the breach including, where possible, the categories and approximate numbers of data subjects and records concerned, a point of contact, the likely consequences, and the measures taken or expected to address the breach, supplying the information in phases without undue further delay where it cannot all be given at once.

What it requires

Comprehensive regime

Data Protection Act 2025

Data Protection Act 2025 ss. 1-11, 14, 18, 21-22, 32-33 (lawful basis, purpose limitation, controller and processor duties, security measures, data protection impact assessments)Act text as published by the Ministry of Information, Communications and Transport (Data Protection Act 2025).

Commencement not set. Binds public and private bodies.

What this law does

Section 5 applies the Act to processing personal data within Kiribati and, outside Kiribati, to processing that offers goods or services to, or monitors the behaviour of, data subjects in Kiribati. Section 5(3) states that the Act binds the Republic.

Section 6 exempts personal, household or recreational processing and excludes processing by legally authorised authorities for criminal law enforcement, public health emergencies or national security, processing necessary to a legal claim, and processing for journalistic, educational, artistic or literary expression. Section 6(2) defers the Act for two years after commencement for a person who is not a controller of major importance.

Section 10 requires a controller to process personal data only for an explicit purpose compatible with the purpose of collection, to limit processing to what that purpose requires, to keep the data accurate and current, and not to retain it longer than necessary unless retention is authorised by law, needed for a legitimate business purpose, or consented to.

Section 11 lists twelve lawful bases for processing, including consent, voluntary provision, contractual necessity, a legal obligation, a public authority's lawful function, a medical or public health emergency, legitimate interests that do not override the data subject's fundamental rights, archiving or research, and data the data subject has intentionally made public.

Section 14 requires a controller to take reasonable measures, including a written agreement, to bind any person processing personal data on its behalf to the Act, and to pass the same written-agreement duty down to further processors. Section 18 requires appropriate technical and organisational security measures against accidental or unlawful destruction, loss, misuse, alteration, or unauthorised disclosure or access.

Section 21 requires a controller of major importance to carry out a data protection impact assessment and submit it to the Digital Transformation Office before processing likely to expose 10,000 or more data subjects to a high risk of significant harm, a duty that does not apply until the second anniversary of commencement. Sections 32 and 33 give the Minister power to make regulations and state that the Act does not limit any other obligation or right under Kiribati law.

Section 2 leaves commencement to a notice the Minister may appoint, and none was located, so nothing in this Act binds anyone yet.

What it requires

Cross border transfer

Data Protection Act 2025, processing and transfers outside Kiribati

Data Protection Act 2025, ss. 23-25 (processing and transfers outside Kiribati)Act text as published by the Ministry of Information, Communications and Transport (Data Protection Act 2025).

Commencement not set. Binds public and private bodies.

What this law does

Section 23(1) requires a person that processes personal data outside Kiribati or transfers it to a person outside Kiribati to take reasonable steps to verify or ensure that there is adequate protection with respect to the personal data.

Section 23(2) defines adequate protection as restrictions and obligations substantially similar to Parts III and V, rights substantially similar to Part IV, and enforceability of those restrictions, obligations and rights, and section 23(3) lets that protection rest on the destination jurisdiction's laws, on binding corporate rules, contractual clauses, a code of conduct or a certification mechanism, or on an international organisation's own policies and measures.

Section 23(4) lets the Office issue guidelines on assessing adequate protection and designate a jurisdiction, organisation, law, or measure as affording or not affording it, and section 23(6) lets the Office prohibit a transfer to a specified jurisdiction, organisation or under specified measures for want of adequate protection or for reasons of national security.

Section 24 lets a person process or transfer personal data outside Kiribati without adequate protection where the data subject has given informed consent to the transfer, the transfer is necessary to a contract with the data subject or to a medical emergency, the transfer is for the data subject's benefit and consent is impracticable but would likely be given, or the transfer follows a court or administrative order under an international agreement such as a mutual legal assistance treaty.

Section 25 requires a person processing or transferring personal data outside Kiribati to keep a written record of the reasonable steps taken under section 23(1) or the basis relied on under section 24, and to make that record available to the Office on request.

What it requires

Data subject rights

Data Protection Act 2025, rights of a data subject

Data Protection Act 2025, ss. 13, 15-17 (information notice and rights of data subjects)Act text as published by the Ministry of Information, Communications and Transport (Data Protection Act 2025).

Commencement not set. Binds public and private bodies.

What this law does

Section 13 requires a controller to tell a data subject, before collecting personal data from them, the controller's identity and contact details, the purpose of the processing, how to exercise the Part IV rights, and how to lodge a complaint with the Office under section 26, and to give that information as soon as possible afterward if it could not be given at collection.

Section 15 gives a data subject the right to obtain from a controller, at no expense and without unreasonable delay, confirmation of whether the controller is processing their personal data, a copy of it in a commonly used electronic format, correction of data that is inaccurate, out of date, incomplete or misleading, and deletion of data the controller is not entitled to retain.

Section 15(2) lets a controller charge a reasonable fee or refuse a request that is manifestly unfounded or excessive, particularly because of its repetitive character, and section 15(4) lets a controller charge a fee for a copy of personal data only to the extent another applicable law otherwise permits.

Section 16 gives a data subject the right to withdraw consent previously given, or to object where no lawful basis applies, requires a controller to make exercising that right as easy as giving consent, and requires the controller to promptly stop processing that relies solely on the withdrawn consent.

Section 17 gives a data subject the right not to be subject to a decision based solely on automated processing of personal data that produces a legal or similarly significant effect on them, except where the decision is necessary to a contract with the data subject, authorised by a law with suitable safeguards, or authorised by the data subject's consent.

What it requires

Enforcement supervision

Data Protection Act 2025, enforcement, offences and civil remedies

Data Protection Act 2025, ss. 26-31 (complaints, investigations, notices, offences and civil remedies)Act text as published by the Ministry of Information

Commencement not set. Binds public and private bodies.

What this law does

Section 26 lets a data subject aggrieved by a violation of the Act lodge a complaint with the Office, which the Office admits where the complainant has an interest in the matter and the complaint is not frivolous or vexatious.

Section 27 lets the Office investigate on the basis of an admitted complaint or of its own accord where it has reason to believe a person has violated or is likely to violate the Act, with power to require attendance, documents, or a sworn statement, and, on a warrant from the appropriate court, to search premises or computer systems and seize items related to a suspected violation.

Section 28 lets the Office, after completing an investigation, issue a notice requiring a person within a specified period to stop or refrain from the violating act, compel a downstream processor to do the same, remedy the violation including compensating an affected data subject, or pay an administrative penalty not exceeding $100,000, proportionate to the violation's gravity and repetitive nature, the person's efforts to comply, any profits made, and the harm caused.

Section 29(1) makes it an offence, punishable by a fine not exceeding $100,000 and imprisonment not exceeding ten years or both, to fail to comply with a notice issued under section 27 or 28 that is not the subject of a duly made and ongoing appeal.

Section 30 lets an affected data subject, the subject of a section 28 notice, or another interested person apply to the appropriate court for judicial review of the notice within thirty days, and section 31 lets a data subject or a consumer organisation acting on their behalf recover damages in civil proceedings for injury, loss or harm caused by a violation, without duplicating compensation already ordered under a section 28 notice.

What it requires

Scraping law1 instrument, 1 enacted but not yet in force

Research summary (285 words)

Kiribati has no scraping-specific statute, so general law governs each dimension separately.

The Cybercrime Act 2021 criminalises unauthorised access to a computer system in broader terms than several neighbouring jurisdictions: section 7 makes access illegal or unauthorised whenever the accessing person is not entitled to control access of that kind and has not obtained the consent of a person who is so entitled, without requiring that the accessor infringe a technical security measure, so a plain reading does not rule out liability for reading a public, unauthenticated page if the site's operator can be shown not to have consented to that kind of access; no reported Kiribati case has tested the point either way.

No Kiribati court has ruled on the enforceability of a browsewrap or clickwrap terms-of-service against a scraper.

The Copyright Act 2018 lists exceptions to copyright infringement for quoting from a work and for copying to report current events to the public, among others, but the operative text of those exceptions is not reproduced in the available copies of the Act, so their specific conditions are not established here; Kiribati has not enacted a text-and-data-mining exception, and its copyright statute confers no sui generis database right, its neighbouring rights covering only performers, producers of sound recordings, and broadcasters.

The Data Protection Act 2025, which would apply Kiribati's first personal-data lawful-basis and purpose-limitation duties to scraped personal data, has passed only a first reading in Parliament and is not yet law, so no privacy-law duty currently reaches personal data scraped from a public Kiribati website.

No Kiribati statute or reported case establishes a scraping-specific unfair-competition, misappropriation, or trespass doctrine, and none assigns legal weight to a robots.txt directive or imposes an AI-training-specific rule.

Computer misuse

Cybercrime Act 2021, unauthorised access

Cybercrime Act 2021 (No. 10 of 2021), s. 7 (Unauthorised access)Official Act text published by the Ministry of Information, Communications and Transport

Commencement not set. Binds public and private bodies.

What this law does

Section 7 makes access of any kind to a computer program or computer data held in a computer system illegal or unauthorised if the accessing person is not entitled to control access of that kind and does not have the consent of a person who is so entitled. A person who knowingly, or recklessly and without authority, causes a computer system to perform a function to secure such access is liable on conviction to a fine not exceeding $10,000 or imprisonment not exceeding 7 years, or both.

The Act applies to an act or omission in Kiribati's territory, on a Kiribati-registered ship or aircraft, or to a Kiribati national's conduct outside Kiribati where that conduct would also be an offence where it occurred. A Cybercrime Unit within the Kiribati Police Service administers the Act. The Act was assented to by the Beretitenti and states that it commences on a date the Minister appoints by notice; no commencement notice has been located.

What it requires

Cybersecurity law2 instruments, 2 enacted but not yet in force

Research summary (617 words)

Kiribati enacted the Cybersecurity Act 2026 (Act No. 7 of 2026), passed by the Maneaba ni Maungatabu on 23 April 2026, alongside the Cybercrime Act 2021 (Act No. 10 of 2021) already documented under this jurisdiction's scraping-topic file for its unauthorised-access, interception, data- and system-interference offences and its investigatory production, preservation and interception-assistance duties on a person or service provider, all bound to a criminal investigation rather than to an operator's own security posture.

The Cybersecurity Act 2026 is the operator-facing instrument researched here.

It lets the Minister, on the advice of the Director of the Digital Transformation Office (DTO), designate a physical, electronic or virtual infrastructure asset, network or information system as critical infrastructure where it is essential for national security or for the population's economic and social well-being, on grounds naming electronic communications, banking and other financial services, electric power, water and wastewater, healthcare and public health, agriculture and food distribution, emergency services, fisheries, tourism and public transportation.

Once designated, the operator, defined broadly enough to reach an individual, a private entity, a public body, a state-owned enterprise or any other body, must register with the DTO, report a change of ownership or operator within 30 days, furnish information the DTO requires to assess the infrastructure's security, submit to cybersecurity standards, audits, inspections and penetration testing, conduct periodic assessments, appoint a Chief Information Security Officer, maintain and document risk-management and third-party and supply-chain risk policies, comply with a remedial-action order, and report a significant cybersecurity incident to the National CERT and any Sectoral CERT within 24 hours of detecting it.

This jurisdiction's Data Protection Act 2025 is a comprehensive data-protection statute whose own Part V (sections 18 to 20, headed Data Security and Personal Data Impact Assessments) carries the security-of-processing and breach-notification duties this topic's seam rule leaves with the privacy row, not restated here.

The Digital Government Act 2023 established an earlier National Computer Emergency Response Team confined to government systems and "public bodies", a government information-security programme of the kind this topic excludes; the Cybersecurity Act 2026 repeals its critical-digital-infrastructure and CERT provisions outright and supersedes them with the framework researched here.

No provision of the Foreign Investment Act 2018 is confirmed either way: no URL for the Act was located on the Ministry of Information, Communications and Transport's own site, and the Pacific Islands Legal Information Institute's Kiribati index answered every request with a Cloudflare CAPTCHA challenge, a stop rather than a wall to read past.

The Communications Act 2013, the sector's general telecommunications statute, part of which the Cybercrime Act 2021 already repeals (its own section 94 and Part XIV), is not read either: its PDF returns an HTTP 200 response that does not decode into text, so whether it separately obligates a licensed telecommunications operator to a network-security standard is not confirmed in the primary text.

No cybersecurity or IT-risk directive for a bank or other financial institution operating in Kiribati was located; Kiribati has no central bank of its own and its legal tender is the Australian dollar, and whether the Ministry of Finance and Economic Development or another body has issued such a directive is an open research gap rather than a confirmed absence.

The Cybersecurity Act 2026's own text carries two internal inconsistencies worth recording rather than silently resolving: its Explanatory Memorandum states penalty figures for the section 25 offence ($10,000 first offence, $20,000 subsequent, $100 per continuing day) ten times lower than the operative section itself ($100,000, $200,000, $200), and the Memorandum's own Part I summary calls the statute "the Cybersecurity Act 2025" once, against the Act's own title, arrangement of sections and Clerk's certification, which all read 2026 and carry Act No. 7 of 2026.

Sector security regimes

Cybersecurity Act 2026, Critical Infrastructure Operator Obligations

Cybersecurity Act 2026 (Act No. 7 of 2026), ss. 12-20, 22-23 (Parts V-VI)Official Act text (Cybersecurity Act 2026, Act No. 7 of 2026)

Commencement not set. Binds public and private bodies.

What this law does

Sections 12 to 15 of the Cybersecurity Act 2026 let the Minister, acting on the advice of the Director of the Digital Transformation Office (DTO), designate a physical, electronic or virtual infrastructure asset, network or information system as critical infrastructure where it is essential for national security or for the economic and social well-being of the population, on grounds naming electronic communications, banking and other financial services, electric power, water and wastewater, healthcare and public health, agriculture and food distribution, emergency services, fisheries, tourism and public transportation.

A designated operator, defined to include an individual, a private entity, a public body, a state-owned enterprise, or any other body that owns, operates, manages or controls the infrastructure or the information systems supporting it, must register with the DTO and notify it of any change of ownership or of the operating person or entity within 30 days.

The DTO may by written notice require the operator to furnish information it needs to assess the infrastructure's security and cybersecurity measures, and the operator must report a material change to the infrastructure's design, configuration, security or operation within 30 days of implementing it.

The DTO may issue cybersecurity standards for critical infrastructure and conduct or require periodic or ad hoc audits, inspections and penetration testing of it, and the operator must conduct and submit periodic cybersecurity assessments of the infrastructure's risk, vulnerability and preparedness to the DTO.

The operator must appoint a member of senior management as Chief Information Security Officer responsible for the operator's cybersecurity preparedness, monitoring, reporting and coordination with the DTO, and must develop, implement, communicate to staff and document technical and organisational policies, practices and processes to manage risk to its network and information infrastructure and to prevent, mitigate and remedy a cybersecurity incident.

The operator must also establish, implement and maintain a cybersecurity risk-management framework and take reasonable contractual, technical and organisational measures to manage cybersecurity risk arising from its third-party suppliers, service providers and contractors.

The operator must comply with an order the DTO, a Sectoral CERT, the Minister or a sector's regulatory authority makes to take preventative, mitigating or remedial action, and must tell the DTO where it cannot meet an obligation under this framework for financial, legal or technical reasons, which lets the Director grant an exception or modify a prescribed standard.

A failure to carry out an obligation under Parts IV or V, absent a granted exemption, is an offence under section 25, punishable on summary conviction by a fine of up to $100,000 for a first offence, up to $200,000 for a subsequent offence, and up to $200 for each day a continuing offence persists.

The Act's own Explanatory Memorandum states a materially lower set of figures for the identical offence, a fine of up to $10,000 for a first offence, up to $20,000 for a subsequent offence, and up to $100 for each day continuing, a discrepancy between the operative text and its own memorandum that is not resolved here.

What it requires

Vulnerability and incident reporting

Cybersecurity Act 2026, Duty to Report a Cybersecurity Incident

Cybersecurity Act 2026 (Act No. 7 of 2026), s. 21 (Part VI)Official Act text (Cybersecurity Act 2026, Act No. 7 of 2026)

Commencement not set. Binds public and private bodies.

What this law does

Section 21 requires an operator of critical infrastructure that is the subject of a cybersecurity incident or threat of one to gather information about it, including its nature and impact, and to assess the risk it poses to the critical infrastructure, customers, suppliers and other stakeholders.

The operator must take appropriate preventative, mitigating and remedial measures to limit that risk, and must report all material information about a significant cybersecurity incident to the National CERT and any relevant Sectoral CERT within 24 hours after the incident is detected, in a form or manner the CERT may prescribe.

The operator must provide any further information the National CERT or a Sectoral CERT requests about the incident, and must allow either CERT to access its network and information infrastructure to analyse the incident, detect other potential threats, identify vulnerabilities, and advise on preventative, mitigating or remedial measures.

A failure to report is enforced through the same section 25 offence as this jurisdiction's companion critical-infrastructure operator-obligations row, punishable on summary conviction by a fine of up to $100,000 for a first offence, up to $200,000 for a subsequent offence, and up to $200 for each day a continuing offence persists, though the Act's own Explanatory Memorandum states a materially lower set of figures for the identical offence.

What it requires

News aggregation law1 instrument, 1 enacted but not yet in force

Research summary (180 words)

Kiribati has no press-publisher neighbouring right and no mandatory platform-to-publisher bargaining code; the general copyright framework of the Copyright Act 2018 is the only law reaching an aggregator's reproduction of news content.

Its arrangement of sections names an exception to copyright infringement titled 'Quoting from work' at section 16, among several others running from sections 14 to 21, but the operative text of those sections is not reproduced in the available copies of the Act, so their specific conditions are not established here.

Neighbouring rights under Part III of the Act protect performers, producers of sound recordings, and broadcasters, not print or online news publishers, so there is no publisher-side neighbouring right of the kind the European Union's Digital Single Market Directive Article 15 creates.

No statute or case law addresses whether a hyperlink is itself a communication to the public, or whether framing or inline display changes the answer, and no hot-news or misappropriation doctrine distinct from ordinary copyright law exists. The Act predates the concept of a machine-readable text-and-data-mining reservation, so no opt-out mechanism of that kind exists.

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.