Law / Saint Kitts and Nevis

Saint Kitts and Nevis

9 of 10 named instruments researched to a stage, across four of the six areas of law we track: 5 in force and 4 enacted but not yet in force. As of 19 September 2026.

  1. AI law 1
  2. Privacy law 4
  3. Scraping law 3
  4. Cybersecurity law none researched
  5. Age gating law none researched
  6. News aggregation law 1

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law1 instrument, 1 in force

Research summary (281 words)

Saint Kitts and Nevis has no AI-transparency, AI-risk-obligations, AI-training-data, AI-governance or AI-sector-rules statute, bill or regulation.

The Electronic Crimes Act (Cap. 4.41; Act 27 of 2009) bans, in its current numbering, publishing, producing for publication, or possessing for publication child pornography, defined to include a visual depiction of a person who appears to be a minor or a realistic image representing a minor engaged in sexually explicit conduct, a definition wide enough to reach a computer-generated or AI-synthesised depiction that shows no real child and binding on any person; a footnote to the current section records that it was renumbered by Act 26 of 2012, which repealed the original section 12 and renumbered the former sections 13 and 14, and whether the definition's wording was itself changed at that time is not established in the available sources.

The Electronic Transactions Act, 2011 recognises that a contract can form through the acts of an 'electronic agent', a program or automated means a person configures to initiate or respond to an electronic record without individual review, and attributes such a transaction back to the person who deployed it, but it imposes no duty to disclose to a counterparty that they are dealing with an automated system, so it establishes no AI-transparency duty and is not recorded here; the same statute's unauthorised-access provisions are recorded under the scraping topic.

The Consumer Protection Act, 2023 (No. 21 of 2023) imposes general trade-practice, pricing-disclosure and product-safety duties on a supplier, read across its unfair-practice, misleading-representation and distance-selling provisions, but contains no reference to artificial intelligence, automated decision-making or a duty to disclose that a person is interacting with a bot, so it creates no AI-specific duty.

AI prohibited practices

Electronic Crimes Act, child pornography, including computer-generated depictions

Electronic Crimes Act (Cap. 4.41; Act 27 of 2009), s. 12 (Child pornography)Electronic Crimes Act

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived November 6, 2023. Publisher's page: https://lawcommission.gov.kn/wp-content/documents/Act17TOC/Ch-04_41-Electronic-Crimes-Act.pdf

In force since 26 November 2009. Binds public and private bodies.

What this law does

Section 12 makes it an offence for a person to knowingly publish child pornography through a computer system, produce it for the purpose of publication through a computer system, or possess it in a computer system or on a data storage medium for the purpose of publication, punishable on conviction on indictment by a fine of up to fifty thousand dollars or five years' imprisonment for an individual, or a fine of up to two hundred and fifty thousand dollars for a corporation.

Section 12(3) defines child pornography to include material that visually depicts a minor engaged in sexually explicit conduct, a person who appears to be a minor engaged in sexually explicit conduct, or a realistic image representing a minor engaged in sexually explicit conduct, a definition that does not require the depicted subject to be a real, identifiable child, so a wholly computer-generated or AI-synthesised depiction meeting it can fall within the ban.

A defence applies to publishing and possession, but not to production, where the material was for a bona fide scientific, research, medical or law enforcement purpose.

A note in the Revised Laws text records that the current section 12 was formerly section 13, the original section 12 having been repealed and sections 13 and 14 renumbered by Act 26 of 2012; whether the child-pornography definition's own wording changed at that renumbering, or was carried forward unchanged from the Act's original 2009 text, is not established in the available sources.

What it requires

Privacy law4 instruments, 4 enacted but not yet in force

Research summary (163 words)

Saint Kitts and Nevis's only comprehensive personal-data statute, the Data Protection Act, 2018 (No. 5 of 2018), regulates the collection, processing and storage of personal data by public and private bodies, but under its own section 1(2) the Act comes into force only on a day fixed by Ministerial order published in the Gazette, and no such order has been located, so its substantive duties are not yet operative.

The Act now files as four provision-scoped instruments: the omnibus regime, covering application, consent, notice, disclosure, security, retention, data integrity and exemptions, processing of sensitive personal data, the rights of data subjects, and the Information Commissioner, enforcement and offences. The Act contains no express cross-border-transfer regime and no express duty to notify the regulator or a data subject of a data breach.

The jurisdiction's Electronic Transactions Act, 2011, read for its definitions, contract-formation, attribution and certification-provider provisions, does not use the term personal data anywhere in its text and creates no separate personal-data duty.

Comprehensive regime

Data Protection Act, 2018

Saint Christopher and Nevis Data Protection Act, 2018 (No. 5 of 2018), ss. 1-12, 19 and 21-22Data Protection Act, 2018 (No. 5 of 2018), Saint Kitts and Nevis Law Commission text, preserved on archive.org

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived July 25, 2024. Publisher's page: https://lawcommission.gov.kn/wp-content/documents/Annual-Laws/2018/ACTs/Act-5-of-2018-Data-Protection-Act-2018.pdf

Commencement not set. Binds public and private bodies.

What this law does

Section 4 applies the Act to a private body processing personal data in respect of commercial transactions, and to any other person meeting a territorial nexus test tied to establishment in Saint Christopher and Nevis or use of equipment there. Section 6 binds the State. Section 7(1) requires a data user to obtain a data subject's consent before processing personal data other than sensitive personal data, or to process sensitive personal data only in accordance with section 20.

Section 7(2) lets a data user process personal data without consent where necessary for a contract, a legal obligation other than a contractual one, the vital interests of the data subject, the administration of justice, or a function conferred by law, and section 7(3) requires the processing to be for a lawful purpose directly related to the data user's activity, necessary for or directly related to that purpose, and adequate but not excessive.

Section 8 requires a data user, on a request for personal data, to tell the data subject the purposes of collection, the source of the data where available, the right to request access and correction, the classes of third party to whom it may be disclosed, and whether supplying the data is obligatory or voluntary.

Section 9 bars disclosure of personal data without the data subject's consent for a purpose other than the one it was collected for or a directly related purpose, or to a class of third party not specified under section 8(d). Section 19 lists the circumstances, including the data subject's consent, crime prevention or detection, legal authorisation, and the public interest, in which such a further disclosure is permitted.

Section 10 requires a data user to take practical steps to protect personal data from loss, misuse, unauthorised access, alteration or destruction, and requires a data processor engaged by the data user to give sufficient security guarantees and to comply with them. Section 11 bars keeping personal data longer than the purpose requires and requires a data user to take reasonable steps to destroy or permanently delete personal data no longer needed.

Section 12 requires a data user to take reasonable steps to keep personal data accurate, complete, not misleading and up to date.

Section 21 exempts personal data processed for an individual's own personal, family or household affairs from the Act entirely, and, subject to listed conditions, exempts data processed for crime prevention or detection, taxation, statistics or research, a court order or judgment, regulatory functions, or journalistic, literary or artistic purposes from some or all of the Act's other principles.

Section 1(2) provides that the Act comes into force on a day fixed by the Minister by Order published in the Gazette, and no commencement order has been located, so the Act's substantive duties are not yet confirmed to be in operation.

What it requires

Data subject rights

Data Protection Act, 2018, rights of data subjects

Data Protection Act, 2018, ss. 13-18 (rights of data subjects)Data Protection Act, 2018 (No. 5 of 2018), Saint Kitts and Nevis Law Commission text, preserved on archive.org

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived July 25, 2024. Publisher's page: https://lawcommission.gov.kn/wp-content/documents/Annual-Laws/2018/ACTs/Act-5-of-2018-Data-Protection-Act-2018.pdf

Commencement not set. Binds public and private bodies.

What this law does

Section 13 gives a data subject the right to be given access to their personal data held by a data user and to have it corrected where inaccurate, incomplete, misleading or out of date, except where an access or correction request is refused under the Act.

Section 14 requires a public body or private body, on a data subject's written request and payment of the prescribed fee, to confirm whether it holds their personal data and, if so, to describe the data, the purposes of processing, the recipients, and the source of the data.

Section 15 requires the body to give written notice of its access decision within thirty days of the request, extendable by up to thirty days in the listed circumstances, and gives the data subject a right to complain to the Information Commissioner about an extension.

Section 16 lets a body refuse an access request only where it lacks information to identify the requester or locate the data, where compliance would breach a Part IV exemption or a duty of confidentiality, where another identifiable individual has not consented to disclosure, or where the Information Commissioner has not approved the refusal in writing, and gives the data subject a right to complain to the Information Commissioner about a refusal.

Section 17 lets the data subject examine the personal data or obtain a copy, and requires an alternative format for a data subject with a sensory disability where practicable.

Section 18 gives a data subject the right to apply in writing for rectification of personal data they claim is incomplete, incorrect, misleading, excessive, or irrelevant, requires the body to amend the data once satisfied of the claim, and gives a right to complain to the Information Commissioner within twenty eight days of a refusal.

What it requires

Enforcement supervision

Data Protection Act, 2018, Information Commissioner, enforcement and offences

Data Protection Act, 2018, ss. 23-38 (Information Commissioner, enforcement and offences)Data Protection Act, 2018 (No. 5 of 2018), Saint Kitts and Nevis Law Commission text, preserved on archive.org

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived July 25, 2024. Publisher's page: https://lawcommission.gov.kn/wp-content/documents/Annual-Laws/2018/ACTs/Act-5-of-2018-Data-Protection-Act-2018.pdf

Commencement not set. Binds public and private bodies.

What this law does

Sections 23 and 24 make the Information Commissioner the officer appointed under section 35 of the Freedom of Information Act, and give the Information Commissioner functions including monitoring compliance, advising public and private bodies, receiving and investigating complaints, and conducting research and education.

Section 25 lets the Information Commissioner investigate, on a data subject's complaint or on the Commissioner's own initiative, whether a public body or private body has contravened the Act, and requires the Commissioner to notify the data subject of the decision and their right of appeal to the Court. Section 28 lets the Information Commissioner serve an information notice requiring a person to furnish access to personal data, documentation of its processing, or information about its security.

Section 30 lets the Information Commissioner serve an enforcement notice on a body that has contravened or is contravening a provision of the Act whose contravention is an offence, specifying the steps required and the time to take them, including rectifying or erasing personal data, and requires the body to notify the data subject and, where reasonably practicable, anyone the data was disclosed to in the twelve months before the notice, within thirty days of complying if compliance materially modifies the data.

Section 31 lets the Information Commissioner assess a body's processing on request or at the Commissioner's own discretion, and report non-compliance to the body with recommendations. Section 32 lets a data subject who suffers damage from a body's contravention of the Act bring civil proceedings in the Court, subject to a defence that the body took reasonable care to comply.

Section 33 makes it an offence, carrying a fine not exceeding five thousand dollars or imprisonment not exceeding six months, to obstruct the Information Commissioner or an authorised officer. Section 34 bars an employer from dismissing, suspending, demoting, disciplining, harassing, disadvantaging, or denying a benefit to an employee for reporting or refusing to participate in a contravention of the Act in good faith.

Section 35 makes it an offence to wilfully disclose personal information in contravention of the Act, or to collect, store, or dispose of personal information in a manner that contravenes the Act, and section 36 makes it an offence to breach the whistleblower confidentiality obligation section 34 establishes. Section 37 makes an officer, director, or agent of a corporation who directed, authorised, assented to, or participated in an offence the corporation committed a party to that offence.

Section 38 sets the residual penalty for an offence with no penalty otherwise specified at, for an individual, a fine of not more than fifty thousand dollars or imprisonment of three years on summary conviction, or one hundred thousand dollars or five years on indictment, and for a body corporate, two hundred and fifty thousand dollars on summary conviction or five hundred thousand dollars on indictment.

What it requires

Sensitive categories

Data Protection Act, 2018, processing of sensitive personal data

Data Protection Act, 2018, s. 20 (processing of sensitive personal data)Data Protection Act, 2018 (No. 5 of 2018), Saint Kitts and Nevis Law Commission text, preserved on archive.org

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived July 25, 2024. Publisher's page: https://lawcommission.gov.kn/wp-content/documents/Annual-Laws/2018/ACTs/Act-5-of-2018-Data-Protection-Act-2018.pdf

Commencement not set. Binds public and private bodies.

What this law does

Section 2 defines sensitive personal data as information about a data subject's physical or mental health or condition, sexual orientation, political opinions, religious or similar beliefs, or the commission or alleged commission of an offence, or any other personal data the Minister determines by order published in the Gazette. Section 20(1) bars a data user from processing sensitive personal data of a data subject except in accordance with the listed conditions.

Section 20(1)(a) permits processing on the data subject's explicit consent, and section 20(1)(b) permits it where necessary for an employment right or obligation, to protect the vital interests of the data subject or another person where consent cannot be given or has been unreasonably withheld, for medical purposes undertaken by a healthcare professional or someone under an equivalent duty of confidentiality, for legal proceedings or advice, for establishing or defending legal rights, for the administration of justice, for a function conferred by law, or for any other purpose the Minister thinks fit.

Section 20(1)(c) also permits processing where the data subject has deliberately made the information public. Section 20(3) makes unlawful processing of sensitive personal data an offence carrying a fine not exceeding two hundred thousand dollars or imprisonment not exceeding two years, or both.

What it requires

Scraping law3 instruments, 3 in force

Research summary (319 words)

Saint Kitts and Nevis has no scraping-specific statute, so general law governs each dimension separately.

The Electronic Crimes Act (Cap. 4.41; Act 27 of 2009, as amended by Act 26 of 2012) criminalises accessing the whole or part of a computer system without lawful excuse or justification, a test that does not on its face require defeating a technical access control, so whether reading a public, unauthenticated page falls inside or outside it is less settled than in a jurisdiction whose offence is expressly limited to infringing a security measure; no reported case construes the point.

The Electronic Transactions Act, 2011 (Cap. 18.44) confirms that a contract may be formed by an act such as clicking an icon on a webpage, so clickwrap acceptance of terms is a recognised route to contract formation, but its text does not separately address whether a browsewrap notice, without an affirmative click, binds a scraper who never accepted it.

The Copyright Act, 2024 (No. 14 of 2024) protects a compilation of data as a literary work only where its selection or arrangement is the author's own intellectual creation, and expressly does not extend protection to the underlying data, so there is no sui generis database right; its general fair-dealing exceptions (research, private study, criticism, review, reporting, non-commercial user-generated content, private use, backup, incidental inclusion, temporary reproduction) do not include a text-and-data-mining ground, so no text and data mining (TDM) exception or machine-readable opt-out exists.

The Data Protection Act, 2018, once in force, would reach personal data scraped from a public web page because its definition of personal data and its general processing principles carry no publicly-available carve-out, but that duty attaches to the data rather than to the act of scraping and is researched under the privacy topic.

No Kittitian or Nevisian statute or reported case establishes a scraping-specific unfair-competition, misappropriation or trespass doctrine, or assigns legal weight to a robots.txt directive or imposes an AI-training-specific rule.

Computer misuse

Electronic Crimes Act, illegal access and related computer-misuse offences

Electronic Crimes Act (Cap. 4.41; Act 27 of 2009, as amended by Act 26 of 2012), ss. 4, 5, 6, 11Electronic Crimes Act

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived November 6, 2023. Publisher's page: https://lawcommission.gov.kn/wp-content/documents/Act17TOC/Ch-04_41-Electronic-Crimes-Act.pdf

In force since 26 November 2009. Binds public and private bodies.

What this law does

Section 4 makes it an offence to knowingly access the whole or part of a computer system without lawful excuse or justification, or in excess of one, punishable on summary conviction by a fine of up to five thousand dollars or one year's imprisonment for a first conviction, rising to ten thousand dollars or two years for a subsequent one. Sections 5 and 6 similarly criminalise interfering with data and interfering with a computer system.

Section 11 creates a heavier offence, up to seventy-five thousand dollars or five years for gaining access to a restricted computer system (one the Minister has designated by Order), rising to one hundred thousand dollars or seven years where the access occurs in the course of an offence under sections 4 to 7.

Unlike a computer-misuse offence conditioned on infringing a security measure, section 4's trigger is accessing a system without lawful excuse or justification, which does not by its own terms require circumventing a technical control, so whether reading a public, unauthenticated page falls inside or outside a plain reading of the section is less clear-cut than in a jurisdiction with an explicit security-measure element, and no reported Kittitian or Nevisian case construes the point.

What it requires

Contract terms of service (ToS)

Electronic Transactions Act, formation and validity of contracts

Electronic Transactions Act (Cap. 18.44; Act 9 of 2011), s. 16 (Formation and validity of contracts)Electronic Transactions Act

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived November 6, 2023. Publisher's page: https://lawcommission.gov.kn/wp-content/documents/Act17TOC/Ch-18_44-Electronic-Transactions-Act.pdf

In force since 14 April 2011. Binds public and private bodies.

What this law does

Section 16(1) provides that, unless the parties otherwise agree, an offer and its acceptance may be expressed by an act intended to result in an electronic communication, such as touching or clicking an appropriate icon on a webpage, confirming that a clickwrap acceptance of terms can validly form a contract.

Section 16 does not separately address whether a browsewrap notice, posted without requiring an affirmative click, is enforceable against a person who never accepted it, and no reported case construes that question in this jurisdiction.

Section 17 attributes an electronic record to its originator where it was sent by a person the originator authorised, or by the originator's own 'electronic agent', a program or automated means configured by that person to initiate or respond to an electronic record without individual review.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (197 words)

Saint Kitts and Nevis has no press-publisher neighbouring right and no mandatory platform-to-publisher bargaining code; the general copyright framework of the Copyright Act, 2024 (No. 14 of 2024) is the only law reaching an aggregator's reproduction of news content.

Its criticism, review and reporting exception permits fair dealing with a work for the purpose of criticism or review, or for reporting current events other than by means of a photograph, so long as it is accompanied by sufficient acknowledgment, but the Act carries no headline-length or short-extract cap distinct from the fair-dealing test in section 55 and no reported Kittitian or Nevisian decision applies it to a systematic news aggregator rather than an individual quoting a published work.

No statute or reported case addresses whether a hyperlink is a communication to the public, or whether framing or inline display changes the answer, and no hot-news or misappropriation doctrine distinct from ordinary copyright law exists.

The Act's fair-dealing exceptions are each tied to a listed purpose (research, private study, criticism, review, reporting, non-commercial user-generated content, private use, backup, incidental inclusion, temporary reproduction), none of which is a text-and-data-mining ground, so no text and data mining (TDM) exception or machine-readable opt-out mechanism exists.

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.