Comprehensive regime
Data Protection Act
Act 11 of 2011 (as amended by Act 2 of 2015), Laws of Saint Lucia, ss. 1-4, 32-34 and 39-43, Part 6 (ss. 58-68) and Schedule 2Data Protection Act No. 11 of 2011, Saint Lucia, full text of the Act as enacted
In force since 31 January 2023. Binds public and private bodies.
What this law does
Part 1 states the Act's preliminary provisions: section 3 applies it to a data controller established in Saint Lucia, or established elsewhere but using equipment in Saint Lucia to process data otherwise than in transit, and section 4 binds the State as well as private actors.
Section 33 bars a data controller from collecting personal data except for a lawful purpose connected with its function or activity where the collection is necessary for that purpose, and requires it to tell the data subject, at the point of collection, what is being collected, why, who will receive it, whether providing it is mandatory, the consequences of not providing it, and the subject's rights of access, correction and destruction.
Section 34 bars processing personal data without the data subject's express consent unless a listed ground applies, such as performing a contract with the subject, complying with a legal obligation, or a legitimate interest that does not override the subject's privacy rights, and lets the subject object to processing done on the public interest or legitimate interest grounds and revoke consent at any time.
Section 39 confines processing of data relating to offences, criminal convictions or security measures to the control of a public authority. Section 40 requires a data controller to keep personal data accurate and up to date. Section 41 requires personal data to be kept only for specified lawful purposes, not used or disclosed incompatibly with those purposes, kept adequate and relevant, and not retained longer than necessary.
Section 42 requires the data controller to take security measures appropriate to the risk of unauthorized access, alteration, or loss, having regard to the state of technology and the cost of the measures. Section 43 requires the data controller to destroy personal data once the purpose for holding it has lapsed. Schedule 2 restates these duties as eight Data Protection Principles.
Part 4, sections 46 to 51, would require a data controller to register with the Commissioner, maintain that registration, and hold a certificate the Commissioner issues, and it is enacted and not in force, as are Part 2 and Part 5.
Part 6 exempts a data controller from specified Principles and sections in listed cases, including national security, crime and taxation, health and social work, regulatory activities, journalism, research, information already public under another enactment, legal proceedings, legal professional privilege, domestic purposes, and Commissioner authorization, such as the section 64 exemption applying where the data controller is itself obliged under another enactment to make the information public.
The 2015 Act reworked four of these provisions: it replaced section 1(2) and added section 1(3) so the Minister may fix different dates for different Parts or sections, substituted the definition of data controller in section 2 and added a definition of privacy impact assessment, cut the penalty in section 34(5) to a fine alone by deleting the alternative of imprisonment, and replaced the domestic-purposes exemption in section 67.
What it requires