Law / Saint Lucia

Saint Lucia

7 of 9 named instruments researched to a stage, across three of the six areas of law we track: 4 in force and 3 enacted but not yet in force. As of 19 September 2026.

  1. AI law none researched
  2. Privacy law 5
  3. Scraping law 1
  4. Cybersecurity law none researched
  5. Age gating law none researched
  6. News aggregation law 1

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law5 instruments, 2 in force, 3 enacted but not yet in force

Research summary (241 words)

Saint Lucia's Data Protection Act (Act 11 of 2011, as amended by Act 2 of 2015) sets the country's general personal-data rules, and it is in force in part. Section 1 brings the Act into force on a day the Minister fixes by Order published in the Gazette, and the 2015 Act added a subsection letting the Minister fix different dates for different Parts or sections, which is the mechanism behind the partial commencement.

In force are the data-controller obligations of sections 32 to 43, the Part 6 exemptions, and the Data Protection Principles in Schedule 2; enacted and not in force are the Part establishing and empowering the Data Protection Commissioner, the registration scheme, the data-subject access and correction rights, the transfer restriction in section 45, and the Act's general offence and penalty provision.

A data controller's enforceable duties are therefore the consent, collection-notice, sensitive-data, accuracy, use-limitation, security, and destruction requirements of sections 32 to 43, backed by the fine section 34(5) sets for a consent breach, which the 2015 Act cut to a fine alone by deleting the alternative of imprisonment.

The Act's definition of personal data expressly includes an individual's fingerprints and DNA, though it does not list biometric data among the narrower sensitive personal data categories that carry heightened processing criteria. Saint Lucia publishes no consolidated text of the Act, so this corpus carries the 2011 Act as enacted and the 2015 amendment as two separate sources.

Comprehensive regime

Data Protection Act

Act 11 of 2011 (as amended by Act 2 of 2015), Laws of Saint Lucia, ss. 1-4, 32-34 and 39-43, Part 6 (ss. 58-68) and Schedule 2Data Protection Act No. 11 of 2011, Saint Lucia, full text of the Act as enacted

In force since 31 January 2023. Binds public and private bodies.

What this law does

Part 1 states the Act's preliminary provisions: section 3 applies it to a data controller established in Saint Lucia, or established elsewhere but using equipment in Saint Lucia to process data otherwise than in transit, and section 4 binds the State as well as private actors.

Section 33 bars a data controller from collecting personal data except for a lawful purpose connected with its function or activity where the collection is necessary for that purpose, and requires it to tell the data subject, at the point of collection, what is being collected, why, who will receive it, whether providing it is mandatory, the consequences of not providing it, and the subject's rights of access, correction and destruction.

Section 34 bars processing personal data without the data subject's express consent unless a listed ground applies, such as performing a contract with the subject, complying with a legal obligation, or a legitimate interest that does not override the subject's privacy rights, and lets the subject object to processing done on the public interest or legitimate interest grounds and revoke consent at any time.

Section 39 confines processing of data relating to offences, criminal convictions or security measures to the control of a public authority. Section 40 requires a data controller to keep personal data accurate and up to date. Section 41 requires personal data to be kept only for specified lawful purposes, not used or disclosed incompatibly with those purposes, kept adequate and relevant, and not retained longer than necessary.

Section 42 requires the data controller to take security measures appropriate to the risk of unauthorized access, alteration, or loss, having regard to the state of technology and the cost of the measures. Section 43 requires the data controller to destroy personal data once the purpose for holding it has lapsed. Schedule 2 restates these duties as eight Data Protection Principles.

Part 4, sections 46 to 51, would require a data controller to register with the Commissioner, maintain that registration, and hold a certificate the Commissioner issues, and it is enacted and not in force, as are Part 2 and Part 5.

Part 6 exempts a data controller from specified Principles and sections in listed cases, including national security, crime and taxation, health and social work, regulatory activities, journalism, research, information already public under another enactment, legal proceedings, legal professional privilege, domestic purposes, and Commissioner authorization, such as the section 64 exemption applying where the data controller is itself obliged under another enactment to make the information public.

The 2015 Act reworked four of these provisions: it replaced section 1(2) and added section 1(3) so the Minister may fix different dates for different Parts or sections, substituted the definition of data controller in section 2 and added a definition of privacy impact assessment, cut the penalty in section 34(5) to a fine alone by deleting the alternative of imprisonment, and replaced the domestic-purposes exemption in section 67.

What it requires

Cross border transfer

Data Protection Act, transfer of personal data

Act 11 of 2011, s. 45 (transfer of personal data)Data Protection Act No. 11 of 2011, Saint Lucia, full text of the Act as enacted

Commencement not set. Binds public and private bodies.

What this law does

Section 45 would bar a data controller from transferring personal data to a country or territory outside Saint Lucia unless the receiving country or territory has comparable safeguards to those in Saint Lucia and the Commissioner has authorized the transfer, subject to exceptions where the data subject consents, the transfer is necessary for a contract with or requested by the data subject, it is necessary to safeguard national security, it concerns public security, or the Commissioner approves the transfer's terms as adequately safeguarding the data subject's rights.

Section 45 sits at the end of Part 3 alongside the data-controller obligations, and it is enacted and not in force, so no transfer condition binds a data controller today. Schedule 2's Eighth Principle, the Transfer of Data Principle, restates the same rule by reference to section 45. The 2015 Act left both untouched.

What it requires

Data subject rights

Data Protection Act, rights of data subjects and others

Act 11 of 2011, ss. 52-57A (rights of data subjects)Data Protection Act No. 11 of 2011, Saint Lucia, full text of the Act as enacted

Commencement not set. Binds public and private bodies.

What this law does

Part 5 of the Act, sections 52 to 57A, would give a data subject or relevant person acting for them a right to access personal data a data controller holds, requiring the controller on written request to disclose whether it holds personal data about the person, describe it, state the purposes and source of processing, explain any automated-processing logic involved, name the recipients, and permit examination or supply a copy on payment of the prescribed fee, in an alternative format where the person has a sensory disability.

Sections 53 to 55 would govern how a data controller complies with an access request, the discretion available to it, and the grounds on which access may be denied. Section 56 would give a right of rectification of inaccurate personal data, and section 57 would give a right to prohibit processing of personal data for direct marketing.

Section 57A, which shields an employee who reports a contravention of the Act to the Commissioner from dismissal or other detriment, is not in the 2011 Act: the 2015 Act inserted it. That Act also added a subsection to section 54, requiring a data controller who does not comply with an access request to notify the Commissioner and the person who made it.

The whole of Part 5 is enacted and not in force, so a data subject's access, rectification, direct-marketing-objection and employee-protection rights do not bind a data controller today. Section 64 reaches Part 5 even so, exempting information a data controller is obliged under another enactment to make public from Part 5 in respect of blocking personal data.

What it requires

Enforcement supervision

Data Protection Act, Commissioner, offences and penalties

Act 11 of 2011, ss. 5-31 and 69-74 (Commissioner, offences and penalties)Data Protection Act No. 11 of 2011, Saint Lucia, full text of the Act as enacted

Commencement not set. Binds public and private bodies.

What this law does

Part 2, sections 5 to 31, would establish a Data Protection Commissioner with functions including maintaining a register of data controllers and of processing operations, verifying compliance on the Commissioner's own motion or a data subject's request, investigating complaints, issuing information notices and enforcement notices, and referring matters to the Director of Public Prosecutions.

Part 7, sections 69 to 74, would give a right of appeal to the Court, and section 71 would make contravening the Act an offence carrying, where no specific penalty is provided, a fine of up to $10,000 for an individual or $100,000 for a body corporate. Both Parts are enacted and not in force, so Saint Lucia has no operating Data Protection Commissioner and the Act's general offence and penalty provision does not bind.

The one penalty in force sits inside the commenced consent duty rather than in Part 7: section 34(5) makes a data controller who contravenes the consent requirement in section 34 liable, on summary conviction, to a fine not exceeding $25,000. The 2015 Act deleted the alternative of imprisonment from that penalty and from the general penalty in section 71(2)(a), leaving both as fines alone.

The same Act inserted section 12A, which lets the Commissioner require a department of government to prepare a privacy impact assessment and submit it for approval. Section 44, titled Unlawful disclosure of personal data, sits in Part 3 alongside the data-controller obligations but is, like section 45, enacted and not in force.

What it requires

Sensitive categories

Data Protection Act, sensitive personal data

Act 11 of 2011, ss. 35-38 (sensitive personal data)Data Protection Act No. 11 of 2011, Saint Lucia, full text of the Act as enacted

In force since 31 January 2023. Binds public and private bodies.

What this law does

Section 35 bars processing sensitive personal data (racial or ethnic origin, political opinion, religious belief, physical or mental health, sexual orientation, or criminal or financial record) except under the grounds section 34(2) and sections 36 to 38 provide, in regulations the Minister prescribes having regard to the public interest, or where the data subject has given explicit consent or has already published the data.

Section 36 lets a data controller process sensitive personal data with appropriate safeguards where necessary to exercise or perform a right or obligation the law imposes on it, to protect the vital interests of the data subject or another person where consent cannot be obtained, or to protect another person's vital interests where the data subject's consent has been unreasonably withheld.

Section 37 lets a health practitioner or another person under a professional confidentiality obligation process sensitive personal data for preventive medicine and the protection of public health, medical diagnosis, medical research, or management of health and hospital care services. The 2015 Act put medical research on that list, in place of health care or treatment.

The same Act added a subsection giving way to another enactment that specifically governs the processing of sensitive personal data for health purposes where the two are inconsistent.

Section 38 lets a data controller process or disclose sensitive personal data for research, including statistical research, only where the research purpose cannot reasonably be accomplished without individually identifiable data, the data will not be used to contact a person to participate in research, any record linkage is not harmful to the data subject, and the responsible officer has approved conditions on security and destruction of identifiers, with the recipient signing an agreement to comply with those conditions.

Section 64 additionally exempts information a data controller is obliged under another enactment to make public from sections 34, 35, 40, 41, 42, 43 and 44 and from Part 5 in respect of blocking personal data.

What it requires

Scraping law1 instrument, 1 in force

Research summary (259 words)

Saint Lucia has no scraping-specific statute, so general law governs each dimension separately.

The Computer Misuse Act (Act 12 of 2011) criminalises unauthorised access to, interception of, and modification of computer data, but each offence turns on the access, interception, or modification being unauthorised or effected without authority, so a scraper reading a public, unauthenticated page without defeating any access control falls outside a plain reading of these provisions, and no reported Saint Lucian case has tested the point.

No Saint Lucian court has ruled on the enforceability of a browsewrap or clickwrap terms-of-service against a scraper, and no statute addresses the question.

The Copyright Act (Act 10 of 1995, as amended by Act 7 of 2000) permits fair dealing for research or private study and for criticism, review, or reporting current events, but Saint Lucia has not enacted a text-and-data-mining exception, so training a model on scraped copyrighted text rests only on the general fair-dealing grounds if the use can be characterised as research or private study, and the Act confers no sui generis database right.

The Data Protection Act (Act 11 of 2011, as amended) applies to personal data with no general carve-out for information that is already publicly accessible, so scraping personal data from a public Saint Lucian website engages the Act's consent, purpose-limitation and security duties to the extent those provisions have been brought into force.

No Saint Lucian statute or reported case establishes a scraping-specific unfair-competition, misappropriation, or trespass doctrine, and none assigns legal weight to a robots.txt directive or imposes an AI-training-specific rule.

Computer misuse

Computer Misuse Act, unauthorized access, interception and modification

Act 12 of 2011, Laws of Saint Lucia, ss. 5, 7 and 8 (unauthorized access, interception and modification)Official Act text, Revised Laws of Saint Lucia (2023 Revised Edition), Attorney General's Chambers

In force since 6 July 2018. Binds public and private bodies.

What this law does

Section 5 prohibits knowingly and without lawful authority causing a computer system to perform a function to secure access to a program or data. Section 7 prohibits, by any means and knowingly, securing access without authority to obtain a computer service, or intercepting without authority any function of or data within a computer system.

Section 8 prohibits knowingly causing an unauthorized modification of data held in a computer system, including to impair the system's operation, hinder access to a program or data, or impair the reliability of data.

Each offence carries a graduated fine, rising for a second or subsequent offence and rising further where the computer system was damaged, impaired, or its data suppressed or modified, up to $50,000 and 18 months' imprisonment; because the trigger for each offence is that the access, interception, or modification be unauthorized or without authority, a scraper reading a public, unauthenticated page without defeating any access control or exceeding a granted authorization falls outside a plain reading of these provisions.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (129 words)

Saint Lucia has no press-publisher neighbouring right, no mandatory platform-to-publisher bargaining regime, and no text-and-data-mining opt-out framework; no Saint Lucian statute or reported case addresses hot-news misappropriation or the liability of hyperlinking or framing third-party journalism.

The Copyright Act (Act 10 of 1995, as amended by Act 7 of 2000) is the only instrument bearing on how an aggregator may reproduce a headline or snippet of another's reporting: fair dealing for the purpose of criticism, review, or reporting current events does not infringe copyright provided the use is accompanied by a sufficient acknowledgement, and a court weighing fair dealing must consider the nature of the work, the extent and substantiality of the part used relative to the whole, and the effect on the work's potential market or commercial value.

Snippet reproduction

Copyright Act, fair dealing for criticism, review and reporting current events

Act 10 of 1995 (as amended by Act 7 of 2000), Laws of Saint Lucia, ss. 3, 55-57Official Act text, Revised Laws of Saint Lucia (2023 Revised Edition), Attorney General's Chambers

In force since 1 October 1996. Binds public and private bodies.

What this law does

Section 56 provides that fair dealing with a work for the purpose of criticism or review, or for reporting current events, does not infringe copyright provided it is accompanied by a sufficient acknowledgement, except that no acknowledgement is required where the reporting is by sound recording, film, broadcast, or cable programme. Section 55 separately permits fair dealing for research or private study.

Section 57 directs a court determining whether an act is fair dealing to weigh the nature of the work, the extent and substantiality of the part used relative to the whole, and the effect of the use on the potential market for or commercial value of the work. Section 3 binds the Crown. The Act creates no press-publisher neighbouring right, no compelled-bargaining regime, and no text-and-data-mining exception, and no provision addresses hyperlinking or framing a third party's content.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.