Law / Marshall Islands

Marshall Islands

5 of 7 named instruments researched to a stage, across two of the six areas of law we track: 5 in force. As of 19 September 2026.

  1. AI law none researched
  2. Privacy law 3
  3. Scraping law none researched
  4. Cybersecurity law 2
  5. Age gating law none researched
  6. News aggregation law none researched

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law3 instruments, 3 in force

Research summary (323 words)

The Marshall Islands enacted its first personal-data statute, the Personal Data Protection Act 2025 (6 MIRC Ch. 4), which commenced on 7 October 2025 and applies to core Government ministries and agencies that collect, use, store, process, disclose, or transfer the personal data of natural persons, including a third party acting as a data controller or data processor on such a ministry's or agency's behalf.

Its principles engage the comprehensive-regime family (purpose limitation, minimization, accuracy, retention, security, and accountability), and its administration, remedies, reporting, and complaints provisions separately engage the enforcement-and-supervision family: the Economic Policy, Planning and Statistics Office is the competent authority, a person residing in the Republic may sue a ministry or agency for improper administration though not for compensatory damages against the ministry or agency itself, and may separately sue an offending employee personally for compensatory damages.

The Act states no consent requirement, no heightened rule for sensitive or biometric data beyond naming them in a definition, no data-subject access, correction, deletion, or portability right, no cross-border transfer restriction, and no breach-notification duty, and it excludes law-enforcement and national-security processing, non-personal data, and publicly available information.

No statute extends a comparable duty to a private-sector controller or processor acting outside a government engagement.

Section 250.12 of the Criminal Code of the Republic of the Marshall Islands 2011 (31 MIRC Ch. 1) separately makes it a misdemeanor for any person to trespass with intent to eavesdrop or surveil, to install a device to observe or record in a private place without consent, to intercept a private telephone, facsimile, electronic-mail, or letter communication without the sender's or receiver's consent, or to divulge such a message knowing it was illegally intercepted; an enforcement-and-supervision offence that is the Republic's closest general privacy protection reaching private parties.

Article II of the Constitution of the Republic of the Marshall Islands protects personal autonomy and privacy against government intrusion but states no operative duty of its own.

Comprehensive regime

Personal Data Protection Act 2025, government personal-data protection principles

Personal Data Protection Act 2025, 6 MIRC Ch. 4 (P.L. 2025-43), ss. 401-405, 409, 415, 418Marshall Islands Revised Code, 6 MIRC Ch. 4 (Personal Data Protection Act 2025), archived capture of the certified text

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2026. Publisher's page: https://www.rmiparliament.org/cms/images/LEGISLATION/PRINCIPAL/2025/2025-0043/2025-0043_1.pdf

In force 12 months, effective 7 October 2025. Binds government bodies.

What this law does

Sections 401 to 405 apply this Chapter to core Government ministries and agencies of the Republic that collect, use, store, process, disclose, or transfer personal data of natural persons, and their definitions of data controller and data processor extend to a third party acting on behalf of such a ministry or agency; the Chapter excludes processing for law enforcement or national intelligence and national security purposes, non-personal data, and publicly available information lawfully obtained from government records, voluntarily made available by the data subject without audience restriction, or otherwise lawfully obtained, truthful, and a matter of public concern.

Section 409 sets six personal data protection principles binding core Government ministries and agencies: a legitimate-purpose principle requiring lawful, fair, transparent processing for specified purposes; a data-minimization principle limiting collection to what the purpose requires; an accuracy principle requiring inaccurate personal data to be corrected or deleted without delay; a retention principle limiting storage to what the purpose requires; an integrity and security principle requiring technical and organizational protection against unauthorized or unlawful processing and unintentional loss, destruction, or damage, and limiting staff access to what their duties need; and an accountability principle making the data controller responsible for demonstrating compliance.

Section 415 lets core Government ministries and agencies voluntarily share personal data with each other under a safe harbor, provided the sharing serves a legitimate function of each ministry or agency and complies with the section 409 principles, and lets the competent authority set standards for such sharing agreements.

Section 418 states the Chapter takes effect twelve months after the date of its certification under Article IV, section 21 of the Constitution, which the Act's own commencement note records as 7 October 2025. The Act states no consent requirement, no data-subject access, correction, deletion, or portability right, no heightened rule for sensitive or biometric data beyond the definition, and no cross-border transfer restriction.

What it requires

Enforcement supervision

Criminal Code 2011, Violation of Privacy (unlawful eavesdropping, surveillance, and breach of privacy of messages)

Criminal Code 2011, 31 MIRC Ch. 1, sec. 250.12Marshall Islands Revised Code, 31 MIRC Ch. 1 (Criminal Code of the Republic of the Marshall Islands 2011), archived consolidated text

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2020. Publisher's page: https://www.paclii.org/mh/legis/consol_act/cc201194/

In force since 17 October 2011. Binds public and private bodies.

What this law does

Section 250.12(1) makes it a misdemeanor, except as authorized by law, to trespass on property with intent to subject anyone to eavesdropping or other surveillance in a private place, to install in a private place, without the consent of the person entitled to privacy there, a device for observing, photographing, recording, amplifying, or broadcasting sounds or events, or to install or use outside a private place a device for hearing, recording, amplifying, or broadcasting sounds originating in that place that would not ordinarily be audible or comprehensible outside, again without that person's consent; a private place is one a person may reasonably expect to be safe from casual or hostile intrusion or surveillance, but does not include a place to which the public or a substantial group of the public has access.

Section 250.12(2)(a) separately makes it a misdemeanor to knowingly intercept, without the consent of the sender or receiver, a message by telephone, telegraph, facsimile, electronic mail, letter, or other means of communicating privately, an offence that does not extend to overhearing a message through a regularly installed telephone party line or extension, or to an interception by the telephone company or a subscriber incident to enforcing regulations that limit use of the facilities.

Section 250.12(2)(b) makes it a misdemeanor to divulge the existence or contents of such a message without the consent of the sender or receiver, where the person divulging it knows the message was illegally intercepted, or learned of it in the course of employment with an agency engaged in transmitting it.

The section states no penalty of its own; a misdemeanor under the Code's general sentencing provisions carries a fine of up to $1,000 and a definite term of imprisonment, fixed by the court, of up to one year.

What it requires

Personal Data Protection Act 2025, competent authority, remedies, and complaints

Personal Data Protection Act 2025, ss. 406-408, 410-414, 416-417 (6 MIRC Ch. 4, P.L. 2025-43)Marshall Islands Revised Code, 6 MIRC Ch. 4 (Personal Data Protection Act 2025), archived capture of the certified text

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2026. Publisher's page: https://www.rmiparliament.org/cms/images/LEGISLATION/PRINCIPAL/2025/2025-0043/2025-0043_1.pdf

In force 12 months, effective 7 October 2025. Binds government bodies.

What this law does

Section 406 designates the Economic Policy, Planning and Statistics Office (EPSSO) as the competent authority responsible for administering this Chapter, and section 407 gives it power to develop guidance and capacity-building initiatives, coordinate data sharing among ministries and agencies, require information from them as needed to comply with this Chapter, and make rules or regulations for its implementation.

Section 408 requires any director, employee, consultant, or other person engaged by the competent authority under this Chapter to maintain confidentiality of personal data obtained in the performance of their duties.

Section 410 lets a natural person residing in the Republic who suffers an injury from a core Government ministry's or agency's alleged improper administration of the Chapter bring suit against that ministry or agency, and separately lets that person sue an employee of the public service personally, in the employee's own capacity, for willful or grossly negligent conduct causing the injury, including for compensatory damages against the employee.

Section 411 lists the remedies a court may impose on the ministry or agency itself, an injunction, mandamus, a corrective order, or a public statement of remedy, but bars a court from awarding compensatory relief against the ministry or agency itself. Section 412 requires the competent authority to report yearly to the Minister for presentation to the Nitijela on this Chapter's implementation.

Section 413 requires core Government ministries and agencies to compile and record each calendar year the policies and actions taken to implement the Chapter and the complaints received, and to report that information to the competent authority by July 1 of each year in anonymized form.

Section 414 requires each ministry and agency to establish a process for a natural person residing in the Republic to submit a complaint about an alleged violation, consistent with the competent authority's guidance. Section 417 lets the competent authority, with Cabinet approval, make regulations for the Chapter's effective performance. The Chapter states no penalty or offence provision of its own.

What it requires

Cybersecurity law2 instruments, 2 in force

Research summary (666 words)

The Marshall Islands enacted the Cybersecurity Act 2025 (40 MIRC Ch. 4, P.L. 2025-0027) the same day as its Telecommunications (Reform) Act 2025 (40 MIRC Ch. 5, P.L. 2025-28) and roughly six months before its Personal Data Protection Act 2025 (6 MIRC Ch. 4, commenced October 7, 2025), a package resembling the Cybersecurity Act, Computer Crimes Act, and Personal Data Protection Act Tonga enacted the same year, though no Marshall Islands Computer Crimes Act was located among the Republic's 2025 legislation.

The Cybersecurity Act creates a Chief Information Security Officer within the Office of National Security, empowers the Director of National Security to designate a computer or computer system as critical information infrastructure supporting an essential service (a service the Director determines is essential to national security, the economy, public health, public safety, public order, or the continuous provision of basic public services), and, once a system is designated, binds its owner, a term the Act defines broadly enough to reach a natural person, a public body, or a commercial or non-commercial organization, to implement cybersecurity risk-management measures (section 406) and to report a significant cybersecurity incident on a fixed 24-hour, 72-hour, and 30-day clock (section 407).

Both duties are filed here as coded instruments under the operates_essential_service activity, the same convention this corpus already applies to the EU's NIS2 Directive, Spain's Real Decreto-ley 12/2018, and South Korea's Network Act critical-infrastructure regime.

The Act separately requires a person providing an accreditable cybersecurity service, chiefly penetration testing or Security Operations Center monitoring under section 414, to hold a Director-issued accreditation; that is a professional-services licensing duty with no bound-party class this corpus's activity vocabulary can express, so it is named here rather than raised against a declared activity, the same treatment this profile gives DORA's financial entities and Singapore's licensable-cybersecurity-service providers.

Part V, which carries that accreditation duty, does not take effect until the Director promulgates its implementing regulations, and no source located during this research confirms that has happened; nor does any source located confirm whether the Director has yet issued the initial critical-information-infrastructure designation order section 419 required within twelve months of the Act's effective date, so which systems are actually bound today is an open question rather than a settled one.

The Personal Data Protection Act 2025 is privacy-shaped rather than security-shaped: it binds only core Government ministries and agencies, not a private-sector controller, and its integrity-and-security principle is one clause of a comprehensive consent-and-processing regime already researched under this jurisdiction's privacy topic, so it is not repeated here.

The Criminal Code 2011's Violation of Privacy offense (unauthorized eavesdropping, surveillance, and interception of a private communication) is an intruder-facing offense rather than an operator-facing duty and is already researched under this jurisdiction's scraping topic.

The Telecommunications (Reform) Act 2025, enacted the same day as the Cybersecurity Act, establishes the sector's licensing and open-market framework and requires an authorized telecommunications provider to maintain lawful-interception capability for national-security and law-enforcement purposes, but no cybersecurity risk-management or incident-reporting duty was found in its text; that ground is instead covered by the standalone Cybersecurity Act.

No source reachable this session establishes whether the National Telecommunications Authority the Reform Act creates has issued its own network-security regulation beyond the Cybersecurity Act, whether a domestic bank operates under a Banking Commission cybersecurity or IT-risk directive, or whether the Foreign Investment Business License Act 1990 conditions a business license on a security-of-systems criterion; PacLII's consolidated Marshall Islands legislation library returned a CAPTCHA challenge on every attempt this session, and this session's web-search tool was unavailable throughout, so each of these is recorded as an open research gap rather than a confirmed absence.

No enacted Marshall Islands statute located this session sets a security requirement a software product or connected device must meet before or after being placed on the market; the Cybersecurity Act's duties attach to the operator of a designated system, not to a manufacturer. Nothing located ties a cybersecurity duty to the Marshall Islands' offshore corporate-registry or vessel-registry business.

Sector security regimes

Cybersecurity Act 2025, Cybersecurity of Critical Information Infrastructure

Cybersecurity Act 2025, 40 MIRC Ch. 4 §§ 405-406 (P.L. 2025-0027)Republic of the Marshall Islands Nitijela legislation portal (rmiparliament.org)

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2026. Publisher's page: https://www.rmiparliament.org/cms/images/LEGISLATION/PRINCIPAL/2025/2025-0027/2025-0027_1.pdf

In force since 21 April 2025. Binds public and private bodies.

What this law does

Section 406 requires the owner of a computer or computer system the Director of the Office of National Security has designated critical information infrastructure under section 405 to implement technical, operational, and organizational measures to manage the cybersecurity risks that may affect it, and measures to prevent and mitigate the impact of a cybersecurity incident or threat.

At minimum the owner must conduct rolling cybersecurity risk assessments at a frequency the Chief Information Security Officer prescribes and develop internal cybersecurity policies and procedures, an internal incident-reporting policy, and an internal cybersecurity awareness program. No later than thirty days after completing that risk assessment, the owner must transmit a copy of the resulting cybersecurity mitigation actions to the Director.

The Director may also order, at the owner's own cost and no more than once every two years, an audit of the critical information infrastructure where the Director has reason to believe the owner has not complied with the Act. A person who intentionally and without reasonable excuse fails to comply with this section's obligations commits a petty misdemeanor, and a corporation may separately be convicted of an offense under this Act.

What it requires

Vulnerability and incident reporting

Cybersecurity Act 2025, Cybersecurity Incident Reporting Obligations

Cybersecurity Act 2025, 40 MIRC Ch. 4 § 407 (P.L. 2025-0027)Republic of the Marshall Islands Nitijela legislation portal (rmiparliament.org)

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2026. Publisher's page: https://www.rmiparliament.org/cms/images/LEGISLATION/PRINCIPAL/2025/2025-0027/2025-0027_1.pdf

In force since 21 April 2025. Binds public and private bodies.

What this law does

Section 407 requires the same designated owner of critical information infrastructure to immediately notify the Director of the Office of National Security and the CSIRT-MH of a significant cybersecurity incident affecting the critical information infrastructure, of a significant incident on any interconnected computer system under the owner's control, or of any other incident type the Director specifies by written order.

To comply, the owner must submit an early warning within twenty-four hours of becoming aware of the incident, a fuller notification with an initial severity and impact assessment within seventy-two hours, and a final report within thirty days of that notification, or, for an ongoing incident, a thirty-day progress report followed by a final report within thirty days of the incident's resolution.

The owner must also establish mechanisms and processes to promptly detect a cybersecurity threat, vulnerability, or incident affecting the critical information infrastructure. A person who intentionally and without reasonable excuse fails to make a notification under this section commits a petty misdemeanor.

What it requires

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.