Comprehensive regime
Personal Data Protection Act 2025, government personal-data protection principles
Personal Data Protection Act 2025, 6 MIRC Ch. 4 (P.L. 2025-43), ss. 401-405, 409, 415, 418Marshall Islands Revised Code, 6 MIRC Ch. 4 (Personal Data Protection Act 2025), archived capture of the certified text
archived copy
Read from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2026. Publisher's page: https://www.rmiparliament.org/cms/images/LEGISLATION/PRINCIPAL/2025/2025-0043/2025-0043_1.pdfIn force 12 months, effective 7 October 2025. Binds government bodies.
What this law does
Sections 401 to 405 apply this Chapter to core Government ministries and agencies of the Republic that collect, use, store, process, disclose, or transfer personal data of natural persons, and their definitions of data controller and data processor extend to a third party acting on behalf of such a ministry or agency; the Chapter excludes processing for law enforcement or national intelligence and national security purposes, non-personal data, and publicly available information lawfully obtained from government records, voluntarily made available by the data subject without audience restriction, or otherwise lawfully obtained, truthful, and a matter of public concern.
Section 409 sets six personal data protection principles binding core Government ministries and agencies: a legitimate-purpose principle requiring lawful, fair, transparent processing for specified purposes; a data-minimization principle limiting collection to what the purpose requires; an accuracy principle requiring inaccurate personal data to be corrected or deleted without delay; a retention principle limiting storage to what the purpose requires; an integrity and security principle requiring technical and organizational protection against unauthorized or unlawful processing and unintentional loss, destruction, or damage, and limiting staff access to what their duties need; and an accountability principle making the data controller responsible for demonstrating compliance.
Section 415 lets core Government ministries and agencies voluntarily share personal data with each other under a safe harbor, provided the sharing serves a legitimate function of each ministry or agency and complies with the section 409 principles, and lets the competent authority set standards for such sharing agreements.
Section 418 states the Chapter takes effect twelve months after the date of its certification under Article IV, section 21 of the Constitution, which the Act's own commencement note records as 7 October 2025. The Act states no consent requirement, no data-subject access, correction, deletion, or portability right, no heightened rule for sensitive or biometric data beyond the definition, and no cross-border transfer restriction.
What it requires