Law / Suriname

Suriname

8 of 9 named instruments researched to a stage, across three of the six areas of law we track: 2 in force and 6 proposed. As of 19 September 2026.

  1. AI law none researched
  2. Privacy law 6
  3. Scraping law 1
  4. Cybersecurity law none researched
  5. Age gating law none researched
  6. News aggregation law 1

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law6 instruments, 6 proposed

Research summary (208 words)

Suriname has no enacted comprehensive data protection statute and no operating data protection supervisory authority. A bill that would create both, the Ontwerpwet Bescherming Privacy en Persoonsgegevens (draft Law on the Protection of Privacy and Personal Data), remains under consideration before De Nationale Assemblee, with no enactment timeline; nothing in it binds anyone today.

As drafted, the bill would define personal data broadly, following the same identified or identifiable natural person test used in the European Union's General Data Protection Regulation, and would engage every family this corpus tracks: a comprehensive processing regime with lawful basis, principles, accountability, security, and registration duties; heightened rules for special categories of personal data, biometric data, and children; a full set of data subject rights including access, portability, objection, erasure, and a right against solely automated decisions; a cross border transfer regime conditioned on an adequate protection instrument, a lawful basis, or the Commissioner's specific authorisation; a breach notification duty running to the Commissioner within 72 hours of the controller becoming aware, and to affected individuals only where the Commissioner requires it; and an independent Commissioner for Personal Data Protection with complaint, investigation, and administrative fining powers, a private right to compensation, and whistleblower protection, but no criminal penalty for a violation.

Breach notification

Draft Law on the Protection of Privacy and Personal Data, breach notification

Art. 20 Wet Bescherming Privacy en PersoonsgegevensDraft text of the Ontwerpwet Bescherming Privacy en Persoonsgegevens

Proposed: draft date not recorded. Binds public and private bodies.

What this law does

This measure is a draft bill; it binds nobody yet, and what follows describes what it would require if enacted in the form read.

Article 20(1) requires a controller to notify the Commissioner for Personal Data Protection of a breach relating to personal data without delay and, if possible, no later than 72 hours after becoming aware of it, unless the breach is unlikely to pose a risk to individuals' rights and freedoms; where notice is not given within 72 hours, the controller must also state the reasons for the delay.

Article 20(2) requires that notice to describe, at minimum, the nature of the breach, the categories and approximate number of data subjects and records affected, the data protection officer's or another contact point's details, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects, with article 20(3) allowing the information to be given in phases without unreasonable delay where it cannot all be given at once.

Article 16(j) requires a processor to inform the controller without unreasonable delay after becoming aware of a breach relating to personal data. Article 20(4) requires a controller to document every breach, including its facts, effects, and the corrective measures taken, in a form that lets the Commissioner verify compliance with the article.

Article 20(5) lets the Commissioner, after weighing the breach's nature, likely consequences, and mitigation measures, require the controller to notify affected individuals and specify the communications and means to use; article 20(6) has the Commissioner keep a non-public register of breach notifications it receives. The bill remains under consideration before De Nationale Assemblee, with no enactment timeline.

What it requires

Comprehensive regime

Draft Law on the Protection of Privacy and Personal Data (Ontwerpwet Bescherming Privacy en Persoonsgegevens)

Wet Bescherming Privacy en Persoonsgegevens, arts. 1-6, 12, 14-19, 21 (general obligations)Draft text of the Ontwerpwet Bescherming Privacy en Persoonsgegevens

Proposed: draft date not recorded. Binds public and private bodies.

What this law does

This measure is a draft bill; it binds nobody yet, and what follows describes what it would require if enacted in the form read.

The bill defines privacy as the right to protection of all information about an identified or identifiable living natural person, and defines personal data the same way, an identifiable natural person being one who can be identified directly or indirectly by reference to an identifier such as a name, an identification number, location data, an online identifier, or one or more factors specific to that person's physical, physiological, genetic, mental, economic, cultural or social identity.

Article 5 sets out the processing principles: lawfulness and fairness, openness and transparency, purpose limitation and data minimization, data quality, storage limitation, security safeguards, data-subject participation, ethical processing, and accountability.

Article 6 requires a lawful basis before processing, running from contractual necessity, a legal obligation, vital interests, a public-interest task, and official authority through to a legitimate interest that does not override the data subject's rights, or the data subject's own specific, informed consent presented separately from other matters and withdrawable at any time.

Article 12 lets specific laws narrow the rights and obligations in article 5, chapter III, and article 20(5) for purposes including national security, defence, public safety, and the prevention, investigation, detection or prosecution of criminal offences. Article 14 requires a controller and, where applicable, a processor to take appropriate technical and organizational measures able to demonstrate compliance on request, and to bind anyone with access to personal data to confidentiality.

Article 15 requires data protection by design and by default under article 17, a written processor contract, and cooperation between joint controllers. Article 18 requires a controller and processor to keep a register of processing activities and notify it to the Commissioner for Personal Data Protection, updated whenever needed and at least once a year. Article 19 requires appropriate technical and organizational security measures matched to the risk.

Article 21 requires a controller and a processor each to appoint a data protection officer to advise on this law's duties, liaise with the Commissioner, and act as the contact point for a data subject exercising their rights. The bill remains under consideration before De Nationale Assemblee, with no enactment timeline.

What it requires

Cross border transfer

Draft Law on the Protection of Privacy and Personal Data, cross border transfer

Art. 22 Wet Bescherming Privacy en PersoonsgegevensDraft text of the Ontwerpwet Bescherming Privacy en Persoonsgegevens

Proposed: draft date not recorded. Binds public and private bodies.

What this law does

This measure is a draft bill; it binds nobody yet, and what follows describes what it would require if enacted in the form read.

Article 22(1) bars a controller or processor from transferring personal data to a recipient in a third country unless the recipient is subject to a law, binding corporate rules, or a binding agreement that offers a level of protection substantially comparable to this law's own processing principles and its rules on onward transfer, or one of the article 6 lawful bases for processing applies, or the Commissioner for Personal Data Protection has authorised that specific transfer.

Article 22(2) narrows that further for special categories of personal data and criminal conviction or offence data, which may only be transferred where the recipient is bound by such an adequate protection instrument or the Commissioner has specifically authorised the transfer, not merely on an article 6 lawful basis.

Article 22(3) lets the Commissioner identify, in accordance with article 31(1)(j), which laws, binding corporate rules or binding agreements offer an adequate level of protection under article 22(1)(a). The bill remains under consideration before De Nationale Assemblee, with no enactment timeline.

What it requires

Data subject rights

Draft Law on the Protection of Privacy and Personal Data, rights of the data subject

Arts. 10-11 Wet Bescherming Privacy en PersoonsgegevensDraft text of the Ontwerpwet Bescherming Privacy en Persoonsgegevens

Proposed: draft date not recorded. Binds public and private bodies.

What this law does

This measure is a draft bill; it binds nobody yet, and what follows describes what it would require if enacted in the form read.

Article 10 requires a controller to give a data subject the identity and contact details of the controller and any representative, the data protection officer's contact details where one exists, the purposes and legal basis of the processing, the categories of data, the recipients including any third country recipient, the storage period, the existence of the data subject's rights, and the right to complain to the Commissioner.

That information is due when the data are collected from the data subject, or, where they were not, within a reasonable time and at latest within one month.

Article 11 gives a data subject the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects for them or otherwise significantly affects them, unless a listed exception applies, and bars such a decision from resting on special categories of personal data unless a narrow exception applies with appropriate safeguards.

It also gives a data subject the right to confirmation of processing and to the reasons underlying a decision applied to them, a right to portability of data they provided under a contract or consent and processed by automated means, a right to object at any time to processing on grounds relating to their situation, with processing for direct marketing and its related profiling stopping outright once the data subject objects, a right to rectification or erasure where processing violated this law, and a right to withdraw consent at any time as easily as it was given.

A controller must act on a rights request without undue delay and within one month of receipt, extendable by one further month for complex or numerous requests with notice of the extension within three weeks, and must tell a data subject who it declines to act for why within one month, including the possibility of a complaint to the Commissioner or a court.

Exercising these rights and receiving the article 10 information is free, except that a controller facing a manifestly unfounded or excessive request, particularly a repetitive one, may charge a reasonable administrative fee or refuse it, bearing the burden of showing the request is unfounded or excessive. The bill remains under consideration before De Nationale Assemblee, with no enactment timeline.

What it requires

Enforcement supervision

Draft Law on the Protection of Privacy and Personal Data, Commissioner, remedies and fines

Arts. 23-42 Wet Bescherming Privacy en PersoonsgegevensDraft text of the Ontwerpwet Bescherming Privacy en Persoonsgegevens

Proposed: draft date not recorded. Binds public and private bodies.

What this law does

This measure is a draft bill; it binds nobody yet, and what follows describes what it would require if enacted in the form read. Article 23 establishes an independent Commissioner for Personal Data Protection (Commissaris voor Persoonsgegevensbescherming), responsible for supervising and enforcing this law, accountable to De Nationale Assemblee.

Article 33 gives every data subject or their legal representative the right to lodge a complaint with the Commissioner, and articles 34 and 37 set the complaint procedure, including a decision within three months, extendable by three months for complex cases, and the factors the Commissioner weighs before imposing a fine.

Article 35 lets the Commissioner fine a controller or processor for a violation: up to SRD 5,000 or 2 percent of worldwide annual turnover, whichever is higher, for violating the chapter V obligations on controllers and processors, and up to SRD 10,000 or 4 percent of worldwide annual turnover, whichever is higher, for violating the principles, rights, or cross border transfer chapters, or for failing to comply with a Commissioner decision, order, or notice or to grant access needed for a complaint investigation.

Articles 38 and 39 give a person effective judicial remedies against the Commissioner and against a controller or processor respectively, before the kantonrechter, and article 40 gives every person who suffers material or non-material damage from a violation of this law the right to compensation from the controller or processor responsible, with joint and several liability where more than one is involved.

Article 41 bars an employer from dismissing, suspending, demoting, disciplining, fining, intimidating or otherwise disadvantaging an employee for reporting in good faith that the employer or another person has violated or will violate this law. Article 42 lets a data subject authorise a nonprofit organisation active in privacy protection to lodge a complaint or exercise their judicial and compensation rights on their behalf.

The bill contains no criminal penalty for a violation; its sanctions are the administrative fine, the compensation claim, and the Commissioner's other decisions and orders. The bill remains under consideration before De Nationale Assemblee, with no enactment timeline.

What it requires

Sensitive categories

Draft Law on the Protection of Privacy and Personal Data, special categories, children and criminal data

Arts. 7-9 Wet Bescherming Privacy en PersoonsgegevensDraft text of the Ontwerpwet Bescherming Privacy en Persoonsgegevens

Proposed: draft date not recorded. Binds public and private bodies.

What this law does

This measure is a draft bill; it binds nobody yet, and what follows describes what it would require if enacted in the form read. Article 7 sets the age at which a child's own consent to processing is valid at sixteen; below that age, processing based on consent is lawful only where a legal representative gave it, the controller must take reasonable steps to verify that, and a child's personal data may never be processed in a way inconsistent with the child's interest.

Article 8(1) prohibits processing personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and prohibits processing genetic data, biometric data, health data, or data concerning a person's sexual behaviour or orientation, subject to the exceptions article 8(2) lists, such as the data subject's explicit consent or processing necessary to protect vital interests.

Article 8(3) requires particular care in processing that data so it does not cause unfair discrimination, prejudice, or other harm to the data subject. The bill defines biometric data as personal data resulting from specific technical processing of a natural person's physical, physiological or behavioural characteristics that allows or confirms that person's unique identification, expressly including facial images, blood type, fingerprints, DNA analysis, retinal scans, and voice recognition.

Article 9(1) allows processing personal data about a criminal conviction or offence only under the supervision of an official authority, or where a specific law permits it with appropriate safeguards, and reserves a comprehensive register of convictions to supervision by an official authority; article 9(2) lets a controller that is not an official authority process such data for an employment-law purpose only if it keeps an internal policy document, available to the Commissioner on request, explaining its article 5 compliance procedures and its retention and erasure policy for that data.

The bill remains under consideration before De Nationale Assemblee, with no enactment timeline.

What it requires

Scraping law1 instrument, 1 in force

Research summary (264 words)

Suriname has no scraping-specific statute, so general law governs each dimension separately.

The Wetboek van Strafrecht (Penal Code), as revised by the law of 30 March 2015 (S.B. 2015 no. 44), criminalises hacking at article 187b: access to an automated work is unlawful only where it was obtained by breaking through a security measure, a technical intervention, false signals or a false key, or a false identity, so a plain reading does not reach reading a public, unauthenticated page that defeats no access control, and no reported Surinamese case has tested the point.

Article 187c separately punishes intentionally and unlawfully hindering another person's access to or use of an automated work by flooding it with data. No Surinamese court has ruled on the enforceability of a browsewrap or clickwrap terms-of-service against a scraper.

The Wet Auteursrecht 1913 (Copyright Act), as amended through Staatsblad 2015 no. 83, predates the concept of a machine-readable text-and-data-mining reservation and creates no such exception; its only reproduction exceptions are narrow ones for newspaper-to-newspaper reprinting of news items and for short quotations or press reviews, neither aimed at automated collection or model training, and the Act confers no sui generis database right.

No enacted comprehensive privacy law reaches personal data scraped from a public Surinamese website; a bill that would create one, the draft Wet Bescherming Privacy en Persoonsgegevens, has been pending before the National Assembly's Rapporteurs committee with no enactment timeline.

No Surinamese statute or reported case establishes a scraping-specific unfair-competition, misappropriation or trespass doctrine, and none assigns legal weight to a robots.txt directive or imposes an AI-training-specific rule.

Computer misuse

Wetboek van Strafrecht, Hacking and Denial of Access (arts. 187b-187c)

Wetboek van Strafrecht (G.B. 1911 no. 1, as revised S.B. 2015 no. 44), arts. 187b-187c (hacking and denial of access)Official consolidated text of the Wetboek van Strafrecht as revised by the law of 30 March 2015

In force. Binds public and private bodies.

What this law does

Article 187b(1) punishes intentionally and unlawfully gaining access to an automated work, or part of one, as hacking, with imprisonment of up to one year and a third-category fine (up to SRD 25,000), or either penalty; access is deemed unlawful specifically where it was obtained by breaking through a security measure, a technical intervention, false signals or a false key, or by assuming a false identity.

Article 187b(2)-(3) raises the penalty to up to four years and a fourth-category fine (up to SRD 50,000) where the offender, having gained unlawful access, then takes over, taps or records the data held on the system, uses its processing capacity for unlawful gain, or pivots through it to a third party's system.

Article 187c separately punishes, with up to one year and a fourth-category fine, intentionally and unlawfully hindering another person's access to or use of an automated work by offering or sending data to it. Because unlawfulness under article 187b turns on defeating a security measure, a technical intervention, or a false signal, key or identity, reading a public, unauthenticated page without any such circumvention falls outside a plain reading of the offence.

The law provides that it takes effect the day after its promulgation in the Staatsblad. De Nationale Assemblee's own legislative record lists this law under Staatsblad 2015 no. 44 and the date 13 April 2015.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (189 words)

Suriname has no press-publisher neighbouring right, no mandatory platform-to-publisher bargaining code, no recognized hot-news misappropriation doctrine distinct from ordinary copyright law, and no located statute or case law addressing hyperlinking or framing liability specifically; the relevant instrument is the Wet Auteursrecht 1913 (Copyright Act), as amended through Staatsblad 2015 no. 83.

Article 15 lets one newspaper or magazine reprint articles, reports, or other items published in another newspaper or magazine, without the maker's permission, provided the source publication is clearly credited; for articles concerning political disputes, news reports, and miscellaneous items specifically, copyright cannot be reserved against this reprinting at all.

Article 15bis separately permits short quotations from newspaper or magazine articles, even in the form of press reviews (persoverzichten), again with the source and author credited if named in it. Neither provision is capped to a headline-length extract, and no reported Surinamese decision applies either to a systematic news aggregator, as opposed to a traditional press review or a reprinting newspaper.

The Act predates the concept of a machine-readable text-and-data-mining reservation entirely, so no opt-out mechanism of that kind exists, and it creates no sui generis database right.

Snippet reproduction

Wet Auteursrecht 1913, Press Reproduction and Quotation Exceptions (arts. 15, 15bis, 15ter)

Wet Auteursrecht 1913 (G.B. 1913 no. 15), as amended S.B. 2015 no. 83, arts. 15, 15bis, 15ter (press reproduction and quotation)Dutch-language consolidated text of the Wet Auteursrecht 1913, as amended up to Staatsblad 2015 no. 83, reproduced by WIPO Lex

In force since 22 March 1913. Binds public and private bodies.

What this law does

Article 15 provides that reproducing, without the maker's or their successors' permission, articles, reports or other items (other than novels and short stories) that appeared in a newspaper or magazine, is not an infringement of copyright when done by another newspaper or magazine, provided the source publication is clearly named along with the author if the source names one, and unless copyright has been expressly reserved.

For articles concerning political disputes, and for news reports and miscellaneous items specifically, no such reservation of copyright can be made at all, so those categories can never be withheld from reprinting under article 15. The same reprinting permission reaches foreign newspapers and magazines only for news reports, miscellaneous items, or current articles on economics, politics, or religion.

Article 15bis separately provides that short quotations from articles that appeared in a newspaper or magazine, including in the form of press reviews, are not copyright infringement, provided the source newspaper or magazine is clearly named along with the author if named in the source.

Article 15ter provides that further publication or reproduction of a literary, scientific or artistic work already made public by or on behalf of the public authority is not an infringement, unless copyright was expressly reserved either generally by regulation or in a specific case.

None of these provisions is capped at a headline-length or short-extract threshold distinct from their own terms, and no reported Surinamese decision applies article 15 or 15bis to a systematic news aggregator's reproduction of headlines and snippets, as opposed to a traditional newspaper reprint or press review.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.