Law / Tonga

Tonga

11 of 15 named instruments researched to a stage, across four of the six areas of law we track: 3 in force and 8 enacted but not yet in force. As of 19 September 2026.

  1. AI law none researched
  2. Privacy law 6
  3. Scraping law 2
  4. Cybersecurity law 2
  5. Age gating law none researched
  6. News aggregation law 1

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law6 instruments, 6 enacted but not yet in force

Research summary (176 words)

Tonga enacted its first comprehensive data-protection statute, the Privacy Act 2025 (Act 34 of 2025), which King Tupou VI assented to on 16 December 2025 after the Legislative Assembly passed it on 6 August 2025.

The Act binds public authorities and private organisations alike, requires a lawful basis (ordinarily consent) for processing personal information and a heightened basis for sensitive categories including biometric data, and grants data subjects rights of access, correction, deletion, objection to direct marketing, and protection from a decision based solely on automated processing.

It restricts transferring personal information outside Tonga absent Privacy Commission consent or an adequate-protection safeguard, requires breach notification to the new Privacy Commission within 72 hours (a duty that does not begin until the second anniversary of commencement), and enforces its duties through civil pecuniary penalties of up to TOP 100,000 rather than criminal liability.

Tonga's Constitution has no general right to privacy; its Bill of Rights restrains entering or searching premises without a warrant, which is a property and search-and-seizure protection rather than a right over personal information.

Breach notification

Privacy Act 2025, personal information breaches

Privacy Act 2025, s. 37 (personal information breaches)Official English text, Privacy Act 2025 (Act 34 of 2025), Tonga Attorney General's Office legislation database, archived copy

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2026. Publisher's page: https://ago.gov.to/cms/images/LEGISLATION/PRINCIPAL/2025/2025-0052/PrivacyAct2025_1.pdf

Commencement not set. Binds public and private bodies.

What this law does

Section 37(1) requires a data processor that becomes aware of a personal information breach to notify the data controller or the data processor that engaged it within seventy-two hours, describing the nature of the breach including, where possible, the categories and approximate numbers of data subjects and records concerned, and to respond without undue delay to information requests from whoever engaged it.

Section 37(2) requires a data controller to notify the Commission within seventy-two hours of becoming aware of a breach that is likely to result in a risk to the rights and freedoms of individuals, with the same description.

Section 37(3) requires the controller to communicate a breach likely to result in a high risk to a data subject to that data subject without undue delay, in plain and clear language, with advice on measures they could take to mitigate the adverse effects, and allows a public communication through widely used media where direct communication would involve disproportionate effort or expense.

Section 1(2) provides that the Act comes into force on a date proclaimed by Cabinet, and no proclamation has been located, so whether these provisions bind today is not established.

What it requires

Comprehensive regime

Privacy Act 2025, comprehensive personal information protection regime

Privacy Act 2025 (Act 34 of 2025), ss. 1-6, 27, 30-32, 34-36 and 38Official English text, Privacy Act 2025 (Act 34 of 2025), Tonga Attorney General's Office legislation database, archived copy

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2026. Publisher's page: https://ago.gov.to/cms/images/LEGISLATION/PRINCIPAL/2025/2025-0052/PrivacyAct2025_1.pdf

Commencement not set. Binds public and private bodies.

What this law does

Section 27 bars a data controller from processing personal information, or permitting a data processor to do so on its behalf, except on a lawful basis it lists, beginning with the data subject's consent to the specific purpose and running through contractual necessity, a legal obligation, vital interests and the public interest.

Section 31 governs reliance on consent and section 32 requires processing to be for a lawful purpose related to the controller's function or activity, personal information to be accurate, complete, not misleading and up to date to the extent the purpose requires, and the information held to be adequate, relevant and limited to that purpose.

Section 34 bars retention for longer than the purpose requires and requires the information to be returned, destroyed, rendered inaccessible or permanently de-identified within a reasonable time once retention is no longer necessary.

Section 35 governs the engagement of a data processor, section 36 requires appropriate and reasonable technical and organisational measures to prevent accidental, unauthorised or unlawful loss, misuse, destruction, damage or access, and section 38 lets the Minister make regulations requiring a personal information protection impact assessment for high-risk processing.

Section 1(2) provides that the Act comes into force on a date proclaimed by Cabinet, and no proclamation has been located, so whether these provisions bind today is not established. Separately, press reporting (Tonga Independent News, 6 January 2026) states the Act was gazetted into force alongside a package of other 2025 governance-reform statutes, and no Cabinet proclamation confirming that has been located.

What it requires

Cross border transfer

Privacy Act 2025, transfers of personal information outside the Kingdom

Privacy Act 2025, ss. 39-41 (transfers outside the Kingdom)Official English text, Privacy Act 2025 (Act 34 of 2025), Tonga Attorney General's Office legislation database, archived copy

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2026. Publisher's page: https://ago.gov.to/cms/images/LEGISLATION/PRINCIPAL/2025/2025-0052/PrivacyAct2025_1.pdf

Commencement not set. Binds public and private bodies.

What this law does

Section 39(1) bars a data controller or data processor from transferring personal information to a country or territory outside the Kingdom unless the Commission has given written consent to the transfer or the recipient is subject to a law, binding corporate rules, contractual clauses, code of conduct or certification mechanism affording an adequate level of protection under section 40.

Section 39(2) disapplies that bar where the data subject has given and not withdrawn consent after being informed of the risks of transferring without adequate protection, or another listed situation applies. Section 40 sets out how adequacy is determined and section 41 provides for the related determinations. Section 1(2) provides that the Act comes into force on a date proclaimed by Cabinet, and no proclamation has been located, so whether these provisions bind today is not established.

What it requires

Data subject rights

Privacy Act 2025, notification to data subjects and rights of data subjects

Privacy Act 2025, ss. 33 and 42-47 (notification and rights)Official English text, Privacy Act 2025 (Act 34 of 2025), Tonga Attorney General's Office legislation database, archived copy

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2026. Publisher's page: https://ago.gov.to/cms/images/LEGISLATION/PRINCIPAL/2025/2025-0052/PrivacyAct2025_1.pdf

Commencement not set. Binds public and private bodies.

What this law does

Section 33 requires a data controller collecting personal information directly from a data subject to tell them, at the time of collection, the controller's identity and contact details, that personal information is being collected, the purpose including any direct marketing, whether sensitive personal information is collected and of what nature, and the intended recipients.

Section 42 gives a data subject the right to obtain, without constraint or unreasonable delay and at no expense, confirmation of whether their personal information is being processed and its source, a copy in a commonly used electronic format, and correction or deletion of information that is inaccurate, out of date, incomplete or misleading or that the controller is not entitled to retain.

Section 43 lets a data subject stop direct marketing by written notice, which the controller must act on as soon as reasonably practicable and in any event within 30 days. Sections 44 to 47 give the rights not to be subject to a decision based solely on automated processing, to object to processing, to withdraw consent and to portability.

Section 1(2) provides that the Act comes into force on a date proclaimed by Cabinet, and no proclamation has been located, so whether these provisions bind today is not established.

What it requires

Enforcement supervision

Privacy Act 2025, penalties, enforcement and third party actions

Privacy Act 2025, ss. 52-66 (penalties, enforcement and investigation)Official English text, Privacy Act 2025 (Act 34 of 2025), Tonga Attorney General's Office legislation database, archived copy

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2026. Publisher's page: https://ago.gov.to/cms/images/LEGISLATION/PRINCIPAL/2025/2025-0052/PrivacyAct2025_1.pdf

Commencement not set. Binds public and private bodies.

What this law does

Section 52 deems every omission or failure to comply with the Act, and every act contrary to it, a contravention. Section 54 lets a court order a pecuniary penalty for a contravention, capped by section 54(4) at TOP 5,000 for an individual's first contravention and, for a subsequent one, the greater of TOP 30,000 or three times the benefit obtained, and at TOP 30,000 for an organisation's or public authority's first contravention rising to TOP 100,000 for a subsequent one.

Section 55 lets the Commission serve an enforcement notice specifying the provisions it considers contravened and the reasons, section 56 provides for enforceable undertakings, and section 57 lets a data subject who has sustained loss or damage recover it by action, with the Commission able to bring the proceeding as representative of a class or to intervene. Sections 58 to 66 provide for information notices, investigation of complaints and the Commission's related powers.

Section 1(2) provides that the Act comes into force on a date proclaimed by Cabinet, and no proclamation has been located, so whether these provisions bind today is not established.

What it requires

Sensitive categories

Privacy Act 2025, sensitive personal information and children

Privacy Act 2025, ss. 28-29 (sensitive personal information and children)Official English text, Privacy Act 2025 (Act 34 of 2025), Tonga Attorney General's Office legislation database, archived copy

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2026. Publisher's page: https://ago.gov.to/cms/images/LEGISLATION/PRINCIPAL/2025/2025-0052/PrivacyAct2025_1.pdf

Commencement not set. Binds public and private bodies.

What this law does

Section 28 bars a data controller from processing sensitive personal information, or permitting a data processor to process it on its behalf, unless a section 27 condition has first been met and, in addition, the data subject has given and not withdrawn consent to the specific purpose, or the processing is necessary on one of the grounds the section lists, such as protecting the vital interests of a data subject who cannot consent.

Section 3 defines sensitive personal information to include biometric data.

Section 29 requires the consent of a parent or other appropriate legal guardian before processing the personal information of a child or an individual lacking legal capacity to consent, and requires appropriate mechanisms, including presentation of government approved identification documents, to verify age and consent, except where the processing is necessary to protect that person's vital interests or falls within the other exception the section states.

Section 1(2) provides that the Act comes into force on a date proclaimed by Cabinet, and no proclamation has been located, so whether these provisions bind today is not established.

What it requires

Scraping law2 instruments, 2 in force

Research summary (360 words)

Tonga has no scraping-specific statute, so general law addresses each dimension separately, and its computer-misuse regime is itself in transition.

The Computer Crimes Act 2003 (Act 14 of 2003) criminalises wilfully accessing any computer system without lawful excuse, with no requirement that a security measure be circumvented, so a plain reading reaches an unauthenticated public page more readily than a narrower foreign statute would; a Computer Crimes Act 2025 (Act 15 of 2025) has since been enacted on the same subject, and whether it repeals or amends the 2003 Act is not established here.

No Tongan court has ruled on the enforceability of a browsewrap or clickwrap terms-of-service against a scraper.

The Copyright Act 2002 permits quoting a short part of a published work, and separately permits reproducing a whole newspaper or periodical article on current economic, political, or religious topics unless the right to do so is expressly reserved, but Tonga has not enacted a text-and-data-mining exception, so training a model on scraped copyrighted text rests only on those general grounds if they can be stretched to fit.

The Copyright Act protects a collection of mere data as a work only where the collection is original by reason of the selection or arrangement of its contents, a compilation-style protection rather than a European sui generis database right, and its related rights cover only performers, phonogram producers, and broadcasting organisations.

Tonga enacted a Privacy Act 2025 (Act 34 of 2025) covering personal data generally, and whether or how it reaches scraped public personal data is not established here. The Protection Against Unfair Competition Act 2002 makes an act or practice, in the course of industrial or commercial activities, that departs from fair dealing in commercial practice an act of unfair competition actionable by whoever it damages, but no reported Tongan case has applied that general clause to a scraper's conduct.

A Cybersecurity Act 2025 (Act 14 of 2025) has also been enacted, addressing digital-system security generally; its text is likewise inaccessible, and no source establishes that it addresses crawling or scraping specifically. No Tongan statute or reported case assigns legal weight to a robots.txt directive or imposes an AI-training-specific rule.

Computer misuse

Computer Crimes Act 2003, unauthorised access

Computer Crimes Act, 2003 (Act 14 of 2003), s. 4 (Illegal access)Official English text, WIPO Lex

In force. Binds public and private bodies.

What this law does

Section 4(2) makes it an offence for a person to wilfully, without lawful excuse, access any computer system, on conviction to a fine not exceeding $10,000 or imprisonment not exceeding two years, or both; unlike some other jurisdictions' computer-misuse statutes, the offence does not require that the accused defeat a security measure to gain access.

Section 4(3) sets a materially higher penalty, a fine not exceeding $100,000 or imprisonment not exceeding twenty years, or both, where the computer accessed is a 'protected computer' tied to security, defence, or international relations; the identity of a confidential law-enforcement source; communications, banking, financial, public-utility, transport, or public-key infrastructure; or public-safety and emergency services, and the accused knew or ought reasonably to have known of that use.

What it requires

Unfair competition

Protection Against Unfair Competition Act 2002, general unfair-competition clause

Protection Against Unfair Competition Act 2002 (Act No. 19 of 2002, 2020 Revised Edition), s. 4Official English text, 2020 Revised Edition, WIPO Lex

In force since 1 September 2008. Binds public and private bodies.

What this law does

Section 4(1) provides that, in addition to the specific acts sections 5 to 9 separately address (causing confusion, damaging goodwill, misleading the public, discrediting an enterprise, and misusing secret information), any act or practice, in the course of industrial or commercial activities, that departs from fair dealing in commercial practice constitutes an act of unfair competition.

Section 4(2) entitles any person damaged or likely to be damaged by an act of unfair competition to the remedies obtainable under the general law of Tonga, without stating a fixed statutory penalty or damages figure of its own. The Act's own text records its commencement as 1 September 2008; the WIPO Lex database record for the same consolidated text separately lists an entry-into-force date of 1 October 2008, a discrepancy left unreconciled here.

What it requires

Cybersecurity law2 instruments, 2 enacted but not yet in force

Research summary (636 words)

Tonga enacted two distinct cybersecurity statutes in 2025, following the same split Singapore draws between a standalone Cybersecurity Act and a separate computer-misuse statute.

The Cybersecurity Act 2025 (Act 14 of 2025), passed by the Legislative Assembly on 14 May 2025 and assented to by King Tupou VI on 28 August 2025, creates a Cybersecurity Advisory Board and a Computer Emergency Response Team (CERT), and empowers the Minister responsible for cybersecurity policy and regulation (Minister CPR) to designate, by publication in the Government Gazette, any physical, electronic or virtual infrastructure asset, system or network as critical infrastructure where it is essential to national security or to the Kingdom's economic or social well-being, including infrastructure necessary for electronic communications, banking or other financial services, electrical energy, public transportation, other public utilities, or public health and emergency services.

Once designated, an operator of critical infrastructure must register with the Minister CPR and keep the register current, comply with the minimum standards the Minister CPR issues and submit to periodic or ad hoc audits, conduct and submit periodic cybersecurity self-assessments, report a cybersecurity incident affecting its systems to the CERT within 24 hours of becoming aware of it, comply with any order to take remedial action, and develop, implement, communicate to staff, and keep records of policies and procedures for detecting, sharing information about, mitigating and responding to cybersecurity threats.

A contravention of these operator duties is pursued as a civil action the Attorney General brings in a court of competent jurisdiction for a pecuniary penalty, capped by section 19(3) at $500,000 for an individual and $1,000,000 for a body corporate; the Act does not itself define what currency the bare "$" denotes, and Tonga's legal tender is the Pa'anga (ISO 4217: TOP).

No enacted Tongan instrument sets security requirements a software product or connected device must meet before or after it is placed on the market, and there is no general reasonable-security or baseline data-security-program duty reaching a business simply because it holds data: the Act's duties bind only a designated critical-infrastructure operator.

Section 1(2) makes the whole Act commence only on a date proclaimed by Cabinet, and no proclamation of a commencement date is recorded here, so none of its duties currently bind.

The companion Computer Crimes Act 2025 (Act 2025-0030), enacted the same year and superseding the Computer Crimes Act 2003, is the jurisdiction's computer-misuse statute; its title and its place in the same enactment cycle as the Cybersecurity Act point toward the same intruder-offense shape already tracked under the scraping topic elsewhere in this corpus, but the publisher's own host answers the direct PDF, a guessed legislation-index page, and the site root alike with an automated bot-verification challenge, and no Internet Archive capture of the 2025 Act exists, so its content is unconfirmed and nothing from it is filed under any topic below.

The Privacy Act 2025 (Act 2025-0052) is Tonga's comprehensive personal-data statute and belongs to the privacy topic's own coverage of a comprehensive regime's security-of-processing and breach-notification articles, rather than restated below; the same publisher bot wall and the absence of a working Internet Archive capture leave its text unconfirmed, so that placement rests on the seam rule rather than a verified reading of the Act.

No published network-security regulation from the Tonga Communications Commission, and no cybersecurity or IT-risk directive from the National Reserve Bank of Tonga, was located; the Reserve Bank is one of the bodies the Minister CPR must invite to nominate a member of the Cybersecurity Advisory Board under section 7(3)(c), which places it inside this Act's own institutional structure rather than evidencing a separate regime of its own, but neither absence is confirmed with confidence, since a guessed Tonga Communications Commission domain did not resolve and a general search for either regulator's own cybersecurity rules was not exhaustive.

Sector security regimes

Cybersecurity Act 2025, Critical Infrastructure Operator Obligations

Act 14 of 2025, ss. 11-14, 16-17Official Act text (Cybersecurity Act 2025, Act 14 of 2025), Attorney General's Office of Tonga, as captured in the Internet Archive

Commencement not set. Binds public and private bodies.

What this law does

Sections 11 to 14, 16 and 17 of the Cybersecurity Act 2025 let the Minister responsible for cybersecurity policy and regulation designate any physical, electronic or virtual infrastructure asset, system or network as critical infrastructure by publication in the Government Gazette, on grounds that include electronic communications, banking or other financial services, electrical energy, public transportation, other public utilities, and public safety or public health including emergency services.

A designated operator must register and keep the register current, comply with the Minister's minimum standards and submit to periodic or ad hoc audits, conduct and submit periodic cybersecurity self-assessments, comply with any order to take remedial, protective or preventative action, and develop, implement, communicate to staff, and keep records of policies and procedures for detecting, sharing information about, mitigating and responding to cybersecurity threats and incidents.

What it requires

Vulnerability and incident reporting

Cybersecurity Act 2025, Duty to Report a Cybersecurity Incident

Act 14 of 2025, s. 15Official Act text (Cybersecurity Act 2025, Act 14 of 2025), Attorney General's Office of Tonga, as captured in the Internet Archive

Commencement not set. Binds public and private bodies.

What this law does

Section 15 requires an operator of critical infrastructure designated under section 11 to report a cybersecurity incident to the Computer Emergency Response Team (CERT) within 24 hours of becoming aware of it, whether the incident affects the information systems of the designated infrastructure itself, any information system interconnected with or communicating with those systems, or any other incident the Minister responsible for cybersecurity policy and regulation has designated as requiring notification, in a form that Minister prescribes.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (308 words)

Tonga has no press-publisher neighbouring right and no mandatory platform-to-publisher bargaining code; the general copyright framework of the Copyright Act 2002 (Act No. 12 of 2002, 2020 Revised Edition) is the primary law reaching an aggregator's reproduction of news content.

Section 13(a) permits reproducing, in a newspaper or periodical, or broadcasting or otherwise communicating to the public, an article published in a newspaper or periodical on current economic, political, or religious topics, or a broadcast work of the same character, without the author's authorisation, unless the right to authorise that reproduction has been expressly reserved on the copies or acknowledged in connection with an earlier broadcast of the work; section 10 separately permits quoting a short part of any published work, subject to a fair-practice and extent-justified test with source and author attribution.

Neither provision carries a headline-length or short-extract cap of its own, and no reported Tongan decision applies either to a systematic news aggregator as opposed to a single act of quotation or republication. Section 5(a) excludes any idea, procedure, system, concept, principle, discovery, or mere data from copyright protection, so a fact reported in the news carries no protection distinct from the specific words describing it, and no separate hot-news or misappropriation doctrine exists.

Neighbouring rights under Part II of the Act protect performers, phonogram producers, and broadcasting organisations, not a print or online news publisher's own reporting, so Tonga has no press-publisher right of the kind the European Union's Digital Single Market Directive Article 15 creates. No statute or reported case addresses whether a hyperlink is itself a communication to the public, or whether framing or inline display changes the answer.

The Act predates the concept of a machine-readable text-and-data-mining reservation, and its section 9 temporary-reproduction exception addresses only transient technical copies made in the course of a digital transmission, not a text and data mining (TDM)-specific opt-out.

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.