Law / Trinidad and Tobago

Trinidad and Tobago

8 of 9 named instruments researched to a stage, across three of the six areas of law we track: 7 in force and 1 enacted but not yet in force. As of 19 September 2026.

When they take effect7 of 8 carry a date, 1 does not. Earlier is before 2014.
Before 2014: 7 instruments (7 in force) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 0 instruments 2019: 0 instruments 2020: 0 instruments ’20 2021: 0 instruments 2022: 0 instruments 2023: 0 instruments 2024: 0 instruments 2025: 0 instruments 2026: 0 instruments ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law none researched
  2. Privacy law 5
  3. Scraping law 2
  4. Cybersecurity law none researched
  5. Age gating law none researched
  6. News aggregation law 1

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law5 instruments, 4 in force, 1 enacted but not yet in force

Research summary (151 words)

Trinidad and Tobago's personal-data statute is the Data Protection Act, 2011 (Act No. 13 of 2011, Chap. 22:04), assented to on 22 June 2011.

Only Part I and specified sections of Part II, which state the General Privacy Principles and establish the Office of the Information Commissioner, came into operation on 6 January 2012 under Legal Notice No. 2 of 2012; Part IV, which would bind private-sector organisations to those Principles, and Part V, which states the Act's offences and penalties, have not been proclaimed and are not in force.

The Principles already in force require a person handling personal information to identify the collection purpose, obtain the individual's knowledge and consent for collection, use, or disclosure, retain the information no longer than necessary, keep it accurate, protect it with appropriate safeguards, and condition any disclosure of personal information outside Trinidad and Tobago on comparable safeguards existing in the receiving jurisdiction.

Comprehensive regime

Data Protection Act, 2011

Act No. 13 of 2011 (Data Protection Act), Chap. 22:04, ss. 1-6, excluding paragraphs (h) and (l) of section 6Consolidated text of the Data Protection Act

In force since 6 January 2012. Binds public and private bodies.

What this law does

Section 1(2) brought Part I into force on 6 January 2012, together with sections 7 to 18, 22, 23, 25(1), 26 and 28 of Part II, while Part III, Part IV and Part V remain enacted but not proclaimed. Section 3 binds the State, and section 4 states the Act's object as protecting an individual's right to privacy and the right to keep sensitive personal information private and personal.

Section 5 keeps the Act from limiting information a party may obtain by law in a proceeding, a Court's power to compel testimony or production, or a judicial officer's own working notes. Section 6 states the General Privacy Principles, applicable to all persons who handle, store or process personal information belonging to another person, independent of whether Part III or Part IV has been brought into force for the body or organisation concerned.

Those Principles make an organisation responsible for the personal information under its control, require it to identify the collection purpose before or at collection, require the individual's knowledge and consent for collection, use or disclosure, limit collection to what is legally undertaken and necessary, limit retention and further disclosure to the purpose of collection, require the information to be accurate, complete and up to date, require appropriate safeguards, require organisations to make their information-handling policies available to individuals, and give the individual a right to challenge an organisation's compliance and receive a timely response.

Two further Principles are researched separately as their own families: paragraph (h) restricts processing sensitive personal information and paragraph (l) restricts disclosing personal information outside Trinidad and Tobago.

What it requires

Cross border transfer

Data Protection Act, 2011, cross border disclosure of personal information

Act 13 of 2011, ss. 6(l), 46 and 72 (cross border disclosure)Consolidated text of the Data Protection Act

In force since 6 January 2012. Binds public and private bodies.

What this law does

Section 6(l) of the General Privacy Principles already requires that personal information requested to be disclosed outside of Trinidad and Tobago be regulated, and that comparable safeguards to those under this Act exist in the receiving jurisdiction, binding every person who handles personal information regardless of whether Part III or Part IV has been proclaimed.

Section 46 would require a public body disclosing personal information to a party in another jurisdiction to tell the individual the purpose of the disclosure and the identity of the requester and the receiving jurisdiction's data protection body, and to obtain consent; where the individual withholds consent the public body would not disclose, and where the receiving jurisdiction's safeguards are in doubt the public body would refer the question to the Commissioner for a determination.

Section 72 would impose the equivalent duty on an organisation disclosing personal information under a mandatory code of conduct, again with a Commissioner referral where the organisation is not satisfied the receiving jurisdiction has comparable safeguards.

Section 28 already lets the Commissioner publish a list of countries the Commissioner considers to have comparable safeguards for personal information, which operationalises the section 6(l) principle even before sections 46 and 72 take effect.

Sections 46 and 72 are not shown as commenced: they sit in Part III and Part IV, which section 1(2) does not name among the provisions brought into force on 6 January 2012, so the detailed consent-and-referral mechanism awaits proclamation while the general section 6(l) principle already binds.

What it requires

Data subject rights

Data Protection Act, 2011, rights of access and correction

Act 13 of 2011, ss. 52-59 and 75-85 (rights of access and correction)Consolidated text of the Data Protection Act

Commencement not set. Binds public and private bodies.

What this law does

Part III, sections 52 to 59, would give every individual in Trinidad and Tobago a right of access to personal information about them held in a public body's personal information bank or otherwise under its custody or control, require the Head of a Public Body to respond within thirty days, and let an individual appeal a refusal to the Commissioner within six weeks.

Section 53 would let the Head of a Public Body refuse access where disclosure would invade another individual's privacy, reveal information supplied in confidence, reveal a confidential source of evaluative material, or fall within a Freedom of Information Act exemption, and section 68 would put the burden of proving an exemption applies on the public body.

Section 57 would give an individual a right to request correction of an error or omission, require the Head of a Public Body to annotate an unactioned correction request, and require notice of a correction to any other public body or third party the information was disclosed to in the year before the request.

Part IV, sections 75 to 85, would give the equivalent access right against an organisation subject to a mandatory code of conduct, with the same Commissioner review and complaint process, but no equivalent correction right of its own; an organisation covered by a mandatory code would instead comply with the code's own provisions.

None of Part III or Part IV is shown as commenced: section 1(2) brought only Part I and specified sections of Part II into force on 6 January 2012, so an individual currently has no statutory access or correction right against either a public body or a private organisation under this Act.

What it requires

Enforcement supervision

Data Protection Act, 2011, Commissioner, contravention and enforcement

Act 13 of 2011, ss. 7-28 and 87-96 (Commissioner, contravention and enforcement)Consolidated text of the Data Protection Act

In force since 6 January 2012. Binds public and private bodies.

What this law does

Sections 7 to 18 establish the Office of the Information Commissioner as a body corporate, provide for the appointment, tenure, removal, remuneration and oath of the Commissioner and up to two Deputy Commissioners, and give the Commissioner powers to audit and investigate compliance, order a public body or organisation to cease a contravening practice, authorise data matching, make orders on fee reasonableness and compliance with the General Privacy Principles, and publish compliance guidelines.

Section 10 gives the Commissioner functions including promoting codes of conduct, disseminating information about the Act, monitoring compliance, cooperating with counterparts in other jurisdictions, researching privacy issues, flagging a body's failure to meet the Principles or Part III or Part IV, publishing compliance reports, and reviewing privacy impact assessments.

Section 25(1) bars the Commissioner and anyone acting under the Commissioner's direction from disclosing information obtained in performing their duties, and section 28 requires the Commissioner to publish a list of countries with comparable safeguards for personal information.

All of these provisions, together with the rest of Part I, came into force on 6 January 2012, so Trinidad and Tobago currently has an operating Information Commissioner with these powers and functions, even though the Parts the Commissioner would chiefly enforce, Part III and Part IV, are not yet proclaimed.

Not commenced within Part II are the designation of inspectors (section 19), the Commissioner's power to audit or enquire pursuant to Part III (section 20) or Part IV (section 21), privileged information (section 24), the exceptions to the Commissioner's confidentiality obligation (section 25(2) and (3)), and the Commissioner's annual report to Parliament (section 27).

Part V, sections 87 to 96, would make it an offence to obstruct the Commissioner, make a false statement, fail to comply with a Commissioner order, violate the whistle-blowing protection, breach a mandatory code of conduct, wilfully disclose or unlawfully collect personal information in contravention of the Act, or breach the Commissioner's own confidentiality obligation under section 25, and would penalise an individual offender with a fine of up to $100,000 or five years' imprisonment on indictment and a body corporate with a fine of up to $500,000 on indictment or up to ten percent of annual turnover.

Part V is not shown as commenced: section 1(2) does not name it among the provisions brought into force on 6 January 2012, so none of the Act's offences or penalties currently apply, and a contravention of the General Privacy Principles, including the confidentiality obligation in section 25(1) that already binds the Commissioner's own office, cannot presently be prosecuted under this Act.

What it requires

Sensitive categories

Data Protection Act, 2011, sensitive personal information

Act 13 of 2011, ss. 6(h), 40 and 76 (sensitive personal information)Consolidated text of the Data Protection Act

In force since 6 January 2012. Binds public and private bodies.

What this law does

Section 6(h) of the General Privacy Principles states that sensitive personal information is protected from processing except where otherwise provided for by written law, and this principle binds every person who handles, stores or processes personal information regardless of whether Part III or Part IV has been proclaimed.

Sensitive personal information is defined as information on a person's racial or ethnic origins, political affiliations or trade union membership, religious or similar beliefs, physical or mental health or condition, sexual orientation or sexual life, or criminal or financial record.

Section 40 would limit a public body's processing of sensitive personal information to cases where it has the person's consent, or the information is processed by a health care professional for preventive medicine, diagnosis, treatment or hospital care management, has already been made public by the person, is processed for research under section 43, serves law enforcement or national security, determines access to social services, or another written law authorises it.

Section 76 states the equivalent limitation for a corporation, in materially the same terms as section 40 except that it does not include a law-enforcement-or-national-security ground.

Neither section 40 nor section 76 is shown as commenced: both sit in Part III and Part IV, which section 1(2) does not name among the provisions brought into force on 6 January 2012, so the detailed conditions for processing sensitive personal information await proclamation while the general prohibition in section 6(h) already binds.

What it requires

Scraping law2 instruments, 2 in force

Research summary (244 words)

Trinidad and Tobago has no scraping-specific statute, so general law governs each dimension separately.

The Computer Misuse Act, Chap. 11:17, criminalises knowingly and without authority causing a computer to perform a function to secure access to a program or data, and access is without authority where the person is not entitled to control it and lacks the consent of the person who is; unlike some computer-misuse statutes, the offence does not require defeating a technical security measure, and no reported case has tested whether reading a public, unauthenticated page satisfies it.

No Trinidadian court has ruled on the enforceability of a browsewrap or clickwrap terms-of-service against a scraper.

The Copyright Act, Chap. 82:80, protects an original collection of works or of mere data (a database) by the selection, coordination, or arrangement of its contents, which is compilation-style protection rather than a sui generis database right, and the Act predates the concept of a text-and-data-mining exception, so no such exception or opt-out mechanism exists; its general quotation and teaching-reproduction exceptions (ss.

10-11) are the closest analogues and do not reach bulk copying for model training. The Data Protection Act, 2011 would reach personal data scraped from a public Trinidadian website once its private-sector Part IV is proclaimed, but that Part has not yet been brought into force.

No Trinidadian statute or reported case establishes a scraping-specific unfair-competition, misappropriation, or trespass doctrine, and none assigns legal weight to a robots.txt directive or imposes an AI-training-specific rule.

Computer misuse

Computer Misuse Act 2000, Unauthorised Access

Act 26 of 2000 (Computer Misuse Act), Chap. 11:17, s. 3 (Unauthorised Access to Computer Program or Data)Official consolidated Act text, Ministry of Legal Affairs, reproduced by the United Nations Office on Drugs and Crime

In force since 2 November 2000. Binds public and private bodies.

What this law does

Section 3(1) prohibits knowingly and without authority causing a computer to perform any function for the purpose of securing access to a program or data held in that computer or another one, on pain of a fine of $15,000 and imprisonment for two years, rising to $30,000 and four years on a second or subsequent conviction.

Section 2(2) defines access as unauthorised where the person is not entitled to control access of that kind and does not have the consent of the person who is; the offence does not require infringing a security measure, so it is drawn more broadly than a computer-misuse statute that turns on circumvention.

Section 3(2) adds a further fine and imprisonment where the access causes damage, and section 9 enhances the penalty to $150,000 and ten years' imprisonment where the offence involves a protected computer. No reported Trinidadian case construes whether reading a public, unauthenticated page without defeating any access control falls within the section absent the consent element being read narrowly.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (212 words)

Trinidad and Tobago has no press-publisher neighbouring right and no mandatory platform-to-publisher bargaining code; the general copyright framework of the Copyright Act, Chap. 82:80, is the only law reaching an aggregator's reproduction of news content.

Its quotation exception permits, without the copyright owner's authorization, reproducing a short part of a published work, including a newspaper article, as a quotation, subject to a fair-dealing and purpose-justified-extent test and a duty to indicate the source and the author's name; the provision carries no headline-length or short-extract cap distinct from that test, and no reported Trinidadian decision applies it to a systematic news aggregator rather than an individual quoting a published work.

A collection of works or of mere data, including a compilation of news content, is separately protected where original by its selection, coordination, or arrangement, which is compilation-style protection rather than a press-publisher neighbouring right of the kind the European Union's Digital Single Market Directive Article 15 creates.

No statute or case law addresses whether a hyperlink is itself a communication to the public, or whether framing or inline display changes the answer, and no hot-news or misappropriation doctrine distinct from ordinary copyright law exists. The Act predates the concept of a machine-readable text-and-data-mining reservation, so no opt-out mechanism of that kind exists.

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.