Frameworks / Barbados Data Protection Act 2019 / BB-DPA-17 Barbados Data Protection Act 2019
Part IV: Transfers of Personal Data Outside Barbados
Barbados Data Protection Act 2019 BB-DPA-17: Section 24 - Appropriate Safeguards Safeguards required for international transfers including binding corporate rules and standard clauses
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 77 controls across 58 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
EHDSREG-1 Mandatory Requirements for EHR Systems (Articles 14-29) EHDSREG-4 Digital Health Authorities, Governance, MyHealth@EU EHDSREG-5 Cross-Border Health Data Flows NDPA-1 Applicability, Scope, and Carve-Outs NDPA-7 Data Protection Assessments and Processor Contracts NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission NG-NDPA-7 Cross-Border Data Transfers and International Cooperation CH-FADP-24 Cross-border transfer safeguards FADP-10 Cross-Border Disclosure (Articles 16-18) AL-DPA-14 Direct Marketing APP-8 APP 8 - Cross-border disclosure of personal information P1-S4 Targeting and Communication AZ-DPA-12 Article 13 - Cross-border transfer LOPDP-EC-Cross-Border-Transfers-Articles-59-65-Adequacy-SCC-BCR-EU-Schrems-LatAm-CBPR-Andean-Community Ecuador LOPDP Cross-Border + Articles 59-65 + Adequacy + Andean Community + LatAm UAE-PDPL-Art.22_23_24 Cross-border data transfers (UAE PDPL Articles 22-24) GDPR-Art.45 Transfers on the basis of an adequacy decision ICP-25 Supervisory Cooperation and Coordination INCDPA-Processor-Contracts-DPA-Subprocessor-Audit-Confidentiality-EndOfContract Indiana CDPA Processor Contracts - Data Processing Agreement (DPA) + Required Provisions + Subprocessor Approval + Confidentiality + End of Contract Deletion + Audit Rights + Assistance IsraelPPL-CrossBorder-Transfer-Sec36-EU-Adequacy-Israel-Adequacy-SCCs-Reciprocity-Foreign-Recipient Israel POPL Cross-Border Transfer + Section 36 + Privacy Protection (Transfer of Data to Databases Abroad) Regulations 5761-2001 + EU Adequacy Decision (2011) + SCCs + Foreign Recipient Obligations + Reciprocity LGPD-BR-Cross-Border-International-Transfer-Article-33-Adequacy-SCC-BCR-ANPD-Approval-Mercosur-RIPD Brazil LGPD Cross-Border + Article 33 + Adequacy + SCC + BCR + Mercosur + RIPD DOM172-Cross-Border-Transfer-Article-80-Vendor-Processor-Management-Marketing-Direct-Communications-Article-23-24-26 Dominican Republic Law 172-13 Cross-Border Transfer + Vendor Management + Marketing + Articles 23-24-26-80 MTCS-Scope-SS-584-Singapore-Standards-Council-IMDA-SAC-3-Tier-2013-2015-2020-2024-Certification MTCS Scope + SS 584 + Singapore Standards Council + IMDA + SAC + 3-Tier Framework + Certification MY-PDPA-Cross-Border-Transfer-Section-129-Whitelist-Abolition-2024-Adequacy-SCC-BCR-Processor-Direct-Marketing Malaysia PDPA Cross-Border + Section 129 + Whitelist Abolition 2024 + Adequacy + SCC + BCR + Processor + Marketing MU-DPA-Enforcement-Commissioner-Section-41-43-MUR-200K-5-Year-Prison-ICT-Appeal-Tribunal-Supreme-Court Mauritius DPA Enforcement + Commissioner + Section 41 + Section 43 + MUR 200K + 5 Year Prison + ICT Appeal Tribunal + Supreme Court MX-LFPDPPP-Enforcement-INAI-Articles-63-64-67-320K-Days-Minimum-Wage-3-Year-Prison-TFJA-Recurso-Revision-SCJN Mexico LFPDPPP Enforcement + INAI + Articles 63-64-67 + 320K Days Minimum Wage + 3 Year Prison + TFJA + Recurso de Revision + SCJN MN-CDPA-Processor-Contract-Security-Section-325O-08-Pseudonymisation-Section-325O-09-De-Identification Minnesota CDPA Processor + Section 325O.08 + Security + Pseudonymisation + Section 325O.09 + De-Identification MT-CDPA-Processor-Contract-Security-MCA-30-14-2809-30-14-2811-Pseudonymisation-De-Identification Montana CDPA Processor + MCA 30-14-2809 + Security + Pseudonymisation + MCA 30-14-2811 + De-Identification NISTSP122-7 PII Sharing, Cross-Border Transfers, and Third-Party Agreements NHPA-7 Data Protection Assessments and Processor Contracts NJDPA-7 Data Protection Assessments and Processor Contracts NZISM-3 Personnel Security, Physical Security, and Cryptography NGNDPR-7 Cross-Border Transfer of Personal Data under NDPR Section 2.7-CBT OREGONCPA-7 Processor Contracts, Cross-Border Transfers, DPAs PDPASG-6 Transfer Limitation, Cross-Border Safeguards, and Data Intermediary Oversight PDPATH-6 Cross-Border Transfer and Processor Engagement POPIASA-6 Transborder Information Flows, Direct Marketing PAKPDPB-6 Cross-Border Transfer and Data Localization NORWAY-6 International Transfers and Processor Agreements NZPRV-5 IPP 11-12 Disclosure, Cross-Border Disclosure (Schedule 8) QATAR-6 Cross-Border Transfer and Processor Management RCEPEC-2 Cross-Border Transfer, Computing Facilities, Localization (12.14-15) SA-PDPL-24 Cross-border transfer safeguards IM8-CLD.4 Cloud Data Sovereignty ISMSP-PI-04 Cross-Border Transfer PIPA-Cross-Border-Transfer-Articles-28-8-28-9-Adequacy-Standard-Contract-Certification-EU Korea PIPA Cross-Border Transfer + Articles 28-8 + 28-9 + Adequacy + EU 2021 TAIWAN-4 DPIA, Privacy by Design TEXASTDPSA-3 Sensitive Data, Children, Sale Notice TURKEYKVKK-3 Special Categories and Sensitive Data UK-DPA18-LE-03 International Transfers (Law Enforcement) UKGDPRREG-3 Controller and Processor (Articles 24-43) URUGUAY-5 Database Registration with AGESIC URCDP VIETNAMPDP-3 Data Subject Rights VIRGINIAVCDPA-4 Privacy Notice and DPIA Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in Part IV: Transfers of Personal Data Outside Barbados Query this from an agent The graph holds this control, the 77 it maps to, and the evidence behind each claim, over MCP and REST.