Jamaica Data Protection Act 2020
JM DPA 2020 Breach Notification

Jamaica Data Protection Act 2020 JM-DPA2020-Breach-Notification-Sec28-30-Duty-Notify-Commissioner-Affected-Subjects-72-Hours-Severe: Jamaica DPA 2020 Personal Data Breach Notification + Sections 28-30 + Duty to Notify Commissioner + Affected Subjects + 72-Hour Reporting + High Risk + Severe + Mitigation + Documentation

Sections 28-30 of the Jamaica Data Protection Act 2020 establish the Personal Data Breach Notification framework. (1) Section 28 Personal Data Breach Definition: (a) breach of security leading to accidental or unlawful (i) destruction; (ii) loss; (iii) alteration; (iv) unauthorised disclosure; (v) access to personal data; (b) covers all data states - at rest + in transit + in use; (c) covers both technical (cyber) + human (insider + negligence) + physical (theft + loss); (d) covers controller + processor breaches. (2) Section 28(2) Duty to Notify Commissioner: (a) NOTIFICATION REQUIRED to OIC without undue delay + WHERE FEASIBLE within 72 HOURS of becoming aware; (b) if delayed beyond 72 hours - reasons must accompany notification; (c) phased notification allowed if full information not available; (d) ongoing updates as investigation progresses. (3) Section 29 Notification Information Required: (a) nature of the breach (i) categories of affected data subjects + approximate numbers; (ii) categories of personal data records + approximate numbers; (b) DPO contact details; (c) likely consequences of the breach; (d) measures taken or proposed to address the breach + mitigate its possible adverse effects. (4) Section 30 Notification to Affected Data Subjects: (a) WHERE BREACH LIKELY TO RESULT IN HIGH RISK to data subject rights and freedoms; (b) WITHOUT UNDUE DELAY; (c) in clear and plain language; (d) Section 30(2) Information - nature of breach + DPO contact + consequences + measures; (e) Section 30(3) Exemptions - if controller implemented appropriate technical/organisational measures rendering data unintelligible (e.g. encryption); if controller subsequently mitigated risk; if would involve disproportionate effort + public communication instead; (f) Commissioner may require notification if not done. (5) Section 28(3) Processor Obligations: (a) processor must notify controller WITHOUT UNDUE DELAY of breach; (b) controller then has 72-hour OIC SLA; (c) Section 26 contract should specify breach notification mechanism. (6) Documentation Requirement per Section 28(5): (a) ALL BREACHES documented regardless of notification threshold; (b) facts + effects + remedial action; (c) enables OIC compliance verification; (d) supports trend analysis + organisational learning. (7) Risk Assessment per Section 30: (a) likelihood + severity assessment; (b) factors include - type of breach + nature/sensitivity/volume of data + ease of identification + severity of consequences + special characteristics of subjects (children/vulnerable) + special characteristics of controller; (c) ENISA + EDPB methodology + WP29 guidelines; (d) Privacy Risk Score frameworks. (8) Cross-Border Breach Notification: (a) if affected data subjects in multiple jurisdictions - notify each Supervisory Authority; (b) lead Supervisory Authority concept where applicable; (c) Commissioner liaison with foreign DPAs; (d) Caribbean + Commonwealth + EU coordination. (9) Breach Response Lifecycle: (a) detection - SIEM + DLP + EDR + insider threat + user reports; (b) containment - isolation + access revocation + system shutdown + business continuity; (c) assessment - scope + impact + risk classification; (d) notification - OIC + subjects + others; (e) eradication - root cause + fix + patches; (f) recovery - restore + monitor; (g) lessons learned - post-mortem + report + improvement. (10) Penalties for Notification Failures: (a) Section 50 administrative penalties up to JMD 10M; (b) Section 31 unauthorised disclosure - up to JMD 4M + 4 years; (c) Section 52 civil compensation; (d) reputational damage + customer churn; (e) potential class action under Section 52. Coordinates with EU GDPR Articles 33 + 34 + UK DPA 2018 + Convention 108+ Article 7(2) + EDPB/WP29 Guidelines on Personal Data Breach Notification + ENISA Methodology + ISO/IEC 27035 + NIST SP 800-61 + Jamaica Section 26 Processor + Section 22 Privacy Notice + Section 25 ROPA + Section 34 DPIA + Section 35 Security + Jamaica Cyber Incident Response Team (Ja-CIRT) coordination + FSC + BoJ cyber breach reporting. Jamaica DPA 2020 Sections 28-30 applies.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 122 controls across 41 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

GDPR · 6 controls

  • GDPR-Art.10 Processing of personal data relating to criminal convictions
  • GDPR-Art.11 Processing which does not require identification
  • GDPR-Art.15 Right of access by the data subject
  • GDPR-Art.19 Notification obligation regarding rectification, erasure or restriction
  • GDPR-Art.20 Right to data portability
  • GDPR-Art.9 Processing of special categories of personal data

APPI · 4 controls

  • APPI-A23 Security Control Measures
  • APPI-A24 Supervision of Employees
  • APPI-A27 Restriction on Provision to Third Parties
  • APPI-A33 Request for Disclosure of Retained Personal Data

Bahrain PDPL · 4 controls

  • UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10)
  • UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21)
  • UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5)
  • UAE-PDPL-Art.8 Records of processing activities (UAE PDPL Article 8)
  • APP-1 APP 1 - Open and transparent management of personal information
  • APP-3 APP 3 - Collection of solicited personal information
  • APP-5 APP 5 - Notification of the collection of personal information
  • AT-DSG-11 Sections 42-45 - Data subject rights (law enforcement)
  • AT-DSG-13 Section 36 - Scope of law enforcement processing
  • AT-DSG-14 Section 38 - Lawfulness of law enforcement processing
  • AZ-DPA-12 Article 13 - Cross-border transfer
  • AZ-DPA-14 Article 16 - Liability for violations
  • AZ-DPA-15 Article 17 - Dispute resolution
  • BB-DPA-14 Section 15 - Right to Data Portability
  • BB-DPA-16 Section 22 - General Principle for Transfers
  • BB-DPA-21 Sections 61-69 - Data Privacy Officer

ISO/IEC 29100:2024 · 3 controls

  • 29100-6.10 Information security
  • 29100-6.5 Use, retention and disclosure limitation
  • 29100-6.9 Accountability

ISO/IEC 29134:2023 · 3 controls

  • 29134-1 Scope
  • 29134-3 Terms and definitions
  • 29134-9.1 PIA report structure
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information
  • AUPRV-5 APP 12-13 Access and Correction of Personal Information
  • AUPRV-7 Notifiable Data Breaches (NDB) Scheme, Incident Response

South Korea ISMS-P · 3 controls

  • ISMSP-PI-01 Personal Information Collection
  • ISMSP-PI-04 Cross-Border Transfer
  • ISMSP-SYS-02 Encryption Implementation
  • LOPDP-EC-Data-Subject-Rights-Access-Rectification-Erasure-Object-Portability-Automated-Decisions-Articles-16-27 Ecuador LOPDP Data Subject Rights + Access + Rectification + Erasure + Articles 16-27
  • LOPDP-EC-Security-Processor-Breach-Notification-Articles-37-45-Encryption-72-Hour-SPDP-Notification-CSIRT Ecuador LOPDP Security + Processor + Breach Notification + Articles 37-45 + 72-Hour
  • FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711)
  • FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704)

ISO/IEC 27400:2022 · 2 controls

  • 27400-5.4 Data and privacy risks
  • 27400-7.3 Data minimization and purpose limitation
  • 27557-3 Terms and definitions
  • 27557-4.3 Individual impact consideration
  • DOM172-Data-Subject-ARCO-Rights-Habeas-Data-Action-Constitutional-Article-70-Access-Rectification-Cancellation-Opposition Dominican Republic Law 172-13 ARCO Rights + Habeas Data Action + Constitutional Article 70
  • DOM172-Lawful-Basis-Consent-Notice-Information-Duty-Articles-4-12-Quality-Principle-Purpose-Limitation-Minimisation Dominican Republic Law 172-13 Lawful Basis + Consent + Notice + Information Duty + Articles 4-12
  • PAKPDPB-3 Data Subject Rights
  • PAKPDPB-8 Enforcement, Penalties, Complaints, Retention, Training
  • RUSPD-1 Scope, Definitions, Principles under 152-FZ
  • RUSPD-4 Special Categories, Biometric Data
  • 502 Interoperability with Assistive Technology
  • 707 Real-Time Text Functionality
  • USMCADIGITAL-1 Cross-Border Data Flows and Localisation
  • USMCADIGITAL-2 Personal Information Protection and Consumer Protection
  • VERMONTAICDA-1 AI System Inventory and Risk Assessment
  • VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency
  • VIETNAMCYBER-2 Prohibited Acts (Access, Interception, Forgery, Content)
  • VIETNAMCYBER-4 Incident Reporting and Cooperation
  • AL-DPA-12 International Data Transfers
  • DS-2 Ensure software supply chain security
  • CA-10 Selects and Develops Control Activities
  • CTDPA-1 Definitions
  • DIQ-1 Data Integration and Interoperability
  • FTC-Safeguards-Scope-Defs Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2)
  • ISO8000-MDG-01 Master Data Quality

ISO/IEC 23894:2023 · 1 control

  • ISO23894-A.5 Privacy and Data Protection in AI
  • NISTPF-1 Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment
  • RIDTPPA-2 Consumer Rights (Access, Correction, Deletion, Portability, Opt-Out)
  • IM8-DAT.3 Data Sharing and Transfer

South Korea PIPA · 1 control

  • PIPA-Pseudonymisation-Article-28-2-3-Enforcement-PIPC-Investigation-Surcharges-3-Percent-Revenue-Article64-2 Korea PIPA Pseudonymisation + Article 28-2 + Enforcement + PIPC + Surcharges 3% + Article 63 + 64-2
  • TEFCAREC-1 Common Agreement Conformance and Onboarding
  • CPSC-STD.4 Interoperability Safety

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 122 it maps to, and the evidence behind each claim, over MCP and REST.