Jamaica Data Protection Act 2020
JM DPA 2020 Complaints + Enforcement

Jamaica Data Protection Act 2020 JM-DPA2020-Complaints-Enforcement-Sec45-50-Investigation-Hearing-Determination-Appeal-Tribunal: Jamaica DPA 2020 Complaints + Enforcement + Sections 45-50 + Complaint Procedure + Investigation + Hearing + Determination + Compliance Orders + Administrative Penalties + Data Protection Tribunal + High Court Appeals

Sections 45-50 of the Jamaica Data Protection Act 2020 establish the complaints and enforcement framework. (1) Section 45 Right to Complain: (a) data subject may complain to OIC against controller or processor; (b) anonymous complaints accepted at OIC discretion; (c) other stakeholders + civil society may file complaints (with subject consent); (d) Commissioner may initiate investigation on own motion. (2) Section 46 Investigation Procedure: (a) preliminary review + admissibility; (b) controller/processor invited to respond; (c) formal investigation with information gathering; (d) interim orders if urgent; (e) interview of witnesses; (f) production of documents; (g) inspection of premises (with warrant or in emergency); (h) cooperation requirement; (i) Privacy of investigation balanced with transparency. (3) Section 47 Hearing: (a) formal hearing where complaint cannot be resolved informally; (b) controller/processor right to legal representation; (c) presentation of evidence; (d) cross-examination; (e) procedural fairness; (f) public or private hearing per circumstances. (4) Section 48 Determination by Commissioner: (a) finding of non-compliance + nature; (b) remedial orders; (c) cease and desist; (d) corrective measures + specific remediation; (e) administrative penalty; (f) recommendation to refer for criminal prosecution; (g) finding of compliance + dismissal of complaint. (5) Section 49 Compliance Orders: (a) Commissioner may issue Compliance Notice requiring specific actions within specified time; (b) Enforcement Notice for ongoing non-compliance; (c) Information Notice requiring production of documents; (d) Penalty Notice imposing administrative fine; (e) Non-compliance with Notice is itself an offence per Section 33; (f) right to contest Notice at Tribunal. (6) Section 50 Administrative Penalties: (a) Commissioner power to impose monetary penalties; (b) Maximum JMD 10 million per violation; (c) considerations - (i) nature + gravity + duration; (ii) intentional or negligent; (iii) measures taken to mitigate; (iv) responsibility level; (v) previous infringements; (vi) cooperation; (vii) categories of data; (viii) manner came to OIC attention; (ix) effect of penalties; (x) other factors; (d) Repeat or aggravated violations may attract maximum; (e) Penalty proceeds to OIC operating budget. (7) Section 31-33 Criminal Offences: (a) Section 31 Unauthorised Disclosure + Use - up to JMD 4 million + 4 years; (b) Section 32 Failure to Register + Provide Information - up to JMD 2 million + 2 years; (c) Section 33 Unauthorised Re-identification + Breach of Notice - up to JMD 4 million + 4 years; (d) Director + Officer Liability for corporate offences; (e) Reasonable Care defence; (f) Limitation periods + statute of limitations. (8) Appeal Mechanism: (a) Data Protection Tribunal (independent body) - first appeal; (b) High Court of Jamaica - judicial review; (c) Supreme Court of Judicature - apex appeal; (d) interim relief available; (e) stay of penalty pending appeal in most circumstances. (9) Section 52 Civil Compensation: (a) data subject right to compensation for material or non-material damage; (b) suit against controller and/or processor; (c) joint and several liability of joint controllers; (d) controller liable for processor breach unless processor solely at fault; (e) limitation period - 3 years (Limitation Act); (f) class action possible. (10) Cross-Border Enforcement: (a) Commissioner cooperation with foreign DPAs; (b) Memoranda of Understanding; (c) Joint investigations; (d) Mutual legal assistance; (e) Convention 108+ framework; (f) Caribbean Privacy Authorities Network; (g) Global Privacy Assembly cooperation. Coordinates with EU GDPR Articles 77-84 + UK DPA 2018 Tribunal + Convention 108+ Article 11 + Jamaica Limitation Act + Jamaica Charter of Fundamental Rights and Freedoms 2011 + Jamaica Constitution Section 16 + Caribbean Privacy Authorities Network + Caribbean Court of Justice + Privy Council (where applicable). Jamaica DPA 2020 Sections 45-52 applies.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 101 controls across 56 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

API 1164 · 3 controls

BSI IT-Grundschutz · 3 controls

  • BSI-03 Multi-factor authentication requirements
  • BSI-04 Remote access controls
  • BSI-05 Wireless access restrictions

IEC 62443 · 3 controls

ISO 13485 · 3 controls

ISO 27019 · 3 controls

ISO 27043 · 3 controls

ISO 27799 · 3 controls

ISO/SAE 21434 · 3 controls

Bahrain PDPL · 2 controls

  • UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7)
  • UAE-PDPL-Status UAE PDPL status, executive regulations, UAE Data Office guidance evolution

ISO/IEC 27010:2015 · 2 controls

ISO/IEC 27011:2024 · 2 controls

OWASP ASVS · 2 controls

  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management
  • DSOMM-6 Metrics, Maturity Measurement, and Continuous Improvement
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information
  • AUPRV-8 OAIC Cooperation, Vendor Management, Training, Complaints, Enforcement
  • PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight
  • PSPF24-4 Physical Security

South Korea ISMS-P · 2 controls

APPI · 1 control

  • APPI-A26 Report of Leakage to the Commission and Notification to the Person
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))

FedRAMP High · 1 control

  • AC-2 Account Management

FedRAMP Moderate · 1 control

  • AC-2 Account Management
  • 62351-8 Role-based access control (RBAC)

ISO 14001 · 1 control

  • ISO14001-03 Legal and regulatory compliance obligations

ISO 20000-1 · 1 control

ISO 22000 · 1 control

ISO 27017 · 1 control

ISO 27018 · 1 control

ISO 45001 · 1 control

ITIL 4 · 1 control

MITRE D3FEND · 1 control

  • NIS2I-6 Access Control, Asset Management, and Physical Security
  • AC-2 Account Management
  • AC-2 Account Management
  • AC-2 Account Management
  • NISTSP34-1 Contingency Planning Policy, Programme, and Plan Coordination
  • OWASPAPI-1 Broken Object Level Authorization (BOLA) and BFLA

OWASP Top 10:2025 · 1 control

  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 101 it maps to, and the evidence behind each claim, over MCP and REST.