Jamaica Data Protection Act 2020
JM DPA 2020 Joint Controller + Processor

Jamaica Data Protection Act 2020 JM-DPA2020-Joint-Controller-Processor-Sec24-25-26-Arrangements-Allocation-Responsibilities-Contracts: Jamaica DPA 2020 Joint Controllers + Processors + Sections 24-26 + Arrangements + Allocation of Responsibilities + Contracts + Records of Processing Activities (ROPA) + Sub-Processors + Vendor Management

Sections 24-26 of the Jamaica DPA 2020 establish the framework for Joint Controllers + Processors + Sub-Processors + and Records of Processing Activities. (1) Section 24 Joint Controllers: (a) two or more controllers jointly determine purposes and means of processing; (b) MUST agree in TRANSPARENT MANNER respective responsibilities for compliance + particularly regarding (i) exercise of data subject rights; (ii) Privacy Notice information; (c) arrangement made available to data subjects; (d) data subjects may exercise rights against either controller. (2) Section 25 Records of Processing Activities (ROPA): (a) MANDATORY for controllers + processors; (b) Section 25(2) Controller ROPA contents - (i) controller identity + contact details + DPO; (ii) purposes; (iii) categories of data subjects; (iv) categories of personal data; (v) categories of recipients; (vi) transfers + adequacy mechanism; (vii) retention; (viii) security measures (general description); (c) Section 25(3) Processor ROPA contents - (i) processor identity + DPO; (ii) controller identity; (iii) categories of processing; (iv) transfers + adequacy mechanism; (v) security measures; (d) Section 25(4) ROPA in writing + electronic + available to OIC on request; (e) Section 25(5) exemption for organisations under 250 employees IF processing not regular + sensitive + risk to rights. (3) Section 26 Processor Contracts: (a) processing by processor governed by contract + binding legal act; (b) Section 26(2) MANDATORY contract terms - (i) subject-matter + duration + nature + purpose; (ii) type of personal data + categories of subjects; (iii) controller obligations + rights; (iv) processor (a) processes only on documented controller instructions; (b) ensures confidentiality of authorised personnel; (c) takes Section 35 security measures; (d) respects sub-processor authorisation conditions; (e) assists controller with Section 37-43 data subject rights; (f) assists controller with Section 28-30 breach + Section 34 DPIA + Section 27 transfers; (g) deletes or returns all data at end of contract; (h) makes available information demonstrating compliance + audits; (i) immediately informs controller of unlawful instructions. (4) Sub-Processor Authorisation: (a) processor must obtain prior specific or general written authorisation; (b) general authorisation - processor informs controller of intended changes + controller may object; (c) sub-processor flow-down of contract obligations; (d) processor remains fully liable to controller for sub-processor performance. (5) Records + Audit: (a) controller right to audit processor (annual or on demand); (b) processor cooperation with controller audits + OIC audits; (c) certification (ISO 27001 + ISO 27701 + SOC 2) may demonstrate compliance + does not replace audit right. (6) Processor Becoming Controller: (a) processor processing beyond instructions becomes controller for that processing; (b) liability shifts; (c) Section 24 joint controller status may apply. (7) Inter-Group + Affiliate Processing: (a) intra-group can use processor mechanism; (b) BCR Binding Corporate Rules may simplify intra-group transfers (Section 27); (c) Section 24 joint controller for shared purposes. (8) Cloud + SaaS: (a) cloud provider often processor; (b) shared responsibility model; (c) sub-processor chain visibility; (d) cloud-region data residency for adequacy; (e) Section 26 contract clauses adapted for cloud terms. (9) Vendor Due Diligence: (a) security questionnaire + SOC 2 + ISO 27001 review; (b) financial stability; (c) reputational; (d) jurisdiction + legal regime; (e) sub-processor chain; (f) DPIA Section 34 if high-risk. (10) Penalties: (a) Section 50 administrative penalties for joint controller + processor failures; (b) Section 26 contract absence is administrative violation; (c) controller liable for processor breaches in some circumstances. Coordinates with EU GDPR Articles 26 + 28 + 30 + UK DPA 2018 + Convention 108+ + EDPB Guidelines on Controllers and Processors + ISO/IEC 27701 + Jamaica Section 22 Privacy Notice + Section 27 Transfers + Section 28-30 Breach + Section 34 DPIA + Section 35 Security. Jamaica DPA 2020 Sections 24-26 applies.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 196 controls across 52 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

GDPR · 8 controls

  • GDPR-Art.10 Processing of personal data relating to criminal convictions
  • GDPR-Art.11 Processing which does not require identification
  • GDPR-Art.15 Right of access by the data subject
  • GDPR-Art.19 Notification obligation regarding rectification, erasure or restriction
  • GDPR-Art.25 Data protection by design and by default
  • GDPR-Art.35 Data protection impact assessment
  • GDPR-Art.38 Position of the data protection officer
  • GDPR-Art.9 Processing of special categories of personal data

Bahrain PDPL · 7 controls

  • AT-DSG-10 Section 29 - Liability and right to compensation / civil jurisdiction
  • AT-DSG-11 Sections 42-45 - Data subject rights (law enforcement)
  • AT-DSG-12 Section 62 - Administrative penalties
  • AT-DSG-13 Section 36 - Scope of law enforcement processing
  • AT-DSG-14 Section 38 - Lawfulness of law enforcement processing
  • AT-DSG-7 Section 18 - Establishment of the Data Protection Authority
  • BB-DPA-1 Section 1 - Short Title
  • BB-DPA-14 Section 15 - Right to Data Portability
  • BB-DPA-16 Section 22 - General Principle for Transfers
  • BB-DPA-21 Sections 61-69 - Data Privacy Officer
  • BB-DPA-4 Section 4 - Principles Relating to Processing
  • UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10)
  • UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21)
  • UAE-PDPL-Art.25_26_27_28_29 UAE Data Office establishment, powers, penalties, complaints (UAE PDPL Articles 25-29)
  • UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5)
  • UAE-PDPL-FreeZones Coordination with DIFC, ADGM and sectoral data protection regimes

ISO/IEC 27400:2022 · 5 controls

  • 27400-5.4 Data and privacy risks
  • 27400-6.3 Secure Update Mechanism
  • 27400-7.1 Network Security for IoT
  • 27400-7.3 Data minimization and purpose limitation
  • 27400-7.4 Data retention and deletion
  • AUPRV-1 APP 1 Open and Transparent Management + Privacy Management Framework
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information
  • AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children
  • AUPRV-7 Notifiable Data Breaches (NDB) Scheme, Incident Response
  • AUPRV-8 OAIC Cooperation, Vendor Management, Training, Complaints, Enforcement

APPI · 4 controls

  • APPI-A23 Security Control Measures
  • APPI-A24 Supervision of Employees
  • APPI-A31 Provision of Personally Referable Information
  • APPI-A33 Request for Disclosure of Retained Personal Data
  • AZ-DPA-12 Article 13 - Cross-border transfer
  • AZ-DPA-14 Article 16 - Liability for violations
  • AZ-DPA-15 Article 17 - Dispute resolution
  • AZ-DPA-6 Article 6 - State regulation in personal data protection
  • AL-DPA-12 International Data Transfers
  • AL-DPA-14 Direct Marketing
  • AL-DPA-7 Right of Access
  • APP-1 APP 1 - Open and transparent management of personal information
  • APP-3 APP 3 - Collection of solicited personal information
  • APP-5 APP 5 - Notification of the collection of personal information
  • LOPDP-EC-Cross-Border-Transfers-Articles-59-65-Adequacy-SCC-BCR-EU-Schrems-LatAm-CBPR-Andean-Community Ecuador LOPDP Cross-Border + Articles 59-65 + Adequacy + Andean Community + LatAm
  • LOPDP-EC-Governance-DPO-ROPA-DPIA-Privacy-by-Design-Training-Articles-46-58-Compliance-Monitoring Ecuador LOPDP Governance + DPO + ROPA + DPIA + Privacy by Design + Training
  • LOPDP-EC-Security-Processor-Breach-Notification-Articles-37-45-Encryption-72-Hour-SPDP-Notification-CSIRT Ecuador LOPDP Security + Processor + Breach Notification + Articles 37-45 + 72-Hour

ISO 27799:2025 · 3 controls

  • ISO27799-03 Minimum necessary standard enforcement
  • ISO27799-04 Patient data de-identification procedures
  • ISO27799-05 Audit trail for ePHI access

ISO/IEC 23894:2023 · 3 controls

  • ISO23894-6.3.1 AI Risk Identification
  • ISO23894-A.1 Data Quality and Representativeness
  • ISO23894-A.5 Privacy and Data Protection in AI
  • ISO-25012-5.1 Establishing data quality requirements
  • ISO-25012-5.2 Defining data quality measures
  • ISO-25012-5.3 Planning and performing data quality evaluations

ISO/IEC 27011:2024 · 3 controls

  • 27011-5.2 Information Security Roles in Telecoms
  • 27011-6.3 Awareness and Training
  • 27011-8.6 Data protection and backup

ISO/IEC 29100:2024 · 3 controls

  • 29100-6.10 Information security
  • 29100-6.5 Use, retention and disclosure limitation
  • 29100-6.9 Accountability

ISO/IEC 29134:2023 · 3 controls

  • 29134-1 Scope
  • 29134-3 Terms and definitions
  • 29134-9.1 PIA report structure
  • DOM172-Lawful-Basis-Consent-Notice-Information-Duty-Articles-4-12-Quality-Principle-Purpose-Limitation-Minimisation Dominican Republic Law 172-13 Lawful Basis + Consent + Notice + Information Duty + Articles 4-12
  • DOM172-Security-Measures-Article-25-Encryption-Pseudonymization-Access-Control-Incident-Handling-Breach-Notification-Article-22 Dominican Republic Law 172-13 Security Measures + Article 25 + Encryption + Breach Notification
  • DOM172-Supervisory-Authority-Cooperation-Sanctions-Penalties-Articles-77-79-Awareness-Training-Retention-DPO-Designation Dominican Republic Law 172-13 Supervisory Authority + Sanctions + Articles 77-79 + DPO + Awareness
  • PAKPDPB-6 Cross-Border Transfer and Data Localization
  • PAKPDPB-7 NCPDP, Registration, Records, Processor Contracts, DPO
  • PAKPDPB-8 Enforcement, Penalties, Complaints, Retention, Training
  • IM8-DAT.2 Data Protection
  • IM8-DAT.4 Data Retention and Disposal
  • IM8-DSS.3 Secure Development Practices

South Korea ISMS-P · 3 controls

  • ISMSP-PI-01 Personal Information Collection
  • ISMSP-PI-04 Cross-Border Transfer
  • ISMSP-SYS-02 Encryption Implementation
  • DIQ-2 Data Quality Management
  • DIQ-3 Metadata Management
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • FTC-Safeguards-Scope-Defs Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2)
  • FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711)
  • FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704)
  • 27557-3 Terms and definitions
  • 27557-4.3 Individual impact consideration
  • DSOMM-2 Implementation Practices, Secure Coding, and Threat Modelling
  • DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing
  • RUSPD-1 Scope, Definitions, Principles under 152-FZ
  • RUSPD-4 Special Categories, Biometric Data
  • USMCADIGITAL-1 Cross-Border Data Flows and Localisation
  • USMCADIGITAL-2 Personal Information Protection and Consumer Protection
  • VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency
  • VERMONTAICDA-4 Vermont AG Enforcement and Cure
  • VIETNAMCYBER-2 Prohibited Acts (Access, Interception, Forgery, Content)
  • VIETNAMCYBER-4 Incident Reporting and Cooperation
  • ASD37-27 Outbound data loss prevention (Very Good)
  • DS-2 Ensure software supply chain security
  • CA-10 Selects and Develops Control Activities
  • CTDPA-1 Definitions
  • FFIEC-08 Application security controls

ISO 26000:2010 · 1 control

  • ISO-26000-6.7 Consumer issues
  • NISTPF-1 Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment
  • EHDS-HOLD-3 Dataset Descriptions and Catalogues
  • RIDTPPA-2 Consumer Rights (Access, Correction, Deletion, Portability, Opt-Out)
  • AIGF-1.3 Data Management

South Korea PIPA · 1 control

  • PIPA-Pseudonymisation-Article-28-2-3-Enforcement-PIPC-Investigation-Surcharges-3-Percent-Revenue-Article64-2 Korea PIPA Pseudonymisation + Article 28-2 + Enforcement + PIPC + Surcharges 3% + Article 63 + 64-2
  • TEFCAREC-1 Common Agreement Conformance and Onboarding
  • CPSC-CS.3 Data Protection for Safety Systems

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 196 it maps to, and the evidence behind each claim, over MCP and REST.