Jamaica Data Protection Act 2020
JM DPA 2020 Standard 3 - Data Minimisation

Jamaica Data Protection Act 2020 JM-DPA2020-Standard3-Adequacy-Relevance-Necessity-Sec21-Data-Minimisation-No-Excess-Processing: Jamaica DPA 2020 Standard 3 - Adequacy + Relevance + Necessity + Section 21 + Data Minimisation + No Excess Processing + Proportionality + Privacy by Default + Field-Level Restraint + Granular Permissions

Standard 3 per Section 21 + the Schedule of the Jamaica Data Protection Act 2020: Personal data shall be adequate + relevant + and necessary in relation to the purposes for which they are processed (Data Minimisation Principle). The third Data Protection Standard requires the LEAST amount of personal data that achieves the legitimate purpose - no more + no less + no longer. (1) Adequate: data must be sufficient to achieve the purpose - not so little that purpose cannot be properly served; (a) operational completeness; (b) decision-quality data; (c) avoid scenarios where insufficient data leads to harmful outcomes (e.g. credit denial based on incomplete record). (2) Relevant: data must relate directly to the purpose; (a) NOT collected because it might be useful later; (b) NOT collected because the form has an empty field; (c) NOT collected to enable future expansion. (3) Necessary: data must be required to achieve the purpose; (a) NECESSITY test - could the purpose be achieved without this data?; (b) considered alternatives - aggregation + pseudonymisation + synthetic data; (c) Field-Level scrutiny - each data field justified individually. (4) Privacy by Default per Section 34: (a) least-privacy settings by default; (b) data minimisation as default option; (c) opt-IN rather than opt-OUT for additional data sharing; (d) minimum retention + minimum access + minimum scope. (5) Implementation Mechanisms: (a) Field-Level review at design + change time - is each field necessary?; (b) Form Design - minimum required fields + clear optional vs mandatory; (c) API Design - request only required fields + GraphQL field selection; (d) Database Schema - avoid wide tables + use views for purpose-restricted access; (e) Photo capture - blur or crop background containing other data subjects; (f) Audio - confine to necessary participants; (g) Location data - precise vs approximate vs coarse; (h) Identifier choices - pseudonymous IDs over direct identifiers; (i) De-identification + Anonymisation at appropriate stages. (6) Excess Data Risks: (a) Increased breach impact - more data lost in breach; (b) Increased Subject Access Request burden; (c) Increased retention cost + storage; (d) Increased legal liability + regulatory risk; (e) Increased third-party exposure. (7) Children Specific: (a) Section 7 enhanced minimisation for children; (b) NO collection of data not strictly necessary for safety + service; (c) NO behavioural advertising profiling under age 18; (d) age-appropriate design code emerging. (8) Sensitive Data Specific: (a) Section 5 sensitive data requires explicit justification per field; (b) genetic + biometric + health data with highest necessity bar; (c) avoid collection where less-sensitive alternative serves purpose. (9) Audit Mechanisms: (a) Data Inventory + Field-Level catalogue; (b) Periodic minimisation review (annually + per material change); (c) DPIA Section 34 examination of minimisation; (d) DPO oversight; (e) Privacy Engineering pattern - Privacy by Design and Default. (10) Vendor + Processor: (a) processor must NOT collect more data than necessary; (b) DPA Article 28-equivalent + Jamaica Section 26 processor contract; (c) sub-processor minimisation chain. Coordinates with EU GDPR Article 5(1)(c) + UK DPA 2018 + Convention 108+ Article 5(4)(c) + OECD Privacy Guidelines Principle 1 + ISO/IEC 29100 + ISO/IEC 27701 + EDPB Guidelines on Data Protection by Design and Default + Jamaica Section 34 DPIA + Section 22 Privacy Notice. Jamaica DPA 2020 Standard 3 + Section 21 applies.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.