Jamaica Data Protection Act 2020
JM DPA 2020 Standard 6 - Data Subject Rights

Jamaica Data Protection Act 2020 JM-DPA2020-Standard6-Subject-Rights-Sec37-43-Access-Correction-Erasure-Portability-Objection-Profiling-Restriction: Jamaica DPA 2020 Standard 6 - Data Subject Rights Enablement + Section 37-43 + Access Right + Correction Right + Erasure Right + Portability Right + Objection Right + Automated Decision-Making Restrictions + Profiling + Restriction Right

Standard 6 per Sections 37-43 + the Schedule of the Jamaica Data Protection Act 2020: Personal data shall be processed in accordance with the rights of data subjects under this Act. The sixth Data Protection Standard establishes comprehensive data subject rights closely modelled on EU GDPR + UK DPA 2018 + Convention 108+. (1) Section 37 Right of Access (Subject Access Request - SAR): (a) right to confirmation whether personal data being processed; (b) right to copy of personal data; (c) right to supplementary information (purposes + categories + recipients + retention + rights + sources + automated decision-making); (d) response within 30 calendar days + extension up to 60 days for complex requests; (e) free for first request per year - reasonable fee for additional or excessive; (f) Section 37(8) refusal grounds limited - manifestly unfounded + excessive + frequency disproportionate. (2) Section 38 Right of Correction (Rectification): (a) right to correct inaccurate data; (b) right to complete incomplete data; (c) 30-day response SLA; (d) notification to recipients of correction; (e) reasoned refusal + appealable. (3) Section 39 Right of Erasure (Right to be Forgotten): (a) right to erasure on grounds of (i) no longer necessary; (ii) consent withdrawn; (iii) objection upheld; (iv) unlawful processing; (v) legal obligation; (vi) child consent revocation; (b) 30-day response SLA; (c) notification to recipients; (d) restrictions per legal preservation + public interest + freedom of expression + Section 41 archival. (4) Section 40 Right to Object: (a) right to object to processing including profiling for (i) public interest task; (ii) legitimate interests; (b) controller MUST stop unless compelling legitimate grounds OR for establishment/defence of legal claims; (c) absolute right to object to direct marketing including profiling; (d) absolute right to object to scientific/historical research/statistical that does not involve public interest task. (5) Section 41 Right of Restriction: (a) right to restrict processing where (i) accuracy contested; (ii) processing unlawful but data subject opposes erasure; (iii) controller no longer needs but data subject requires for legal claims; (iv) objection pending review; (b) restricted data can only be stored + other processing requires consent or legal claim. (6) Section 42 Right to Data Portability: (a) right to receive personal data in structured + commonly used + machine-readable format; (b) right to transmit to another controller; (c) applies where processing based on consent or contract + carried out by automated means; (d) does NOT apply to processing for public interest task; (e) NOT to the right or freedoms of others. (7) Section 43 Right Not to Be Subject to Automated Decision-Making and Profiling: (a) right not to be subject to decision based SOLELY on automated processing (including profiling) which produces legal effects concerning him/her or significantly affects; (b) exceptions - explicit consent + contract performance + legal authorisation with safeguards; (c) MANDATORY safeguards including (i) human intervention; (ii) ability to express views; (iii) ability to contest decision; (d) NO solely automated decisions based on sensitive data (Section 5) except explicit consent or substantial public interest; (e) Jamaica AI Strategy alignment + emerging guidance. (8) Subject Rights Mechanism Requirements: (a) DSAR portal + verification; (b) Identity verification proportionate to risk; (c) Workflow + ticketing + SLA tracking; (d) Audit trail of requests + decisions + actions; (e) Downstream propagation; (f) DPO oversight + escalation; (g) OIC appeal; (h) Court action under Section 52. (9) Children Specific: (a) Section 7 enhanced rights; (b) Parental + guardian intervention; (c) Age-appropriate communication; (d) Special consideration for age-of-consent. (10) Penalties: (a) Section 50 administrative penalties for failure to enable rights; (b) Section 52 civil compensation for material/non-material damage; (c) JMD 10 million administrative ceiling. Coordinates with EU GDPR Articles 12-22 + UK DPA 2018 Part 3 + Convention 108+ Article 9 + ISO/IEC 27701 + EDPB Guidelines on Data Subject Rights + Jamaica Section 22 Privacy Notice + Section 24-26 Processor Contracts + Section 50-52 Penalties. Jamaica DPA 2020 Standard 6 + Sections 37-43 applies.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 84 controls across 46 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

API 1164 · 3 controls

  • API1164-17 Wireless and Field Communications
  • API1164-18 Field Device Security
  • API1164-19 Safety Instrumented Systems Interface

BSI IT-Grundschutz · 3 controls

  • BSI-18 Incident response planning and testing
  • BSI-20 Incident reporting and notification
  • BSI-21 Forensic analysis capabilities
  • IS.AR.215 Information Security Incident Response
  • IS.D.OR.225 External Reporting of Information Security Events
  • IS.I.OR.225 External Reporting
  • FFIEC-23 Regulatory reporting requirements
  • FFIEC-24 Customer notification procedures
  • FFIEC-25 Post-incident review and improvement

IEC 62443 · 3 controls

  • IEC62443-16 Incident response plan for operational disruptions
  • IEC62443-17 Recovery plan for critical systems
  • IEC62443-20 Exercises and drills for OT incidents

ISO 22320:2018 · 3 controls

  • ISO-22320-5.2 Incident management process
  • ISO-22320-B Annex B: Incident management plan structure
  • ISO-22320-C Annex C: Incident management task examples

ISO/IEC 27019:2024 · 3 controls

  • ISO27019-16 Incident response plan for operational disruptions
  • ISO27019-18 Reporting obligations to authorities
  • ISO27019-20 Exercises and drills for OT incidents

APPI · 2 controls

  • APPI-A41 Preparation and Handling of Pseudonymized Personal Information
  • APPI-A43 Preparation of Anonymized Personal Information

APRA CPS 234 · 2 controls

  • CPS234-21 Implementation of Information Security Controls
  • CPS234-25 Internal Audit Review of Information Security Controls
  • ASD37-31 Hunt to discover incidents (Very Good)
  • ASD37-33 Capture network traffic (Limited)

Bahrain PDPL · 2 controls

  • UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10)
  • UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21)

ISO/IEC 30111:2019 · 2 controls

  • 30111-3 Terms and definitions
  • 30111-5.2 Vulnerability handling team
  • D.1 Incident Response Planning
  • D.2 Incident Reporting
  • CYB-5 Cyber Incident Response Plan
  • USMTSA-2 Cybersecurity Assessment and CSO Designation
  • CPS230-13 Board Accountability for Operational Risk Management
  • 4.4.7 Emergency and Incident Response
  • BB-DPA-20 Sections 50-60 - Registration and Responsibilities
  • CA-12 Deploys Through Policies and Procedures
  • CA-ITSG33-SC-01 Security Control Catalogue
  • LOPDP-EC-Security-Processor-Breach-Notification-Articles-37-45-Encryption-72-Hour-SPDP-Notification-CSIRT Ecuador LOPDP Security + Processor + Breach Notification + Articles 37-45 + 72-Hour
  • CAT-D5-1 Incident planning and strategy
  • FTC-Safeguards-IR-Plan-BoardReporting-FTC-Notification Written Incident Response Plan + Board Reporting + FTC Breach Notification (16 CFR 314.4(h), (i), (j))
  • ISO28001-PC-04 Supply Chain Continuity Planning
  • ISO20000-11 Incident management

ISO/IEC 27010:2015 · 1 control

  • 27010-16.1 Continuity of Sharing

ISO/IEC 27400:2022 · 1 control

  • 27400-6.5 Security monitoring and incident response

ITIL 4 · 1 control

  • ITIL4-11 Incident management
  • DOM172-Security-Measures-Article-25-Encryption-Pseudonymization-Access-Control-Incident-Handling-Breach-Notification-Article-22 Dominican Republic Law 172-13 Security Measures + Article 25 + Encryption + Breach Notification
  • NGCB-6 Incident Response, 72-Hour NGCB Notification, and Independent Investigation
  • DSOMM-1 Culture, Organization, Education, and Governance

OWASP Top 10:2025 · 1 control

  • OWASPTOP10-9 A09:2025 Security Logging and Monitoring Failures
  • PAKPDPB-5 Security of Processing and Personal Data Breach Notification
  • AUPRV-7 Notifiable Data Breaches (NDB) Scheme, Incident Response
  • PSPF24-1 Security Culture, Governance, Risk Management
  • SGCYBER-1 Critical Information Infrastructure (CII) Designation and Registration

South Korea ISMS-P · 1 control

  • ISMSP-SYS-05 Incident Response
  • TEFCAREC-1 Common Agreement Conformance and Onboarding
  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)
  • VIETNAMCYBER-2 Prohibited Acts (Access, Interception, Forgery, Content)
  • VPSHR-3 Implementation Guidance and Reporting

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 84 it maps to, and the evidence behind each claim, over MCP and REST.