Standard 8 per Section 27 + the Schedule of the Jamaica Data Protection Act 2020: Personal data shall not be transferred outside Jamaica unless adequate protection is provided. The eighth Data Protection Standard governs international data transfers + closely modelled on EU GDPR Chapter V. (1) Section 27 General Prohibition: transfer outside Jamaica prohibited UNLESS one of the following grounds applies (a) Adequacy Decision; (b) Appropriate Safeguards; (c) Specific Derogations; (d) Compelling Legitimate Interests (narrow). (2) Adequacy Decisions: (a) Commissioner determines third country provides adequate level of protection; (b) consideration includes (i) rule of law + respect for human rights; (ii) data protection legislation + enforcement; (iii) supervisory authority independence; (iv) international commitments; (v) Convention 108+ accession; (c) Commissioner has discretion + may issue partial or sectoral adequacy; (d) emerging Caribbean Community adequacy via CARICOM mechanism; (e) EU GDPR adequacy decisions used as reference. (3) Appropriate Safeguards per Section 27 + emerging regulations: (a) Standard Contractual Clauses (SCCs) approved by Commissioner; (b) Binding Corporate Rules (BCRs) approved by Commissioner; (c) Code of Conduct approved + binding; (d) Certification mechanism approved; (e) Legally binding instrument between public authorities; (f) Ad hoc contractual clauses authorised by Commissioner. (4) Specific Derogations for individual transfers: (a) Explicit consent of data subject (informed of risks); (b) Necessary for performance of contract with data subject; (c) Necessary for conclusion + performance of contract in data subject's interest; (d) Important reasons of public interest; (e) Establishment + exercise + defence of legal claims; (f) Vital interests where data subject incapable of consent; (g) Public register transfers (limited); (h) Compelling legitimate interests (limited scope + Commissioner notification). (5) US-Specific Transfer Concerns: (a) post-Schrems II considerations; (b) US surveillance laws (FISA Section 702 + Executive Order 12333) impact on transfers; (c) EU-US Data Privacy Framework reference; (d) Transfer Impact Assessment (TIA) recommended. (6) Caribbean Regional Data Flows: (a) CARICOM Single Market and Economy considerations; (b) regional integration data transfer easements emerging; (c) bilateral arrangements between CARICOM member states; (d) Jamaica-Trinidad-Barbados emerging coordination. (7) Cloud-Based Processing: (a) hyperscaler cloud (AWS + Azure + GCP) with data residency in Jamaica/Caribbean increasingly available; (b) data export to processor in adequacy jurisdiction; (c) sub-processor chain transparency required; (d) Section 26 processor contracts including transfer mechanisms. (8) Transfer Impact Assessment (TIA): (a) risk assessment for each transfer destination; (b) legal regime evaluation; (c) supplementary measures (encryption + pseudonymisation + access restriction); (d) periodic review; (e) Commissioner consultation for high-risk. (9) Section 27 Implementation Mechanics: (a) Data Map - which data flows to where; (b) Transfer Inventory + lawful basis tracking; (c) DPIA Section 34 triggered for international transfers; (d) Data Processing Agreement clauses for transfers; (e) Notification to data subject in Privacy Notice (Section 22). (10) Penalties: (a) Section 50 administrative penalties for unlawful transfers; (b) Section 31 unauthorised disclosure overlap; (c) civil compensation; (d) injunctive relief by Commissioner. Coordinates with EU GDPR Chapter V Articles 44-50 + UK DPA 2018 + Convention 108+ Article 14 + Caribbean Community CARICOM + Commonwealth + OECD Trans-Border Data Flow Declaration + Jamaica Section 26 Processor + Section 22 Privacy Notice + Section 34 DPIA. Jamaica DPA 2020 Standard 8 + Section 27 applies.
This control maps to 131 controls across 43 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 131 it maps to, and the evidence behind each claim, over MCP and REST.