Jamaica Data Protection Act 2020
JM DPA 2020 Standard 8 - International Transfers

Jamaica Data Protection Act 2020 JM-DPA2020-Standard8-Transfers-Outside-Jamaica-Sec27-Adequacy-Decisions-Standard-Contractual-Clauses-BCR-Derogations: Jamaica DPA 2020 Standard 8 - Transfers Outside Jamaica + Section 27 + Adequacy Decisions + Standard Contractual Clauses + Binding Corporate Rules + Derogations + Cross-Border Data Flows + Caribbean Community + International Data Privacy

Standard 8 per Section 27 + the Schedule of the Jamaica Data Protection Act 2020: Personal data shall not be transferred outside Jamaica unless adequate protection is provided. The eighth Data Protection Standard governs international data transfers + closely modelled on EU GDPR Chapter V. (1) Section 27 General Prohibition: transfer outside Jamaica prohibited UNLESS one of the following grounds applies (a) Adequacy Decision; (b) Appropriate Safeguards; (c) Specific Derogations; (d) Compelling Legitimate Interests (narrow). (2) Adequacy Decisions: (a) Commissioner determines third country provides adequate level of protection; (b) consideration includes (i) rule of law + respect for human rights; (ii) data protection legislation + enforcement; (iii) supervisory authority independence; (iv) international commitments; (v) Convention 108+ accession; (c) Commissioner has discretion + may issue partial or sectoral adequacy; (d) emerging Caribbean Community adequacy via CARICOM mechanism; (e) EU GDPR adequacy decisions used as reference. (3) Appropriate Safeguards per Section 27 + emerging regulations: (a) Standard Contractual Clauses (SCCs) approved by Commissioner; (b) Binding Corporate Rules (BCRs) approved by Commissioner; (c) Code of Conduct approved + binding; (d) Certification mechanism approved; (e) Legally binding instrument between public authorities; (f) Ad hoc contractual clauses authorised by Commissioner. (4) Specific Derogations for individual transfers: (a) Explicit consent of data subject (informed of risks); (b) Necessary for performance of contract with data subject; (c) Necessary for conclusion + performance of contract in data subject's interest; (d) Important reasons of public interest; (e) Establishment + exercise + defence of legal claims; (f) Vital interests where data subject incapable of consent; (g) Public register transfers (limited); (h) Compelling legitimate interests (limited scope + Commissioner notification). (5) US-Specific Transfer Concerns: (a) post-Schrems II considerations; (b) US surveillance laws (FISA Section 702 + Executive Order 12333) impact on transfers; (c) EU-US Data Privacy Framework reference; (d) Transfer Impact Assessment (TIA) recommended. (6) Caribbean Regional Data Flows: (a) CARICOM Single Market and Economy considerations; (b) regional integration data transfer easements emerging; (c) bilateral arrangements between CARICOM member states; (d) Jamaica-Trinidad-Barbados emerging coordination. (7) Cloud-Based Processing: (a) hyperscaler cloud (AWS + Azure + GCP) with data residency in Jamaica/Caribbean increasingly available; (b) data export to processor in adequacy jurisdiction; (c) sub-processor chain transparency required; (d) Section 26 processor contracts including transfer mechanisms. (8) Transfer Impact Assessment (TIA): (a) risk assessment for each transfer destination; (b) legal regime evaluation; (c) supplementary measures (encryption + pseudonymisation + access restriction); (d) periodic review; (e) Commissioner consultation for high-risk. (9) Section 27 Implementation Mechanics: (a) Data Map - which data flows to where; (b) Transfer Inventory + lawful basis tracking; (c) DPIA Section 34 triggered for international transfers; (d) Data Processing Agreement clauses for transfers; (e) Notification to data subject in Privacy Notice (Section 22). (10) Penalties: (a) Section 50 administrative penalties for unlawful transfers; (b) Section 31 unauthorised disclosure overlap; (c) civil compensation; (d) injunctive relief by Commissioner. Coordinates with EU GDPR Chapter V Articles 44-50 + UK DPA 2018 + Convention 108+ Article 14 + Caribbean Community CARICOM + Commonwealth + OECD Trans-Border Data Flow Declaration + Jamaica Section 26 Processor + Section 22 Privacy Notice + Section 34 DPIA. Jamaica DPA 2020 Standard 8 + Section 27 applies.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 131 controls across 43 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

GDPR · 6 controls

  • GDPR-Art.10 Processing of personal data relating to criminal convictions
  • GDPR-Art.11 Processing which does not require identification
  • GDPR-Art.15 Right of access by the data subject
  • GDPR-Art.19 Notification obligation regarding rectification, erasure or restriction
  • GDPR-Art.45 Transfers on the basis of an adequacy decision
  • GDPR-Art.9 Processing of special categories of personal data
  • APP-1 APP 1 - Open and transparent management of personal information
  • APP-3 APP 3 - Collection of solicited personal information
  • APP-5 APP 5 - Notification of the collection of personal information
  • APP-8 APP 8 - Cross-border disclosure of personal information

Bahrain PDPL · 4 controls

  • BB-DPA-14 Section 15 - Right to Data Portability
  • BB-DPA-16 Section 22 - General Principle for Transfers
  • BB-DPA-17 Section 24 - Appropriate Safeguards
  • BB-DPA-21 Sections 61-69 - Data Privacy Officer

APPI · 3 controls

  • APPI-A23 Security Control Measures
  • APPI-A24 Supervision of Employees
  • APPI-A33 Request for Disclosure of Retained Personal Data
  • AT-DSG-11 Sections 42-45 - Data subject rights (law enforcement)
  • AT-DSG-13 Section 36 - Scope of law enforcement processing
  • AT-DSG-14 Section 38 - Lawfulness of law enforcement processing

ISO/IEC 29100:2024 · 3 controls

ISO/IEC 29134:2023 · 3 controls

  • AUPRV-3 APP 6-9 Use/Disclosure, Direct Marketing, Cross-Border, Government Identifiers
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information
  • AUPRV-7 Notifiable Data Breaches (NDB) Scheme, Incident Response
  • EHDSREG-1 Mandatory Requirements for EHR Systems (Articles 14-29)
  • EHDSREG-4 Digital Health Authorities, Governance, MyHealth@EU
  • EHDSREG-5 Cross-Border Health Data Flows

South Korea ISMS-P · 3 controls

  • FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711)
  • FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704)

ISO/IEC 27014:2020 · 2 controls

ISO/IEC 27400:2022 · 2 controls

  • PAKPDPB-6 Cross-Border Transfer and Data Localization
  • PAKPDPB-8 Enforcement, Penalties, Complaints, Retention, Training
  • RUSPD-1 Scope, Definitions, Principles under 152-FZ
  • RUSPD-4 Special Categories, Biometric Data
  • DS-2 Ensure software supply chain security
  • CA-10 Selects and Develops Control Activities
  • ICP-25 Supervisory Cooperation and Coordination

ISO/IEC 23894:2023 · 1 control

  • NISTPF-1 Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment
  • RIDTPPA-2 Consumer Rights (Access, Correction, Deletion, Portability, Opt-Out)

South Korea PIPA · 1 control

  • TEFCAREC-1 Common Agreement Conformance and Onboarding
  • USCOPPA-3 Data Minimisation, Retention, Erasure (Eraser Button)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 131 it maps to, and the evidence behind each claim, over MCP and REST.