Barbados Data Protection Act 2019
The Barbados Data Protection Act 2019 (Cap. 380A) establishes a data protection framework for Barbados. The Data Protection Commissioner oversees compliance. The Act establishes processing principles, individual rights, and provisions for cross-border transfers. Modelled on Caribbean Community (CARICOM) model data protection legislation. Applies to the processing of personal data by controllers in Barbados.
Get the official standard — this page is an AI-assisted companion tool, not a replacement for the authoritative text.
Visit oag.gov.bbFramework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (8)
Part I: Preliminary
| Code | Title |
|---|---|
| BB-DPA-1 | Section 1 - Short Title |
| BB-DPA-2 | Section 2 - Interpretation |
| BB-DPA-3 | Section 3 - Application of Act |
Part II: Data Protection Principles
| Code | Title |
|---|---|
| BB-DPA-4 | Section 4 - Principles Relating to Processing |
| BB-DPA-5 | Section 5 - Fairness of Processing |
| BB-DPA-6 | Section 6 - Lawfulness of Processing |
| BB-DPA-7 | Section 7 - Conditions for Consent |
| BB-DPA-8 | Section 8 - Child's Consent |
| BB-DPA-9 | Section 9 - Sensitive Personal Data |
Part III: Rights of a Data Subject
| Code | Title |
|---|---|
| BB-DPA-10 | Section 10 - Right of Access |
| BB-DPA-11 | Section 11 - Right to Rectification |
| BB-DPA-12 | Section 12 - Right to Erasure |
| BB-DPA-13 | Section 13 - Right to Restriction of Processing |
| BB-DPA-14 | Section 15 - Right to Data Portability |
| BB-DPA-15 | Section 18 - Automated Decision-Making Including Profiling |
Part IV: Transfers of Personal Data Outside Barbados
| Code | Title |
|---|---|
| BB-DPA-16 | Section 22 - General Principle for Transfers |
| BB-DPA-17 | Section 24 - Appropriate Safeguards |
| BB-DPA-18 | Section 25 - Binding Corporate Rules |
Part V: Exemptions
| Code | Title |
|---|---|
| BB-DPA-19 | Sections 29-49 - General Exemptions |
Part VI: Data Controller and Data Processor
| Code | Title |
|---|---|
| BB-DPA-20 | Sections 50-60 - Registration and Responsibilities |
| BB-DPA-21 | Sections 61-69 - Data Privacy Officer |
Part VII: Data Protection Commissioner
| Code | Title |
|---|---|
| BB-DPA-22 | Sections 70-75 - Commissioner Functions |
Part VIII: Enforcement
| Code | Title |
|---|---|
| BB-DPA-23 | Sections 76-89 - Enforcement Provisions |
Your Compliance Coverage
If you comply with Barbados Data Protection Act 2019, you already cover:
Rwanda Law No. 058/2021 Relating to the Protection of Personal Data
57%
13 controls mapped
Compare →GDPR
52%
12 controls mapped
Compare →NIS2 Directive
39%
9 controls mapped
Compare →+ 495 more: Serbia Law on Personal Data Protection (2018) (39%), Singapore Payment Services Act (PSA) - Digital Payment Token Regulation (35%)
See all 498 mapped frameworks ↓Maps to 498 other frameworks
Frequently Asked Questions
What is Barbados Data Protection Act 2019?
Barbados Data Protection Act 2019 is a compliance framework from Barbados with 8 domains and 23 controls. The Barbados Data Protection Act 2019 (Cap. 380A) establishes a data protection framework for Barbados. The Data Protection Commissioner oversees compliance. The Act establishes processing principles, individual rights, and provisions for cross-border transfers. Modelled on Caribbean Community (CARICOM) model data protection legislation. Applies to the processing of personal data by controllers in Barbados. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Barbados Data Protection Act 2019 have?
Barbados Data Protection Act 2019 has 23 controls organised across 8 domains. The largest domains are Part II: Data Protection Principles (6 controls), Part III: Rights of a Data Subject (6 controls), Part I: Preliminary (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Barbados Data Protection Act 2019 map to?
Barbados Data Protection Act 2019 maps to 498 other compliance frameworks. The top mapping partners are Rwanda Law No. 058/2021 Relating to the Protection of Personal Data (57% coverage), GDPR (52% coverage), NIS2 Directive (39% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Barbados Data Protection Act 2019 compliance?
Start your Barbados Data Protection Act 2019 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Barbados Data Protection Act 2019 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 23 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.
Get Started Free →Free forever — no credit card required