Subscribe Login
Jamaica Observer
ePaper
The Edge 105 FM Radio Fyah 105 FM
Jamaica Observer
ePaper
The Edge 105 FM Radio Fyah 105 FM
    • Home
    • News
      • Latest News
      • Cartoon
      • International News
      • Central
      • North & East
      • Western
      • Environment
      • Health
      • #
    • Business
      • Business Bites
      • Social Love
    • Sports
      • Football
      • Basketball
      • Cricket
      • Horse Racing
      • World Champs
      • Commonwealth Games
      • FIFA World Cup 2022
      • Olympics
      • #
    • Entertainment
      • Music
      • Movies
      • Art & Culture
      • Bookends
      • #
    • Lifestyle
      • Page2
      • Food
      • Tuesday Style
      • Food Awards
      • JOL Takes Style Out
      • Design Week JA
      • Black Friday
      • #
    • All Woman
      • Home
      • Relationships
      • Features
      • Fashion
      • Fitness
      • Rights
      • Parenting
      • Advice
      • #
    • Obituaries
    • Classifieds
      • Employment
      • Property
      • Motor Vehicles
      • Place an Ad
      • Obituaries
    • More
      • Games
      • Elections
      • Jobs & Careers
      • Study Centre
      • Jnr Study Centre
      • Letters
      • Columns
      • Advertorial
      • Editorial
      • Supplements
      • Webinars
    • Home
    • News
      • Latest News
      • Cartoon
      • International News
      • Central
      • North & East
      • Western
      • Environment
      • Health
      • #
    • Business
      • Business Bites
      • Social Love
    • Sports
      • Football
      • Basketball
      • Cricket
      • Horse Racing
      • World Champs
      • Commonwealth Games
      • FIFA World Cup 2022
      • Olympics
      • #
    • Entertainment
      • Music
      • Movies
      • Art & Culture
      • Bookends
      • #
    • Lifestyle
      • Page2
      • Food
      • Tuesday Style
      • Food Awards
      • JOL Takes Style Out
      • Design Week JA
      • Black Friday
      • #
    • All Woman
      • Home
      • Relationships
      • Features
      • Fashion
      • Fitness
      • Rights
      • Parenting
      • Advice
      • #
    • Obituaries
    • Classifieds
      • Employment
      • Property
      • Motor Vehicles
      • Place an Ad
      • Obituaries
    • More
      • Games
      • Elections
      • Jobs & Careers
      • Study Centre
      • Jnr Study Centre
      • Letters
      • Columns
      • Advertorial
      • Editorial
      • Supplements
      • Webinars
  • Home
  • News
    • International News
  • Latest
  • Business
    • Business Bites
  • Cartoon
  • Games
  • Food Awards
  • Health
  • Entertainment
    • Bookends
  • Regional
  • Sports
    • Sports
    • World Cup
    • World Champs
    • Olympics
  • All Woman
  • Career & Education
  • Environment
  • Webinars
  • More
    • Football
    • Elections
    • Letters
    • Advertorial
    • Columns
    • Editorial
    • Supplements
  • Epaper
  • Classifieds
  • Design Week
Responding to a data breach in Jamaica
Akil Williams.
Business
March 11, 2026

Responding to a data breach in Jamaica

Notification requirements and risk-reduction recommendations for data controllers

TODAY, personal data has become one of the most valuable assets for organisations. Businesses, government agencies, financial institutions, and service providers collect large amounts of personal data daily, ranging from simple identifiers such as a customer’s name, phone number, and address to sensitive information like health records and biometric data.

The Data Protection Act (2020) (“DPA”) has imposed strict obligations on entities that determine how personal data is processed and for what purposes (“data controllers”), aimed at promoting transparency, ensuring personal data is adequately protected, and establishing a system that holds data controllers accountable. These obligations apply at all stages of data processing and become most critical when safeguards fail and a data breach occurs.

 

Reporting Obligations under the DPA

Under the DPA, a data controller that experiences a security breach affecting, or potentially affecting, personal data must report it to the information commissioner within 72 hours of becoming aware of the breach. The data controller should not use this72 hour period to determine whether personal data has in fact been affected or to assess the extent of such an impact. Once the security breach has the potential to affect personal data, the obligation to report arises. This report must include the following details:

1. The facts surrounding the security breach;

2. A description of the security breach, which should include:

a. the categories and number of data subjects concerned

b. the type and number of personal data concerned;

3. The measures taken or proposed to be taken to mitigate or address the possible adverse effects of the breach;

4. The consequences of the breach; and

5. The name, address and other relevant contact information of its data protection officer.

The DPA places an obligation on data controllers, in the event of a data breach, to promptly notify data subjects whose personal data is affected about the nature of the breach, the measures taken or proposed to mitigate or address potential adverse effects, and to provide the contact information of its data protection officer, including name, address, and other relevant details.

 

The importance of having a checklist

The DPA requires all data controllers to implement suitable technical and organisational measures to ensure that the information commissioner is notified promptly of any breach of the data controller’s security measures that affects or might affect personal data. Furthermore, these measures must safeguard against unauthorised or unlawful processing of personal data as well as accidental loss, destruction, or damage to personal data. As a data controller it is essential to have a checklist outlining clear steps for achieving compliance. Once a data controller identifies the purpose for processing personal data the checklist should define procedures for data collection, access, storage, retention, erasure, transfer, along with technical and organisational measures that are appropriate to that purpose.

 

Technical Measures

Technical measures are security safeguards put in place through physical controls and technological means, such as software and hardware, to protect personal data. The complexity of these technological measures, along with the costs of implementing them, should reflect the data controller’s assessment of the necessary security level to prevent harm from unauthorised or unlawful processing, as well as accidental loss, destruction, or damage of personal data, considering the nature of the data being processed. These technical measures include multi-factor authentication, pseudonymisation, encryption, and regular penetration and vulnerability testing.

 

Organisational Measures

In addition to implementing technical measures and safeguards, it is equally important for data controllers to take reasonable steps to ensure that their employees and agents with access to personal data are not only aware of, but also comply with the security measures in place. In this regard, limiting access to a customer’s personal data to only authorised employees who need it to perform their duties is a simple and effective way to prevent misuse and unauthorised disclosure. These measures will also protect the interests of both employees and customers. For example, a data controller that develops a clear and comprehensive privacy notice outlining how a data subject’s information is collected, used, shared, retained, and the lawful basis for processing it, fulfils its obligation to inform the data subject while setting clear boundaries for employee access to that information. Therefore, data controllers must recognise the importance of having documented internal policies, procedures, guidelines, restricted access controls, routine staff training, and awareness sessions. These should be supported by periodic reviews.

 

Conclusion

Ultimately, under the DPA, effective data protection requires a proactive and risk-based approach. Data breach notification requirements are vital for accountability, transparency, and protecting data subjects’ rights. Prompt and proper notification after a breach allows affected individuals to take steps to safeguard themselves, enables data controllers to evaluate whether sufficient safeguards were in place, and helps implement preventive and corrective measures to minimise both the impact of the breach and the chance of it happening again.

 

Akil Williams is an associate at Myers, Fletcher & Gordon, and is a member of the firm’s Commercial Department. Akil may be contacted via akil.williams@mfg.com.jm or www.myersfletcher.com. This article is for general information purposes only and does not constitute legal advice.

{"xml":"xml"}{"jamaica-observer":"Jamaica Observer"}
img img
0 Comments · Make a comment

ALSO ON JAMAICA OBSERVER

Ten firearms, $1.2m seized in Westmoreland raids
Latest News, News
Ten firearms, $1.2m seized in Westmoreland raids
March 10, 2026
WESTMORELAND, Jamaica –  Ten illegal firearms, including a high-powered rifle, were seized in Westmoreland on Tuesday. A combination of law enforcemen...
{"jamaica-observer":"Jamaica Observer"}
Mount Pleasant clash with Galaxy to go ahead despite visa woes, says Concacaf
Latest News, Sports
Mount Pleasant clash with Galaxy to go ahead despite visa woes, says Concacaf
March 10, 2026
LOS ANGELES, United States (AFP) — Mount Pleasant's Champions Cup clash with Los Angeles Galaxy will go ahead as planned despite a visa controversy wh...
{"jamaica-observer":"Jamaica Observer"}
Harvey Weinstein says prison is ‘hell’
International News, Latest News
Harvey Weinstein says prison is ‘hell’
March 10, 2026
LOS ANGELES, United States (AFP) — Disgraced movie mogul and convicted rapist Harvey Weinstein says life in prison is "hell" in an interview where he ...
{"jamaica-observer":"Jamaica Observer"}
Jamaicans gear up for NCAA Indoor championships
Latest News, Sports
Jamaicans gear up for NCAA Indoor championships
BY PAUL A REID Observer writer reidp@jamaicaobserver.com 
March 10, 2026
KINGSTON, Jamaica —  Twenty-two Jamaicans are set to compete in individual events at this weekend’s NCAA Division 1 and Division 2 Indoor championship...
{"jamaica-observer":"Jamaica Observer"}
Kingston Poetry Week promises blended experience for all poetry lovers
Entertainment, Latest News
Kingston Poetry Week promises blended experience for all poetry lovers
March 10, 2026
A week of multi-faceted poetry events is coming to Kingston this month, with organisers promising a treat for everyone. Founder and Managing Director ...
{"jamaica-observer":"Jamaica Observer"}
Police nab three in alleged $1m robbery
Latest News, News
Police nab three in alleged $1m robbery
March 10, 2026
ST MARY, Jamaica — Three men have been arrested for alleged involvement in a robbery where commuters experiencing car trouble were held up. Reports in...
{"jamaica-observer":"Jamaica Observer"}
Budget Debate: Regulations to be amended to ease process for life insurance companies to invest in corporate debt
Latest News, News
Budget Debate: Regulations to be amended to ease process for life insurance companies to invest in corporate debt
March 10, 2026
KINGSTON, Jamaica — Regulation 47 of the Insurance Regulation is to be simplified to make it easier for life insurance companies to invest in corporat...
{"jamaica-observer":"Jamaica Observer"}
War in the Middle East: latest developments
International News, Latest News
War in the Middle East: latest developments
March 10, 2026
WASHINGTON, United States (AFP) — Here are the latest events in the Middle East war: - Israel announces fresh strikes on Iran - Israel's military said...
{"jamaica-observer":"Jamaica Observer"}
❮ ❯

Polls

HOUSE RULES

  1. We welcome reader comments on the top stories of the day. Some comments may be republished on the website or in the newspaper; email addresses will not be published.
  2. Please understand that comments are moderated and it is not always possible to publish all that have been submitted. We will, however, try to publish comments that are representative of all received.
  3. We ask that comments are civil and free of libellous or hateful material. Also please stick to the topic under discussion.
  4. Please do not write in block capitals since this makes your comment hard to read.
  5. Please don't use the comments to advertise. However, our advertising department can be more than accommodating if emailed: advertising@jamaicaobserver.com.
  6. If readers wish to report offensive comments, suggest a correction or share a story then please email: community@jamaicaobserver.com.
  7. Lastly, read our Terms and Conditions and Privacy Policy

Recent Posts

Archives

Facebook
Twitter
Instagram
Tweets

Polls

Recent Posts

Archives

Logo Jamaica Observer
Breaking news from the premier Jamaican newspaper, the Jamaica Observer. Follow Jamaican news online for free and stay informed on what's happening in the Caribbean
Featured Tags
  • Editorial
  • Columns
  • Health
  • Auto
  • Business
  • Letters
  • Page2
  • Football
Categories
  • Business
  • Politics
  • Entertainment
  • Page2
  • Business
  • Politics
  • Entertainment
  • Page2
Ads
img
Jamaica Observer, © All Rights Reserved
  • Home
  • Contact Us
  • RSS Feeds
  • Feedback
  • Privacy Policy
  • Editorial Code of Conduct