Subscribe Login
Jamaica Observer
ePaper
The Edge 105 FM Radio Fyah 105 FM
Jamaica Observer
ePaper
The Edge 105 FM Radio Fyah 105 FM
    • Home
    • News
      • Latest News
      • Cartoon
      • International News
      • Central
      • North & East
      • Western
      • Environment
      • Health
      • #
    • Business
      • Business Bites
      • Social Love
    • Sports
      • Football
      • Basketball
      • Cricket
      • Horse Racing
      • World Champs
      • Commonwealth Games
      • FIFA World Cup 2022
      • Olympics
      • #
    • Entertainment
      • Music
      • Movies
      • Art & Culture
      • Bookends
      • #
    • Lifestyle
      • Page2
      • Food
      • Tuesday Style
      • Food Awards
      • JOL Takes Style Out
      • Design Week JA
      • Black Friday
      • #
    • All Woman
      • Home
      • Relationships
      • Features
      • Fashion
      • Fitness
      • Rights
      • Parenting
      • Advice
      • #
    • Obituaries
    • Classifieds
      • Employment
      • Property
      • Motor Vehicles
      • Place an Ad
      • Obituaries
    • More
      • Games
      • Elections
      • Jobs & Careers
      • Study Centre
      • Jnr Study Centre
      • Letters
      • Columns
      • Advertorial
      • Editorial
      • Supplements
      • Webinars
    • Home
    • News
      • Latest News
      • Cartoon
      • International News
      • Central
      • North & East
      • Western
      • Environment
      • Health
      • #
    • Business
      • Business Bites
      • Social Love
    • Sports
      • Football
      • Basketball
      • Cricket
      • Horse Racing
      • World Champs
      • Commonwealth Games
      • FIFA World Cup 2022
      • Olympics
      • #
    • Entertainment
      • Music
      • Movies
      • Art & Culture
      • Bookends
      • #
    • Lifestyle
      • Page2
      • Food
      • Tuesday Style
      • Food Awards
      • JOL Takes Style Out
      • Design Week JA
      • Black Friday
      • #
    • All Woman
      • Home
      • Relationships
      • Features
      • Fashion
      • Fitness
      • Rights
      • Parenting
      • Advice
      • #
    • Obituaries
    • Classifieds
      • Employment
      • Property
      • Motor Vehicles
      • Place an Ad
      • Obituaries
    • More
      • Games
      • Elections
      • Jobs & Careers
      • Study Centre
      • Jnr Study Centre
      • Letters
      • Columns
      • Advertorial
      • Editorial
      • Supplements
      • Webinars
  • Home
  • News
    • International News
  • Latest
  • Business
    • Business Bites
  • Cartoon
  • Games
  • Food Awards
  • Health
  • Entertainment
    • Bookends
  • Regional
  • Sports
    • Sports
    • World Cup
    • World Champs
    • Olympics
  • All Woman
  • Career & Education
  • Environment
  • Webinars
  • More
    • Football
    • Elections
    • Letters
    • Advertorial
    • Columns
    • Editorial
    • Supplements
  • Epaper
  • Classifieds
  • Design Week
Responding to a data breach in Jamaica
Akil Williams.
Business
March 11, 2026

Responding to a data breach in Jamaica

Notification requirements and risk-reduction recommendations for data controllers

TODAY, personal data has become one of the most valuable assets for organisations. Businesses, government agencies, financial institutions, and service providers collect large amounts of personal data daily, ranging from simple identifiers such as a customer’s name, phone number, and address to sensitive information like health records and biometric data.

The Data Protection Act (2020) (“DPA”) has imposed strict obligations on entities that determine how personal data is processed and for what purposes (“data controllers”), aimed at promoting transparency, ensuring personal data is adequately protected, and establishing a system that holds data controllers accountable. These obligations apply at all stages of data processing and become most critical when safeguards fail and a data breach occurs.

 

Reporting Obligations under the DPA

Under the DPA, a data controller that experiences a security breach affecting, or potentially affecting, personal data must report it to the information commissioner within 72 hours of becoming aware of the breach. The data controller should not use this72 hour period to determine whether personal data has in fact been affected or to assess the extent of such an impact. Once the security breach has the potential to affect personal data, the obligation to report arises. This report must include the following details:

1. The facts surrounding the security breach;

2. A description of the security breach, which should include:

a. the categories and number of data subjects concerned

b. the type and number of personal data concerned;

3. The measures taken or proposed to be taken to mitigate or address the possible adverse effects of the breach;

4. The consequences of the breach; and

5. The name, address and other relevant contact information of its data protection officer.

The DPA places an obligation on data controllers, in the event of a data breach, to promptly notify data subjects whose personal data is affected about the nature of the breach, the measures taken or proposed to mitigate or address potential adverse effects, and to provide the contact information of its data protection officer, including name, address, and other relevant details.

 

The importance of having a checklist

The DPA requires all data controllers to implement suitable technical and organisational measures to ensure that the information commissioner is notified promptly of any breach of the data controller’s security measures that affects or might affect personal data. Furthermore, these measures must safeguard against unauthorised or unlawful processing of personal data as well as accidental loss, destruction, or damage to personal data. As a data controller it is essential to have a checklist outlining clear steps for achieving compliance. Once a data controller identifies the purpose for processing personal data the checklist should define procedures for data collection, access, storage, retention, erasure, transfer, along with technical and organisational measures that are appropriate to that purpose.

 

Technical Measures

Technical measures are security safeguards put in place through physical controls and technological means, such as software and hardware, to protect personal data. The complexity of these technological measures, along with the costs of implementing them, should reflect the data controller’s assessment of the necessary security level to prevent harm from unauthorised or unlawful processing, as well as accidental loss, destruction, or damage of personal data, considering the nature of the data being processed. These technical measures include multi-factor authentication, pseudonymisation, encryption, and regular penetration and vulnerability testing.

 

Organisational Measures

In addition to implementing technical measures and safeguards, it is equally important for data controllers to take reasonable steps to ensure that their employees and agents with access to personal data are not only aware of, but also comply with the security measures in place. In this regard, limiting access to a customer’s personal data to only authorised employees who need it to perform their duties is a simple and effective way to prevent misuse and unauthorised disclosure. These measures will also protect the interests of both employees and customers. For example, a data controller that develops a clear and comprehensive privacy notice outlining how a data subject’s information is collected, used, shared, retained, and the lawful basis for processing it, fulfils its obligation to inform the data subject while setting clear boundaries for employee access to that information. Therefore, data controllers must recognise the importance of having documented internal policies, procedures, guidelines, restricted access controls, routine staff training, and awareness sessions. These should be supported by periodic reviews.

 

Conclusion

Ultimately, under the DPA, effective data protection requires a proactive and risk-based approach. Data breach notification requirements are vital for accountability, transparency, and protecting data subjects’ rights. Prompt and proper notification after a breach allows affected individuals to take steps to safeguard themselves, enables data controllers to evaluate whether sufficient safeguards were in place, and helps implement preventive and corrective measures to minimise both the impact of the breach and the chance of it happening again.

 

Akil Williams is an associate at Myers, Fletcher & Gordon, and is a member of the firm’s Commercial Department. Akil may be contacted via akil.williams@mfg.com.jm or www.myersfletcher.com. This article is for general information purposes only and does not constitute legal advice.

{"xml":"xml"}{"jamaica-observer":"Jamaica Observer"}
img img
0 Comments · Make a comment

ALSO ON JAMAICA OBSERVER

Groovy start to final night of Barbados Reggae Weekend
Entertainment, Latest News, Regional
Groovy start to final night of Barbados Reggae Weekend
April 26, 2026
Patrons at Reggae in the Gardens, the third and final night of Barbados Reggae Weekend, are enjoying a groovy start to the event thanks to openers Spi...
{"jamaica-observer":"Jamaica Observer"}
Antigua’s PM says rally shooting ‘not political’, pledges tough action on gun violence
Latest News, Regional
Antigua’s PM says rally shooting ‘not political’, pledges tough action on gun violence
April 26, 2026
ST JOHN’S, Antigua (CMC) — Antiguan Prime Minister Gaston Browne has strongly condemned the shooting incident that disrupted a major political rally o...
{"jamaica-observer":"Jamaica Observer"}
Jamaican-born instructor marks 30 years teaching yoga in New York
Latest News, News
Jamaican-born instructor marks 30 years teaching yoga in New York
April 26, 2026
Long before it became fashionable, Michael Eaton was an exponent of yoga. For the devout Rastafarian, the ancient Indian discipline is more than limb-...
{"jamaica-observer":"Jamaica Observer"}
Norris Man shines during Barbados Reggae Festival
Entertainment, Latest News
Norris Man shines during Barbados Reggae Festival
April 26, 2026
Reggae singer Norris Man delivered a commanding set that resonated deeply with fans of conscious music on Friday night during the Legends of Reggae Sh...
{"jamaica-observer":"Jamaica Observer"}
ITA reports encouraging first quarter with road deaths down 33 per cent
Latest News, News
ITA reports encouraging first quarter with road deaths down 33 per cent
April 26, 2026
KINGSTON, Jamaica — The Island Traffic Authority (ITA) is reporting that 62 people have been killed in 55 fatal crashes as at the end of the first qua...
{"jamaica-observer":"Jamaica Observer"}
Michael Jackson biopic debuts atop North America box office
International News, Latest News
Michael Jackson biopic debuts atop North America box office
April 26, 2026
LOS ANGELES, United States (AFP) — "Michael," the much-anticipated biopic about late superstar Michael Jackson, debuted atop the North American box of...
{"jamaica-observer":"Jamaica Observer"}
All set for IMPACT x Mystique 2026
Latest News, News
All set for IMPACT x Mystique 2026
April 26, 2026
KINGSTON, Jamaica — The stage is set for the inaugural staging of IMPACT x Mystique 2026, a new flagship marketing conference by Mystique Integrated, ...
{"jamaica-observer":"Jamaica Observer"}
MP Samuda commends USF Connect a Child Programme as investment in students’ digital future
Latest News, News
MP Samuda commends USF Connect a Child Programme as investment in students’ digital future
April 26, 2026
ST ANN, Jamaica — Member of Parliament for St Ann North East, Matthew Samuda, has commended the Universal Service Fund (USF) for what he described as ...
{"jamaica-observer":"Jamaica Observer"}
❮ ❯

Polls

HOUSE RULES

  1. We welcome reader comments on the top stories of the day. Some comments may be republished on the website or in the newspaper; email addresses will not be published.
  2. Please understand that comments are moderated and it is not always possible to publish all that have been submitted. We will, however, try to publish comments that are representative of all received.
  3. We ask that comments are civil and free of libellous or hateful material. Also please stick to the topic under discussion.
  4. Please do not write in block capitals since this makes your comment hard to read.
  5. Please don't use the comments to advertise. However, our advertising department can be more than accommodating if emailed: advertising@jamaicaobserver.com.
  6. If readers wish to report offensive comments, suggest a correction or share a story then please email: community@jamaicaobserver.com.
  7. Lastly, read our Terms and Conditions and Privacy Policy

Recent Posts

Archives

Facebook
Twitter
Instagram
Tweets

Polls

Recent Posts

Archives

Logo Jamaica Observer
Breaking news from the premier Jamaican newspaper, the Jamaica Observer. Follow Jamaican news online for free and stay informed on what's happening in the Caribbean
Featured Tags
  • Editorial
  • Columns
  • Health
  • Auto
  • Business
  • Letters
  • Page2
  • Football
Categories
  • Business
  • Politics
  • Entertainment
  • Page2
  • Business
  • Politics
  • Entertainment
  • Page2
Ads
img
Jamaica Observer, © All Rights Reserved
  • Home
  • Contact Us
  • RSS Feeds
  • Feedback
  • Privacy Policy
  • Editorial Code of Conduct