Does the Data Protection Act apply to my business? A plain-language answer for Jamaican company directors.
This article is general information, not legal advice. For guidance specific to your firm, book an exposure check.
Most directors ask this question after receiving a letter, a client contract clause, or a WhatsApp message from someone worried about it. The honest, short answer: almost certainly yes.
The test isn't your size. It's your data.
The Data Protection Act 2020 doesn't carve out an exemption for small firms. It applies based on whether you collect, hold, or process personal data, not on how many people work for you. A five-person clinic with a filing cabinet of patient records is in scope in the same way a 500-person company is.
Ask yourself three questions instead:
- Do you keep a customer or client list with names, contact details, or financial information?
- Do you hold staff records: payroll, ID numbers, medical notes, disciplinary files?
- Do you collect information from people who aren't your employees, in order to provide a service to them?
If you answered yes to any of those, the Act applies to you. That covers most microcredit institutions, medical and dental practices, law firms, accounting firms, credit unions, and BPO subcontractors operating in Jamaica, which is exactly why these sectors come up constantly in this conversation.
What "applies to you" actually means
It doesn't mean you've done something wrong. It means the law sets standards for how you're expected to handle personal data, and depending on what you process and how, you may be required to register with the Information Commissioner's Office (OIC).
Those standards cover things like:
- Having a proper basis for collecting and using someone's data
- Not using data for a purpose beyond what people were told
- Keeping only what you need, and keeping it accurate
- Protecting it against loss, theft, or unauthorised access
- Being able to show, not just claim, that you're doing the above
None of this is exotic. Most well-run firms already do some of it out of habit. The problem is rarely that a firm is careless. It's that nothing has been written down, reviewed, or tested, so nobody, including the director, actually knows where the gaps are.
Why directors carry the responsibility
Compliance obligations under the Act sit with the organisation, and by extension with the people who direct it. It isn't something you can fully hand off to an IT provider, a receptionist who "handles the files," or a software vendor. IT support secures your systems; it doesn't establish a lawful basis for processing, write your data-handling policies, or file your registration.
That's the gap most firms don't realise they have until someone asks: a client, an auditor, an insurer, or the OIC itself.
What to do next
You don't need to guess, and you don't need to overreact. The practical first step is a structured assessment: someone reviews what data you actually hold, checks it against what the Act requires, and tells you plainly, in writing, where you stand and what, if anything, needs fixing.
That's a different exercise from hiring a lawyer for a formal opinion, and it's usually the right place to start. It's also usually faster and less expensive than directors expect.
If you're not sure whether your firm is exposed, the fastest way to find out is a short conversation, not a guess.
Book a 15-minute exposure check.
No pitch. We tell you plainly whether the Act applies to you and what it would take to fix.