Know exactly where you stand under the Data Protection Act.
The DPA 2020 sets out specific standards for how Jamaican firms must handle personal data. COMPLY tells you, in writing, whether you meet them, and fixes what doesn't.
What the Act requires of a firm like yours.
If you hold personal data on customers, patients, clients, or staff, the Act sets standards for how that data is collected, used, stored, and protected. This is a descriptive summary, not a substitute for the statute itself:
Fair and lawful processing
Personal data is collected and used on a proper basis, and people know it's happening.
Purpose limitation
Data collected for one reason isn't quietly repurposed for another.
Data minimisation
You hold what you need, not everything you could.
Accuracy
Records are kept correct and current.
Storage limitation
Data isn't kept indefinitely once its purpose has passed.
Security and confidentiality
Data is protected against loss, misuse, and unauthorised access.
Accountability
You can show, not just claim, that the above is true.
What non-compliance means.
Registration and compliance obligations under the Act are enforceable by the Information Commissioner's Office, which has powers of investigation and enforcement. Responsibility for compliance sits with the firm's directors, not with an IT provider or a junior staff member. Most firms don't find out where they stand until something has already gone wrong.
What COMPLY includes.
Gap review
A structured review of your current data handling against the Act's standards.
Data inventory
A record of what personal data you hold, where it lives, and who can reach it.
OIC registration filing support
We prepare and support the filing of your registration with the Information Commissioner's Office, where required.
Policy pack
The written policies a compliant firm needs, in plain language your staff will actually read.
Executive briefing
A short session with your leadership covering findings, exposure, and what to do next.
From US$3,500fixed fee
- Delivered in 2–3 weeks.
- No hourly billing. One fee, one scope, one deliverable.
Before you book.
We're too small for this to apply to us.+
Size isn't the test; holding personal data is. A five-person clinic with patient files is in scope the same way a 500-person company is. The assessment tells you precisely what your size and sector require.
Our IT company already handles this.+
IT support and data-protection compliance are different disciplines. An IT provider secures your systems; the Act requires documented policies, a lawful basis for processing, and, often, formal registration. Most IT contracts don't cover any of that.
What if the assessment finds problems?+
It's designed to. Finding the gaps while they're still just gaps, not incidents, is the point. You get a clear list of what needs fixing and, if you want it, our help fixing it.
Do we have to register with the OIC?+
It depends on what data you process and how. The assessment tells you definitively, and if registration applies, we handle the filing as part of the engagement.
What happens after the assessment?+
You get a written report and the policy pack, regardless of what happens next. Many firms move to GUARD for ongoing compliance; some just implement the report themselves. Both are fine outcomes.
Is this legal advice?+
No. It's a structured compliance assessment. For matters requiring formal legal opinion, we'll tell you plainly and point you to counsel.
Start with the assessment.
From US$3,500 fixed, delivered in 2–3 weeks.