Skip to main content

Barbados DPA

Data Protection Act 2019 (Act 2019-4)

Barbados' GDPR-aligned data protection law with biometric data definitions, mandatory DPO, and extraterritorial scope.

Jurisdiction

Barbados

Enacted

Mar 11, 2019

Effective

Mar 11, 2021

Enforcement

Data Protection Commissioner

GDPR-aligned framework with extraterritorial application

Barbados Parliament

Why It Matters

Barbados' GDPR-aligned framework with extraterritorial scope creates familiar compliance pathway for European AI companies serving Caribbean markets.

At a Glance

Applies to

AI CompanionMental Health AppGeneral Chatbot

Who Must Comply

  • Data controllers and processors in Barbados
  • Entities outside Barbados processing data of Barbadian residents
  • High-risk processing including biometric data

Safety Provisions

  • Biometric data explicitly defined as special category
  • Mandatory Data Protection Officer for certain controllers
  • Data Protection Impact Assessment for high-risk processing
  • Breach notification required
  • Extraterritorial application to data of Barbadian residents

Compliance & Enforcement

Penalties

Fines and enforcement actions

View on map

Barbados

Focus Areas

Mental health & crisis
Algorithmic accountability

Cite This

APA

Barbados. (2019). Data Protection Act 2019 (Act 2019-4).

Last updated January 22, 2026. Verify against primary sources before relying on this information.