SlideShare a Scribd company logo
1 of 13
JAMAICA'S DATA
PROTECTION
ACT
Compliance required from the business
community
THE DATA PROTECTION
ACT
(ACT 7 OF 2020)
PART I—Preliminary
PART II—Rights of Data Subjects and Others
PART III—Requirements for Data Controllers
PART IV—Standards for Processing Personal Data
PART V—Exemptions to Data Protection Standards or to
Disclosure to Data Subject Requirements
PART VI—Enforcement
PART VII—Miscellaneous and General
12/1/2023 BCI - Data Protection Act Compliance 2
PRIVACY AND
PROTECTION OF PIIS
12/1/2023 BCI - Data Protection Act Compliance 3
Personally Identifiable Information (PII) in Privacy Law
1. PII and similar terms exist in the legislation of many countries and territories: In the
United States, the National Institute of Standards and Technology (NIST)’s Guide
to Protecting the Confidentiality of Personally Identifiable Information defines
“personally identifiable” as information like name, social security number, and
biometric records, which can be used to distinguish or trace an individual’s identity.
2. In the European Union, directive 95/46/EC defines “personal data” as information
which can identify a person via an ID number, or factors specific to physical,
physiological, mental, economic, cultural or social identity.
3. Jamaica passed its Data Protection Act (DPA) in June 2020 and, on December 1,
2021, appointed Celia Barclay as the first Information Commissioner. With that, the
process to implement a system to ensure compliance of data controllers with data
protection standards commenced. data controllers have a transition period of two
years, from December 1, 2021, to November 30, 2023, to ensure full compliance
with the requirements under the Act.
OFFICE OF THE INFORMATION
COMMISSIONER (OIC)
12/1/2023 BCI - Data Protection Act Compliance 4
The Information Commissioner ('the Commissioner') is the main regulator
under Part I, s. 4 of the DPA. The main powers, duties, and responsibilities
of the Commissioner include:
• monitoring compliance with the Act and any regulations made under the Act;
• providing advice to the relevant minister on any matter relating to the operation of the Act
or otherwise for the protection of personal data;
• promoting the observance of the requirements under the Act and the following of good
practice by data controllers;
• disseminating information to the public about the operation of the Act, about good practice,
and advising persons about any of those matters;
• preparing and disseminating guidelines under the Act; and
• the Commissioner may intervene as a party in any proceedings before a court, in respect
of any matter concerning the processing of personal data or the enforcement of any
provision of the Act, other than proceedings for the prosecution of an offence.
PRIVACY DEFINED UNDER THE
DPA
12/1/2023 BCI - Data Protection Act Compliance 5
Personal data is ‘information (however stored) relating to a living individual, or
an individual who has been deceased for less than 30 years, who can be
identified from that information alone or from that information and other
information in the possession of, or likely to come into the possession of, the
data controller, and which includes any expression of opinion about that
individual and any indication of the intentions of the data controller or any other
person in respect of that individual.’
Sensitive personal data is personal data consisting of any of the following
information in respect of a data subject:
• genetic data or biometric data;
• filiation, racial, or ethnic origin;
• political opinions, philosophical beliefs, religious beliefs or other beliefs of a similar
nature;
• membership in any trade union;
• physical or mental health or condition;
• sex life; or
• the alleged commission of any offence by the data subject or any proceedings for any
offence alleged to have been committed by the data subject.
12/1/2023 BCI - Data Protection Act Compliance 6
Personal data can be processed where necessary for the administration of justice,
exercise of any functions conferred by or under any enactment, or conditions for
processing personal data in accordance with the first standard, and for the exercise of any
other functions of a public nature exercised in the public interest (Article 23(e) of the
Act).
DATA CONTROLLER & DATA PROCESSOR
12/1/2023 BCI - Data Protection Act Compliance 7
A data controller is defined under the Act as 'any person
or public authority, who, either alone or jointly or in
common with other persons determines the purposes for
which and the manner in which any personal data are, or
are to be, processed, and where personal data is
processed only for purposes for which they are required
under any enactment to be processed, the person on
whom the obligation to process the personal data is
imposed by or under that enactment is for the purposes of
this Act a data controller'.
A data processor is defined under the Act as 'any person,
other than an employee of the data controller, who
processes the data on behalf of the data controller'.
Prior to processing personal data, all data controllers must pay a
prescribed fee and register certain 'registration particulars' with the
Commissioner.
Additionally, certain categories of data controllers are required to
appoint a data protection officer ('DPO') under the Act. These categories
include:
• data controllers who are public authorities;
• data controllers who process or intend to process sensitive personal
data or data relating to criminal convictions;
• data controllers who process personal data on a large scale; and
• data controllers that are designated by the Commissioner as
requiring a DPO.
Also, data controllers are required to submit annually to the
Commissioner, a Data Protection Impact Assessment ('DPIA') with
respect to all data in their possession.
12/1/2023
BCI - Data Protection Act
Compliance
8
THE DATA PROTECTION
OFFICER
THE 8 DATA RIGHTS
PRINCIPLES
12/1/2023 BCI - Data Protection Act Compliance 9
1. Personal data must be processed fairly and lawfully (sections 22-24); which essentially amounts to
ensuring that the consent of the data subject (i.e. the person who the personal data relates to) is
obtained prior to processing the data or there is a legitimate basis for the processing.
2. Personal data is only to be obtained for specified purposes and is not to be processed for any other
purposes (section 25).
3. Personal data is to be adequate, relevant, and not excessive in relation to the purpose for which it is to
be processed (section 26); essentially preventing data controllers from obtaining more information from
data subjects than is necessary for the intended processing purposes. (minimalist approach)
4. Personal data must be accurate, and, where necessary, kept up to date.
5. Personal data must not be kept for longer than is necessary to satisfy the intended processing
purposes and must be disposed of in accordance with regulations to be promulgated under the
legislation.
6. Personal data must be processed in accordance with the rights of data subjects under the
legislation.
7. Personal data is to be protected by taking the appropriate technical and organizational measures and
by prompt notification of security breaches to an Information Commissioner to be established under the
legislation.
8. Personal data must not be transferred outside Jamaica to another state without adequate levels of
data protection for Jamaican data subjects.
DPA AND OTHER RELATED INITIATIVES
12/1/2023 BCI - Data Protection Act Compliance 10
Local laws and initiatives:
• There are local initiatives such as NIDS, and Jamaica Eye;
• As outlined in Clause 76 of the DPA Jamaica, there will be a transition period to
allow for compliance and to facilitate administrative restructuring.
DPA Penalties (local):
• Breach of certain provisions of the legislation will constitute criminal offences
attracting penalties both for corporations and individual corporate officers.
• Corporate: fine not exceeding 4% of annual gross worldwide turnover for the preceding
year of assessment in accordance with the Income Tax Act. Individuals: JMD 5 million
(approx. €32,050) and/or imprisonment up to a maximum of 10 years.
GDPR Penalties (global):
• Two levels of fines based on the GDPR:
1. The first is up to €10 million or 2% of the company's global annual turnover of the
previous financial year, whichever is higher.
2. The second is up to €20 million or 4% of the company's global annual turnover of
the previous financial year, whichever is higher.
OVERALL DPA COMPLIANCE
CLOSING THE GAP: 8 DATA
PRINCIPLES
1. Consent (sec. 22-24)
2. Notification as to reason for collection (sec. 25)
3. Minimalist approach to collection (sec. 26)
4. Data must be accurate (sec. 27)
5. Data retention must be for minimum period (sec. 11.(2)(d) & 28)
6. Rights of data subjects respected (Part II & sec. 29)
7. Personal data to be protected (sec. 30)
8. Personal data restricted to Jamaican jurisdiction (sec. 31)
TARGET AUDIENCE
All Visitors
Vendors
Staff
Office of the Information Commissioner (OIC)
COST SAVINGS
Monitoring System on new platform
(Reports to Internal Stakeholders)
Compliance under the DPA
(Annual Reports to the OIC)
Cybersecurity & Risk Management
EASY TO USE
Data Protection Notice
Data Protection Policy/Procedures
Registration as a Data Controller with OIC
Data Protection Officer (DPO)
Data Protection Impact Assessment (DPIA)
Training and Awareness Programme
Data Incident Reporting Mechanism
Annual Reports
12/1/2023 BCI - Data Protection Act Compliance 11
BCI - Data Protection Act Compliance
12/1/2023 12
THANK YOU
Emerson Bryan
876-584-3414
emerson.bryan@gmail.com
12/1/2023 BCI - Data Protection Act Compliance 13

More Related Content

What's hot

Data Privacy Introduction
Data Privacy IntroductionData Privacy Introduction
Data Privacy IntroductionG Prachi
 
Privacy and Data Security
Privacy and Data SecurityPrivacy and Data Security
Privacy and Data SecurityWilmerHale
 
Data recovery
Data recoveryData recovery
Data recoverybhaumik_c
 
Applying the Personal Data Protection Act (Singapore)
Applying the Personal Data Protection Act (Singapore)Applying the Personal Data Protection Act (Singapore)
Applying the Personal Data Protection Act (Singapore)Benjamin Ang
 
what is data security full ppt
what is data security full pptwhat is data security full ppt
what is data security full pptShahbaz Khan
 
Personal Information Protection and Electronic Documents Act (PIPEDA) and Imp...
Personal Information Protection and Electronic Documents Act (PIPEDA) and Imp...Personal Information Protection and Electronic Documents Act (PIPEDA) and Imp...
Personal Information Protection and Electronic Documents Act (PIPEDA) and Imp...Michael Sukachev
 
Data Privacy and Protection Presentation
Data Privacy and Protection PresentationData Privacy and Protection Presentation
Data Privacy and Protection Presentationmlw32785
 
Invisible Preadators: Hidden Dangers of the Internet
Invisible Preadators: Hidden Dangers of the InternetInvisible Preadators: Hidden Dangers of the Internet
Invisible Preadators: Hidden Dangers of the Internetmalissa_1041
 
Computer crimes and forensics
Computer crimes and forensics Computer crimes and forensics
Computer crimes and forensics Avinash Mavuru
 
Personal Data Protection Singapore - Pdpc corporate-brochure
Personal Data Protection Singapore - Pdpc corporate-brochurePersonal Data Protection Singapore - Pdpc corporate-brochure
Personal Data Protection Singapore - Pdpc corporate-brochureJean Luc Creppy
 
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...Qualsys Ltd
 
Cyber Space Threats and Opportunities
Cyber Space Threats and OpportunitiesCyber Space Threats and Opportunities
Cyber Space Threats and OpportunitiesJayakumar PP
 
Security v. Privacy: the great debate
Security v. Privacy: the great debateSecurity v. Privacy: the great debate
Security v. Privacy: the great debateDavid Strom
 

What's hot (20)

Data Privacy Introduction
Data Privacy IntroductionData Privacy Introduction
Data Privacy Introduction
 
Privacy and Data Security
Privacy and Data SecurityPrivacy and Data Security
Privacy and Data Security
 
Data recovery
Data recoveryData recovery
Data recovery
 
Applying the Personal Data Protection Act (Singapore)
Applying the Personal Data Protection Act (Singapore)Applying the Personal Data Protection Act (Singapore)
Applying the Personal Data Protection Act (Singapore)
 
what is data security full ppt
what is data security full pptwhat is data security full ppt
what is data security full ppt
 
Personal Information Protection and Electronic Documents Act (PIPEDA) and Imp...
Personal Information Protection and Electronic Documents Act (PIPEDA) and Imp...Personal Information Protection and Electronic Documents Act (PIPEDA) and Imp...
Personal Information Protection and Electronic Documents Act (PIPEDA) and Imp...
 
Data Protection Presentation
Data Protection PresentationData Protection Presentation
Data Protection Presentation
 
Overview on data privacy
Overview on data privacy Overview on data privacy
Overview on data privacy
 
Data recovery
Data recoveryData recovery
Data recovery
 
Data Privacy and Protection Presentation
Data Privacy and Protection PresentationData Privacy and Protection Presentation
Data Privacy and Protection Presentation
 
Gdpr presentation
Gdpr presentationGdpr presentation
Gdpr presentation
 
Cyber forensics
Cyber forensicsCyber forensics
Cyber forensics
 
Invisible Preadators: Hidden Dangers of the Internet
Invisible Preadators: Hidden Dangers of the InternetInvisible Preadators: Hidden Dangers of the Internet
Invisible Preadators: Hidden Dangers of the Internet
 
Computer crimes and forensics
Computer crimes and forensics Computer crimes and forensics
Computer crimes and forensics
 
pda forensics
pda forensicspda forensics
pda forensics
 
Personal Data Protection Singapore - Pdpc corporate-brochure
Personal Data Protection Singapore - Pdpc corporate-brochurePersonal Data Protection Singapore - Pdpc corporate-brochure
Personal Data Protection Singapore - Pdpc corporate-brochure
 
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
 
Multimedia communication networks
Multimedia communication networksMultimedia communication networks
Multimedia communication networks
 
Cyber Space Threats and Opportunities
Cyber Space Threats and OpportunitiesCyber Space Threats and Opportunities
Cyber Space Threats and Opportunities
 
Security v. Privacy: the great debate
Security v. Privacy: the great debateSecurity v. Privacy: the great debate
Security v. Privacy: the great debate
 

Similar to Jamaica's Data Protection Act: Compliance required from the business community

Indonesian Legislatives Passes Personal Data Protection Bill.pdf
Indonesian Legislatives Passes Personal Data Protection Bill.pdfIndonesian Legislatives Passes Personal Data Protection Bill.pdf
Indonesian Legislatives Passes Personal Data Protection Bill.pdfAHRP Law Firm
 
All_you_need_to Know_About_the_Data_Privacy_Act.pdf
All_you_need_to Know_About_the_Data_Privacy_Act.pdfAll_you_need_to Know_About_the_Data_Privacy_Act.pdf
All_you_need_to Know_About_the_Data_Privacy_Act.pdfJakeAldrinDegala1
 
PERSONAL-DATA-PROTECTION-BILL-2018.pptx
PERSONAL-DATA-PROTECTION-BILL-2018.pptxPERSONAL-DATA-PROTECTION-BILL-2018.pptx
PERSONAL-DATA-PROTECTION-BILL-2018.pptxssuser36d167
 
UAE-Personal-Data-Protection-Law.pdf
UAE-Personal-Data-Protection-Law.pdfUAE-Personal-Data-Protection-Law.pdf
UAE-Personal-Data-Protection-Law.pdfDaviesParker
 
Bahrain-Personal-Data-Protection-Law.pdf
Bahrain-Personal-Data-Protection-Law.pdfBahrain-Personal-Data-Protection-Law.pdf
Bahrain-Personal-Data-Protection-Law.pdfDaviesParker
 
Hexagon presentation light.pptx
Hexagon presentation light.pptxHexagon presentation light.pptx
Hexagon presentation light.pptxPabRonaldCalanoc1
 
General Data Protection Regulation or GDPR
General Data Protection Regulation or GDPRGeneral Data Protection Regulation or GDPR
General Data Protection Regulation or GDPRNupur Samaddar
 
NEW DECREE ON PERSONAL DATA PROTECTION AND CROSS-BORDER PROVISION OF DATA THE...
NEW DECREE ON PERSONAL DATA PROTECTION AND CROSS-BORDER PROVISION OF DATA THE...NEW DECREE ON PERSONAL DATA PROTECTION AND CROSS-BORDER PROVISION OF DATA THE...
NEW DECREE ON PERSONAL DATA PROTECTION AND CROSS-BORDER PROVISION OF DATA THE...Dr. Oliver Massmann
 
Examples of international privacy legislation
Examples of international privacy legislationExamples of international privacy legislation
Examples of international privacy legislationUlf Mattsson
 
Personal data protection bill
Personal data protection bill Personal data protection bill
Personal data protection bill Mathew Chacko
 
Draft Bill on the Protection of Personal Data
Draft Bill on the Protection of Personal DataDraft Bill on the Protection of Personal Data
Draft Bill on the Protection of Personal DataRenato Monteiro
 
GDPR - The new era of data protection
GDPR - The new era of data protectionGDPR - The new era of data protection
GDPR - The new era of data protectionInterlogica
 
General Data Protection Regulation (GDPR) | Privacy Law in India |
General Data Protection Regulation (GDPR) | Privacy Law in India |General Data Protection Regulation (GDPR) | Privacy Law in India |
General Data Protection Regulation (GDPR) | Privacy Law in India |Bivas Chatterjee
 
Data Privacy Act in the Philippines
Data Privacy Act in the PhilippinesData Privacy Act in the Philippines
Data Privacy Act in the PhilippinesShirley Ingles-Cruz
 
Managing Data Protection guide powerpoint presentation
Managing Data Protection guide powerpoint presentationManaging Data Protection guide powerpoint presentation
Managing Data Protection guide powerpoint presentationsilvereyez11
 
Digital Personal Data Protection (DPDP) Practical Approach For CISOs
Digital Personal Data Protection (DPDP) Practical Approach For CISOsDigital Personal Data Protection (DPDP) Practical Approach For CISOs
Digital Personal Data Protection (DPDP) Practical Approach For CISOsPriyanka Aash
 
KSA PDPL - Personal Data Protection Law.pdf
KSA PDPL - Personal Data Protection Law.pdfKSA PDPL - Personal Data Protection Law.pdf
KSA PDPL - Personal Data Protection Law.pdfDaviesParker
 
Development & GDPR (v2)
Development & GDPR (v2)Development & GDPR (v2)
Development & GDPR (v2)Andrea Tino
 

Similar to Jamaica's Data Protection Act: Compliance required from the business community (20)

Indonesian Legislatives Passes Personal Data Protection Bill.pdf
Indonesian Legislatives Passes Personal Data Protection Bill.pdfIndonesian Legislatives Passes Personal Data Protection Bill.pdf
Indonesian Legislatives Passes Personal Data Protection Bill.pdf
 
All_you_need_to Know_About_the_Data_Privacy_Act.pdf
All_you_need_to Know_About_the_Data_Privacy_Act.pdfAll_you_need_to Know_About_the_Data_Privacy_Act.pdf
All_you_need_to Know_About_the_Data_Privacy_Act.pdf
 
PERSONAL-DATA-PROTECTION-BILL-2018.pptx
PERSONAL-DATA-PROTECTION-BILL-2018.pptxPERSONAL-DATA-PROTECTION-BILL-2018.pptx
PERSONAL-DATA-PROTECTION-BILL-2018.pptx
 
UAE-Personal-Data-Protection-Law.pdf
UAE-Personal-Data-Protection-Law.pdfUAE-Personal-Data-Protection-Law.pdf
UAE-Personal-Data-Protection-Law.pdf
 
Bahrain-Personal-Data-Protection-Law.pdf
Bahrain-Personal-Data-Protection-Law.pdfBahrain-Personal-Data-Protection-Law.pdf
Bahrain-Personal-Data-Protection-Law.pdf
 
Hexagon presentation light.pptx
Hexagon presentation light.pptxHexagon presentation light.pptx
Hexagon presentation light.pptx
 
General Data Protection Regulation or GDPR
General Data Protection Regulation or GDPRGeneral Data Protection Regulation or GDPR
General Data Protection Regulation or GDPR
 
NEW DECREE ON PERSONAL DATA PROTECTION AND CROSS-BORDER PROVISION OF DATA THE...
NEW DECREE ON PERSONAL DATA PROTECTION AND CROSS-BORDER PROVISION OF DATA THE...NEW DECREE ON PERSONAL DATA PROTECTION AND CROSS-BORDER PROVISION OF DATA THE...
NEW DECREE ON PERSONAL DATA PROTECTION AND CROSS-BORDER PROVISION OF DATA THE...
 
Examples of international privacy legislation
Examples of international privacy legislationExamples of international privacy legislation
Examples of international privacy legislation
 
Personal data protection bill
Personal data protection bill Personal data protection bill
Personal data protection bill
 
China-PIPL.pdf
China-PIPL.pdfChina-PIPL.pdf
China-PIPL.pdf
 
Draft Bill on the Protection of Personal Data
Draft Bill on the Protection of Personal DataDraft Bill on the Protection of Personal Data
Draft Bill on the Protection of Personal Data
 
GDPR - The new era of data protection
GDPR - The new era of data protectionGDPR - The new era of data protection
GDPR - The new era of data protection
 
General Data Protection Regulation (GDPR) | Privacy Law in India |
General Data Protection Regulation (GDPR) | Privacy Law in India |General Data Protection Regulation (GDPR) | Privacy Law in India |
General Data Protection Regulation (GDPR) | Privacy Law in India |
 
Data Privacy Act in the Philippines
Data Privacy Act in the PhilippinesData Privacy Act in the Philippines
Data Privacy Act in the Philippines
 
Managing Data Protection guide powerpoint presentation
Managing Data Protection guide powerpoint presentationManaging Data Protection guide powerpoint presentation
Managing Data Protection guide powerpoint presentation
 
Digital Personal Data Protection (DPDP) Practical Approach For CISOs
Digital Personal Data Protection (DPDP) Practical Approach For CISOsDigital Personal Data Protection (DPDP) Practical Approach For CISOs
Digital Personal Data Protection (DPDP) Practical Approach For CISOs
 
KSA PDPL - Personal Data Protection Law.pdf
KSA PDPL - Personal Data Protection Law.pdfKSA PDPL - Personal Data Protection Law.pdf
KSA PDPL - Personal Data Protection Law.pdf
 
Development & GDPR (v2)
Development & GDPR (v2)Development & GDPR (v2)
Development & GDPR (v2)
 
Personal Data Protection in Malaysia
Personal Data Protection in MalaysiaPersonal Data Protection in Malaysia
Personal Data Protection in Malaysia
 

More from Emerson Bryan

Professional Certificate in Supervisory Management
Professional Certificate in Supervisory ManagementProfessional Certificate in Supervisory Management
Professional Certificate in Supervisory ManagementEmerson Bryan
 
RIM a filip to KM through the SECI Model
RIM a filip to KM through the SECI ModelRIM a filip to KM through the SECI Model
RIM a filip to KM through the SECI ModelEmerson Bryan
 
International Archives and Records and Information Management
International Archives and Records and Information ManagementInternational Archives and Records and Information Management
International Archives and Records and Information ManagementEmerson Bryan
 
Certified Archivist (CA)
Certified Archivist (CA)Certified Archivist (CA)
Certified Archivist (CA)Emerson Bryan
 
ACP Attestation - Emerson Bryan
ACP Attestation - Emerson Bryan ACP Attestation - Emerson Bryan
ACP Attestation - Emerson Bryan Emerson Bryan
 
UWI OC Letter of Attestation
UWI OC Letter of Attestation UWI OC Letter of Attestation
UWI OC Letter of Attestation Emerson Bryan
 
BNSI - Letter of Attestation
BNSI - Letter of AttestationBNSI - Letter of Attestation
BNSI - Letter of AttestationEmerson Bryan
 
Certified Records Analyst (CRA)
Certified Records Analyst (CRA)Certified Records Analyst (CRA)
Certified Records Analyst (CRA)Emerson Bryan
 
Certified Records Analyst (CRA) Qualification
Certified Records Analyst (CRA) QualificationCertified Records Analyst (CRA) Qualification
Certified Records Analyst (CRA) QualificationEmerson Bryan
 
MIND Policy Forum - December 2017
MIND Policy Forum - December 2017MIND Policy Forum - December 2017
MIND Policy Forum - December 2017Emerson Bryan
 
E. Bryan - Changing the Paradigm - Record and Information Management for Pub...
E. Bryan -  Changing the Paradigm - Record and Information Management for Pub...E. Bryan -  Changing the Paradigm - Record and Information Management for Pub...
E. Bryan - Changing the Paradigm - Record and Information Management for Pub...Emerson Bryan
 
Feith - Records Management Diploma
Feith - Records Management DiplomaFeith - Records Management Diploma
Feith - Records Management DiplomaEmerson Bryan
 
University Certificate: Museum Conservation Skills
University Certificate: Museum Conservation SkillsUniversity Certificate: Museum Conservation Skills
University Certificate: Museum Conservation SkillsEmerson Bryan
 
The CARIFESTA XIII Symposium - Schedule August 11-23, 2017
The CARIFESTA XIII Symposium - Schedule August 11-23, 2017The CARIFESTA XIII Symposium - Schedule August 11-23, 2017
The CARIFESTA XIII Symposium - Schedule August 11-23, 2017Emerson Bryan
 
E. Bryan Digital curation of digital cultural assets- Mutual interest of AL...
E. Bryan   Digital curation of digital cultural assets- Mutual interest of AL...E. Bryan   Digital curation of digital cultural assets- Mutual interest of AL...
E. Bryan Digital curation of digital cultural assets- Mutual interest of AL...Emerson Bryan
 
E. Bryan - Traditional Knowledge Digital Repository - Considerations for Domi...
E. Bryan - Traditional Knowledge Digital Repository - Considerations for Domi...E. Bryan - Traditional Knowledge Digital Repository - Considerations for Domi...
E. Bryan - Traditional Knowledge Digital Repository - Considerations for Domi...Emerson Bryan
 
IVCC - Certificate (Basico II)
IVCC - Certificate (Basico II)IVCC - Certificate (Basico II)
IVCC - Certificate (Basico II)Emerson Bryan
 
SLCC 2016 Presentation Schedule - Day 2
SLCC 2016 Presentation Schedule - Day 2SLCC 2016 Presentation Schedule - Day 2
SLCC 2016 Presentation Schedule - Day 2Emerson Bryan
 
SLCC 2016 Presentation Schedule - Day 2
SLCC 2016 Presentation Schedule - Day 2SLCC 2016 Presentation Schedule - Day 2
SLCC 2016 Presentation Schedule - Day 2Emerson Bryan
 

More from Emerson Bryan (20)

Professional Certificate in Supervisory Management
Professional Certificate in Supervisory ManagementProfessional Certificate in Supervisory Management
Professional Certificate in Supervisory Management
 
RIM a filip to KM through the SECI Model
RIM a filip to KM through the SECI ModelRIM a filip to KM through the SECI Model
RIM a filip to KM through the SECI Model
 
International Archives and Records and Information Management
International Archives and Records and Information ManagementInternational Archives and Records and Information Management
International Archives and Records and Information Management
 
Certified Archivist (CA)
Certified Archivist (CA)Certified Archivist (CA)
Certified Archivist (CA)
 
ACP Attestation - Emerson Bryan
ACP Attestation - Emerson Bryan ACP Attestation - Emerson Bryan
ACP Attestation - Emerson Bryan
 
UWI OC Letter of Attestation
UWI OC Letter of Attestation UWI OC Letter of Attestation
UWI OC Letter of Attestation
 
BNSI - Letter of Attestation
BNSI - Letter of AttestationBNSI - Letter of Attestation
BNSI - Letter of Attestation
 
Certified Records Analyst (CRA)
Certified Records Analyst (CRA)Certified Records Analyst (CRA)
Certified Records Analyst (CRA)
 
ICRM Email - CRA
ICRM Email - CRAICRM Email - CRA
ICRM Email - CRA
 
Certified Records Analyst (CRA) Qualification
Certified Records Analyst (CRA) QualificationCertified Records Analyst (CRA) Qualification
Certified Records Analyst (CRA) Qualification
 
MIND Policy Forum - December 2017
MIND Policy Forum - December 2017MIND Policy Forum - December 2017
MIND Policy Forum - December 2017
 
E. Bryan - Changing the Paradigm - Record and Information Management for Pub...
E. Bryan -  Changing the Paradigm - Record and Information Management for Pub...E. Bryan -  Changing the Paradigm - Record and Information Management for Pub...
E. Bryan - Changing the Paradigm - Record and Information Management for Pub...
 
Feith - Records Management Diploma
Feith - Records Management DiplomaFeith - Records Management Diploma
Feith - Records Management Diploma
 
University Certificate: Museum Conservation Skills
University Certificate: Museum Conservation SkillsUniversity Certificate: Museum Conservation Skills
University Certificate: Museum Conservation Skills
 
The CARIFESTA XIII Symposium - Schedule August 11-23, 2017
The CARIFESTA XIII Symposium - Schedule August 11-23, 2017The CARIFESTA XIII Symposium - Schedule August 11-23, 2017
The CARIFESTA XIII Symposium - Schedule August 11-23, 2017
 
E. Bryan Digital curation of digital cultural assets- Mutual interest of AL...
E. Bryan   Digital curation of digital cultural assets- Mutual interest of AL...E. Bryan   Digital curation of digital cultural assets- Mutual interest of AL...
E. Bryan Digital curation of digital cultural assets- Mutual interest of AL...
 
E. Bryan - Traditional Knowledge Digital Repository - Considerations for Domi...
E. Bryan - Traditional Knowledge Digital Repository - Considerations for Domi...E. Bryan - Traditional Knowledge Digital Repository - Considerations for Domi...
E. Bryan - Traditional Knowledge Digital Repository - Considerations for Domi...
 
IVCC - Certificate (Basico II)
IVCC - Certificate (Basico II)IVCC - Certificate (Basico II)
IVCC - Certificate (Basico II)
 
SLCC 2016 Presentation Schedule - Day 2
SLCC 2016 Presentation Schedule - Day 2SLCC 2016 Presentation Schedule - Day 2
SLCC 2016 Presentation Schedule - Day 2
 
SLCC 2016 Presentation Schedule - Day 2
SLCC 2016 Presentation Schedule - Day 2SLCC 2016 Presentation Schedule - Day 2
SLCC 2016 Presentation Schedule - Day 2
 

Recently uploaded

Comparison of GenAI benchmarking models for legal use cases
Comparison of GenAI benchmarking models for legal use casesComparison of GenAI benchmarking models for legal use cases
Comparison of GenAI benchmarking models for legal use casesritwikv20
 
Sports Writing for PISAYyyyyyyyyyyyyyy.pptx
Sports Writing for PISAYyyyyyyyyyyyyyy.pptxSports Writing for PISAYyyyyyyyyyyyyyy.pptx
Sports Writing for PISAYyyyyyyyyyyyyyy.pptxmarielouisetulaytay
 
如何办理(UoM毕业证书)曼彻斯特大学毕业证学位证书
如何办理(UoM毕业证书)曼彻斯特大学毕业证学位证书如何办理(UoM毕业证书)曼彻斯特大学毕业证学位证书
如何办理(UoM毕业证书)曼彻斯特大学毕业证学位证书srst S
 
Special Accounting Areas - Hire purchase agreement
Special Accounting Areas - Hire purchase agreementSpecial Accounting Areas - Hire purchase agreement
Special Accounting Areas - Hire purchase agreementShubhiSharma858417
 
定制(BU文凭证书)美国波士顿大学毕业证成绩单原版一比一
定制(BU文凭证书)美国波士顿大学毕业证成绩单原版一比一定制(BU文凭证书)美国波士顿大学毕业证成绩单原版一比一
定制(BU文凭证书)美国波士顿大学毕业证成绩单原版一比一st Las
 
Constitutional Values & Fundamental Principles of the ConstitutionPPT.pptx
Constitutional Values & Fundamental Principles of the ConstitutionPPT.pptxConstitutional Values & Fundamental Principles of the ConstitutionPPT.pptx
Constitutional Values & Fundamental Principles of the ConstitutionPPT.pptxsrikarna235
 
如何办理(Curtin毕业证书)科廷科技大学毕业证学位证书
如何办理(Curtin毕业证书)科廷科技大学毕业证学位证书如何办理(Curtin毕业证书)科廷科技大学毕业证学位证书
如何办理(Curtin毕业证书)科廷科技大学毕业证学位证书SD DS
 
Trial Tilak t 1897,1909, and 1916 sedition
Trial Tilak t 1897,1909, and 1916 seditionTrial Tilak t 1897,1909, and 1916 sedition
Trial Tilak t 1897,1909, and 1916 seditionNilamPadekar1
 
如何办理(UNK毕业证书)内布拉斯加大学卡尼尔分校毕业证学位证书
如何办理(UNK毕业证书)内布拉斯加大学卡尼尔分校毕业证学位证书如何办理(UNK毕业证书)内布拉斯加大学卡尼尔分校毕业证学位证书
如何办理(UNK毕业证书)内布拉斯加大学卡尼尔分校毕业证学位证书SD DS
 
如何办理(GWU毕业证书)乔治华盛顿大学毕业证学位证书
如何办理(GWU毕业证书)乔治华盛顿大学毕业证学位证书如何办理(GWU毕业证书)乔治华盛顿大学毕业证学位证书
如何办理(GWU毕业证书)乔治华盛顿大学毕业证学位证书SD DS
 
Key Factors That Influence Property Tax Rates
Key Factors That Influence Property Tax RatesKey Factors That Influence Property Tax Rates
Key Factors That Influence Property Tax RatesHome Tax Saver
 
Succession (Articles 774-1116 Civil Code
Succession (Articles 774-1116 Civil CodeSuccession (Articles 774-1116 Civil Code
Succession (Articles 774-1116 Civil CodeMelvinPernez2
 
Alexis O'Connell lexileeyogi Bond revocation for drug arrest Alexis Lee
Alexis O'Connell lexileeyogi Bond revocation for drug arrest Alexis LeeAlexis O'Connell lexileeyogi Bond revocation for drug arrest Alexis Lee
Alexis O'Connell lexileeyogi Bond revocation for drug arrest Alexis LeeBlayneRush1
 
如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书
如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书
如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书Fir L
 
The Prevention Of Corruption Act Presentation.pptx
The Prevention Of Corruption Act Presentation.pptxThe Prevention Of Corruption Act Presentation.pptx
The Prevention Of Corruption Act Presentation.pptxNeeteshKumar71
 
Alexis O'Connell Arrest Records Houston Texas lexileeyogi
Alexis O'Connell Arrest Records Houston Texas lexileeyogiAlexis O'Connell Arrest Records Houston Texas lexileeyogi
Alexis O'Connell Arrest Records Houston Texas lexileeyogiBlayneRush1
 
An Introduction guidance of the European Union Law 2020_EU Seminar 4.pptx
An Introduction guidance of the European Union Law 2020_EU Seminar 4.pptxAn Introduction guidance of the European Union Law 2020_EU Seminar 4.pptx
An Introduction guidance of the European Union Law 2020_EU Seminar 4.pptxKUHANARASARATNAM1
 
如何办理密德萨斯大学毕业证(本硕)Middlesex学位证书
如何办理密德萨斯大学毕业证(本硕)Middlesex学位证书如何办理密德萨斯大学毕业证(本硕)Middlesex学位证书
如何办理密德萨斯大学毕业证(本硕)Middlesex学位证书FS LS
 
Alexis O'Connell Alexis Lee mugshot Lexileeyogi 512-840-8791
Alexis O'Connell Alexis Lee mugshot Lexileeyogi 512-840-8791Alexis O'Connell Alexis Lee mugshot Lexileeyogi 512-840-8791
Alexis O'Connell Alexis Lee mugshot Lexileeyogi 512-840-8791BlayneRush1
 

Recently uploaded (20)

Comparison of GenAI benchmarking models for legal use cases
Comparison of GenAI benchmarking models for legal use casesComparison of GenAI benchmarking models for legal use cases
Comparison of GenAI benchmarking models for legal use cases
 
Sports Writing for PISAYyyyyyyyyyyyyyy.pptx
Sports Writing for PISAYyyyyyyyyyyyyyy.pptxSports Writing for PISAYyyyyyyyyyyyyyy.pptx
Sports Writing for PISAYyyyyyyyyyyyyyy.pptx
 
如何办理(UoM毕业证书)曼彻斯特大学毕业证学位证书
如何办理(UoM毕业证书)曼彻斯特大学毕业证学位证书如何办理(UoM毕业证书)曼彻斯特大学毕业证学位证书
如何办理(UoM毕业证书)曼彻斯特大学毕业证学位证书
 
Special Accounting Areas - Hire purchase agreement
Special Accounting Areas - Hire purchase agreementSpecial Accounting Areas - Hire purchase agreement
Special Accounting Areas - Hire purchase agreement
 
定制(BU文凭证书)美国波士顿大学毕业证成绩单原版一比一
定制(BU文凭证书)美国波士顿大学毕业证成绩单原版一比一定制(BU文凭证书)美国波士顿大学毕业证成绩单原版一比一
定制(BU文凭证书)美国波士顿大学毕业证成绩单原版一比一
 
Constitutional Values & Fundamental Principles of the ConstitutionPPT.pptx
Constitutional Values & Fundamental Principles of the ConstitutionPPT.pptxConstitutional Values & Fundamental Principles of the ConstitutionPPT.pptx
Constitutional Values & Fundamental Principles of the ConstitutionPPT.pptx
 
如何办理(Curtin毕业证书)科廷科技大学毕业证学位证书
如何办理(Curtin毕业证书)科廷科技大学毕业证学位证书如何办理(Curtin毕业证书)科廷科技大学毕业证学位证书
如何办理(Curtin毕业证书)科廷科技大学毕业证学位证书
 
Trial Tilak t 1897,1909, and 1916 sedition
Trial Tilak t 1897,1909, and 1916 seditionTrial Tilak t 1897,1909, and 1916 sedition
Trial Tilak t 1897,1909, and 1916 sedition
 
如何办理(UNK毕业证书)内布拉斯加大学卡尼尔分校毕业证学位证书
如何办理(UNK毕业证书)内布拉斯加大学卡尼尔分校毕业证学位证书如何办理(UNK毕业证书)内布拉斯加大学卡尼尔分校毕业证学位证书
如何办理(UNK毕业证书)内布拉斯加大学卡尼尔分校毕业证学位证书
 
如何办理(GWU毕业证书)乔治华盛顿大学毕业证学位证书
如何办理(GWU毕业证书)乔治华盛顿大学毕业证学位证书如何办理(GWU毕业证书)乔治华盛顿大学毕业证学位证书
如何办理(GWU毕业证书)乔治华盛顿大学毕业证学位证书
 
Key Factors That Influence Property Tax Rates
Key Factors That Influence Property Tax RatesKey Factors That Influence Property Tax Rates
Key Factors That Influence Property Tax Rates
 
Succession (Articles 774-1116 Civil Code
Succession (Articles 774-1116 Civil CodeSuccession (Articles 774-1116 Civil Code
Succession (Articles 774-1116 Civil Code
 
young Call Girls in Pusa Road🔝 9953330565 🔝 escort Service
young Call Girls in  Pusa Road🔝 9953330565 🔝 escort Serviceyoung Call Girls in  Pusa Road🔝 9953330565 🔝 escort Service
young Call Girls in Pusa Road🔝 9953330565 🔝 escort Service
 
Alexis O'Connell lexileeyogi Bond revocation for drug arrest Alexis Lee
Alexis O'Connell lexileeyogi Bond revocation for drug arrest Alexis LeeAlexis O'Connell lexileeyogi Bond revocation for drug arrest Alexis Lee
Alexis O'Connell lexileeyogi Bond revocation for drug arrest Alexis Lee
 
如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书
如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书
如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书
 
The Prevention Of Corruption Act Presentation.pptx
The Prevention Of Corruption Act Presentation.pptxThe Prevention Of Corruption Act Presentation.pptx
The Prevention Of Corruption Act Presentation.pptx
 
Alexis O'Connell Arrest Records Houston Texas lexileeyogi
Alexis O'Connell Arrest Records Houston Texas lexileeyogiAlexis O'Connell Arrest Records Houston Texas lexileeyogi
Alexis O'Connell Arrest Records Houston Texas lexileeyogi
 
An Introduction guidance of the European Union Law 2020_EU Seminar 4.pptx
An Introduction guidance of the European Union Law 2020_EU Seminar 4.pptxAn Introduction guidance of the European Union Law 2020_EU Seminar 4.pptx
An Introduction guidance of the European Union Law 2020_EU Seminar 4.pptx
 
如何办理密德萨斯大学毕业证(本硕)Middlesex学位证书
如何办理密德萨斯大学毕业证(本硕)Middlesex学位证书如何办理密德萨斯大学毕业证(本硕)Middlesex学位证书
如何办理密德萨斯大学毕业证(本硕)Middlesex学位证书
 
Alexis O'Connell Alexis Lee mugshot Lexileeyogi 512-840-8791
Alexis O'Connell Alexis Lee mugshot Lexileeyogi 512-840-8791Alexis O'Connell Alexis Lee mugshot Lexileeyogi 512-840-8791
Alexis O'Connell Alexis Lee mugshot Lexileeyogi 512-840-8791
 

Jamaica's Data Protection Act: Compliance required from the business community

  • 2. THE DATA PROTECTION ACT (ACT 7 OF 2020) PART I—Preliminary PART II—Rights of Data Subjects and Others PART III—Requirements for Data Controllers PART IV—Standards for Processing Personal Data PART V—Exemptions to Data Protection Standards or to Disclosure to Data Subject Requirements PART VI—Enforcement PART VII—Miscellaneous and General 12/1/2023 BCI - Data Protection Act Compliance 2
  • 3. PRIVACY AND PROTECTION OF PIIS 12/1/2023 BCI - Data Protection Act Compliance 3 Personally Identifiable Information (PII) in Privacy Law 1. PII and similar terms exist in the legislation of many countries and territories: In the United States, the National Institute of Standards and Technology (NIST)’s Guide to Protecting the Confidentiality of Personally Identifiable Information defines “personally identifiable” as information like name, social security number, and biometric records, which can be used to distinguish or trace an individual’s identity. 2. In the European Union, directive 95/46/EC defines “personal data” as information which can identify a person via an ID number, or factors specific to physical, physiological, mental, economic, cultural or social identity. 3. Jamaica passed its Data Protection Act (DPA) in June 2020 and, on December 1, 2021, appointed Celia Barclay as the first Information Commissioner. With that, the process to implement a system to ensure compliance of data controllers with data protection standards commenced. data controllers have a transition period of two years, from December 1, 2021, to November 30, 2023, to ensure full compliance with the requirements under the Act.
  • 4. OFFICE OF THE INFORMATION COMMISSIONER (OIC) 12/1/2023 BCI - Data Protection Act Compliance 4 The Information Commissioner ('the Commissioner') is the main regulator under Part I, s. 4 of the DPA. The main powers, duties, and responsibilities of the Commissioner include: • monitoring compliance with the Act and any regulations made under the Act; • providing advice to the relevant minister on any matter relating to the operation of the Act or otherwise for the protection of personal data; • promoting the observance of the requirements under the Act and the following of good practice by data controllers; • disseminating information to the public about the operation of the Act, about good practice, and advising persons about any of those matters; • preparing and disseminating guidelines under the Act; and • the Commissioner may intervene as a party in any proceedings before a court, in respect of any matter concerning the processing of personal data or the enforcement of any provision of the Act, other than proceedings for the prosecution of an offence.
  • 5. PRIVACY DEFINED UNDER THE DPA 12/1/2023 BCI - Data Protection Act Compliance 5 Personal data is ‘information (however stored) relating to a living individual, or an individual who has been deceased for less than 30 years, who can be identified from that information alone or from that information and other information in the possession of, or likely to come into the possession of, the data controller, and which includes any expression of opinion about that individual and any indication of the intentions of the data controller or any other person in respect of that individual.’ Sensitive personal data is personal data consisting of any of the following information in respect of a data subject: • genetic data or biometric data; • filiation, racial, or ethnic origin; • political opinions, philosophical beliefs, religious beliefs or other beliefs of a similar nature; • membership in any trade union; • physical or mental health or condition; • sex life; or • the alleged commission of any offence by the data subject or any proceedings for any offence alleged to have been committed by the data subject.
  • 6. 12/1/2023 BCI - Data Protection Act Compliance 6 Personal data can be processed where necessary for the administration of justice, exercise of any functions conferred by or under any enactment, or conditions for processing personal data in accordance with the first standard, and for the exercise of any other functions of a public nature exercised in the public interest (Article 23(e) of the Act).
  • 7. DATA CONTROLLER & DATA PROCESSOR 12/1/2023 BCI - Data Protection Act Compliance 7 A data controller is defined under the Act as 'any person or public authority, who, either alone or jointly or in common with other persons determines the purposes for which and the manner in which any personal data are, or are to be, processed, and where personal data is processed only for purposes for which they are required under any enactment to be processed, the person on whom the obligation to process the personal data is imposed by or under that enactment is for the purposes of this Act a data controller'. A data processor is defined under the Act as 'any person, other than an employee of the data controller, who processes the data on behalf of the data controller'.
  • 8. Prior to processing personal data, all data controllers must pay a prescribed fee and register certain 'registration particulars' with the Commissioner. Additionally, certain categories of data controllers are required to appoint a data protection officer ('DPO') under the Act. These categories include: • data controllers who are public authorities; • data controllers who process or intend to process sensitive personal data or data relating to criminal convictions; • data controllers who process personal data on a large scale; and • data controllers that are designated by the Commissioner as requiring a DPO. Also, data controllers are required to submit annually to the Commissioner, a Data Protection Impact Assessment ('DPIA') with respect to all data in their possession. 12/1/2023 BCI - Data Protection Act Compliance 8 THE DATA PROTECTION OFFICER
  • 9. THE 8 DATA RIGHTS PRINCIPLES 12/1/2023 BCI - Data Protection Act Compliance 9 1. Personal data must be processed fairly and lawfully (sections 22-24); which essentially amounts to ensuring that the consent of the data subject (i.e. the person who the personal data relates to) is obtained prior to processing the data or there is a legitimate basis for the processing. 2. Personal data is only to be obtained for specified purposes and is not to be processed for any other purposes (section 25). 3. Personal data is to be adequate, relevant, and not excessive in relation to the purpose for which it is to be processed (section 26); essentially preventing data controllers from obtaining more information from data subjects than is necessary for the intended processing purposes. (minimalist approach) 4. Personal data must be accurate, and, where necessary, kept up to date. 5. Personal data must not be kept for longer than is necessary to satisfy the intended processing purposes and must be disposed of in accordance with regulations to be promulgated under the legislation. 6. Personal data must be processed in accordance with the rights of data subjects under the legislation. 7. Personal data is to be protected by taking the appropriate technical and organizational measures and by prompt notification of security breaches to an Information Commissioner to be established under the legislation. 8. Personal data must not be transferred outside Jamaica to another state without adequate levels of data protection for Jamaican data subjects.
  • 10. DPA AND OTHER RELATED INITIATIVES 12/1/2023 BCI - Data Protection Act Compliance 10 Local laws and initiatives: • There are local initiatives such as NIDS, and Jamaica Eye; • As outlined in Clause 76 of the DPA Jamaica, there will be a transition period to allow for compliance and to facilitate administrative restructuring. DPA Penalties (local): • Breach of certain provisions of the legislation will constitute criminal offences attracting penalties both for corporations and individual corporate officers. • Corporate: fine not exceeding 4% of annual gross worldwide turnover for the preceding year of assessment in accordance with the Income Tax Act. Individuals: JMD 5 million (approx. €32,050) and/or imprisonment up to a maximum of 10 years. GDPR Penalties (global): • Two levels of fines based on the GDPR: 1. The first is up to €10 million or 2% of the company's global annual turnover of the previous financial year, whichever is higher. 2. The second is up to €20 million or 4% of the company's global annual turnover of the previous financial year, whichever is higher.
  • 11. OVERALL DPA COMPLIANCE CLOSING THE GAP: 8 DATA PRINCIPLES 1. Consent (sec. 22-24) 2. Notification as to reason for collection (sec. 25) 3. Minimalist approach to collection (sec. 26) 4. Data must be accurate (sec. 27) 5. Data retention must be for minimum period (sec. 11.(2)(d) & 28) 6. Rights of data subjects respected (Part II & sec. 29) 7. Personal data to be protected (sec. 30) 8. Personal data restricted to Jamaican jurisdiction (sec. 31) TARGET AUDIENCE All Visitors Vendors Staff Office of the Information Commissioner (OIC) COST SAVINGS Monitoring System on new platform (Reports to Internal Stakeholders) Compliance under the DPA (Annual Reports to the OIC) Cybersecurity & Risk Management EASY TO USE Data Protection Notice Data Protection Policy/Procedures Registration as a Data Controller with OIC Data Protection Officer (DPO) Data Protection Impact Assessment (DPIA) Training and Awareness Programme Data Incident Reporting Mechanism Annual Reports 12/1/2023 BCI - Data Protection Act Compliance 11
  • 12. BCI - Data Protection Act Compliance 12/1/2023 12

Editor's Notes

  1. RELATED DOCUMENTS Enterprise Risk Management Reporting Calendar GraceKennedy Risk Management Group Policy GraceKennedy Risk Appetite Governance Standard GraceKennedy Risk Assessment Guideline GraceKennedy Risk Assessment Reporting Standard GraceKennedy Business Continuity and Crisis Response Group Policy GraceKennedy Delegation of Authority Policy Information Security Management Policy Privacy Policy
  2. Under sec. 24. (2) of the DPA, 2020, anti-fraud organization is accommodated, and this would be the window under which the Bank would be able to collect personal data using the AI for the purposes mentioned in the case. Closing the Gap using the Data Principles under Part IV of the DPA