Status: Passed and gazetted. Not yet in force.
The Data Protection Act, 2025 was published in the Official Gazette on 11 December 2025. Under s.1(2) it comes into operation on a date the Minister appoints by notice in the Gazette, and different provisions may start on different dates. As of our last review, no commencement notice had been published.
In one minute
Every organization in The Bahamas that handles information about people, from a two-person office to a resort, becomes a data controller with duties it can be fined for missing.
Your IT provider, payroll service, cloud host and web developer become data processors with duties of their own, and you must have a written contract with each one (s.52).
A breach must be reported to the Commissioner within 72 hours of becoming aware of it (s.48), and to the affected people within 72 hours when the risk is high (s.49).
Section 53 lists the security measures the law expects: encryption, access control, the ability to restore data after an incident, and regular testing of all of it. This is the part an IT provider can put in place for you.
Penalties range from $10,000 penalty notices for security and breach failures (s.90) to $50,000 fines and up to three years for processing contrary to the principles (s.4(3)). Directors can be personally liable (s.95).
The Act is law but not yet in force. The time to prepare is now, while the clock is not running.
The Act at a glance
- Full name
- Data Protection Act, 2025
- Gazetted
- 11 December 2025 (Official Gazette, Supplement Part I)
- In force
- Not yet. Commencement by Ministerial notice, possibly in phases (s.1(2)).
- Replaces
- Data Protection (Privacy of Personal Information) Act, 2003 (Ch. 324A), in force since 2 April 2007. Repealed by s.101 on commencement.
- Regulator
- Office of the Data Protection Commissioner (s.12). The current Commissioner is Michael Wright.
- Applies to
- Any organization established in The Bahamas that processes personal data, plus foreign organizations that offer goods or services to, or monitor, people in The Bahamas (s.3(1)).
- Does not apply to
- Purely personal or household activity with no commercial connection (s.3(2)).
Four definitions that decide whether this applies to you
The Act turns on a handful of terms defined in s.2. They are broad on purpose.
Personal data is "information relating to an identifiable natural person". A name in a spreadsheet, an email address, a CCTV image, a customer file, a staff record. If a person can be identified from it, it counts.
Sensitive personal data includes racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic and biometric data, sex life or sexual orientation, medical data and health records, financial record or financial position, and criminal records. The financial category matters: a law office, an accountant, an insurer, a bank, a landlord or any business that keeps client account information holds sensitive data under this Act.
Data controller is the person or body that "determines the purpose and means of processing personal data". That is your organization, for the data you keep about clients, staff and contacts.
Data processor is a body that "processes personal data on behalf of the data controller". Your managed IT provider, your cloud email host, your payroll bureau and your website developer are processors.
Processing means almost any operation on personal data: collection, storage, use, disclosure, erasure and everything in between, whether automated or on paper. A personal data breach is any security failure leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data.
What changes from the 2003 Act
The 2003 Act has been in force since 2007 with, in practice, no enforcement history. The 2025 Act adds the machinery that makes enforcement possible. The Data Protection Commissioner's own comparison, presented in February 2026, lists the gaps the new law closes.
Accountability. Controllers and processors must take appropriate measures to comply with the data protection principles and, on request, demonstrate that compliance to the Commissioner (s.4(1)). The 2003 Act had no such duty.
Registration of both controllers and processors with the Commissioner (s.38). Regulations will set which categories must register and which are exempt (s.38(5)).
Records of processing (s.44). Required for organizations with 150 or more staff, and for smaller ones whose processing is likely to result in a risk to people's rights and freedoms (s.44(5)).
A data protection officer (s.46). As drafted, the trigger is processing "carried out by a public body or private body", which on its face is every organization. The Minister may exempt small and medium businesses by regulation (s.46(5)). Until those regulations appear, plan for it.
Breach notification to the Commissioner and to affected people within 72 hours (ss.48 and 49). The 2003 Act had no breach duty at all.
Data protection impact assessments (s.51) for categories set by regulation, or where the Commissioner directs one for high-risk processing.
Written contracts with processors on prescribed terms (s.52).
Named security measures (s.53), backed by a duty to review them periodically and to tell data subjects what they are (s.53(3) to (5)).
Conditions on transfers outside The Bahamas (Part VI, ss.54 to 56), and a rule that where data sits on a server abroad, the cost of the Commissioner reviewing or auditing that server falls on the organization (s.45(2)).
Enforcement with teeth: enforcement notices (s.74), penalty notices of up to $10,000 with the force of a Supreme Court judgment (s.90), an Appeal Tribunal (Part IX), a right to compensation for data subjects (s.32), and personal liability for directors and managers (s.95).
The duties, section by section
This table covers the duties most organizations will meet first. Read the Act itself for the full text; the link is in the sources at the end.
| Duty | Section | What it means in practice | Who |
|---|---|---|---|
| Comply with the principles and be able to prove it | s.4(1) | Lawful, fair and transparent processing; accurate data; kept no longer than necessary; kept secure (ss.5 to 11). You must be able to show the Commissioner how you comply. | Controllers and processors |
| Register with the Commissioner | s.38 | Apply for registration once regulations name your category. Operating unregistered when required is an offence (s.38(6)). | Controllers and processors |
| Keep records of processing | s.44 | A written record of what data you hold, why, who receives it, where it goes, when it is erased, and a general description of your s.53 security measures. Exempt under 150 staff unless the processing is risky (s.44(5)). | Controllers and processors |
| Appoint a data protection officer | s.46 | A qualified person who advises, trains staff, monitors compliance, helps with impact assessments and is the contact point for the Commissioner. SME exemptions possible by regulation (s.46(5)). | Controllers and processors |
| Notify the Commissioner of a breach within 72 hours | s.48(1) | Clock starts when you become aware. Late notifications must be explained (s.48(3)). Every breach must be recorded, reported or not (s.48(7)). | Controllers |
| Tell the controller of a breach within 72 hours | s.48(4) | A processor that discovers a breach must inform its controller within 72 hours. | Processors |
| Tell affected people within 72 hours | s.49 | Required where the breach is likely to violate rights and freedoms or exposes sensitive data. Not required if the data was encrypted or otherwise unintelligible to the attacker (s.49(3)(a)). | Controllers |
| Carry out impact assessments | s.51 | For categories to be prescribed by regulation, or when the Commissioner directs one for high-risk processing. | Controllers and processors |
| Contract with every processor in writing | s.52 | Only use processors that give "sufficient guarantees" on security, and sign a contract with the terms the section lists. | Controllers |
| Implement and review security measures | s.53 | Encryption and pseudonymization, confidentiality-integrity-availability-resilience, timely restore after an incident, regular testing. Periodic review under Commissioner guidelines. | Controllers and processors |
| Meet the conditions for transfers abroad | ss.54 to 56 | Cloud services hosted outside The Bahamas are transfers. Document where data sits and on what basis it goes there. | Controllers |
| Submit to audit | s.45 | The Commissioner may audit your policies and processing annually. | Controllers and processors |
Section 53: the security measures, translated
Section 53(1) requires every controller and processor to protect personal data against "accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to" it. Section 53(2) then names four measures. They read like an IT provider's statement of work, because that is effectively what they are.
| The Act says | What it means | What a defensible setup looks like |
|---|---|---|
| (a) Maintain integrity "using methods of pseudonymization and encryption" | Data is unreadable to anyone who steals a laptop, a drive or a backup | Full-disk encryption on every computer, encrypted backups, encrypted email and file sharing, no personal data on unencrypted USB sticks |
| (b) Ensure "ongoing confidentiality, integrity, availability and resilience of processing systems and services" | Only the right people get in, and the systems stay up | Multi-factor authentication on every account, endpoint protection, patching on a schedule, access rights matched to roles, monitoring with alerting |
| (c) "Restore the availability and access to personal data in a timely manner in the event of a physical or technical incident" | Backups that have been proven to restore, fast enough to matter | Daily backups with an off-site copy, scheduled restore tests with a written result, a recovery plan someone has actually read |
| (d) "A process for regularly testing, assessing and evaluating the effectiveness" of the measures | Evidence, not assumptions | A periodic written status of patching, backups and security controls; a review calendar; records you can hand to the Commissioner, an insurer or a client |
Two further subsections are easy to miss. Section 53(3) requires controllers to inform data subjects of the measures used to protect their data, which means your privacy notice needs a security paragraph. Sections 53(4) and (5) require periodic review of the measures in line with Commissioner guidelines, so a one-time setup is not compliance.
Section 11 adds the standard: measures must be appropriate to the harm that could result and the nature of the data, "having regard to the state of technological development and the cost of implementation". A firm holding financial or medical records is held to a higher bar than one holding a mailing list.
The 72-hour breach clock
The clock starts when you become aware of the breach, not when you finish investigating it. Section 48(2) deems a breach likely to result in a risk, and therefore reportable, if it involves sensitive data, could cause humiliation, harm, distress, reputational damage or economic loss, or "exposes personal data to unauthorized access, use, or disclosure". That last limb covers most real incidents, including ransomware.
- 1
Contain. Isolate affected machines, revoke compromised credentials, preserve logs. Your IT provider should be the first call; under s.48(4) a processor has its own 72-hour duty to tell you.
- 2
Assess. What data, how many people, what harm. Note whether the data was encrypted, because that decides whether affected people must be told (s.49(3)(a)).
- 3
Notify the Commissioner within 72 hours with the contents s.48(5) lists: nature and categories of the breach, number of people and records affected, a contact point, consequences, measures taken and measures to mitigate. If you cannot provide everything at once, s.48(6) allows phases within seven working days. If you miss 72 hours, s.48(3) requires reasons.
- 4
Tell affected people within 72 hours where the risk is high (s.49(1)), in clear and plain language. A public notice can substitute where individual contact would be disproportionate (s.49(3)(c)).
- 5
Record it. Section 48(7) requires a record of every breach: the facts, the effects and the remedial action, whether or not it was reportable.
The practical lesson is that the notification cannot be assembled from scratch in three days by someone who is also fighting the incident. The breach plan, the contact list and a template notification need to exist before anything happens.
Your IT provider is a data processor
Section 52 is the part of the Act written for the relationship between a business and the people who run its technology. A controller may "only use data processors that provide sufficient guarantees" on security, and must sign a written contract covering the subject matter, duration, nature and purpose of the processing, the data types involved, and the controller's rights. The contract must require the processor to:
process personal data only on the controller's written instructions, including on any transfer abroad (s.52(2)(a));
bind its staff to confidentiality (s.52(2)(b));
implement the s.53 security measures (s.52(2)(c));
not engage a sub-processor without the controller's written authorization (s.52(2)(d) and (3));
help the controller respond to data subject requests and meet its breach, impact assessment and security duties (s.52(2)(e) and (f));
delete or return all personal data at the end of the engagement (s.52(2)(g));
make available everything needed to demonstrate compliance and allow audits (s.52(2)(h)).
Section 53(1) also binds processors directly, and s.48(4) gives them their own 72-hour clock. Any IT provider, ourselves included, should be prepared to sign these terms and to show the evidence behind them. If a provider cannot tell you when your backups were last restored, cannot show that multi-factor authentication is on everywhere, or wants to keep your documentation, that is the answer to the "sufficient guarantees" question.
Penalties
All amounts are Bahamian dollars and are maximums set in the Act. Regulations may add administrative detail.
| Failure | Section | Maximum |
|---|---|---|
| Processing contrary to the data protection principles | s.4(3) | $50,000 fine, three years imprisonment, or both. Defence under s.4(4): acted in good faith, took all reasonable steps, exercised all due diligence. |
| Operating as a controller or processor without required registration | s.38(6) | $10,000 fine, six months imprisonment, or both. |
| Failing to keep records, appoint a DPO, notify a breach, inform data subjects, carry out a required impact assessment, or implement security measures (ss.44, 46, 48, 49, 51, 53), or the register duties in ss.42(2) and 43(2) | s.90 | Penalty notice of up to $10,000, filed in the Supreme Court and enforceable as a judgment (s.90(3) and (4)). Whether you self-reported is a listed factor (s.90(2)(g)). |
| Failing to comply with an enforcement notice, information notice or request for assessment | s.80(4) | $50,000 fine, three years imprisonment, or both. |
| Knowingly or recklessly obtaining or disclosing personal data without the controller's consent | s.96(3) | $50,000 fine, three years imprisonment, or both. |
| Selling, renting or offering to sell unlawfully obtained personal data | s.96(4) | $100,000 fine, five years imprisonment, or both. |
| Offences by a company committed with the consent, connivance or neglect of a director, manager, secretary or officer | s.95 | That person is personally guilty of the offence alongside the company. |
Separately, s.32 gives data subjects a right to compensation, so a breach can carry civil exposure on top of the regulatory kind.
Why this matters now: it is already happening here
The Act arrives against a run of publicly reported incidents at Bahamian institutions. Under the 2025 Act, each of these would have started a 72-hour clock.
Arawak Port Development, April 2024. The operator of Nassau Container Port identified an Akira ransomware attack on 18 April 2024 that encrypted data systems including those used for financial records. The port reverted to manual processes; the company reported paying no ransom and resolving the incident in just over two weeks (The Tribune, 29 October 2024).
University of The Bahamas, February 2025. A ransomware attack on 2 February 2025 took down internet, telephones, email and teaching systems across three campuses serving about 5,000 students. The University warned that personal information may have been affected, told students to change passwords, and restored the network in phases through 10 February (The Tribune, 6 February 2025; University of The Bahamas restoration notice).
Water and Sewerage Corporation, March 2025. A ransomware attack around 1 March 2025 breached internal systems. The Corporation engaged external specialists, police and the national CIRT, and was still addressing the fallout in mid-April (Eyewitness News; The Tribune, 15 April 2025).
None of these organizations was small or careless. They were targets because they held data and ran systems, which describes every business reading this.
What to do before commencement
Ten steps, in the order we would do them. Most are inexpensive. All of them produce evidence you will want on the day the Act starts.
- 1
Map your personal data. List where information about people lives: email, practice or accounting software, point of sale, CCTV, HR files, shared drives, phones. Mark what is sensitive under s.2, especially financial and medical records.
- 2
Turn on multi-factor authentication everywhere, starting with email and remote access. This is the single control that stops the most incidents.
- 3
Encrypt every laptop, desktop and backup. Section 53(2)(a) names it, and s.49(3)(a) rewards it: encrypted data that is stolen may not need to be reported to the people affected.
- 4
Prove your backups restore. Run a restore test and keep the written result. A backup that has never been restored is a hope, not a control (s.53(2)(c)).
- 5
Patch on a schedule and keep the log. Unpatched systems are how ransomware gets in. The log is your s.53(2)(d) evidence.
- 6
Write a one-page breach plan. Who is called first, who decides whether it is reportable, who drafts the s.48(5) notification, who contacts affected people. Include a template.
- 7
Put a written contract in place with every processor. IT provider, payroll, cloud host, website developer, anyone who touches your data. Use the s.52 terms as the checklist.
- 8
Update your privacy notice to state your security measures (s.53(3)) and people's rights under Part IV.
- 9
Decide who owns data protection. Name a data protection officer or, until SME regulations arrive, a responsible person who can grow into the role.
- 10
Watch the Gazette for the commencement notice and the registration regulations, and put a reminder in the calendar to review all of the above every quarter (s.53(5)).
Where CalTec fits
We are an IT services firm, not a law firm, and this page is not legal advice. What we can do is make the technical side of the Act true in your organization and documented, which is most of what an inspector, an insurer or a client will ask to see.
Every CalTec managed plan already includes the s.53 spine: tested backups, multi-factor authentication, patching that happens, endpoint protection, and documentation you keep. It is included in every tier and never sold back as an add-on, because being defensible should not be a premium feature.
The free consultation now includes a readiness walkthrough against the checklist above. You leave knowing where you stand and what it would take, whether or not you hire us.
Book a free readiness walkthroughQuestions and answers
Is the Data Protection Act 2025 in force?
No. It was gazetted on 11 December 2025 but comes into operation only on a date the Minister appoints by notice in the Gazette (s.1(2)). Different sections may start on different dates. As of our last review, no commencement notice had been published. The 2003 Act remains the law in force until then.
Does the Act apply to a small business?
Yes. Section 3 applies the Act to any controller or processor established in The Bahamas, with no size threshold. Two duties have size-related relief: records of processing are not required under 150 staff unless the processing is risky (s.44(5)), and the Minister may exempt small and medium businesses from the data protection officer requirement by regulation (s.46(5)). Security, breach notification, processor contracts and the principles apply regardless of size.
Do I need a data protection officer?
As gazetted, s.46(1)(a) requires one wherever processing is carried out by a public body or private body, which reads as every organization. Section 46(5) allows regulations to exempt small and medium businesses in whole or in part. Until those regulations are published, the prudent course is to name a responsible person and document their role.
Do I have to register with the Data Protection Commissioner?
Section 38 requires controllers and processors to apply for registration, and s.38(5) says regulations will prescribe which categories are subject to or exempt from mandatory registration. Operating unregistered when registration is required is an offence carrying a fine of up to $10,000 or six months imprisonment (s.38(6)). Watch for the regulations.
What counts as sensitive personal data?
Under s.2: racial or ethnic origin, political opinions, religious or similar beliefs, trade union membership, genetic data, biometric data used to identify someone, sex life or sexual orientation, medical data, health records, financial record or financial position, criminal records and related proceedings. Financial information being on the list means most professional offices hold sensitive data.
How quickly must a breach be reported?
Within 72 hours of becoming aware of it, to the Commissioner (s.48(1)), where the breach is likely to result in a risk to people or involves sensitive data. Affected individuals must also be told within 72 hours where the risk is high (s.49(1)). A processor must tell its controller within 72 hours (s.48(4)). Every breach must be recorded whether or not it is reportable (s.48(7)).
Is my IT provider responsible under the Act?
Yes, in its own right. A managed IT provider is a data processor. Section 53(1) binds processors directly to implement security measures, s.48(4) gives them a 72-hour duty to report breaches to you, and s.52 requires a written contract between you that sets out their obligations, including confidentiality, sub-processor approval, assistance with your duties, deletion or return of data at the end, and cooperation with audits.
My email and files are hosted overseas. Is that allowed?
Transfers outside The Bahamas are governed by Part VI (ss.54 to 56), which sets a general principle and conditions rather than a ban. You should document where your data is hosted and on what basis. Note s.45(2): where data sits on a server or data centre abroad, the cost of the Commissioner reviewing or auditing it is borne by the controller and processor.
What are the penalties?
Penalty notices of up to $10,000 for failures in records, DPO, breach notification, impact assessments or security (s.90). Fines of up to $50,000 and up to three years imprisonment for processing contrary to the principles (s.4(3)), for ignoring Commissioner notices (s.80(4)), or for unlawfully obtaining or disclosing personal data (s.96(3)). Up to $100,000 and five years for selling unlawfully obtained data (s.96(4)). Directors and managers can be personally liable (s.95), and data subjects have a right to compensation (s.32).
Does CalTec provide legal advice on the Act?
No. We are an IT services firm. We implement and document the technical and organizational measures the Act requires, and we can work alongside your attorney on the contractual and registration side. For legal advice on your specific obligations, consult a Bahamian attorney.
Sources
- Data Protection Act, 2025 (gazetted text)Official Gazette of The Bahamas, Supplement Part I, 11 December 2025. All section references on this page are to this text.
- Office of the Data Protection CommissionerThe regulator. Email [email protected].
- Privacy Law Developments, Commonwealth of The Bahamas 2026Presentation by Michael Wright, Data Protection Commissioner, February 2026. Source for the 2003 Act commencement date and the comparison of the two Acts.
- Data Protection Bill, 2025 (consultation draft)Disseminated 21 August 2025. Useful for comparing what changed before enactment.
- Ransomware attack on universityThe Tribune, 6 February 2025.
- Phased Network RestorationUniversity of The Bahamas, February 2025.
- Water and Sewerage Corporation responds to cybersecurity incidentEyewitness News, March 2025.
- Water Corp still grappling with ransomware fall-outThe Tribune, 15 April 2025.
- Port operator's $1m stake in electricity grid companyThe Tribune, 29 October 2024. Reports the April 2024 Akira ransomware incident at Arawak Port Development.
This guide is general information prepared by Caltec Bahamas Ltd. from the gazetted text of the Act and the public sources listed. It is not legal advice. The Act is not yet in force, and regulations that will shape registration, data protection officer and impact assessment duties have not been published. Check the sources and consult a Bahamian attorney for advice on your organization.
