Skip to main content

Sagentix Cyber & AI

Six regimes.
One control baseline.

An organization operating across the Caribbean, North America and Europe does not need a separate privacy programme per country. The obligations converge far more than the statutes suggest — but only if you know precisely where they diverge.

We build the harmonized baseline and document the deltas. We are not a law firm and we give no legal opinions — this is readiness work. The regulator remains the regulator, and what the law means stays with your counsel.

Privacy takes two professionals, and they do different jobs

Confusing them is expensive in both directions. Here is the line, stated plainly.

What a CISSP builds — this is us

  • The control baseline, and the security architecture behind it
  • Data inventory, processing register and data-flow mapping
  • Access control, encryption, logging, retention and secure disposal
  • Impact-assessment and breach-response methodology, and running it
  • Vendor and processor due diligence against the controls
  • The evidence a regulator or an auditor would be shown

The engineering and organizational work: what your organization actually does with personal data, and whether it can prove it.

What a lawyer decides — this is not us

  • Whether a statute applies to you, and how it should be read
  • The lawful basis you rely on, and the risk in relying on it
  • Contract and data-transfer instruments, drafted and negotiated
  • Regulatory filings, and representation before a supervisory authority
  • Breach notifiability as a legal determination, and privilege
  • Any opinion on liability, penalties or enforcement exposure

The legal work: what the law means, and what it requires of you. Sagentix is not a law firm and gives no legal advice or opinions.

In practice the two run together and the handoffs are obvious once the line is drawn. Your counsel establishes which obligations bind you; we build the programme that meets them and produces the evidence. Where a question crosses the line, we say so at the time rather than answering it.

What you are actually subject to

Four regions, four different shapes of obligation. Status stated as at August 2026 — in this field, a summary without a date is a liability.

European Union

GDPR

Regulation (EU) 2016/679, applicable since May 2018. The reference model the newer Acts are drafted against — lawful basis, data-subject rights, records of processing, impact assessments, breach notification, and restrictions on international transfer.

Reaches organizations outside the EU that offer goods or services to, or monitor, people inside it.

United States

A patchwork, not a statute

There is no single federal privacy law. A growing set of state regimes led by California, alongside sectoral rules that reach specific industries directly — health information, and the financial-privacy obligations that apply to banks.

The practical question is rarely "are we compliant" but "which states and which sector rules reach us".

Canada

PIPEDA, and Quebec separately

PIPEDA remains the federal private-sector law in force. Reform has been attempted and has not landed: the previous bill died in January 2025, and a replacement was tabled in June 2026 at first reading only. Quebec’s Law 25 is fully in force and does carry substantial monetary penalties.

Status as at August 2026. Anyone quoting the reform bill’s penalty figures as current is quoting a bill that is not law.

Caribbean

Five jurisdictions, five realities

The regimes below are GDPR-adjacent in substance and genuinely different in force. Sequencing a programme by where obligations actually bite — rather than by where a statute exists on paper — is most of the value of the first conversation.

Set out jurisdiction by jurisdiction in the table below.

“The Caribbean” is not one regime

Treating it as one is the most expensive mistake available in this market — in both directions. You can build for an obligation that does not bind you, and miss the one that does.

JurisdictionStatuteOperative statusWhat matters most
JamaicaData Protection Act, 2020In force since 1 December 2023Information Commissioner with enforcement powers; breach reporting within 72 hours
BarbadosData Protection Act, 2019In effect since 1 January 2022Seven GDPR-aligned principles; Data Protection Commissioner established
Cayman IslandsData Protection Act (2021 Revision)In forceEight principles; the data-protection function sits with the Office of the Ombudsman
The BahamasData Protection Act, 2007In force, regulator establishedVery little enforcement activity in practice — a low practical risk today, not an absent obligation
Trinidad and TobagoData Protection Act, 2011NOT fully in force — no regulatorOne of the earliest Acts in the region and still incomplete. Widely listed as if operative; it is not

The Trinidad and Tobago entry is the reason this table exists. Its Act is among the earliest in the region, appears in nearly every comparative summary, and is still not fully in force with no regulator standing behind it. An adviser who reads a comparison table rather than the commencement position will build you a programme against an obligation that does not bind, and will miss that the real compliance pressure in that market comes from somewhere else entirely.

One baseline, deltas documented

These Acts are GDPR-adjacent by design. The underlying obligations are near-identical in substance even where numbering, wording and penalty schedules differ.

An organization operating across several of these jurisdictions does not need several control sets. One harmonized baseline is sufficient — provided the jurisdictional deltas are written down rather than assumed away, and provided the baseline is calibrated to the strictest clock that actually applies to you.

Sagentix maintains its own cross-mapping of the Jamaican, Barbadian and Cayman Acts onto ISO/IEC 27001, NIST CSF 2.0 and the SOC 2 Trust Services Criteria, so the privacy programme and the security programme are built as one thing rather than two. It is a technical mapping, not a legal opinion.

What gets built once

  • A single data inventory and records-of-processing register
  • One lawful-basis and consent model, with the jurisdictional deltas documented
  • One set of data-subject-rights procedures, tuned per regime for timelines
  • One breach-response runbook, calibrated to the shortest clock that applies to you
  • One transfer-mechanism position covering the regimes that restrict transfers
  • Retention and disposal schedules that satisfy the strictest applicable rule

What the engagement covers

Advisory, architecture and authoring. The regulator judges, and your counsel interprets the law.

Jurisdictional applicability

Which regimes actually reach you, on the facts of where your data sits, who your customers are and what you do with their information — before anyone builds anything.

The harmonized baseline

One control set built to satisfy every regime in scope, with the deltas documented rather than duplicated. Mapped to ISO/IEC 27001, NIST CSF 2.0 and the SOC 2 privacy criteria so the privacy programme and the security programme are one programme.

The instrument set

Privacy policy and notices, processing register, impact-assessment methodology, data-subject-rights procedures, retention schedules, vendor and processor clauses, and the breach-response runbook.

Governance and accountability

Who decides, who is accountable, and what a regulator would be shown — including the data-protection officer question where a regime requires the role.

Supervisory readiness

Preparing the organization for the questions a supervisory authority asks, and for the evidence it expects to see, before it asks them.

Carrying it into the security gates

Where the same baseline also has to satisfy an ISO/IEC 27018 assessment, a SOC 2 privacy category or a Canadian Protected B authorization, mapping it once.

Where you will want someone else

  • Provide legal advice or a legal opinion
  • Act as your registered data protection officer
  • Certify, audit or attest a privacy programme
  • Represent you before a supervisory authority
  • Interpret a statute where qualified local counsel should

This work is technical and organizational, not legal. Sagentix is not a law firm, holds no legal practising certificate in any jurisdiction, and provides no legal advice or legal opinions. Interpretation of any statute on this page belongs to qualified counsel there — and we will tell you when you have reached that line rather than step over it.

Which regimes actually reach you?

Thirty minutes. We establish which regimes bind you on the facts rather than on the map, where your obligations genuinely diverge, and whether one baseline can carry all of them alongside the security gates you already face.

See the full practice

Sources

  • European Union — Regulation (EU) 2016/679 (General Data Protection Regulation). eur-lex.europa.eu.
  • Government of Jamaica — The Data Protection Act, 2020; Office of the Information Commissioner. oic.gov.jm.
  • Government of Barbados — Data Protection Act, 2019.
  • Cayman Islands — Data Protection Act (2021 Revision); Office of the Ombudsman. ombudsman.ky.
  • The Bahamas — Data Protection (Privacy of Personal Information) Act, 2007.
  • Trinidad and Tobago — Data Protection Act, 2011 (partially proclaimed; no Information Commissioner appointed as at August 2026).
  • Office of the Privacy Commissioner of Canada — PIPEDA. priv.gc.ca. Bill C-27 died on the Order Paper in January 2025; Bill C-36 was tabled 15 June 2026 and is at first reading.
  • Commission d’accès à l’information du Québec — Law 25, fully in force since September 2024. cai.gouv.qc.ca.

Status stated as at August 2026 and subject to change — commencement, regulators and penalties all move. This page is general information, not legal advice. Confirm the current position with qualified counsel in the relevant jurisdiction before acting on it.