Sagentix Cyber & AI
Six regimes.
One control baseline.
An organization operating across the Caribbean, North America and Europe does not need a separate privacy programme per country. The obligations converge far more than the statutes suggest — but only if you know precisely where they diverge.
We build the harmonized baseline and document the deltas. We are not a law firm and we give no legal opinions — this is readiness work. The regulator remains the regulator, and what the law means stays with your counsel.
Privacy takes two professionals, and they do different jobs
Confusing them is expensive in both directions. Here is the line, stated plainly.
What a CISSP builds — this is us
- The control baseline, and the security architecture behind it
- Data inventory, processing register and data-flow mapping
- Access control, encryption, logging, retention and secure disposal
- Impact-assessment and breach-response methodology, and running it
- Vendor and processor due diligence against the controls
- The evidence a regulator or an auditor would be shown
The engineering and organizational work: what your organization actually does with personal data, and whether it can prove it.
What a lawyer decides — this is not us
- Whether a statute applies to you, and how it should be read
- The lawful basis you rely on, and the risk in relying on it
- Contract and data-transfer instruments, drafted and negotiated
- Regulatory filings, and representation before a supervisory authority
- Breach notifiability as a legal determination, and privilege
- Any opinion on liability, penalties or enforcement exposure
The legal work: what the law means, and what it requires of you. Sagentix is not a law firm and gives no legal advice or opinions.
In practice the two run together and the handoffs are obvious once the line is drawn. Your counsel establishes which obligations bind you; we build the programme that meets them and produces the evidence. Where a question crosses the line, we say so at the time rather than answering it.
What you are actually subject to
Four regions, four different shapes of obligation. Status stated as at August 2026 — in this field, a summary without a date is a liability.
European Union
GDPR
Regulation (EU) 2016/679, applicable since May 2018. The reference model the newer Acts are drafted against — lawful basis, data-subject rights, records of processing, impact assessments, breach notification, and restrictions on international transfer.
Reaches organizations outside the EU that offer goods or services to, or monitor, people inside it.
United States
A patchwork, not a statute
There is no single federal privacy law. A growing set of state regimes led by California, alongside sectoral rules that reach specific industries directly — health information, and the financial-privacy obligations that apply to banks.
The practical question is rarely "are we compliant" but "which states and which sector rules reach us".
Canada
PIPEDA, and Quebec separately
PIPEDA remains the federal private-sector law in force. Reform has been attempted and has not landed: the previous bill died in January 2025, and a replacement was tabled in June 2026 at first reading only. Quebec’s Law 25 is fully in force and does carry substantial monetary penalties.
Status as at August 2026. Anyone quoting the reform bill’s penalty figures as current is quoting a bill that is not law.
Caribbean
Five jurisdictions, five realities
The regimes below are GDPR-adjacent in substance and genuinely different in force. Sequencing a programme by where obligations actually bite — rather than by where a statute exists on paper — is most of the value of the first conversation.
Set out jurisdiction by jurisdiction in the table below.
“The Caribbean” is not one regime
Treating it as one is the most expensive mistake available in this market — in both directions. You can build for an obligation that does not bind you, and miss the one that does.
| Jurisdiction | Statute | Operative status | What matters most |
|---|---|---|---|
| Jamaica | Data Protection Act, 2020 | In force since 1 December 2023 | Information Commissioner with enforcement powers; breach reporting within 72 hours |
| Barbados | Data Protection Act, 2019 | In effect since 1 January 2022 | Seven GDPR-aligned principles; Data Protection Commissioner established |
| Cayman Islands | Data Protection Act (2021 Revision) | In force | Eight principles; the data-protection function sits with the Office of the Ombudsman |
| The Bahamas | Data Protection Act, 2007 | In force, regulator established | Very little enforcement activity in practice — a low practical risk today, not an absent obligation |
| Trinidad and Tobago | Data Protection Act, 2011 | NOT fully in force — no regulator | One of the earliest Acts in the region and still incomplete. Widely listed as if operative; it is not |
The Trinidad and Tobago entry is the reason this table exists. Its Act is among the earliest in the region, appears in nearly every comparative summary, and is still not fully in force with no regulator standing behind it. An adviser who reads a comparison table rather than the commencement position will build you a programme against an obligation that does not bind, and will miss that the real compliance pressure in that market comes from somewhere else entirely.
One baseline, deltas documented
These Acts are GDPR-adjacent by design. The underlying obligations are near-identical in substance even where numbering, wording and penalty schedules differ.
An organization operating across several of these jurisdictions does not need several control sets. One harmonized baseline is sufficient — provided the jurisdictional deltas are written down rather than assumed away, and provided the baseline is calibrated to the strictest clock that actually applies to you.
Sagentix maintains its own cross-mapping of the Jamaican, Barbadian and Cayman Acts onto ISO/IEC 27001, NIST CSF 2.0 and the SOC 2 Trust Services Criteria, so the privacy programme and the security programme are built as one thing rather than two. It is a technical mapping, not a legal opinion.
What gets built once
- A single data inventory and records-of-processing register
- One lawful-basis and consent model, with the jurisdictional deltas documented
- One set of data-subject-rights procedures, tuned per regime for timelines
- One breach-response runbook, calibrated to the shortest clock that applies to you
- One transfer-mechanism position covering the regimes that restrict transfers
- Retention and disposal schedules that satisfy the strictest applicable rule
What the engagement covers
Advisory, architecture and authoring. The regulator judges, and your counsel interprets the law.
Jurisdictional applicability
Which regimes actually reach you, on the facts of where your data sits, who your customers are and what you do with their information — before anyone builds anything.
The harmonized baseline
One control set built to satisfy every regime in scope, with the deltas documented rather than duplicated. Mapped to ISO/IEC 27001, NIST CSF 2.0 and the SOC 2 privacy criteria so the privacy programme and the security programme are one programme.
The instrument set
Privacy policy and notices, processing register, impact-assessment methodology, data-subject-rights procedures, retention schedules, vendor and processor clauses, and the breach-response runbook.
Governance and accountability
Who decides, who is accountable, and what a regulator would be shown — including the data-protection officer question where a regime requires the role.
Supervisory readiness
Preparing the organization for the questions a supervisory authority asks, and for the evidence it expects to see, before it asks them.
Carrying it into the security gates
Where the same baseline also has to satisfy an ISO/IEC 27018 assessment, a SOC 2 privacy category or a Canadian Protected B authorization, mapping it once.
Where you will want someone else
- Provide legal advice or a legal opinion
- Act as your registered data protection officer
- Certify, audit or attest a privacy programme
- Represent you before a supervisory authority
- Interpret a statute where qualified local counsel should
This work is technical and organizational, not legal. Sagentix is not a law firm, holds no legal practising certificate in any jurisdiction, and provides no legal advice or legal opinions. Interpretation of any statute on this page belongs to qualified counsel there — and we will tell you when you have reached that line rather than step over it.
Which regimes actually reach you?
Thirty minutes. We establish which regimes bind you on the facts rather than on the map, where your obligations genuinely diverge, and whether one baseline can carry all of them alongside the security gates you already face.
Sources
- European Union — Regulation (EU) 2016/679 (General Data Protection Regulation). eur-lex.europa.eu.
- Government of Jamaica — The Data Protection Act, 2020; Office of the Information Commissioner. oic.gov.jm.
- Government of Barbados — Data Protection Act, 2019.
- Cayman Islands — Data Protection Act (2021 Revision); Office of the Ombudsman. ombudsman.ky.
- The Bahamas — Data Protection (Privacy of Personal Information) Act, 2007.
- Trinidad and Tobago — Data Protection Act, 2011 (partially proclaimed; no Information Commissioner appointed as at August 2026).
- Office of the Privacy Commissioner of Canada — PIPEDA. priv.gc.ca. Bill C-27 died on the Order Paper in January 2025; Bill C-36 was tabled 15 June 2026 and is at first reading.
- Commission d’accès à l’information du Québec — Law 25, fully in force since September 2024. cai.gouv.qc.ca.
Status stated as at August 2026 and subject to change — commencement, regulators and penalties all move. This page is general information, not legal advice. Confirm the current position with qualified counsel in the relevant jurisdiction before acting on it.