Jamaica Data Protection Act 2020 · Evidence & Implementation Kit
Comply with Jamaica's Data Protection Act, without decoding the eight standards into a program yourself.
Every obligation, from the eight data protection standards and registration with the Information Commissioner through the mandatory DPO, 72-hour breach notification and cross-border transfer rules, handed to you as an adopt-ready control with the records that prove it.
Compliant in a weekend, not a quarter.
Here is the honest situation. Jamaica's Data Protection Act 2020 is a GDPR-style regime with real teeth: eight data protection standards, mandatory registration with the Information Commissioner, a required data protection officer for many controllers, seven data subject rights with a 30-day access deadline, 72-hour breach notification, and penalties reaching four percent of turnover. Working out which duties apply to you, building the DPO function and the breach process, and evidencing each standard is weeks of legal interpretation.
This Kit removes that interpretation. It is every obligation written as an adopt-ready control you personalize in a weekend, with the records that prove compliance.
What you get, the moment you buy
34
Obligations as adopt-ready controls. Every duty, from the eight standards and registration through the DPO, data subject rights, breach notification and transfer, written so you personalize and apply it. The 72-hour clock and DPO triggers are built in.
34
Evidence-that-proves-it checklists. For each obligation, exactly the records that show compliance, plus where organizations most often fall short, so you close the gap first.
1
Data Protection Control Matrix, pre-built. Every obligation in a working spreadsheet, ready to record status, owner and evidence location.
1
Gap & Readiness Assessment. Score each obligation and the workbook returns your readiness as a single percentage, and exactly what to fix next.
Grounded in the Jamaica Data Protection Act 2020 and the Information Commissioner's eight data protection standards, with the registration duty, the mandatory DPO and the 72-hour breach notification called out. Editable Word and Excel files.
Registration and the DPO come first
The Act requires controllers to register with the Information Commissioner and, for many, to appoint a data protection officer. This Kit gets those two threshold duties and their evidence right, so the obligations that trigger enforcement first are handled first.
What one control looks like
This is fair and lawful processing, the first of the eight standards. All 34 are built to this depth.
JDPA-1 Fair and lawful processing with a valid legal basis STANDARDS
Put this control in place
[Organization] shall process personal data only where it is fair and lawful and rests on a documented legal basis identified before processing begins, shall never obtain personal data by deception or misleading representations, and shall maintain a written record mapping each processing activity to its purpose, its legal basis, and the categories of data subjects affected, reviewing that record whenever a processing activity materially changes.
Legal note.
Reflects the first standard published by the Office of the Information Commissioner: personal data must be processed fairly and lawfully.
Evidence that proves compliance
- Register of processing activities recording purpose and legal basis for each activity
- Lawful basis assessment templates completed for representative processing operations
- Data collection notices and forms reviewed for fairness and transparency
- Records confirming no deceptive or misleading collection practices are in use
Common finding they raise: Legal basis is assumed rather than documented, and no register links each processing activity to a specific lawful ground before processing starts.
Why this is not another template pack
- The evidence is the point. A duty you cannot evidence is exposure. This tells you the records that prove compliance and where organizations fall short, for every obligation.
- The teeth are real. Penalties reach four percent of turnover, and breach notification is a 72-hour clock. The Kit is built to close those exposures before they trigger.
- Built on a mapped compliance corpus, not one person's opinion, from a graph of thousands of controls across standards.
- It compounds. The eight standards map closely onto GDPR duties, so this work feeds a broader multi-jurisdiction privacy program.
Who buys this
Any organization processing personal data of individuals in Jamaica, the privacy, legal and compliance leads who own it, and consultants advising on the Act. Whether it is a first assessment or a registration deadline, you save weeks and walk in with the standards, DPO and records ready.
By the end of the weekend you will have
✓ An adopt-ready control for all 34 obligations
✓ A completed data protection control matrix
✓ The records that prove compliance
✓ Your registration and DPO duties handled
✓ A readiness percentage and a fix list
✓ The common gaps closed
Common questions
Is it really editable? Yes. Word and Excel files you own and adapt. No portal, no subscription.
Is this legal advice? No. It is an implementation toolkit grounded in the Act. For a specific matter consult counsel; this gets your controls and records in order fast.
Does it cover registration and the DPO? Yes. Registration with the Information Commissioner and the mandatory DPO triggers are their own control group, because they are threshold duties.
Does it cover breach notification? Yes, including the 72-hour notification to the Commissioner and data subjects and the required content.
What if it is not for me? A 30-day money-back guarantee.
Do not decode the eight standards by hand.
Every obligation is fast to adopt with the Kit. It is instant, and it is guaranteed.
Add it to your cart and be compliant this weekend.
Instant digital download · 30-day money-back guarantee · The Art of Service Pty Ltd, GPO Box 2673, Brisbane QLD 4001 · support@theartofservice.com