Barbados’ Data Protection Watchdog Has Real Teeth on Paper. Why Hasn’t It Bitten?

Introduction

Barbados demonstrated a level of progressiveness compared to its Caribbean neighbours when it gazetted the Data Protection Act, 2019 (the “DPA”), a GDPR-inspired law with registration requirements, mandatory breach notification, data subject rights, and penalties of up to BBD $500,000 or three years’ imprisonment for serious violations. The Act became enforceable in March 2021, and Lisa Greaves was appointed as the island’s first Data Protection Commissioner (“DPC”) in July the same year.

Four years on, the legal architecture remains solid, but the performance of the Office that’s supposed to enforce it is a different story. From a national voters list exposed on the open Internet to a children’s survey investigation that appears to have simply gone quiet, a pattern emerges of a privacy regulator that reacts late, if at all, and rarely tells the public what happened next. In this blog post, I will explore where the Office of the Data Protection Commissioner (“ODPC”) appears to be falling short, case-by-case, and what needs to change.

No visible enforcement record

The DPA gives the Commissioner real enforcement powers in the form of audits, enforcement notices, warrants to investigate suspected breaches, and fines that scale up to half a million Barbadian dollars. Four years into an active mandate, there is no public register of enforcement notices issued, no published list of completed investigations, and no visible history of fines levied against non-compliant organizations in the public or private sectors.

A regulator that never visibly uses its enforcement powers sends an unintended signal to data controllers that the risk of actually being penalised is low. Regulatory deterrence depends on organisations believing that non-compliance carries consequences, and that belief has to be built on evidence, not the text of a statute.

The government’s own breaches expose the gap between law and practice

The clearest test of any data protection regime is how it performs when something goes wrong, and 2022 through 2024 presented Barbados with three major tests.

A December 2022 cybersecurity attack on the Queen Elizabeth Hospital (QEH) severely disrupted the country’s healthcare infrastructure, forcing a total network shutdown and reversion to manual, paper-based operations for several months. The outage caused the postponement of surgeries, delayed appointments in the Radiology Department, and temporarily shut down outpatient pharmacies. Despite the scale of the breach and the highly sensitive nature of patient data at risk, the incident was characterized by a distinct lack of public transparency. In the aftermath of the hack, there was no public record of a formal, published investigation or conclusive regulatory action by the DPC. This administrative silence, coupled with a failure to provide the public with clear reassurances regarding the containment of personal health information is a major concern in terms of lack of accountability and enforcement within the island’s data privacy regulations.

In September 2024, the Barbados Revenue Authority (BRA) suffered what may be the largest data breach in the country’s history, where roughly 230GB of data, including driver’s licenses, passports, vehicle registration records, tax information, and other sensitive documents, was exfiltrated by a threat actor and offered for sale online. I publicly challenged the government’s characterization of the incident, arguing the breach was more serious than officials were letting on and that international supervisory authorities and data subjects in the EU, UK, and Canada should have been notified given foreign nationals’ data was involved. The government’s own account, weeks later, sought to downplay the risk, describing much of the exposed material as “reasonably low risk” administrative documentation; a characterization at odds with the sensitive data confirmed in the leak.

A second breach hit the Barbados Statistical Service in October 2024, involving a ransomware group. To its credit, the Statistical Service notified the Commissioner and issued public updates, but the fact that two significant government bodies were breached within weeks of each other, with the public first learning of the scale from independent researchers and journalists rather than proactive disclosure, does not reflect well on the state of data governance the Data Protection Commissioner is meant to be driving across government.

In neither case is there public evidence that the DPC conducted a visible, independent post-incident audit, issued findings, or required corrective measures with any public accountability attached.

The 2021 election roll: a foreseeable exposure met with near-silence

If the BRA and BSS incidents show how the DPC handles a crisis after the fact, the 2021 voters list exposure shows something arguably worse – a foreseeable privacy failure the ODPC appears to have done little to prevent or answer for, even though it happened on its own watch.

On 29 December 2021, days after a snap election was called, the Barbados Government Information Service published a full preliminary voters list online with 5,520 pages containing the full name, national registration number (NRN), date of birth, gender, residential status, constituency, and address of more than 264,000 people. It was freely downloadable by anyone in the world, not just Barbadians, and was quickly mirrored on social media, the Dark Web, and other platforms once attention turned to it. Commissioner Greaves had already been in post for roughly five months at that point, and the DPA had been enforceable since March of that year.

The Electoral and Boundaries Commission (EBC) defended the release as a legal obligation under the Representation of the People Act, and its Chairman (now the Chief Justice of the Supreme Court) publicly maintained that identifiers like the NRN were “not really anything that is private.” I pushed back against his contention arguing that publishing the full NRN and date of birth of every voter violated the basic data minimisation principle the DPA itself is built on, and pointed out that safer alternatives existed, including a searchable lookup tool, or controlled distribution to election officials and campaign managers, that would have satisfied the legal publication requirement without exposing sensitive identifiers to the open Internet. My assessment at the time was blunt: the Office of the DPC was too under-resourced or politically captured to make enforcement of the DPA against this kind of exposure realistic.

What’s conspicuously absent from the public record is any comment from the DPC herself. She never visibly weighed in on whether the EBC’s actions were consistent with the DPA, no public guidance issued to the EBC on safer methods of publication, and no indication the office pushed for the promised legislative harmonisation between the Representation of the People Act and the newer DPA, despite commentators flagging that exact conflict in real time. By March 2023, I again raised the alarm, saying there was evidence the leaked list was already being used to commit identity fraud against Barbadians internationally, and that the EBC had ignored my warnings. Once again, there was no public record of the DPC’s Office weighing in.

This case is arguably the most damaging of the three discussed here, because it wasn’t a hack, a rogue vendor, or a third-party contractor’s mistake; it was the government’s own statutory election process, running headlong into the DPA’s core principles, in the regulator’s first year of operation. If the DPC couldn’t or wouldn’t intervene on this one, in public, it raises a hard question about how much it can be relied on to check the rest of the government.

The IDB school survey: an investigation opened, never closed

The clearest example of the Office starting strong and then going quiet involves children’s data, the category the DPA should be most protective of.

In September 2022, more than 700 first-form students across five secondary schools were given a roughly 300-question survey administered as part of an Inter-American Development Bank (IDB)-funded project. The questionnaire asked children as young as 11 or 12 about their sexuality, gender identity, self-harm and suicidal ideation, and drug use, along with details about their families, and all without parental consent. Parents only learned about it after the fact, when local media broke the story following complaints.

To its credit, the Ministry of Education referred the matter to the Data Protection Commissioner, and the Office opened a formal investigation, with a spokesperson for Commissioner Greaves confirming publicly that it was examining whether the DPA had been breached and would advise the Ministry accordingly.

That’s where the public trail ends. There are no published findings from that investigation, no statement on whether the DPA was in fact breached, no enforcement notice, no public accounting of what the IDB, the Ministry, or the schools involved were required to change. What followed instead was driven by everyone but the regulator. Parents organised protests calling for resignations and a class-action lawsuit, the IDB and Ministry apologised on their own initiative, and the Ministry quietly tightened its internal approval process for any research conducted in schools. As recently as early 2026, officials cited that internal Ministry protocol, not any DPC ruling, as the safeguard now governing school-based research, framing it as something developed in “consultation with” the Commissioner rather than the product of a completed DPC investigation.

This is a hard case to explain away as “still ongoing.” The underlying facts were never seriously disputed. Both the IDB and the Ministry admitted the survey happened and apologised for its content, so there was little for a regulator to adjudicate that wasn’t already conceded. What was missing was the one thing only the DPC’s Office could provide, which was an authoritative, public determination of whether Barbadian children’s sensitive data had been unlawfully collected, and what accountability followed. Four years on, parents still don’t have that answer from the body legally responsible for giving it to them.

Other notable data breaches

There’s been a recurring wave of cyber incidents in Barbados between 2024 and 2026, most notably the viral February 2026 Digicel data breach and systemic ransomware attacks targeting local law firms. These too have been met with notable silence from the DPC, despite detailed customer records, highly sensitive corporate legal files, land titles, and other private client data been exposed. Moreover, the dataset from the Digicel breach appeared to have been highly targeted by political campaigns with subscribers found on the list reportedly receiving highly personalized, unsolicited campaign calls from political canvassers who matched their names to the leaked database. Local cybersecurity experts also note that several corporate cyber incidents go completely unrecorded because companies choose not to report data breaches to protect their reputation (this is a clear violation of the DPA’s mandatory breach notification requirement). Despite legal mandates for swift oversight, the DPC’s failure to issue timely public statements, definitive enforcement actions, or transparent status updates has left the public in the dark. While corporate victims quietly manage reputation damage and thousands of exposed citizens fall prey to targeted political spam and phishing risks, the Commissioner’s lack of visible intervention severely undermines national trust in Barbados’ privacy frameworks.

Reactive, not proactive, engagement

Where the Office has visibly acted, it has largely been in response to complaints or media pressure rather than through its own initiative (e.g., investigating a school survey after the Ministry of Education flagged it, or responding to a political party’s e-voting system after journalists reported member concerns). These interventions show the Office can act, but a regulator whose only visible activity is complaint-driven reaction, rather than proactive audits of high-risk data controllers (government ministries, financial institutions, telecoms, credit bureaus), is not fulfilling the supervisory role the DPA envisions. Barbados only rolled out a national cybersecurity and data-protection public awareness campaign after the BRA breach forced the issue. A competent regulator builds public and institutional awareness ahead of a crisis, not in response to one.

No public compliance picture

Every data controller and processor operating in or targeting Barbados is required to register with the Commissioner. There is no publicly accessible register showing how many organisations have actually registered, no compliance rate disclosed, and no announced deadline was ever set for organisations to come into compliance; a fact regulators themselves acknowledged years after the law took effect. Without a visible baseline of who is and isn’t complying, neither the public nor businesses trying to do the right thing have any way to gauge how seriously the law is being taken.

Limited transparency and reporting

The DPA requires the Commissioner to submit annual reports to Parliament. Whether or not this is technically happening, there is little to no public visibility into these reports, complaint statistics, breach notification numbers, or the Office’s own resourcing and staffing levels. A regulator’s credibility rests substantially on transparency about its own performance (e.g., publishing how many complaints it receives, how long they take to resolve, and what outcomes result). That data isn’t publicly available in Barbados today. 

Furthermore, the DPC’s Office does not even have a dedicated website with key resources. As a model, an effective website should feature public advisories, data subject rights explanations, organizational toolkits, reporting channels, and public enforcement logs at a bare minimum. This state of affairs cannot and should not be acceptable for a function that is nearly 5 years old.

Resourcing and capacity questions

The Office sits within the Ministry of Industry, Innovation, Science and Technology (MIST) rather than as a fully independent statutory body with its own budget line, staffing complement, and governance mechanisms. Regional commentary has repeatedly noted Caribbean regulators, including Barbados’, are still looking to more established regulators in the UK and EU for guidance on how to function effectively. This is a sign that institutional capacity, not just legal authority, remains a work in progress. Whether the Office currently has the technical (cybersecurity), legal, and investigative staff to audit large government agencies and private-sector data controllers is not publicly documented, but the scale and apparent surprise of the 2024 breaches suggests the answer is “not at all.”

Recommendations

  1. Publish an enforcement track record. Even a simple public log of enforcement notices, audits, and (where appropriate, anonymised) outcomes would materially improve deterrence and public trust.
  2. Conduct and publish independent post-breach reviews. After incidents like the BRA and BSS breaches, the Commissioner’s Office should issue its own public findings — separate from the breached agency’s political messaging — including root cause, scope, and remediation timelines.
  3. Set and enforce a compliance deadline. Give data controllers and processors a hard registration and compliance deadline, publish aggregate compliance statistics, and follow through with enforcement against those who miss it.
  4. Move to proactive supervision. Shift resources toward scheduled audits of high-risk sectors such as government ministries and statutory bodies holding ID, tax, and health data; financial institutions; telecoms; credit bureaus rather than relying primarily on complaints and media coverage to trigger action.
  5. Report to the public, not just Parliament. Publish an accessible annual report with complaint volumes, resolution times, breach notifications received, and enforcement actions taken, in the way the UK’s ICO or similar regional regulators do.
  6. Strengthen institutional independence and resourcing. Give the Office a clearer statutory footing, independent budget, and dedicated technical staff (IT, cybersecurity, audit, digital forensics) so it isn’t reliant on other ministries’ capacity when a major incident hits.
  7. Build cross-border notification protocols now, not during a crisis. Given tourism and the size of Barbados’s foreign customer/visitor base, the Office should have clear, pre-agreed procedures for notifying overseas supervisory authorities when non-Barbadian data subjects are affected rather than that becoming a point of public dispute after the fact.
  8. Harmonise conflicting legislation proactively. The 2021 election roll exposure happened because the Representation of the People Act’s publication requirements were never reconciled with the DPA’s data minimisation principle. The Office should maintain and publish a running review of older statutes that conflict with DPA principles, rather than waiting for a public controversy to expose the gap, and should be willing to publicly and specifically weigh in when another public body’s statutory obligations collide with data protection principles, as it did not do in the 2021 case.
  9. Set a time-bound duty to publish investigation outcomes, especially involving children. The IDB survey investigation shows what happens without one: an inquiry opened under public pressure, then never publicly concluded. A statutory deadline, even a lengthy one, for the Office to publish at least a summary finding on completed investigations would prevent cases from quietly disappearing, and should apply with particular urgency to cases involving minors or other vulnerable groups.
  10. Invest in proactive public education. Continue and expand the post-BRA cybersecurity awareness push, but as an ongoing programme rather than a reactive one.

The Bottom Line

Barbados did the hard part in passing a modern, GDPR-aligned law and standing up a regulator years before most of its regional peers. What’s missing now is the visible, consistent exercise of that authority. A voters list containing the identifiers of a quarter-million people sat exposed on the open Internet with no public intervention from the regulator responsible for preventing exactly that. Children were surveyed about their sexuality and mental health without consent, and the investigation into it appears to have quietly died. Two major government agencies were breached within weeks of each other in 2024, and the public learned the real scale from independent researchers, not proactive disclosure. Each case follows the same modus operandi of an initial acknowledgement, then silence where a public finding should be.

Until that changes, and until the ODPC consistently shows its work, in public, on the cases that matter most, the Data Protection Act risks being a well-drafted law without a regulator willing, or resourced, to enforce it.

One thought on “Barbados’ Data Protection Watchdog Has Real Teeth on Paper. Why Hasn’t It Bitten?

  • Well written article which highlights the importance of choosing the right people, and not simply based on paper qualifications.

Leave a comment