Barbados’ Data Protection Watchdog Has Real Teeth on Paper. Why Hasn’t It Bitten?

Introduction

Barbados demonstrated a level of progressiveness compared to its Caribbean neighbours when it gazetted the Data Protection Act, 2019 (the “DPA”), a GDPR-inspired law with registration requirements, mandatory breach notification, data subject rights, and penalties of up to BBD $500,000 or three years’ imprisonment for serious violations. The Act became enforceable in March 2021, and Lisa Greaves was appointed as the island’s first Data Protection Commissioner (“DPC”) in July the same year.

Four years on, the legal architecture remains solid, but the performance of the Office that’s supposed to enforce it is a different story. From a national voters list exposed on the open Internet to a children’s survey investigation that appears to have simply gone quiet, a pattern emerges of a privacy regulator that reacts late, if at all, and rarely tells the public what happened next. In this blog post, I will explore where the Office of the Data Protection Commissioner (“ODPC”) appears to be falling short, case-by-case, and what needs to change.

No visible enforcement record

The DPA gives the Commissioner real enforcement powers in the form of audits, enforcement notices, warrants to investigate suspected breaches, and fines that scale up to half a million Barbadian dollars. Four years into an active mandate, there is no public register of enforcement notices issued, no published list of completed investigations, and no visible history of fines levied against non-compliant organizations in the public or private sectors.

A regulator that never visibly uses its enforcement powers sends an unintended signal to data controllers that the risk of actually being penalised is low. Regulatory deterrence depends on organisations believing that non-compliance carries consequences, and that belief has to be built on evidence, not the text of a statute.

The government’s own breaches expose the gap between law and practice

The clearest test of any data protection regime is how it performs when something goes wrong, and 2022 through 2024 presented Barbados with three major tests.

A December 2022 cybersecurity attack on the Queen Elizabeth Hospital (QEH) severely disrupted the country’s healthcare infrastructure, forcing a total network shutdown and reversion to manual, paper-based operations for an extended period. The outage caused the postponement of surgeries, delayed appointments in the Radiology Department, and temporarily shut down outpatient pharmacies. Despite the scale of the breach and the highly sensitive nature of patient data at risk, the incident was characterized by a distinct lack of public transparency. In the aftermath of the hack, there was no public record of a formal, published investigation or conclusive regulatory action by the DPC. This administrative silence, coupled with a failure to provide the public with clear reassurances regarding the containment of personal health information is a major concern in terms of lack of accountability and enforcement within the island’s data privacy regulations.

In September 2024, the Barbados Revenue Authority (BRA) suffered what may be the largest data breach in the country’s history, where roughly 230GB of data, including driver’s licenses, passports, vehicle registration records, tax information, and other sensitive documents, was exfiltrated by a threat actor and offered for sale online. I publicly challenged the government’s characterization of the incident, arguing the breach was more serious than officials were letting on and that international supervisory authorities and data subjects in the EU, UK, and Canada should have been notified given foreign nationals’ data was involved. The government’s own account, weeks later, sought to downplay the risk, describing much of the exposed material as “reasonably low risk” administrative documentation; a characterization at odds with the sensitive data confirmed in the leak.

A second breach hit the Barbados Statistical Service in October 2024, involving a ransomware group. To its credit, the Statistical Service notified the Commissioner and issued public updates, but the fact that two significant government bodies were breached within weeks of each other, with the public first learning of the scale from independent researchers and journalists rather than proactive disclosure, does not reflect well on the state of data governance the Data Protection Commissioner is meant to be driving across government.

In neither case is there public evidence that the DPC conducted a visible, independent post-incident audit, issued findings, or required corrective measures with any public accountability attached.

The 2021 election roll: a foreseeable exposure met with near-silence

If the BRA and BSS incidents show how the DPC handles a crisis after the fact, the 2021 voters list exposure shows something arguably worse – a foreseeable privacy failure the ODPC appears to have done little to prevent or answer for, even though it happened on its own watch.

On 29 December 2021, days after a snap election was called, the Barbados Government Information Service published a full preliminary voters list online with 5,520 pages containing the full name, national registration number (NRN), date of birth, gender, residential status, constituency, and address of more than 264,000 people. It was freely downloadable by anyone in the world, not just Barbadians, and was quickly mirrored on social media, the Dark Web, and other platforms once attention turned to it. Commissioner Greaves had already been in post for roughly five months at that point, and the DPA had been enforceable since March of that year.

The Electoral and Boundaries Commission (EBC) defended the release as a legal obligation under the Representation of the People Act, and its Chairman (now the Chief Justice of the Supreme Court) publicly maintained that identifiers like the NRN were “not really anything that is private.” I pushed back against his contention arguing that publishing the full NRN and date of birth of every voter violated the basic data minimisation principle the DPA itself is built on, and pointed out that safer alternatives existed, including a searchable lookup tool, or controlled distribution to election officials and campaign managers, that would have satisfied the legal publication requirement without exposing sensitive identifiers to the open Internet. My assessment at the time was blunt: the Office of the DPC was too under-resourced or politically captured to make enforcement of the DPA against this kind of exposure realistic.

What’s conspicuously absent from the public record is any comment from the DPC herself. She never visibly weighed in on whether the EBC’s actions were consistent with the DPA, no public guidance issued to the EBC on safer methods of publication, and no indication the office pushed for the promised legislative harmonisation between the Representation of the People Act and the newer DPA, despite commentators flagging that exact conflict in real time. By March 2023, I again raised the alarm, saying there was evidence the leaked list was already being used to commit identity fraud against Barbadians internationally, and that the EBC had ignored my warnings. Once again, there was no public record of the DPC’s Office weighing in.

This case is arguably the most damaging of the three discussed here, because it wasn’t a hack, a rogue vendor, or a third-party contractor’s mistake; it was the government’s own statutory election process, running headlong into the DPA’s core principles, in the regulator’s first year of operation. If the DPC couldn’t or wouldn’t intervene on this one, in public, it raises a hard question about how much it can be relied on to check the rest of the government.

The IDB school survey: an investigation opened, never closed

The clearest example of the Office starting strong and then going quiet involves children’s data, the category the DPA should be most protective of.

In September 2022, more than 700 first-form students across five secondary schools were given a roughly 300-question survey administered as part of an Inter-American Development Bank (IDB)-funded project. The questionnaire asked children as young as 11 or 12 about their sexuality, gender identity, self-harm and suicidal ideation, and drug use, along with details about their families, and all without parental consent. Parents only learned about it after the fact, when local media broke the story following complaints.

To its credit, the Ministry of Education referred the matter to the Data Protection Commissioner, and the Office opened a formal investigation, with a spokesperson for Commissioner Greaves confirming publicly that it was examining whether the DPA had been breached and would advise the Ministry accordingly.

That’s where the public trail ends. There are no published findings from that investigation, no statement on whether the DPA was in fact breached, no enforcement notice, no public accounting of what the IDB, the Ministry, or the schools involved were required to change. What followed instead was driven by everyone but the regulator. Parents organised protests calling for resignations and a class-action lawsuit, the IDB and Ministry apologised on their own initiative, and the Ministry quietly tightened its internal approval process for any research conducted in schools. As recently as early 2026, officials cited that internal Ministry protocol, not any DPC ruling, as the safeguard now governing school-based research, framing it as something developed in “consultation with” the Commissioner rather than the product of a completed DPC investigation.

This is a hard case to explain away as “still ongoing.” The underlying facts were never seriously disputed. Both the IDB and the Ministry admitted the survey happened and apologised for its content, so there was little for a regulator to adjudicate that wasn’t already conceded. What was missing was the one thing only the DPC’s Office could provide, which was an authoritative, public determination of whether Barbadian children’s sensitive data had been unlawfully collected, and what accountability followed. Four years on, parents still don’t have that answer from the body legally responsible for giving it to them.

Other notable data breaches

There’s been a recurring wave of cyber incidents in Barbados between 2024 and 2026, most notably the viral February 2026 Digicel data breach and systemic ransomware attacks targeting local law firms. These too have been met with notable silence from the DPC, despite detailed customer records, highly sensitive corporate legal files, land titles, and other private client data being exposed. Moreover, the dataset from the Digicel breach appeared to have been highly targeted by political campaigns with subscribers found on the list reportedly receiving highly personalized, unsolicited campaign calls from political canvassers who matched their names to the leaked database. Local cybersecurity experts also note that several corporate cyber incidents go completely unrecorded because companies choose not to report data breaches to protect their reputation (this is a clear violation of the DPA’s mandatory breach notification requirement). Despite legal mandates for swift oversight, the DPC’s failure to issue timely public statements, definitive enforcement actions, or transparent status updates has left the public in the dark. While corporate victims quietly manage reputation damage and thousands of exposed citizens fall prey to targeted political spam and phishing risks, the Commissioner’s lack of visible intervention severely undermines national trust in Barbados’ privacy framework.

Reactive, not proactive, engagement

Where the Office has visibly acted, it has largely been in response to complaints or media pressure rather than through its own initiative (e.g., investigating a school survey after the Ministry of Education flagged it, or responding to a political party’s e-voting system after journalists reported member concerns). These interventions show the Office can act, but a regulator whose only visible activity is complaint-driven reaction, rather than proactive audits of high-risk data controllers (government ministries, financial institutions, telecoms, credit bureaus), is not fulfilling the supervisory role the DPA envisions. Barbados only rolled out a national cybersecurity and data-protection public awareness campaign after the BRA breach forced the issue. A competent regulator builds public and institutional awareness ahead of a crisis, not in response to one.

No registry of data controllers and data processors

Under the text of the DPA, every data controller and processor operating in or targeting Barbados is required to register with the Commissioner. However, this requirement is not currently active because sections 55 through 57 (which cover processor registration) were explicitly excluded from proclamation by the government. There is no publicly accessible register showing how many organizations are engaged in personal data processing, and no announced deadline was ever set for when these provisions will become active; a fact the DPC only publicly acknowledged years after the law took effect. The absence of an active, centralized registry for data controllers and data processors creates significant regulatory and operational friction. Without a registry, the ODPC lacks a definitive, up-to-date master list of every entity handling citizen data. The regulator cannot easily audit who exists, what data they possess, or whether they have appointed a mandatory Data Protection Officer (DPO). This makes proactive compliance enforcement incredibly difficult, forcing the Commission to operate responsively only after a breach occurs. Without the verified emergency contacts for an organization’s data team that would be recorded in a pre-vetted registry, communication lines during a high-stakes data breach can also be slowed down by bureaucratic lag. As Barbados has heavily modeled its legislation after the GDPR to attract international investment and secure “adequacy status” for seamless cross-border data flows, a law that is partially unproclaimed or missing its enforcement registry can raise flags for foreign companies questioning if the local privacy framework is truly robust and active.

Limited transparency and reporting

The DPA requires the Commissioner to submit annual reports to Parliament. Whether or not this is technically happening, there is little to no public visibility into these reports, complaint statistics, breach notification numbers, or the Office’s own resourcing and staffing levels. A regulator’s credibility rests substantially on transparency about its own performance (e.g., publishing how many complaints it receives, how long they take to resolve, and what outcomes result). That data isn’t publicly available in Barbados today. 

Furthermore, the DPC’s Office does not even have a dedicated website with key resources. As a model, an effective website should feature public advisories, data subject rights explanations, organizational toolkits, reporting channels, and public enforcement logs at a bare minimum. This state of affairs cannot and should not be acceptable for a function that is nearly 5 years old.

Resourcing and capacity questions

The Office sits within the Ministry of Industry, Innovation, Science and Technology (MIST) rather than as a fully independent statutory body with its own budget line, staffing complement, and governance mechanisms. Regional commentary has repeatedly noted Caribbean regulators, including Barbados’, are still looking to more established regulators in the UK and EU for guidance on how to function effectively. This is a sign that institutional capacity, not just legal authority, remains a work in progress. Whether the Office currently has the technical (cybersecurity), legal, and investigative staff to audit large government agencies and private-sector data controllers is not publicly documented, but the scale and apparent surprise of the 2024 breaches suggests the answer is “not at all.”

Recommendations

  1. Publish an enforcement track record. Even a simple public log of enforcement notices, audits, and (where appropriate, anonymised) outcomes would materially improve deterrence and public trust.
  2. Conduct and publish independent post-breach reviews. After incidents like the BRA and BSS breaches, the Commissioner’s Office should issue its own public findings — separate from the breached agency’s political messaging — including root cause, scope, and remediation timelines.
  3. Set and enforce a compliance deadline. Give data controllers and processors a hard registration and compliance deadline, publish aggregate compliance statistics, and follow through with enforcement against those who miss it.
  4. Move to proactive supervision. Shift resources toward scheduled audits of high-risk sectors such as government ministries and statutory bodies holding ID, tax, and health data; financial institutions; telecoms; credit bureaus rather than relying primarily on complaints and media coverage to trigger action.
  5. Report to the public, not just Parliament. Publish an accessible annual report with complaint volumes, resolution times, breach notifications received, and enforcement actions taken, in the way the UK’s ICO or similar regional regulators do.
  6. Strengthen institutional independence and resourcing. Give the Office a clearer statutory footing, independent budget, and dedicated technical staff (IT, cybersecurity, audit, digital forensics) so it isn’t reliant on other ministries’ capacity when a major incident hits.
  7. Build cross-border notification protocols now, not during a crisis. Given tourism and the size of Barbados’s foreign customer/visitor base, the Office should have clear, pre-agreed procedures for notifying overseas supervisory authorities when non-Barbadian data subjects are affected rather than that becoming a point of public dispute after the fact.
  8. Harmonise conflicting legislation proactively. The 2021 election roll exposure happened because the Representation of the People Act’s publication requirements were never reconciled with the DPA’s data minimisation principle. The Office should maintain and publish a running review of older statutes that conflict with DPA principles, rather than waiting for a public controversy to expose the gap, and should be willing to publicly and specifically weigh in when another public body’s statutory obligations collide with data protection principles, as it did not do in the 2021 case.
  9. Set a time-bound duty to publish investigation outcomes, especially involving children. The IDB survey investigation shows what happens without one: an inquiry opened under public pressure, then never publicly concluded. A statutory deadline, even a lengthy one, for the Office to publish at least a summary finding on completed investigations would prevent cases from quietly disappearing, and should apply with particular urgency to cases involving minors or other vulnerable groups.
  10. Invest in proactive public education. Continue and expand the post-BRA cybersecurity awareness push, but as an ongoing programme rather than a reactive one.

The Bottom Line

Barbados did the hard part in passing a modern, GDPR-aligned law and standing up a regulator years before most of its regional peers. What’s missing now is the visible, consistent exercise of that authority. A voters list containing the identifiers of a quarter-million people sat exposed on the open Internet with no public intervention from the regulator responsible for preventing exactly that. Children were surveyed about their sexuality and mental health without consent, and the investigation into it appears to have quietly died. Two major government agencies were breached within weeks of each other in 2024, and the public learned the real scale from independent researchers, not proactive disclosure. Each case follows the same modus operandi of an initial acknowledgement, then silence where a public finding should be.

Until that changes, and until the ODPC consistently shows its work, in public, on the cases that matter most, the Data Protection Act risks being a well-drafted law without a regulator willing, or resourced, to enforce it.

A Dark Day for Digital Freedom: The RightsCon Cancellation in Zambia

The sudden, last-minute cancellation of RightsCon 2026 by the Zambian government is more than just a logistical nightmare for the 5,000 delegates already en route, it is a chilling signal for the future of global civic discourse and Internet freedom.

As the world’s premier summit on human rights in the digital age, RightsCon was set to provide a vital platform for activists, technologists, and policymakers to tackle urgent issues like online censorship, AI surveillance, and the protection of marginalized voices.

Why this matters for all of us:

  • The “National Values” Trap: The government’s justification, citing a lack of “alignment with national values”, is a familiar and dangerous euphemism used to suppress difficult conversations. When “values” are used as a filter for human rights dialogue, it sets a precedent that the state, not the citizens, decides which rights are worthy of discussion.
  • The Closing of African Civic Space: Hosting RightsCon in Lusaka was supposed to be a milestone for African digital sovereignty. Instead, this cancellation reinforces a growing trend of “digital authoritarianism” across the continent, where governments prioritize state control over open, transparent debate.
  • Silencing the Marginalized: RightsCon is one of the few global spaces where LGBTQ+ advocates, Sexual and Reproductive Health and Rights (SRHR) researchers, and digital rights defenders from the Global South can organize. Shutting it down disproportionately harms those already facing criminalization and digital exclusion.
  • A Blow to Accountability: From surveillance technology to data privacy, holding Big Tech and governments accountable requires international collaboration. By blocking the gates to this summit, the Zambian government hasn’t just stopped a conference; it has attempted to stall the global movement for a free, open and human-centric Internet.

Digital rights are human rights. When a space for these rights is forcibly closed, the silence is deafening.

New ISACA Research: 63 Percent of Privacy Professionals Find Their Jobs More Stressful Now Than Five Years Ago

The ISACA State of Privacy 2025 survey report, which gathered responses from over 1,600 privacy professionals globally, revealed that 63% of these professionals find their roles more stressful than they were five years ago, with 34% reporting a significant increase in stress levels. The primary sources of stress identified in the survey were the rapid pace of technological advancements (63%), difficulties with compliance (61%), and a lack of resources (59%).

“In an increasingly complex international regulatory environment, often with lacklustre resources, it is understandable that many privacy professionals are feeling strain from their efforts to stay compliant and keep their organizations’ data safe. Addressing these challenges and getting practitioners the support they need will be vital to not only ensure a healthy privacy workforce, but also to maintain data integrity and security, and avoid potential harm to data subjects.” I made these comments via BusinessWire on the report to emphasize not only the challenges associated with implementing privacy programs, but also the importance of organizations demonstrating their commitment to data governance, data ethics, privacy rights, and overall digital trust.

With AI, the privacy landscape has changed dramatically, including the regulatory burdens for companies. Continued leadership in the boardroom, at the executive level, as well as embedding privacy principles in organizational values is integral to nurturing the trust relationship between enterprises, their customers, and society at large.

Caribbean telecoms operators seek to deepen their monopoly strangleholds

This past Friday, Caribbean telecommunications operators held a meeting in Miami to fine tune their strategy to have Big Tech companies contribute financially to regional telecoms network infrastructure. Hosted by the Caribbean Telecommunications Union (CTU), and taking a similar perspective to the “fair share” proposal currently being debated in the European Union, regional network operators are arguing that over-the-top (OTT) service providers such as Meta (Facebook, Instagram and WhatsApp), Alphabet (Google), TikTok, Netflix, Amazon and Microsoft are responsible for 67 per cent of the total Internet traffic in the Caribbean, but make no contributions or investments toward local delivery networks. Moreover, they further asserted that a market failure is occurring with resultant stalled revenues for telcos, and limited prospects for future growth.

This “fair share” argument is literally reviving antiquated telecoms regulations from the era of the public switched telephone network (PSTN) and circuit switched networks. There is no evidence that a real problem or market failure exists in the Caribbean telecoms sector and there has been no credible evidence warranting the introduction of network fees. I challenge Caribbean network operators to provide conclusive data that shows their networks are over capacity, and that they are financially incapable of investing in their own infrastructure, especially when we consider that consumers are already paying for the use and improvement of their networks (Caribbean consumers are currently subjected to some of the highest mobile data costs in the world) – Hence ISPs effectively want to charge twice for the same infrastructure. The Internet has proven its ability to cope with increasing traffic volumes, changes in demand patterns, technology, business models, as well as in the (relative) market power between market players. These developments are reflected in the Internet Protocol (IP) interconnection mechanisms governing the Internet which evolved without a need for regulatory intervention. There are multiple ways to finance network investments that don’t result in irreparable harm to the Internet’s technical architecture, the rights of consumers, and the overall Internet economy (e.g., joint ventures, private investors, spinning off segments into separate companies and seeking limited financing, special purpose vehicles based on public infrastructure funds, etc.).

From a technical standpoint, the Internet is based on different networks negotiating simple connection agreements between each other, based on interoperable technical standards. What Caribbean telcos will more than likely achieve – similar to their European counterparts – is where consumers will be restricted to only accessing content and services that are subject to agreements between ISPs and OTTs, and the quality and conditions of the content delivery will also be subject to the negotiated commercial arrangements. The technical danger of requiring network fees will invalidate the global and open Internet model for permissionless innovation and can lead to a highly fragmented Internet. It is a terrible policy suggestion for our region, and for the Internet as a whole, to suggest ‘rules’ that seek to artificially regulate how IP networks are managed.

This proposal also presents a rights-based threat to Internet users across the Caribbean. One of the most sacrosanct rules of the Internet is ‘net neutrality’, which is that Internet service providers (ISPs) must enable access to all content and applications regardless of the source, and without favouring or blocking specific websites or services. Given that ISPs also own what is known as the “last mile” (the physical connectivity to our homes), they can filter what content or services we are able to access, as well as determine the quality of our access. They can do so by blocking content, throttling network performance, and by introducing prolonged congestion that affects consumers negatively […].

The full article can be found on the CircleID website.

Would love to hear your thoughts on this important topic!

Regulating AI Tech is No Longer an Option: It’s a Must!

“Responsible, ethical use of AI is the key. From a corporate perspective, business leaders need to articulate why they are planning to use AI and how it will benefit individuals. Companies should develop policies and standards for monitoring algorithms and enhancing data governance and be transparent with the results of AI algorithms. Corporate leadership should establish and define company values and AI guidelines, creating frameworks for determining acceptable uses of AI technologies.

Achieving the delicate balance between innovation and human-centered design is the optimal approach for developing responsible technology and guaranteeing that AI delivers on its promise for this and future generations. Discussions of the risks and harms of artificial intelligence should always be front and center, so leaders can find solutions to deliver the technology with human, social and economic benefits as core underlying principles.”

I recently wrote a short piece on the ISACA Now Blog explaining why a robust framework of laws and regulations are needed for the potential of “AI” to be truly realised.

Check it out and let me know your thoughts!

Digital ID Explained: Pros, Cons, and “Should I get the Trident ID card?”

PURPOSE

I continue to receive countless questions from various walks of Bajan society about the Trident ID card and the national digital ID program. This is stark evidence that the Government of Barbados HAS NOT done an adequate and effective job of alleviating the concerns of the public. As such, I wanted to clarify once and for all the pros and cons of digital ID systems, and answer the million dollar question I am repeatedly asked, “Should I get the Trident ID card?”

INTRODUCTION

Digital identity (ID) has become the topic of the moment in Barbados, given the government’s poor implementation, failure to address the fears and anxieties of the public, and generally ineffectual communication to the average person on the street as to why they need digital ID and what value it will bring to their lives. The government has set out to provide a single digital identity to all residents/citizens through the collection, storage, and use of their biographic data (e.g., name, address, date of birth, gender, national registration number, etc.) and possibly their biometrics (e.g., fingerprints, iris scans, facial scans, etc.) as the primary means of establishing and verifying their identity. They will achieve this through a legally mandated, centralised national digital ID system.

Governments, international organizations, and multilateral banks (e.g., International Monetary Fund, World Bank, etc.) argue that digital ID systems provide benefits such as more effective and efficient delivery of government services; poverty reduction and welfare programs; financial inclusion through better access to banking and other products/services; minimise corruption; and preservation of national security interests. Multilateral banks are providing significant funding to developing countries to implement digital ID. In some cases, they’re even making the implementation of digital ID systems a ‘condition’ of loan agreements.

Critics maintain that digital ID systems may actually not guarantee more effective access to social and economic benefits, enhance service delivery, or improve governance, while at the same time, they raise serious issues, including worries about how they are developed and managed; social exclusion and discrimination; privacy and data protection; cybersecurity; and major risks for human rightsWith regards to human rights, they threaten the right to privacy, freedom of movement, freedom of expression, and other protected rights. Additionally, since they usually involve the creation and maintenance of centralised databases of sensitive personal data, they are also prone to breaches by hackers or abuse/misuse by government institutions. These issues may lead to digital IDs becoming widespread tools for identification, surveillance, persecution, discrimination, and control, especially where identities are linked to biometrics and made mandatory. 

For a more detailed explanation of both sides of the debate, please see below the PROS and CONS related to digital ID systems.

PROS

Easier access to services: digital ID systems can enable more efficient digital transformation across the local economy and increase Barbados’  participation in the global digital economy, especially given that many transactions – local and international – require personal identification. With Barbadians presented with less obstacles to prove their identity, commercial activities (including e-commerce) and government services (including e-government) become more accessible and effective.

Faster and cheaper transactions: the use of digital ID can allow for reductions in costs and response times, resulting in speedier execution, less red tape, and the availability of more responsive and relevant services. The quickness and trust with which a person’s identification can be verified allows for cheaper and more efficient interactions for all involved.

Fraud reduction: digital ID systems can offer several benefits in terms of online security, thus reducing the occurrence of online scams, fraud, and personal data breaches. A number of countries that have implemented digital ID have experienced significant decreases in fraud, saving them tens and even hundreds of millions of dollars.

The graphic below outlines several ways in which digital ID can be used based on the roles played by organizations and individuals (Source: McKinsey).

The four (4) main areas of direct economic value for individuals have been identified as increased access to financial services, improved employment opportunities, greater agricultural productivity, and time savings. The five (5) highest sources of value for institutions – both the private and public sectors – are cost savings, fraud prevention, increased revenues from goods and services, improved employee productivity, and higher tax revenues.

CONS

Privacy and security: digital ID systems process billions of data points of our private information, regularly without our consent or knowledge. This information can include biographic details (NGN, date of birth, gender), biometrics (facial recognition, iris scans, fingerprints), banking and transactional data, and location-based info when digital ID is used for example in public transportation (the government has expressed plans to use the Trident ID for cashless payments on buses). The centralisation of so much data, excessive sharing of personal data without user consent, inability to control your personal data, exposure to cyber attacks and data breaches, and in worst case scenarios – mass surveillance by corporations and governments – are all issues which show the potential negative impact of digital ID.

Discrimination, biases and exclusion: the Barbados Digital Identity Act has a number of clauses which generate concerns about discrimination and exclusion. The Act states in several places that the digital ID will be required for persons to be added to the register of voters, to vote in elections, to access public and private services, and to obtain a driver’s license. There are no provisions in the Act for mandatory accessibility features in the digital ID and related services. As such, persons with disabilities may be excluded (e.g., the Trident ID website currently DOES NOT have several accessibility features for the disabled). Digital ID technologies are also at the end of the day developed by humans, and through poorly designed algorithms and data analytics, can reinforce their biases. Discrimination against key communities such as immigrants, LGBTQ+, homeless, and the disabled, among others have been highlighted in many digital ID related studies globally.

Technical errors: unintended consequences can occur that lead to restricted access to critical services (e.g., failures in authentication at points of service with no redundancy; websites that aren’t user friendly or stable; duplicate or inaccurate records; inability to add essential information; or the lack of reliable technical support, etc.). The government must fully consider availability risks and identify user-centric and privacy-enabling solutions to mitigate them. In African and Asian countries, numerous instances of technical errors were uncovered which presented citizens with major challenges.

Deployment challenges: five key problems exist, which are the lack of funding to maintain secure cyber systems and to hire or retain critical human resources to administer them; unequal access to mobile Internet and smartphones – the technology with the most potential to drive the uptake of digital ID; dependency on a specific technology or vendor; low trust in government; and the difficulty of rolling out in rural areas.

SHOULD YOU GET THE TRIDENT ID CARD?

As I have stated before, my concern is not particularly with the Trident ID card. The card is only one small piece of the overall digital ID ecosystem. My biggest concerns are as follows:

Poor legislation underpinning the digital ID system: Digital ID must be supported by a legal and regulatory framework that supports trust in the system, prevents abuse such as warrantless and disproportionate surveillance, guarantees data privacy and security, prevents discrimination, and maintains provider (government and corporations) accountability. This includes laws for digital ID management along with laws and regulations for e-government, privacy and data protection, computer misuse, data sovereignty/localisation, electronic transactions, limited-purpose ID systems, accreditation of participants, and freedom of information, among others. Unfortunately, a number of these laws are not available in Barbados at this time, and where they are, the language is problematic, enforcement is deeply lacking, or the legislation is outdated.

Government’s atrocious record in terms of protecting IT systems and the personal data privacy of individuals: The Government of Barbados DOES NOT have the resources (people, processes, or technologies) to secure complex IT systems and provide consistent privacy-enabling solutions. If they did, there would not be so many successful cyber-attacks and data breaches of government online systems in recent years (e.g., Queen Elizabeth Hospital, Ministry of Information and Smart Technology, Immigration Department, Barbados Police Service, and many others). Until government invests significantly in building their capacity in these areas, their IT systems and the personal data of Barbadians will be AT RISK.

The communication (or lack of) by government addressing the public angst around their digital ID program: Government has not effectively articulated the benefits of digital ID, its value to the average person on the street (in real and meaningful terms), its potential disadvantages and risks, what they are doing to manage these risks, and what Barbadians can do to protect themselves. Instead they have chosen to evade questions, avoid public discussion with experts involved, and turn their resources towards attacking private citizens who are expressing concerns.

In 2018, I conducted a European Union (EU) cybersecurity assessment for the the Government of Barbados. In the report, I clearly stated:

Trust in the Internet and in the use of online services is critical to developing a thriving local Internet economy and to participating widely in the global digital economy. Low trust in the Internet, e-government services, and e-commerce services hampers the government, businesses and consumers from fully taking advantage of all the economic benefits the Internet has to offer. Given the high fixed broadband and mobile data penetration rates in Barbados, this is especially concerning.

European Union Consultancy to Develop a Government Cybersecurity Assessment and Strategic Roadmap – Cybersecurity Assessment Report (Authored by Niel Harper)

From 2018 to this present day, the government has failed to address the low levels of trust or their lack of expertise in delivering secure and privacy respecting IT solutions, all of which are undoubtedly preventing them from delivering their digital transformation and modernisation agenda (including the implementation of the digital ID).

Ultimately, Barbadians need to decide for themselves if the value of obtaining the Trident ID outweighs the associated risks. I cannot make this decision for anyone. All I can do is educate and build awareness, and try to put some pressure on the government to be more accountable and take greater responsibility for protecting citizens from the negative effects of digital ID, mass personal data processing, cyber attacks and data breaches, human rights violations, online fraud, and other harms resulting from widespread government use of information and communication technologies (ICTs).

ADDITIONAL RESOURCES

FACT CHECK: The Electoral and Boundaries Commission’s Response

Why the Barbados Election Least Data Leak is Problematic – And How It Could Have Been Prevented

Comments on the National Identity Management System Act

Too Many Unanswered Questions: The Barbados National Digital Identification

Creating a good ID system presents risks and challenges, but there are common success factors

What is a digital identity ecosystem?

Understanding the risks of Digital IDs

The Cost of 1GB of Mobile Data: Why It Matters!

While not the only barrier to access, the high cost of data is the biggest factor keeping people offline. Undoubtedly, those countries/regions with the least affordable data are also those with the fewest people connected to the Internet. A failure to deliver affordable Internet access keeps citizens offline and compounds global inequalities.

From a personal perspective, I have complained bitterly over the years about the cost of mobile data in my country Barbados and how it negatively impacts economic growth and the effective transition to a digital economy. Based on available statistics, the cost of 1 GB of mobile data in Barbados is USD$9.32 (ranked 196th globally).

In comparison, below are the prices/rankings for a sample of other countries:

>> India: $0.09 (1st)
>> Somalia: $0.50 (7th)
>> Russian Federation: $0.52 (9th)
>> China: $0.61 (12th)
>> Denmark: $0.80 (29th)
>> Brazil: $1.01 (38th)
>> United Kingdom: $1.39 (59th)
>> Hong Kong: $2.55 (101st)
>> United Arab Emirates: $3.78 (130th)
>> Jamaica: $3.88 (138th)
>> United States: $8.00 (188th)
>> Canada: $12.55 (209th)
>> Cuba: $13.33 (212th)
>> Bermuda: $28.75 (225th)

High mobile data costs also have a negative knock-on effect on the diffusion of existing and emerging technologies and applications (e.g. IoT, smart cities, telemedicine, mobile payments, etc.), many of them with high social benefits.

Do you know where your country ranks? What do you think of these statistics?

No More Obscurity

With revenues of $36 billion in 2018, the global video surveillance market is growing exponentially, allowing for every mundane activity to be captured and made publicly accessible. Acclaimed artist Xu Bing reviewed thousands of hours of online surveillance videos and transformed this journey into a story about (in)visibility and today’s culture of permanent exposure.

I joined Xu Bing and Jennifer Lyn Morone in a panel discussion titled ‘No More Obscurity’ at the World Economic Forum 2019 Annual Meeting for New Champions (Summer Davos) in Dalian, China.

Using Xu Bing’s story as a backdrop, we discussed the impact of online surveillance on individual privacy and society as a whole in terms of pervasive monitoring.