What Is Data Protection Act, 2013 (No. 10 of 2013)?
The governing statute located is the Data Protection Act, 2013 (No. 10 of 2013), which received assent on 28 October 2013 and was published in the Official Gazette on 7 November 2013. Because the Act does not specify a separate commencement date, it is treated as having come into operation on Gazette publication under section 5(1) of the Statutes Act. No Data Protection Amendment Act or amending Gazette instrument was located in the official searches. This is a no-amendment-identified result, not proof that no amendment exists. The Act's section 21 imports Information Commissioner's powers from Parts V-VII of the Freedom of Information Act, 2004, but no official commencement notice for that imported machinery was located. The current framework provides access, rectification, notice and retention protections, but it does not establish a standalone GDPR-style portability, objection, restriction, or erasure-request right. Its definition of personal data is also limited to information connected with commercial transactions, automated processing, intended automated processing, or a relevant filing system.
At a glance
- Full name
- Data Protection Act, 2013 (No. 10 of 2013)
- Short code
- Data Protection Act 2013
- Jurisdiction
- Antigua and Barbuda
- Enacted
- 2013
- Last major update
- Assented to 28 October 2013 and treated as in force from 7 November 2013 under the Statutes Act; no-amendment-identified result, not proof that no amendment exists
- Regulator
- Information Commissioner under the Data Protection Act and imported Freedom of Information Act machinery; operational status unresolved
- Private right of action
- Limited
- Statutory citation
- Data Protection Act, 2013 (No. 10 of 2013)
Scope, who Data Protection Act 2013 covers
Protected data
Data subject rights
Right of access by written request, including confirmation of processing, an intelligible description of the data, processing purposes, recipients or recipient classes, and available source information
Right to examine personal data or obtain a copy; an alternative format may be available to a sensory-disabled data subject where it already exists or conversion is reasonably required
Right to rectification where data is incomplete, incorrect, misleading, excessive, or irrelevant
Right to receive notice information about purposes, source, access and correction rights, complaint routes, recipient classes, whether supply is mandatory or voluntary, and consequences of non-supply
Protection against retaining data longer than necessary, with destruction or permanent deletion when it is no longer required
Right to complain about a rectification refusal within 28 days of receiving the refusal communication
No standalone statutory right to portability, objection, restriction, or general erasure was located
Notable features
The framework combines access and rectification rights with a narrow commercial-transaction definition of personal data. The Act appears operative from Gazette publication, but the operational status of the Information Commissioner's imported Freedom of Information Act machinery remains unresolved.
Enforcement & penalties
Penalties: Sensitive-data offence: fine up to $200,000, imprisonment up to 3 years, or both. Other offences without a specific penalty may carry, for an individual, up to $50,000 or 3 years on summary conviction, or up to $100,000 or 5 years on conviction on indictment; for a body corporate, up to $200,000 on summary conviction or $500,000 on conviction on indictment. No separate administrative-fine schedule or breach-notification penalty was located.
Private right of action: No general private compensation or civil-action route was located in the reviewed materials. The framework provides a complaint route to the Information Commissioner, including a 28-day period for a rectification-refusal complaint, and High Court review of a Commissioner decision or order within 28 days.
Relevance to data brokers
No data-broker-specific registration, complaint, deletion, suppression, or republication route was located. General access and rectification provisions might be relevant to a covered data user, but coverage is uncertain because personal data is framed around commercial transactions. No public-record deletion or opt-out route was located; the Freedom of Information Act rule concerning unreasonable disclosure of third-party personal information is an access and disclosure rule, not a deletion route.
Generate requests in under 60 seconds
Generate removal requests for 1,034 US/global profiles, $9
FAQ
Does Antigua and Barbuda have a data-protection law?+
Yes. The Data Protection Act, 2013 appears operative from 7 November 2013. No-amendment-identified result, not proof that no amendment exists, and the operational status of the imported Information Commissioner machinery remains unresolved.
What privacy rights does the Antigua and Barbuda Act provide?+
The Act provides written-request access and rectification rights, notice information, and protection against retaining data longer than necessary. No standalone GDPR-style portability, objection, restriction, or general erasure-request right was located.
Can I request deletion from a data broker in Antigua and Barbuda?+
No dedicated data-broker deletion or suppression route was located. The retention principle is not a general broker-erasure mechanism, and any general access or rectification route depends on whether the broker’s processing falls within the Act’s narrow personal-data definition.
Official sources & citations
Other international privacy regimes
Data Protection Act 2013 sits in a global ecosystem of data-protection laws. Compare with other jurisdictions that shape cross-border data flows:
