What Is Data Protection (Privacy of Personal Information) Act, 2003?
As reviewed on 28 August 2026, the governing enacted framework is the Data Protection (Privacy of Personal Information) Act, 2003, Chapter 324A. The official consolidated text records commencement on 2 April 2007, and the current official legislation index continues to list the Act under current Acts. No official 2023 Data Protection amendment Act or appointed-day notice was located. The Data Protection Bill, 2025 proposes repeal and replacement of Chapter 324A, but its commencement depends on a future Ministerial Gazette notice. No enacted 2025 replacement Act or appointed-day notice was located, so the Bill must be treated as prospective rather than current law. The current Act provides access within 40 working days, conditional rectification or erasure, a direct-marketing opt-out, complaints to the Data Protection Commissioner, and transfer-prohibition powers. It does not provide a separate general portability, automated-decision, restriction, or general erasure right. No data-broker-specific or public-record-specific complaint or deletion route was located.
At a glance
- Full name
- Data Protection (Privacy of Personal Information) Act, 2003
- Short code
- DPA 2003
- Jurisdiction
- Bahamas
- Enacted
- 2003
- Last major update
- Commenced 2 April 2007; the Data Protection Bill, 2025 proposes repeal and replacement but no enacted replacement Act or appointed-day notice was located
- Regulator
- Data Protection Commissioner
- Private right of action
- Limited
Scope, who DPA 2003 covers
Protected data
Data subject rights
Right of access within 40 working days to confirmation whether relevant personal data are held, a copy of the data, and an explanation of unintelligible terms
Right to receive written reasons for an access refusal and notice of the right to complain to the Commissioner
Right to rectification where the controller contravenes the section 6(1) data-protection requirements
Right to erasure where appropriate following a section 6(1) contravention
Right to request erasure of data used solely for direct marketing, or cessation of that use where the data has other purposes
Right to complain to the Data Protection Commissioner about an actual, ongoing, or likely contravention
Right to appeal a Commissioner complaint decision to the Court within 21 days
No separate general right to portability, restriction, automated-decision protection, or general erasure was located
Notable features
The current framework is an enacted 2003 law with a 40-working-day response period for access, rectification or erasure, and direct-marketing requests. The Data Protection Bill, 2025 is a prospective replacement only because no enacted replacement Act or appointed-day notice was located.
Enforcement & penalties
Regulator: Data Protection Commissioner
Penalties: Under section 29, an offence carries a fine not exceeding $2,000 on summary conviction or $100,000 on conviction on information. The Court may order connected data material forfeited or destroyed and relevant data erased. Directors, managers, secretaries, or other officers may be liable where a corporate offence occurred with their consent, connivance, or neglect. No current statutory imprisonment figure or administrative penalty schedule was located in the enacted 2003 Act.
Private right of action: The Act provides a complaint route to the Data Protection Commissioner and a 21-day appeal to the Court against a Commissioner complaint decision. No general private compensation or direct civil-action route for every privacy dispute was identified in the report.
Relevance to data brokers
No data-broker-specific complaint, deletion, registry, or suppression route was located. A generic Commissioner complaint may be available where a broker is a covered controller or processor. Information legally required to be public is excluded from the Act, and no public-record-specific deletion or privacy complaint route was located in the reviewed materials.
Generate requests in under 60 seconds
Generate removal requests for 1,034 US/global profiles, $9
FAQ
Is the 2025 Bahamas Data Protection Bill currently law?+
No. The Data Protection Bill, 2025 proposes repeal and replacement of Chapter 324A, but no enacted replacement Act or appointed-day notice was located. Its provisions must therefore be treated as prospective.
How long does a controller have to answer an access request in The Bahamas?+
The current Act provides 40 working days for an access request. Rectification or erasure requests and direct-marketing requests also use a 40-working-day period under the Act.
Can I request deletion from a data broker in The Bahamas?+
No data-broker-specific deletion or suppression route was located. A generic Commissioner complaint may be available where the broker is a covered controller or processor, but information legally required to be public is excluded from the Act.
Official sources & citations
Other international privacy regimes
DPA 2003 sits in a global ecosystem of data-protection laws. Compare with other jurisdictions that shape cross-border data flows:
