What Is Data Protection Act, 2021 (Act No. 45 of 2021)?
Belize enacted the Data Protection Act, 2021 (Act No. 45 of 2021), which was assented to on 29 November 2021 and gazetted on 30 November 2021. The statute regulates the collection, keeping, use, disclosure, and protection of personal data and contains a broad rights and enforcement structure. Currentness remains unresolved. Section 97 requires a Ministerial Gazette Order to bring the Act into force, potentially in stages. No official commencement Order, amending Act, implementing regulation, appointed Commissioner, or operational complaint portal was located in the official sources reviewed through 28 August 2026. A 2023 official identity strategy stated that the oversight agency had not yet been created or implemented. The Act should therefore be described as an enacted 2021 framework with unresolved commencement and implementation status, not as a confirmed operational rights-and-enforcement regime. No Belize-specific data-broker registry, broker complaint form, broker deletion process, or public-record suppression or takedown route was located.
At a glance
- Full name
- Data Protection Act, 2021 (Act No. 45 of 2021)
- Short code
- Data Protection Act 2021
- Jurisdiction
- Belize
- Enacted
- 2021
- Last major update
- Assented to 29 November 2021 and gazetted 30 November 2021; no official commencement Order, amending Act, implementing regulation, appointed Commissioner, or operational complaint portal was located
- Regulator
- Data Protection Commissioner; appointment and operational status not located
- Private right of action
- Limited
- Statutory citation
- Data Protection Act, 2021 (Act No. 45 of 2021)
Scope, who Data Protection Act 2021 covers
Protected data
Data subject rights
Right of access and information about processing, purposes, data categories, recipients and countries, storage period, source, safeguards, complaints, and automated decision-making
Right to rectification and completion of inaccurate or incomplete data
Right to erasure without undue delay on specified grounds
Right to restriction of processing
Right to data portability in a structured, commonly used, machine-readable format where statutory conditions apply
Right to object to processing likely to cause substantial, unwarranted damage or distress
Right to object to direct marketing
Protection against solely automated decisions producing legal or similarly significant effects
Right to withdraw consent without invalidating prior lawful processing
Right to complain to the Commissioner, appeal rights, and compensation for damage or distress caused by a contravention
Notable features
Section 97 requires a Ministerial Gazette Order for commencement, potentially in stages. The Act contains GDPR-style access, correction, erasure, restriction, portability, objection, automated-decision, complaint, and compensation provisions, but the reviewed official sources do not establish that these provisions are currently operative.
Enforcement & penalties
Regulator: Data Protection Commissioner; appointment and operational status not located
Penalties: The Act states, generally on summary conviction, a fine of 500,000 dollars, imprisonment for three years, or both for failure by a data controller to comply with the data-protection principles. Unlawful cross-border transfer, processor or authorised-person processing contrary to instructions, breach of Commissioner confidentiality, and false statements relating to warrant execution carry specified fines of 20,000 dollars. Failure to comply with an Enforcement, Information, or Special Information Notice carries a fine of 5,000 dollars. Knowing or reckless unauthorised obtaining, disclosure, or procurement of personal data carries a fine of 10,000 dollars. Compensation is available for damage or distress, but no fixed compensation amount was located.
Private right of action: The Act provides compensation for damage or distress caused by a contravention and appeal rights under the statutory framework. No separate general civil-action route or fixed compensation amount was located, and the Act’s commencement remains unresolved.
Relevance to data brokers
No Belize-specific data-broker registry, broker complaint form, broker deletion process, or public-record suppression or takedown route was located. If the Act is in force and its statutory conditions are met, a broker may be covered; trading in personal information is excluded from the small-business exemption, and general access, rectification, erasure, restriction, objection, and Commissioner-assessment provisions could be relevant.
Generate requests in under 60 seconds
Generate removal requests for 1,034 US/global profiles, $9
FAQ
Does Belize currently have an operational data-protection law?+
Belize enacted the Data Protection Act, 2021, but current operative status remains unresolved. Section 97 requires a Ministerial Gazette Order to bring the Act into force, and no official commencement Order was located in the reviewed sources through 28 August 2026.
What rights does the Belize Data Protection Act provide?+
Subject to statutory exemptions and commencement, the Act provides access, rectification, erasure, restriction, portability, objection, direct-marketing objection, automated-decision protections, consent withdrawal, complaint and appeal rights, and compensation for damage or distress.
Is there a Belize data-broker deletion route?+
No Belize-specific data-broker registry, broker complaint form, broker deletion process, or public-record suppression or takedown route was located. General rights provisions could be relevant if the Act is in force and the statutory conditions are met.
Official sources & citations
Other international privacy regimes
Data Protection Act 2021 sits in a global ecosystem of data-protection laws. Compare with other jurisdictions that shape cross-border data flows:
