What Is Data Protection Act, Act No. 11 of 2011, as amended by Act No. 2 of 2015?
Saint Lucia's Data Protection Act, Act No. 11 of 2011, was amended by Act No. 2 of 2015 (in force 13 April 2015). Statutory Instrument No. 4 of 2023 brought specific parts into force on 31 January 2023: Part I, sections 32–43 of Part III, Part VI, and paragraphs (a)–(g) of Schedule 2 — a partial commencement, so other provisions should not be assumed operative. The Act applies to a data controller established in Saint Lucia processing in that context, and to an external controller using equipment in Saint Lucia (other than for transit), which must nominate a local representative. Section 52 provides a written access-request route (data, purposes, source, automated-processing logic, and recipients), to be met within 30 days per section 53; if the controller cannot comply and no extension is agreed within 48 hours of notifying the requester, it must apply to the Commissioner for a new deadline. Section 56 provides rectification, blocking, erasure, destruction, or annotation for data claimed incomplete, incorrect, misleading, excessive, or irrelevant, with Commissioner directions to be complied with within 14 days. Section 57 gives a direct-marketing stop right, requiring compliance or erasure within 30 days. This is a source-backed evidence profile. No dedicated current Commissioner portal, public register, complaint email, or published service-level timeline was located, so the operational complaint route remains unconfirmed. No Saint Lucia-specific data-broker registry or public-record removal route was located.
At a glance
- Full name
- Data Protection Act, Act No. 11 of 2011, as amended by Act No. 2 of 2015
- Short code
- Saint Lucia DPA 2011
- Jurisdiction
- Saint Lucia
- Enacted
- 2011
- Last major update
- Statutory Instrument No. 4 of 2023 brought Part I, sections 32–43 of Part III, Part VI, and Schedule 2(a)–(g) into force on 31 January 2023 — a partial commencement, not the whole Act
- Regulator
- Data Protection Commissioner (operational contact channel not confirmed in official sources reviewed)
- Private right of action
- Limited
- Statutory citation
- Data Protection Act, Act No. 11 of 2011, as amended by Act No. 2 of 2015
Scope, who Saint Lucia DPA 2011 covers
Protected data
Data subject rights
Written access request: confirmation of holding, the data, purposes, source, automated-processing logic, and recipients, within 30 days (sections 52–53)
Rectification, blocking, erasure, destruction, or annotation of incomplete, incorrect, misleading, excessive, or irrelevant data, with Commissioner enforcement within 14 days where the controller does not act (section 56)
Written notice to stop or prevent direct-marketing processing, with compliance or erasure required within 30 days (section 57)
Notable features
The 2023 commencement order (S.I. No. 4 of 2023) brought only specified parts of the Act into force, more than a decade after original enactment — a partial-commencement pattern that should not be read as full operative status for every section.
Enforcement & penalties
Penalties: The reviewed official law index and government privacy page for this research pass did not surface a consolidated penalty schedule; check the Act’s offence provisions directly before publishing a fine figure.
Private right of action: Complaints under the Act go to the Commissioner in writing (or another authorized method); the Act does not state a fixed complaint-resolution deadline in the sources reviewed, and no confirmed current operational Commissioner complaint channel was located.
Relevance to data brokers
No Saint Lucia-specific data-broker registry, people-search suppression route, public-record removal route, or sector-specific personal-data removal procedure was located. The general controller access/rectification/marketing-stop routes above are not broker-specific and any broker page would need independent provider evidence.
Generate requests in under 60 seconds
Generate removal requests for 1,034 US/global profiles, $9
FAQ
Is all of Saint Lucia’s Data Protection Act currently in force?+
No. Statutory Instrument No. 4 of 2023 brought only Part I, sections 32–43 of Part III, Part VI, and Schedule 2(a)–(g) into force on 31 January 2023 — a partial commencement.
How quickly must a Saint Lucia controller respond to an access request?+
Section 53 sets a 30-day deadline; if the controller cannot comply, it must notify the requester before the period expires and, absent an agreed extension within 48 hours, apply to the Commissioner for a new deadline.
Official sources & citations
Other international privacy regimes
Saint Lucia DPA 2011 sits in a global ecosystem of data-protection laws. Compare with other jurisdictions that shape cross-border data flows:
