BARBADOS
Since January 1985, last amended in May 2019
Pillar Cross-border data policies |
Indicator Local storage requirement
Companies Act 1982
Section 170 of the Companies Act 1982 lists a series of registers and records that must be maintained at a company's registered office or at some other place in Barbados designated by the directors of the company, including minutes of meetings and resolutions of shareholders, the name and latest known address of shareholders, and a register showing the name and latest known address of each person to whom privileges, options or rights have been granted. In addition, under Section 172 of the Companies Act, adequate accounting records and records containing minutes of meetings and resolutions of the directors and any committees of the directors shall be kept at the registered office of the company or at some other place in Barbados designated by the directors. Furthermore, according to Section 172.3, when any accounting records of a company are kept at a place outside Barbados, accounting records that are adequate to enable the directors to ascertain the financial position of the company with reasonable accuracy on a quarterly basis must be kept at the company's registered office or at some other place in Barbados designated by the directors.
Coverage Horizontal
BARBADOS
Since December 2018, entry into force in January 2019
Pillar Cross-border data policies |
Indicator Local storage requirement
Trusts (Miscellaneous Provisions) Act, 2018
Section 12 of the Trusts (Miscellaneous Provisions) Act 2018 mandates that a trustee of a trust established under section 9 must retain, within Barbados, a copy of the instrument creating the trust together with any amending or supplementary instruments, as well as a register detailing specific information. This register must include the name of the settlor, a concise statement of the trust’s purposes, the name of the protector, and all documents necessary to accurately reflect the financial position of the trust.
Coverage Trusts
BARBADOS
Since August 2019, entry into force in March 2021
Pillar Cross-border data policies |
Indicator Conditional flow regime
Data Protection Act, 2019
According to Art. 22 of the Data Protection Act 2019, personal data shall not be transferred to a country or territory outside Barbados unless that country or territory provides for: (i) an adequate level of protection for the rights and freedoms of data subjects in relation to the processing of their personal data; and (ii) appropriate safeguards on condition that the rights of the data subject are enforceable and there are available, effective legal remedies for data subjects.
Coverage Horizontal
BARBADOS
N/A
Pillar Cross-border data policies |
Indicator Participation in trade agreements committing to open cross-border data flows
Lack of participation in agreements with binding commitments on data flows
Barbados has not joined any agreement with binding commitments to open transfers of data across borders.
Coverage Horizontal
BARBADOS
Since August 2019, entry into force in March 2021
Pillar Domestic data policies |
Indicator Framework for data protection
Data Protection Act, 2019
The Data Protection Act establishes a comprehensive data protection framework in Barbados, modelled closely on the European Union’s General Data Protection Regulation (GDPR). It grants individuals various rights, including access, rectification, erasure, restriction of processing (including in relation to direct marketing), and data portability, and it imposes extensive obligations on organisations, such as requirements for breach notification, international data transfers, and data protection impact assessments. The Act also has extraterritorial reach and applies to the processing of personal data of individuals in Barbados by controllers or processors located outside the jurisdiction when the processing relates to the provision of goods or services to data subjects in Barbados. Although the Act entered into force on 31 March 2021 by proclamation of the Governor-General, several provisions concerning the mandatory registration of data controllers and data processors and the creation of official registers, specifically Sections 50, 51, 52, 55, 56 and 57, have not yet been brought into effect as of 2025.
Coverage Horizontal
BARBADOS
Since August 2019, entry into force in March 2021
Pillar Domestic data policies |
Indicator Requirement to perform a Data Protection Impact Assessment (DPIA) or have a data protection officer (DPO)
Data Protection Act, 2019
According to Art. 65.1 of the Data Protection Act 2019, the data controller must conduct an assessment of the potential impact of the proposed processing operations on the safeguarding of personal data. This is applicable when a specific form of processing, particularly one utilising emerging technologies, is anticipated to potentially pose a significant risk to the rights and freedoms of an individual. The assessment takes into consideration the characteristics of the processing, including its nature, scope, context, and purposes.
In accordance with Art. 67.1 of the Act, a data privacy officer (DPO) must be appointed by both the data controller and data processor in situations where: (i) the processing is conducted by a public authority or body, excluding instances involving a court of competent jurisdiction acting in its judicial capacity; (ii) the fundamental activities of the data controller or data processor encompass processing operations that, due to their nature, scope, and objectives, necessitate regular and systematic monitoring of data subjects on a significant scale; or (iii) the core activities of the data controller or data processor entail large-scale processing of sensitive personal data.
Additionally, Art 69.1 outlines the responsibilities and functions of the DPO, which include: (i) informing and advising the data controller, data processor, and relevant employees about their obligations under the Data Protection Act; (ii) monitoring compliance with the Act and the data controller's or data processor's data protection policies; (iii) providing guidance on data protection impact assessments and overseeing their implementation in line with Art. 65; and (iv) working closely with the Commissioner, serving as the main point of contact for processing-related matters, including prior consultation as mentioned in Art. 66, and offering consultation on other pertinent issues when necessary.
In accordance with Art. 67.1 of the Act, a data privacy officer (DPO) must be appointed by both the data controller and data processor in situations where: (i) the processing is conducted by a public authority or body, excluding instances involving a court of competent jurisdiction acting in its judicial capacity; (ii) the fundamental activities of the data controller or data processor encompass processing operations that, due to their nature, scope, and objectives, necessitate regular and systematic monitoring of data subjects on a significant scale; or (iii) the core activities of the data controller or data processor entail large-scale processing of sensitive personal data.
Additionally, Art 69.1 outlines the responsibilities and functions of the DPO, which include: (i) informing and advising the data controller, data processor, and relevant employees about their obligations under the Data Protection Act; (ii) monitoring compliance with the Act and the data controller's or data processor's data protection policies; (iii) providing guidance on data protection impact assessments and overseeing their implementation in line with Art. 65; and (iv) working closely with the Commissioner, serving as the main point of contact for processing-related matters, including prior consultation as mentioned in Art. 66, and offering consultation on other pertinent issues when necessary.
Coverage Horizontal
BARBADOS
Since March 2001, last amended in March 2014
Pillar Intermediary liability |
Indicator Safe harbour for intermediaries for copyright infringement
Electronic Transactions Act, Chapter 308B
The Electronic Transactions Act establishes a safe harbour regime for intermediaries for copyright infringements. According to Section 23, there is no intermediary liability for information within electronic records they handle if: (i) they did not create the record; (ii) they have no actual knowledge that the information could lead to legal liability; and (iii) they are not aware of any facts indicating that the information could reasonably result in legal liability.
Coverage Internet intermediaries
BARBADOS
Since March 2001, last amended in March 2014
Pillar Intermediary liability |
Indicator Safe harbour for intermediaries for any activity other than copyright infringement
Electronic Transactions Act, Chapter 308B
The Electronic Transactions Act establishes a safe harbour regime for intermediaries for copyright infringements. According to Section 23, there is no intermediary liability for information within electronic records they handle if: (i) they did not create the record; (ii) they have no actual knowledge that the information could lead to legal liability; and (iii) they are not aware of any facts indicating that the information could reasonably result in legal liability.
Coverage Internet intermediaries
BARBADOS
Reported in 2021, last reported in 2025
Pillar Intermediary liability |
Indicator User identity requirement
Identity requirement for SIM cards
It is reported that the SIM registration regime in Barbados obliges mobile network operators to collect and store users’ personal data together with proof of identity. Nevertheless, the relevant legislative provisions could not be identified.
Coverage Mobile network operators
BARBADOS
Since December 2002
Since May 2003
Since May 2003
Pillar Quantitative trade restrictions for ICT goods and online services |
Indicator Other import restrictions, including non-transparent/discriminatory import procedures
Telecommunications Act, Cap. 282B
Telecommunications (Prescribed Telecommunications and Radiocommunications Apparatus) Regulations, 2003
Telecommunications (Prescribed Telecommunications and Radiocommunications Apparatus) Regulations, 2003
According to Arts. 56(2) and 58(3) of the Telecommunications Act, Cap. 282B, prescribed telecommunications and radiocommunications apparatus may not be imported for sale without a dealer’s licence, and Customs may not release commercial consignments of telecommunications apparatus or radiocommunications apparatus unless the importer produces the required dealer’s licence or other applicable authority.
The Telecommunications (Prescribed Telecommunications and Radiocommunications Apparatus) Regulations, 2003 apply this regime to products including Bluetooth and Wireless Fidelity equipment, modems, facsimile transceivers, telephones, digital leased-circuit equipment and other information and communication technology equipment.
The Telecommunications (Prescribed Telecommunications and Radiocommunications Apparatus) Regulations, 2003 apply this regime to products including Bluetooth and Wireless Fidelity equipment, modems, facsimile transceivers, telephones, digital leased-circuit equipment and other information and communication technology equipment.
Coverage ICT products
Sources
BARBADOS
N/A
Pillar Technical standards applied to ICT goods and online services |
Indicator Self-certification for product safety
General and certification requirements for licensed and licence-exempt radio apparatus used for radiocommunication
According to the "General and certification requirements for licensed and license-exempt radio apparatus used for radio communication, " all transmitting devices must be type-approved before sale in the country. The following documentation is required when submitting a request for type approval: the test reports, the name of the device, the name and address of the applicant & manufacturer, the model number, the certification from a recognised standards body FCC, ETSI or ICC, pictures of the device/component, and the device Manual. This process usually takes 3–5 business days, depending on the backlog of approvals and whether all the information has been submitted.
Coverage Electronic products
BARBADOS
N/A
Pillar Online sales and transactions |
Indicator Restrictions on online payments
Reported restrictions on currency use for international payments
It is reported that, for online purchases made by credit card in foreign transactions, cardholders must select USD or the relevant foreign currency at the checkout or payment stage. Such transactions count towards an annual foreign exchange allowance and are subject to a 2% foreign exchange fee. It is also reported that exchange controls do not apply to foreign currency accounts. Where the annual allowance is exceeded, a foreign exchange application must be submitted for approval.
Coverage Horizontal
BARBADOS
Reported in 2024
Pillar Online sales and transactions |
Indicator Threshold for ‘De Minimis’ rule
Low de minimis threshold
It is reported that the de minimis threshold, defined as the minimum value of goods below which customs authorities do not levy duties, is BBD 60 (approx. USD 30), which is considerably lower than the USD 200 threshold recommended by the International Chamber of Commerce (ICC).
Coverage Horizontal
BARBADOS
Reported in 2022, last reported in 2026
Pillar Online sales and transactions |
Indicator Restrictions on domain names
Local company requirement for domain registration
It is reported that applicants for the “.bb” domain must be domiciled in Barbados. Moreover, the registration of a “.bb” domain name requires a locally incorporated Barbadian company, together with a local contact, physical address, and telephone number.
Coverage Horizontal
