Itaca Advisory
Technology advisory & compliance team
Key takeaways
- “Not yet in force” is wrong. The Data Protection Act 2011 is partially proclaimed, and the parts in force include the general privacy principles.
- In force since 6 January 2012: Part I and sections 7 to 18, 22, 23, 25(1), 26 and 28 (Legal Notice No. 2 of 2012).
- In force since 23 August 2021: section 42(a) and (b) (Legal Notice No. 220 of 2021).
- Financial institutions face a nearer deadline: the Miscellaneous Provisions (FATF Compliance) Act 2025 has been in full force since 17 November 2025.
- The whole file rests on three things: an inventory, an owner, and a written record.
On this page
Who it's for
Owners and directors in Trinidad and Tobago whose businesses are starting to be asked for proof of controls: by banks, by auditors, by the clients that matter.
What it covers
- What “evidence” means in practice: access lists, backup logs, policies with owners.
- What is actually in force under the Data Protection Act, precisely.
- How to build the file from what already exists, without new tools.
- How to keep it current in an hour a month.
What is actually in force under Trinidad and Tobago's Data Protection Act?
Most summaries of Trinidad and Tobago's Data Protection Act 2011 say it is “not yet in force.” That is imprecise, and the imprecision is expensive. The Act is partially proclaimed: Part I and sections 7 to 18, 22, 23, 25(1), 26 and 28 have been in force since 6 January 2012 (Legal Notice No. 2 of 2012), and section 42(a) and (b) since 23 August 2021 (Legal Notice No. 220 of 2021). What is in force includes the general privacy principles and the framework of the Information Commissioner's office.
| Provision | In force since | Instrument |
|---|---|---|
| Part I and sections 7 to 18, 22, 23, 25(1), 26 and 28 of the Data Protection Act 2011 | 6 January 2012 | Legal Notice No. 2 of 2012 |
| Section 42(a) and (b) | 23 August 2021 | Legal Notice No. 220 of 2021 |
| Remaining sections of the Data Protection Act 2011 | Not proclaimed | None yet |
| Miscellaneous Provisions (FATF Compliance) Act 2025 | 17 November 2025, in full | The Act itself |
The defensible position for a business handling personal data
Operationally, the defensible position for a business handling personal data (client files, patient records, employee data) is to operate as if the remaining sections were coming, because the general principles already apply and the direction is set. Map where personal data lives, control who reaches it, and be able to show both. Those two records are the first pages of the evidence file.
Why financial institutions are on a shorter clock
For financial institutions, the pressure is more immediate. The FATF-driven review of the sector has produced new obligations: the Miscellaneous Provisions (FATF Compliance) Act 2025 has been in full force since 17 November 2025, and institutions are being asked for evidence, not intentions.
None of this requires panic. It requires an inventory, an owner, and a written record: the same three things the rest of this file is built from.
What does “evidence” mean in practice?
Evidence is a record someone can produce, not an intention or a verbal assurance. The file is built from four records. Two of them are already named above: where personal data lives, and who reaches it. The other two are the ones a bank or an auditor asks for next: proof that the backups work, and the policies that govern all of it, each with a named owner.
| Record | What it looks like when it exists | Who asks for it |
|---|---|---|
| 1. Data map | A list of the systems that hold personal data (client files, patient records, employee data), and what each holds | A regulator, a client, an auditor |
| 2. Access record | Who can reach each system, how that access is granted, and how it is removed when someone leaves | An auditor, a bank |
| 3. Backup log | The dates the backups ran, the date someone last restored from them, and how long that restore took | An auditor, a bank |
| 4. Policies with owners | The rules in force, each with a named owner and a review date | A bank, an auditor, a client |
How do you build the file from what you already have?
Without new tools. Each of the four records already exists somewhere in the business; the work is to export or screenshot it into one place and give it an owner. The data map comes from the list of systems you already pay for. The access record comes from the directory or the mail tenant, which knows every account and its status. The backup log comes from the backup console, and the date of the last restore from whoever did it. The policies come from the documents the business already follows, once each has a name beside it.
The tax firm case study is the worked example: it began with an inventory of every user, every device and every application that touches client data, and both office networks drawn as diagrams the partners can read.
How do you keep the file current in an hour a month?
Once the file exists, keeping it true is a short monthly routine and a few triggers. Monthly: confirm the access list still matches the people, check that the backups ran, and note any change to a policy. Quarterly: restore a file from backup and write down how long it took. Out of cycle: a departure, a new system or a new client requirement updates the record it touches the same week.
| Task | Frequency | Owner |
|---|---|---|
| Confirm the access list matches the people | Monthly | Whoever manages the accounts |
| Check the backup log | Monthly | Whoever runs the backups |
| Note any change to a policy | Monthly | The policy's owner |
| Restore a file and time it | Quarterly | Whoever runs the backups |
| Update the record a departure, a new system or a new client requirement touches | Same week | The record's owner |


