Itaca Technologies
Guide
3 min readUpdated

The evidence file: what a Trinidad and Tobago business should be able to show

The records that answer an auditor, a bank, or a large client, before they ask.

I

Itaca Advisory

Technology advisory & compliance team

Key takeaways

  • “Not yet in force” is wrong. The Data Protection Act 2011 is partially proclaimed, and the parts in force include the general privacy principles.
  • In force since 6 January 2012: Part I and sections 7 to 18, 22, 23, 25(1), 26 and 28 (Legal Notice No. 2 of 2012).
  • In force since 23 August 2021: section 42(a) and (b) (Legal Notice No. 220 of 2021).
  • Financial institutions face a nearer deadline: the Miscellaneous Provisions (FATF Compliance) Act 2025 has been in full force since 17 November 2025.
  • The whole file rests on three things: an inventory, an owner, and a written record.
On this page
  1. Who it's for
  2. What it covers
  3. What is actually in force under Trinidad and Tobago's Data Protection Act?
  4. What does “evidence” mean in practice?
  5. How do you build the file from what you already have?
  6. How do you keep the file current in an hour a month?

Who it's for

Owners and directors in Trinidad and Tobago whose businesses are starting to be asked for proof of controls: by banks, by auditors, by the clients that matter.

What it covers

  • What “evidence” means in practice: access lists, backup logs, policies with owners.
  • What is actually in force under the Data Protection Act, precisely.
  • How to build the file from what already exists, without new tools.
  • How to keep it current in an hour a month.

What is actually in force under Trinidad and Tobago's Data Protection Act?

Most summaries of Trinidad and Tobago's Data Protection Act 2011 say it is “not yet in force.” That is imprecise, and the imprecision is expensive. The Act is partially proclaimed: Part I and sections 7 to 18, 22, 23, 25(1), 26 and 28 have been in force since 6 January 2012 (Legal Notice No. 2 of 2012), and section 42(a) and (b) since 23 August 2021 (Legal Notice No. 220 of 2021). What is in force includes the general privacy principles and the framework of the Information Commissioner's office.

ProvisionIn force sinceInstrument
Part I and sections 7 to 18, 22, 23, 25(1), 26 and 28 of the Data Protection Act 20116 January 2012Legal Notice No. 2 of 2012
Section 42(a) and (b)23 August 2021Legal Notice No. 220 of 2021
Remaining sections of the Data Protection Act 2011Not proclaimedNone yet
Miscellaneous Provisions (FATF Compliance) Act 202517 November 2025, in fullThe Act itself
What is in force, and since when

The defensible position for a business handling personal data

Operationally, the defensible position for a business handling personal data (client files, patient records, employee data) is to operate as if the remaining sections were coming, because the general principles already apply and the direction is set. Map where personal data lives, control who reaches it, and be able to show both. Those two records are the first pages of the evidence file.

The evidence file01Where personal data lives02Who can reach it03Backup logs04Policies with named ownersWhat is already in force2012Part I and sections 7 to 18, 22, 23,25(1), 26 and 28 of the Data ProtectionAct, since 6 January2021Section 42(a) and (b), since 23 August2025Miscellaneous Provisions (FATFCompliance) Act, in full force since 17November
The four records the file is built from, and what is already in force.

Why financial institutions are on a shorter clock

For financial institutions, the pressure is more immediate. The FATF-driven review of the sector has produced new obligations: the Miscellaneous Provisions (FATF Compliance) Act 2025 has been in full force since 17 November 2025, and institutions are being asked for evidence, not intentions.

None of this requires panic. It requires an inventory, an owner, and a written record: the same three things the rest of this file is built from.

What does “evidence” mean in practice?

Evidence is a record someone can produce, not an intention or a verbal assurance. The file is built from four records. Two of them are already named above: where personal data lives, and who reaches it. The other two are the ones a bank or an auditor asks for next: proof that the backups work, and the policies that govern all of it, each with a named owner.

RecordWhat it looks like when it existsWho asks for it
1. Data mapA list of the systems that hold personal data (client files, patient records, employee data), and what each holdsA regulator, a client, an auditor
2. Access recordWho can reach each system, how that access is granted, and how it is removed when someone leavesAn auditor, a bank
3. Backup logThe dates the backups ran, the date someone last restored from them, and how long that restore tookAn auditor, a bank
4. Policies with ownersThe rules in force, each with a named owner and a review dateA bank, an auditor, a client
The four records, and what each looks like when it exists

How do you build the file from what you already have?

Without new tools. Each of the four records already exists somewhere in the business; the work is to export or screenshot it into one place and give it an owner. The data map comes from the list of systems you already pay for. The access record comes from the directory or the mail tenant, which knows every account and its status. The backup log comes from the backup console, and the date of the last restore from whoever did it. The policies come from the documents the business already follows, once each has a name beside it.

The tax firm case study is the worked example: it began with an inventory of every user, every device and every application that touches client data, and both office networks drawn as diagrams the partners can read.

How do you keep the file current in an hour a month?

Once the file exists, keeping it true is a short monthly routine and a few triggers. Monthly: confirm the access list still matches the people, check that the backups ran, and note any change to a policy. Quarterly: restore a file from backup and write down how long it took. Out of cycle: a departure, a new system or a new client requirement updates the record it touches the same week.

TaskFrequencyOwner
Confirm the access list matches the peopleMonthlyWhoever manages the accounts
Check the backup logMonthlyWhoever runs the backups
Note any change to a policyMonthlyThe policy's owner
Restore a file and time itQuarterlyWhoever runs the backups
Update the record a departure, a new system or a new client requirement touchesSame weekThe record's owner
Keeping the file current

Questions readers ask

Partially. Saying it is “not yet in force” is imprecise. Part I and sections 7 to 18, 22, 23, 25(1), 26 and 28 have been in force since 6 January 2012 under Legal Notice No. 2 of 2012, and section 42(a) and (b) since 23 August 2021 under Legal Notice No. 220 of 2021. The remaining sections are not proclaimed.

Customer Success Team

Itaca Technologies

Your question isn't here?

Ask it as you'd ask it across the table. The team that does the work reads it and answers with a concrete next step.

Founded in 2011
No software resale
No vendor commissions