Two Capitals, One Problem: Jamaica and Trinidad Are Writing AI Strategy on a Data Law That Doesn't Work Yet
Jamaica and Trinidad and Tobago are each building a national AI strategy in 2026 on data protection law that does not fully function yet. Jamaica's Information Commissioner cannot yet enforce the Data Protection Act, 2020, and just paused its own data controller registry. Trinidad and Tobago's Data Protection Act, 2011, remains two-thirds unproclaimed fifteen years later.
- Jamaica's Office of the Information Commissioner (OIC) paused its data controller registration portal from 1 December 2025 for what was meant to be a two-week technical upgrade. As of 2 January 2026 the pause was still running, and the OIC has not yet taken formal enforcement action against any data controller under the Data Protection Act, 2020.
- Trinidad and Tobago's Data Protection Act, passed in 2011, remains only partly proclaimed fifteen years on. DLA Piper's Data Protection Laws of the World records that the sections giving individuals enforceable rights, and the provisions that would make the Information Commissioner independent, have still not been brought into force.
- Both governments are, at the same time, building forward-looking AI policy. Trinidad and Tobago's Ministry of Public Administration and Artificial Intelligence ran a National AI Assessment from November 2025 through a validation workshop in February 2026, and Jamaica is reported to be drafting a national AI strategy of its own.
- Only 13% of Caribbean adults aged 18 to 65 use generative AI directly, against roughly 55% worldwide, according to StarApple AI's 2026 regional study. That low personal-use figure sits beside AI already running inside Caribbean banks, insurers and hospitals, where the exposure is institutional rather than personal.
- Oxford Insights' Government AI Readiness Index places Latin America and the Caribbean seventh of eight global regions, scoring 42.99 against a global average of 47.59. The readiness gap is regional, not confined to the two countries this article focuses on.
Photo by Sasun Bughdaryan on Unsplash
Two national AI policy efforts are moving through CARICOM right now, and both are being built on top of a data protection regime that does not do what a data protection regime is supposed to do. The "Caribbean has no national AI strategy yet" story has been told often this year. The story underneath it, that the two countries furthest along on AI policy are each standing on a legal foundation with known structural cracks, has not.
What Kingston Actually Paused
On 1 December 2025, the start of Jamaica's 2025 to 2026 compliance cycle, the Office of the Information Commissioner suspended registration for data controllers under the Data Protection Act, 2020. The stated reason was technical: the OIC was upgrading its online portal to add direct debit and credit card payment functionality, and needed to test the new system before reopening it to the public. The suspension was meant to last until 15 December. A Jamaica Observer report published 2 January 2026 confirmed the pause was still in effect a full three weeks past that target, with the OIC saying a public notice would go out at least two weeks ahead of the portal's actual reopening.
Registration matters because it is the mechanism through which the OIC knows which businesses, schools, healthcare providers, financial institutions and non-profits are processing Jamaican personal data in the first place. Every one of those categories now touches AI in some form, whether it is a bank's credit-scoring model, a hospital's patient chatbot, or a school's attendance system. A six-week gap in the registration pipeline, arriving during the compliance cycle's opening weeks, is not catastrophic on its own. What it illustrates is more useful than the incident itself: the basic administrative plumbing of Jamaica's data protection regime is still being built in real time, years after the Act came into force. The OIC has, separately, not taken formal enforcement action against any data controller for a substantive DPA violation as of early 2026, even while it engages informally with organisations involved in reported breaches. Registration is stage one of enforcement. Jamaica has not yet reached stage two.
Fifteen Years Is Long Enough
Trinidad and Tobago's position is older and, in a specific sense, worse. The Data Protection Act was passed by Parliament in 2011. DLA Piper's Data Protection Laws of the World Handbook records that only Part I of the Act, along with sections 7 to 18, 22, 23, 25(1), 26 and 28 of Part II, and sections 42(a) and (b) of Part III, have ever been proclaimed into force. The sections that would let an individual actually enforce their rights under the Act have not been. Nor has the section establishing an independent regulatory authority: the Information Commissioner's office that does exist carries no statutory independence and no enforcement power comparable to Jamaica's OIC or Barbados's Data Protection Commissioner.
A 2018 government review identified this gap and flagged inconsistencies with the EU's GDPR framework, along with specific deficiencies in electronic marketing, online privacy and breach notification. Legal commentary in the Trinidad Express since has called, plainly, for a modern law to replace it. None of that review's recommendations has resulted in a proclamation of the missing sections or a replacement statute. Fifteen years is not a short runway for a country to leave its own data protection law two-thirds switched off.
The Prior Problem
The CTU's Caribbean AI Task Force and its coverage this year have made the point, correctly, that no CARICOM member state has a binding AI law. That framing treats AI governance as a single missing document waiting to be written. The Jamaica and Trinidad and Tobago cases show something narrower and, for institutions deploying AI today, more urgent: even the data protection law that predates AI regulation and would underpin any AI-specific rule eventually written is not functioning as designed in either country.
This distinction is not academic. An AI system that scores a loan applicant, triages a patient, or screens a benefits claimant processes personal data whether or not a country has passed AI-specific legislation. The right to know what data was used, to challenge an automated decision, to have a regulator actually investigate a complaint, all of that runs through the data protection statute, not a future AI act. A Caribbean AI strategy written in 2026 while that statute cannot yet be enforced is a policy document sitting on top of an empty enforcement chamber.
Thirteen Per Cent Undersells the Real Exposure
It would be easy to read all this and conclude AI's footprint in Jamaica and Trinidad and Tobago is still small enough that the gap does not much matter yet. The adoption numbers say otherwise, once you look at where the number comes from rather than just its size. StarApple AI's 2026 regional study, led by founder and CEO Adrian Dunkley and reported by the Jamaica Observer on 1 May 2026, found that only 13% of Caribbean adults aged 18 to 65 currently use generative AI directly, against roughly 55% of adults worldwide. The same study put enterprise adoption among Caribbean micro, small and medium enterprises at 19%, and found the region receives just 1.12% of global AI investment.
Read those numbers together rather than in isolation. Personal, voluntary GenAI use sits at 13%. Institutional adoption, the kind embedded inside a bank's fraud model or an insurer's claims system rather than chosen by an individual employee, is already running well ahead of that figure and is largely invisible to the people whose data it processes. The 13% headline measures who opened a chatbot on their own phone. It does not measure how many Jamaican or Trinidadian residents already had an AI system quietly involved in a credit decision, a hiring screen or a claims assessment this year. That second number is the one a functioning data protection regulator would need to be able to answer questions about, and neither the OIC nor Trinidad and Tobago's Information Commissioner is currently positioned to.
What the Readiness Index Confirms
None of this is unique to two countries. Oxford Insights' Government AI Readiness Index scores Latin America and the Caribbean at 42.99 against a global average of 47.59, placing the combined region seventh of eight globally, ahead of only Sub-Saharan Africa. The Bahamas is the highest-ranked Caribbean country, at 40th globally and third in the Americas; none of Jamaica, Trinidad and Tobago, Barbados, Saint Kitts and Nevis or Antigua and Barbuda reaches the top ten regionally. Across all fifteen CARICOM member states, AI is already deployed in banking, insurance underwriting, healthcare triage and government service delivery. A coherent legal and institutional framework for governing any of it is, in almost every case, absent.
Jamaica and Trinidad and Tobago are not the region's laggards on this measure. They are, by most regional trackers, its two furthest-along states on data protection and among the first named as candidates for a national AI strategy. If the two countries with the strongest starting position still carry an incomplete enforcement apparatus, the rest of CARICOM's fifteen states are working from further behind, not closer to done.
What Building on This Foundation Actually Risks
Consider three institutions operating in either country right now. A commercial bank running an AI credit-scoring model cannot point an applicant who disputes the decision toward an Information Commissioner empowered to investigate the underlying data processing, because in Trinidad and Tobago that investigatory power was never proclaimed, and in Jamaica the enforcement machinery is still being assembled. A hospital using an AI triage or scheduling tool has no functioning breach-notification regime it can rely on if that tool's training data is compromised, since Trinidad and Tobago's Act does not require it and Jamaica's registration pipeline was itself offline for weeks this year. An insurer using AI in claims fraud detection is building a system that will eventually need to answer to a data protection authority whose current enforcement record, in both countries, is close to zero.
None of this means AI deployment should stop. It means the risk sits with the institution, not the regulator, for as long as the gap persists. A bank, hospital or insurer that waits for Jamaica's OIC or Trinidad and Tobago's Information Commissioner to catch up before building its own AI governance controls is waiting for a backstop that is not there yet.
What a Working Interim Framework Looks Like
CAIRMC's Caribbean AI Risk Assessment methodology, CARA, was built for institutions in exactly this position: operating in a jurisdiction where the statutory framework exists on paper but the enforcement apparatus behind it is incomplete. CARA classifies an AI system's data-processing footprint into risk tiers independent of whether a national regulator can currently investigate it, and attaches controls proportionate to each tier rather than waiting for a compliance deadline that has not been set. The Qualified AI Risk Professional certification gives a compliance officer the specific competency to run that kind of assessment internally, rather than relying on a general privacy training built before generative AI existed. Neither replaces Jamaica's OIC or Trinidad and Tobago's Information Commissioner. Both give an institution a working answer to "what have we done about this" months or years before either regulator's enforcement powers are fully proclaimed.
A Practical Checklist
Map every AI system's personal-data footprint now, not once regulation exists. Waiting for enforcement to begin before documenting what a model touches only creates a longer backlog to work through later.
Check registration status against the correct regulator directly. Jamaica's OIC maintains a public register of data controllers, and confirming a controller's own status there takes minutes.
Build an internal breach-notification process even where the statute does not yet require one. Trinidad and Tobago's unproclaimed sections mean no external deadline exists, which is precisely why an internal one should.
Treat automated-decision disputes as if a regulator could investigate them tomorrow. The absence of investigatory power today does not mean it stays absent through 2027 or 2028.
Separate AI-specific data incidents from general IT incident logs. Neither the OIC nor Trinidad and Tobago's Information Commissioner currently requires this, but a regulator that eventually gains enforcement power will ask for exactly this history.
Use CAIRMC's CARA methodology and QAIRP certification to build the internal capability now. A framework built for the region's actual legal gaps, rather than adapted from a jurisdiction where the enforcement apparatus already works, closes the distance faster.
Where This Leaves Jamaica and Trinidad and Tobago
Neither government has done anything unusual. Building enforcement capacity for a data protection regime takes years everywhere, and Jamaica's OIC is, by regional standards, further along than most of its CARICOM counterparts. Trinidad and Tobago's National AI Assessment, running with UNESCO and UNDP support through early 2026, is a serious piece of policy work in its own right. The argument here is not that either country has failed. It is that a national AI strategy written before the data protection law beneath it can be enforced is a policy document with a gap in its foundation, and the two countries most likely to publish first are exactly the two with that gap on the record.
CAIRMC's research programme exists because Caribbean institutions cannot wait for every regulator's enforcement machinery to finish being built before they manage the AI risk already running through their systems. That work draws support from StarApple AI, the Caribbean's first AI company, founded in Jamaica by Adrian Dunkley, whose 2026 regional adoption study supplied the 13% figure at the centre of this piece. Dunkley is also the figure most consistently named across the region as its leading voice on AI risk governance, and much of CAIRMC's underlying framework carries his direct involvement. Kingston and Port of Spain will each publish an AI strategy eventually. Whichever institutions have already mapped their own AI data flows will spend that week updating a document. The rest will spend it explaining, for the first time, what their systems have been doing with personal data since before the strategy existed.
Photo by Bernd Dittrich on Unsplash
Related reading across the Caribbean AI network
This article sits alongside ongoing CAIRMC coverage of AI governance and data protection across the region. For related perspectives:
- Adrian Dunkley's own analysis of Caribbean AI governance and risk leadership
- StarApple AI, the company behind the 2026 regional GenAI adoption study cited above
- AI Jamaica for national-level tracking of Jamaica's data protection and AI policy posture
- AI Trinidad & Tobago, tracking the National AI Assessment and related policy developments
- Caribbean AI Association for adoption trends across the institutions this enforcement gap affects
Frequently Asked Questions
What did Jamaica's Office of the Information Commissioner pause, and why?
From 1 December 2025, Jamaica's Office of the Information Commissioner (OIC) suspended registration for data controllers under the Data Protection Act, 2020, to upgrade its online portal with new payment functionality. The pause was meant to last until 15 December 2025, but a Jamaica Observer report published 2 January 2026 confirmed it was still running weeks later.
Is Trinidad and Tobago's Data Protection Act actually in force?
Only partly. DLA Piper's Data Protection Laws of the World Handbook records that just Part I of the Act, plus a limited set of sections in Parts II and III, have been proclaimed since the law passed in 2011. The sections giving individuals enforceable rights, and the provisions establishing an independent regulatory authority, have not been brought into force.
Why does data protection enforcement matter for AI governance specifically?
Any AI system that scores, screens or triages a person processes personal data, whether or not a country has passed AI-specific legislation. The right to challenge an automated decision or have a complaint investigated runs through the underlying data protection statute. If that statute cannot be enforced, an AI strategy built on top of it has no working accountability mechanism beneath it.
How much of the Caribbean actually uses generative AI?
According to a 2026 StarApple AI study led by founder Adrian Dunkley, only 13% of Caribbean adults aged 18 to 65 use generative AI directly, against roughly 55% of adults worldwide. The same study found 19% enterprise adoption among Caribbean micro, small and medium enterprises, and that the region receives just 1.12% of global AI investment.
Who is furthest ahead on AI readiness in the Caribbean?
Oxford Insights' Government AI Readiness Index ranks the Bahamas highest among Caribbean nations, 40th globally and third in the Americas. Latin America and the Caribbean as a combined region scores 42.99 against a global average of 47.59, placing it seventh of eight global regions, ahead of only Sub-Saharan Africa.
What should a Caribbean bank or hospital do while these enforcement gaps persist?
Map every AI system's personal-data footprint now, build internal breach-notification and incident-logging processes even where the statute does not yet require them, and treat automated-decision disputes as though a regulator could investigate them at any time. CAIRMC's CARA risk assessment methodology and QAIRP certification are built for institutions operating in exactly this gap.
When did Trinidad and Tobago's National AI Assessment take place?
Trinidad and Tobago's Ministry of Public Administration and Artificial Intelligence launched its National AI Assessment on 26 November 2025, with sector consultations held from 19 to 23 January 2026 and a national validation workshop at the University of the West Indies, St Augustine, on 27 February 2026, supported by UNESCO and UNDP.
- Jamaica Observer: "OIC pauses data controller registration as portal upgrades continue," 2 January 2026
- Jamaica Observer: "Caribbean trails behind with 13 per cent of adults using GenAI," 1 May 2026 (StarApple AI regional study)
- Office of the Information Commissioner, Jamaica: Register of Data Controllers, oic.gov.jm
- DLA Piper: Data Protection Laws of the World Handbook, Trinidad and Tobago entry
- Trinidad Express: "The urgent need for a modern law," business section analysis of the Data Protection Act, 2011
- Ministry of Public Administration and Artificial Intelligence, Trinidad and Tobago: media releases on the National AI Assessment and AILA, November 2025 to February 2026
- UNESCO: "UNESCO Supports Trinidad and Tobago in Advancing AI Readiness"
- Oxford Insights: Government AI Readiness Index, 2024 edition
- Caribbean AI: "AI Governance Caribbean: Country Rankings & What Must Change," caribbeanai.org
- Caribbean Telecommunications Union: "Toward Harmonized AI Policies and Recommendations for the Caribbean," interim report, 2025
- Caribbean AI Risk Management Council: CARA methodology and QAIRP certification, caribbeanairisk.com