Jamaica's Data Protection Act Promises a Right to Erasure. AI Models Do Not Have a Delete Button.
- Dr Tiou Clarke of the University of Technology, Jamaica, wrote in the Gleaner on 9 September 2026 that the Jamaica Data Protection Act's eight data protection standards, in force under the Office of the Information Commissioner since 1 December 2023, were built around a database record that can be found and deleted. A trained AI model has no such record.
- A model stores weights shaped by training data, not a retrievable file per person. Honouring an erasure request against data that was used to train or fine-tune a model usually means retraining or discarding that model, not deleting a row, and the JDPA gives no guidance on which one a controller owes a data subject.
- The JDPA also restricts transferring personal data outside Jamaica unless the receiving territory offers adequate protection. Most commercial AI tools run inference on infrastructure outside Jamaica, which puts the transfer question ahead of the erasure question for any institution that has not mapped where its AI vendor actually processes data.
- Jamaica's OIC has live enforcement power today. Trinidad and Tobago's Data Protection Act, passed in 2011, remains only partially proclaimed 14 years later, so the erasure right this article describes for Jamaica has no directly enforceable equivalent next door, a divergence any regional operator has to design around rather than assume away.
- CAIRMC's Caribbean AI Risk Management Standard already requires data controllers to document which of three data flows, inference-only, fine-tuning, or foundation-model training, applies to each AI system, which is the record an institution needs before it can answer an erasure request honestly.
Photo via Unsplash.
Dr Tiou Clarke, a lecturer at the University of Technology, Jamaica's School of Business Administration, used a Gleaner commentary on 9 September 2026 to name a specific problem: the Jamaica Data Protection Act's eight data protection standards, the ones the Office of the Information Commissioner has supervised since 1 December 2023, assume a personal data record can be located and removed. A large language model or a trained classifier does not keep a record. It keeps weights, numbers adjusted by every document the model saw during training, and no single row in that structure maps back to one person's name.
The direct answer to the question this raises: Jamaica's Data Protection Act does give data subjects a right to have inaccurate or unlawfully processed personal data erased, but that right was written for a record sitting in a database. A model trained or fine-tuned on that record does not hold a deletable copy of it. Honouring the request typically means retraining the model without the data or discarding it, not removing a row, and the Act itself does not say which obligation applies.
Three Kinds of Data, Three Different Erasure Answers
Clarke's commentary treats "AI" as one category. For an erasure request, it is not, and the distinction is the first thing a compliance officer needs before answering one.
Inference-time data. Many Caribbean deployments of AI tools, a chatbot answering from a document store, a search system re-ranking a customer's own file, do not train on the data they touch. The data lives in a database or a retrieval index that the AI system queries at the moment of use. Erasure here works close to how the JDPA imagines it: delete the record, and the system stops surfacing it. This is the easy case, and it is also the case most institutions assume covers every AI system they run, which is the assumption Clarke's piece is aimed at.
Fine-tuning data. A model adjusted on an institution's own customer records, loan files, or claims history has folded those records into its weights through gradient updates. No commercial technique removes one person's influence from a fine-tuned model without retraining it, in whole or in a targeted way, on the remaining data. Machine unlearning research is advancing but is not yet something an institution can write into a vendor contract and expect executed on demand. The honest answer to an erasure request here is retrain or withdraw the model, a promise the JDPA implies an institution can keep and, without that budget already set aside, cannot.
Foundation-model training data. If personal data entered a foundation model's original training run, the Jamaican institution using that model by API almost never controls the training pipeline. The obligation, if one exists, sits with a foreign vendor under a foreign law, and the JDPA has no direct mechanism to reach it. It is also the case an institution is least likely to have inventoried, because the data may have entered the training corpus through a channel, a public filing, a scraped webpage, a prior vendor relationship, that nobody at the institution chose.
The Transfer Restriction Sitting Underneath the Erasure Question
Before an institution can answer an erasure request, it has to know where the data went, and the JDPA has a separate standard for that: personal data must not be transferred outside Jamaica unless the receiving jurisdiction provides an adequate level of protection, or another statutory basis applies. Most commercial large language model APIs run inference on servers outside Jamaica, frequently outside the Caribbean altogether, which means the transfer question arrives before the erasure question does, and for many institutions it arrives unexamined.
Clarke's recommended sequence, a data protection impact assessment before deployment, data masking or anonymisation where feasible, and a vendor due-diligence contract that states where processing happens, maps directly onto controls the NIST AI Risk Management Framework already asks for under its MAP and GOVERN functions, and onto the AI system impact assessment ISO/IEC 42001:2023 requires before an organisation certifies. None of this needs a new Jamaican statute to start; it needs an institution to run the assessment it is already supposed to be running before the AI tool goes live, not after a data subject asks a question the vendor contract does not answer.
StarApple AI's Jamaican arm, StarApple AI Jamaica, has spent much of 2026 running AI-readiness assessments and staff training across schools, businesses and government agencies on the island, exactly the groundwork a data inventory of this kind depends on. An institution that does not know which of its systems does inference-only, fine-tuning, or foundation-model training cannot answer Clarke's question, let alone a regulator's, and that inventory is a staff-training and process problem before it is a legal one.
Why One Erasure Policy Does Not Travel Across the Region
A regional bank, insurer, or BPO operator with staff in more than one Caribbean jurisdiction cannot write a single erasure policy and apply it everywhere, because the underlying statutes are not at the same stage of life. Jamaica's OIC has been an active regulator since 1 December 2023, with the statutory power to investigate a complaint and order a remedy today. Trinidad and Tobago's Data Protection Act, passed in 2011, remains only partially proclaimed: Part I and a short list of named sections came into force in January 2012, and the provisions establishing a functioning commissioner's office with erasure and enforcement powers have never been brought into operation, 14 years on, despite a 2018 government review that flagged the gap against the EU's GDPR and a 2019 consultation that produced no amending legislation. Barbados has its own 2019 Data Protection Act, and the OECS member states share a model bill rather than a single enacted law, so the erasure obligation an institution owes a customer in Kingston has no direct equivalent for the same institution's customer in Port of Spain, even though both are personal data processed by the same AI system.
That divergence is not a footnote. It is the reason CARICOM's own AI Task Force spent 2025 and 2026 building toward a harmonised regional framework rather than leaving each member state to legislate alone, and it is the reason the Caribbean AI Association, which represents AI-adopting businesses across more than a dozen jurisdictions, is a natural venue for building a single reference document that a regional operator can map its systems against once, instead of once per island. Until that document exists, CAIRMC's own Caribbean AI Risk Management Standard, which ties its four risk tiers to the Data Protection Acts of Jamaica, Trinidad and Tobago, Barbados, the Cayman Islands, and Guyana individually, is the closest thing available to a working cross-jurisdiction map, and it treats the JDPA's erasure standard as the strictest test in the region rather than the regional default.
Frequently Asked Questions
What is the right to erasure under Jamaica's Data Protection Act?
It is one of the JDPA's eight data protection standards, giving a data subject the right to have personal data that is inaccurate, incomplete, or unlawfully processed erased or corrected by the data controller holding it. The Office of the Information Commissioner has supervised compliance with this and the other seven standards since 1 December 2023.
Does the right to erasure apply to AI models trained on my personal data?
The right applies to the personal data itself. Whether it can be practically enforced against a trained model depends on how that data was used. Data queried at inference time from a database can usually be deleted in the ordinary sense. Data folded into a model through fine-tuning or foundation-model training cannot be surgically removed with current commercial technique; the model has to be retrained or withdrawn.
How can a Jamaican organisation comply with an erasure request when the data trained a model?
First, determine which of the three data flows applies: inference-only, fine-tuning, or foundation-model training. For inference-only systems, delete the underlying record. For a fine-tuned model, the organisation needs a documented retraining path, and should build that into its AI vendor contract before deployment rather than after a request arrives. For a foundation model controlled entirely by an external vendor, the organisation's real leverage is contractual: it should have already asked the vendor, in writing, what erasure the vendor itself can perform.
What does it cost to comply with an erasure request against a trained model?
There is no fixed figure, because the cost depends on model size and how the data was used. Deleting a database record is close to free. Retraining a fine-tuned model can cost from a few hundred to several thousand US dollars in compute depending on scale, plus staff time to rebuild and revalidate the model. Discarding and rebuilding a model entirely is the most expensive path and the one institutions should be budgeting to avoid by not fine-tuning on data they cannot commit to retraining around.
How does Jamaica's erasure right compare with the EU's GDPR right to erasure for AI systems?
Both instruments state the same underlying right in similar language, and both were written before large-scale machine learning made "erase this record" ambiguous for a trained model. The GDPR has produced more regulatory guidance and case law on this specific tension, largely through the European Data Protection Board and national regulators, than the JDPA has produced to date. Jamaica's OIC has not yet issued dedicated guidance on how the erasure standard applies to AI training data.
Could the Office of the Information Commissioner order a foreign AI vendor to delete data from a trained model?
The OIC's statutory authority runs to data controllers subject to Jamaican jurisdiction. A foreign vendor processing Jamaican personal data through a foundation model trained abroad sits largely outside that direct reach unless the vendor has a Jamaican presence or the local institution's contract with the vendor creates an enforceable obligation the OIC can act against through the local party. This is precisely why Clarke's recommended vendor due-diligence contract matters more than the statute's own wording.
What is the biggest risk in ignoring this gap between the JDPA and an institution's AI contracts?
An institution that tells a data subject their data has been erased, without knowing whether that data shaped a fine-tuned model still in production, has made a representation to a regulator it cannot support if challenged. The exposure is not theoretical: an OIC complaint that surfaces a fine-tuned model still reflecting supposedly erased data is a compliance failure the institution created by not inventorying its own AI systems, not a failure of the statute.
Will Jamaica's Data Protection Act be updated to address AI and machine learning specifically?
No amendment has been tabled as of September 2026. Given that the OIC has been an active regulator for under three years and CARICOM's own AI Task Force is still working toward a harmonised regional framework, dedicated JDPA guidance on AI training data is a plausible next step rather than a scheduled one, and institutions should build their own documented data-flow inventory now rather than wait for it.
Clarke's piece names a gap the JDPA's drafters could not have anticipated in 2020, before large language models were something a Jamaican insurer or bank would run in production. The Office of the Information Commissioner has the statutory standing to close that gap through guidance rather than new legislation, and the institutions it supervises do not need to wait for either. The inventory that answers "which of my systems does inference, fine-tuning, or training" is buildable this quarter, with the tools already in a compliance officer's hands.
- Jamaica Gleaner: Dr Tiou Clarke, "Artificial intelligence and the Jamaica Data Protection Act: navigating statutory alignment," Commentary, 9 September 2026
- Jamaica Information Service: "Jamaicans Urged to Get Acquainted with Data-Protection Standards"
- Office of the Information Commissioner, Jamaica: data protection standards, oic.gov.jm
- The Data Protection Act, 2011 (Trinidad and Tobago), partial proclamation status, Ministry of Legal Affairs, Trinidad and Tobago
- Caribbean Telecommunications Union: CTU Caribbean AI Task Force interim and final reports, 2025-2026
- Caribbean AI Risk Management Council: Caribbean AI Risk Management Standard