Skip to main content

Caribbean tracker

Cybersecurity law and institutions across 15 Caribbean countries covered by the OAS–IDB 2025 report and later sources, with page references. Open a country for its profile.

Cybercrime law

12/15

1 more in progress

Data protection

9/15

3 more in progress

National strategy

5/15

3 more in progress

CSIRT

9/15

5 more in progress

Budapest Convention

2/15

2 more in progress

15 of 15 countries

In place In progress None reported Not stated
CountryCybercrime lawData protectionNational strategyCSIRTBudapest Convention
GuyanaIn placeIn progressIn place
National Cybersecurity Policy Framework, 43 policies, launched by NDMA in 2024 p. 112
In place
CIRT.GY, established 2013, now part of the NDMA under the Office of the Prime Minister p. 112
None reported
Antigua and BarbudaIn place
Electronic Crimes Act 2013 p. 43
In place
Data Protection Act, in force since 2013 p. 43
None reported
No national strategy yet; Cybersecurity Director appointed p. 42
In placeIn progress
The BahamasIn place
Computer Misuse Act p. 51
In place
Data Protection Act p. 51
In place
National Cybersecurity Strategy in place p. 50
In place
CIRT-BS, implements the strategy and coordinates incident response p. 50
None reported
BarbadosIn place
Computer Misuse Act; Cybercrime Bill 2024 introduced p. 54
In placeIn progress
National cybersecurity strategy in development p. 54
In place
CIRT-BB (national CSIRT directory) pp. 183–184
None reported
BelizeIn place
Cybercrime Act 2020 p. 59
In place
Data Protection Act, November 2021 p. 59
In place
First strategy in place; second in development with the OAS since 2024 p. 58
None reported
No national CERT/CIRT p. 58
None reported
DominicaNone reported
No cybercrime law among those the report lists; legal framework “in a developmental stage” p. 85
None reported
No data protection law among those the report lists p. 85
Not statedIn progress
CIRT establishment plan workshop with CARICOM IMPACS p. 85
None reported
Dominican RepublicIn place
Law 53-07 on high-tech crimes p. 90
In place
Law 172-13 on data protection p. 90
In place
Second strategy, Decree 313-22, running to 2030 p. 89
In place
CSIRT-RD (national CSIRT directory) pp. 183–184
In place
GrenadaIn place
Electronic Crimes Act 2013, amended 2014 p. 104
In place
Data Protection Act (No. 1 of 2023) p. 104
None reported
No national strategy yet p. 104
In place
National CSIRT in place p. 104
In place
HaitiNone reported
No comprehensive law reported p. 116
None reported
No comprehensive law reported p. 116
None reported
No comprehensive national strategy p. 116
In progress
None yet; planned under an IDB project p. 116
None reported
JamaicaIn place
Cybercrimes Act 2015 p. 124
In place
Data Protection Act 2020 p. 124
In progress
New strategy not yet published; implementation under way p. 124
In place
JaCIRT, under the Ministry of Science, Energy, Telecommunications and Transport p. 124
None reported
St Kitts and NevisIn place
Electronic Crimes Act No. 27 p. 148
In progressNone reported
No national cybersecurity strategy described; the report cites the National ICT Strategic Plan p. 147
In progress
National CIRT assessment under way p. 147
None reported
Saint LuciaIn place
Computer Misuse Act 2018 p. 151
In placeNone reported
The report says it lacks a comprehensive national cybersecurity strategy p. 151
In progress
Working to establish a national CERT; no operational team yet p. 151
None reported
St Vincent and the GrenadinesIn place
Cybercrime Act, August 2016 p. 155
Not statedNone reported
No national cybersecurity framework p. 155
In progress
No designated CSIRT; establishment plan workshop in 2025 p. 155
None reported
SurinameIn progress
Defined in the Criminal Code 2025; dedicated legislation in draft p. 160
In progress
Draft legislation under review p. 160
In progress
Draft national strategy in development; National Digital Strategy 2023–2030 includes cybersecurity p. 159
In place
SURCSIRT p. 159
None reported
Trinidad and TobagoIn place
Computer Misuse Act 2000; Cybercrime Bill 2017 under consideration p. 164
In placeIn place
2012 strategy, not overhauled p. 164
In place
TT-CSIRT, established 2015 p. 164
In progress

How to read this. Entries come from the country chapters of the OAS–IDB 2025 Cybersecurity Report, with page numbers. Where a later or fuller source differs from the report, the entry cites that source instead, and a Budapest Convention entry is checked against the Council of Europe’s list. Guyana’s laws also link to the Parliament of Guyana. † marks a secondary source. “Not stated” means the report does not say, not that the item does not exist. Laws change, so check the source. Updated 2026-10-03.

Budapest Convention context​

Grenada deposited its instrument of accession to the Budapest Convention on 22 April 2024, and the Council of Europe said this may set an example for other Caribbean countries (Council of Europe). For the current list of parties, start from the Council of Europe’s page on the Convention, which links to the Treaty Office. As of the Council of Europe’s list of Parties and invitees (checked 3 October 2026), the Dominican Republic and Grenada are Parties, Antigua and Barbuda and Trinidad and Tobago are invited to accede, and none of the other countries in this tracker appears. Countries that align their laws with the Convention without acceding, such as the Bahamas and Belize, are shown separately from those invited.