Caribbean tracker
Cybersecurity law and institutions across 15 Caribbean countries covered by the OAS–IDB 2025 report and later sources, with page references. Open a country for its profile.
Cybercrime law
12/15
1 more in progress
Data protection
9/15
3 more in progress
National strategy
5/15
3 more in progress
CSIRT
9/15
5 more in progress
Budapest Convention
2/15
2 more in progress
| Country | Cybercrime law | Data protection | National strategy | CSIRT | Budapest Convention |
|---|---|---|---|---|---|
| Guyana | In place | In progress | In place National Cybersecurity Policy Framework, 43 policies, launched by NDMA in 2024 p. 112 | In place CIRT.GY, established 2013, now part of the NDMA under the Office of the Prime Minister p. 112 | None reported Not a Party or invited to accede CoE list |
| Antigua and Barbuda | In place Electronic Crimes Act 2013 p. 43 | In place Data Protection Act, in force since 2013 p. 43 | None reported No national strategy yet; Cybersecurity Director appointed p. 42 | In place AB govCIRT, launched 28 August 2026 by the Ministry of ICTs † Antigua Observer, 1 Sep 2026 | In progress Invited to accede on 24 September 2025 (valid five years) Council of Europe |
| The Bahamas | In place Computer Misuse Act p. 51 | In place Data Protection Act p. 51 | In place National Cybersecurity Strategy in place p. 50 | In place CIRT-BS, implements the strategy and coordinates incident response p. 50 | None reported Not a Party or invited; regulations align with the Convention p. 51 · CoE list |
| Barbados | In place Computer Misuse Act; Cybercrime Bill 2024 introduced p. 54 | In place Data Protection Act 2019, in operation since 31 March 2021 (registration provisions not yet proclaimed) † Bartlett Morgan, Mar 2021 | In progress National cybersecurity strategy in development p. 54 | In place CIRT-BB (national CSIRT directory) pp. 183–184 | None reported Not a Party or invited to accede CoE list |
| Belize | In place Cybercrime Act 2020 p. 59 | In place Data Protection Act, November 2021 p. 59 | In place First strategy in place; second in development with the OAS since 2024 p. 58 | None reported No national CERT/CIRT p. 58 | None reported |
| Dominica | None reported No cybercrime law among those the report lists; legal framework “in a developmental stage” p. 85 | None reported No data protection law among those the report lists p. 85 | Not stated | In progress CIRT establishment plan workshop with CARICOM IMPACS p. 85 | None reported Not a Party or invited to accede CoE list |
| Dominican Republic | In place Law 53-07 on high-tech crimes p. 90 | In place Law 172-13 on data protection p. 90 | In place Second strategy, Decree 313-22, running to 2030 p. 89 | In place CSIRT-RD (national CSIRT directory) pp. 183–184 | In place |
| Grenada | In place Electronic Crimes Act 2013, amended 2014 p. 104 | In place Data Protection Act (No. 1 of 2023) p. 104 | None reported No national strategy yet p. 104 | In place National CSIRT in place p. 104 | In place Party, acceded 22 April 2024 Council of Europe |
| Haiti | None reported No comprehensive law reported p. 116 | None reported No comprehensive law reported p. 116 | None reported No comprehensive national strategy p. 116 | In progress None yet; planned under an IDB project p. 116 | None reported Not a Party or invited to accede CoE list |
| Jamaica | In place Cybercrimes Act 2015 p. 124 | In place Data Protection Act 2020 p. 124 | In progress New strategy not yet published; implementation under way p. 124 | In place JaCIRT, under the Ministry of Science, Energy, Telecommunications and Transport p. 124 | None reported Not a Party or invited to accede CoE list |
| St Kitts and Nevis | In place Electronic Crimes Act No. 27 p. 148 | In progress | None reported No national cybersecurity strategy described; the report cites the National ICT Strategic Plan p. 147 | In progress National CIRT assessment under way p. 147 | None reported Not a Party or invited to accede CoE list |
| Saint Lucia | In place Computer Misuse Act 2018 p. 151 | In place Data Protection Act (Cap. 8.18), partially in force since January 2023 † Bartlett Morgan, Mar 2023 | None reported The report says it lacks a comprehensive national cybersecurity strategy p. 151 | In progress Working to establish a national CERT; no operational team yet p. 151 | None reported Not a Party or invited to accede CoE list |
| St Vincent and the Grenadines | In place Cybercrime Act, August 2016 p. 155 | Not stated | None reported No national cybersecurity framework p. 155 | In progress No designated CSIRT; establishment plan workshop in 2025 p. 155 | None reported Not a Party or invited to accede CoE list |
| Suriname | In progress Defined in the Criminal Code 2025; dedicated legislation in draft p. 160 | In progress Draft legislation under review p. 160 | In progress Draft national strategy in development; National Digital Strategy 2023–2030 includes cybersecurity p. 159 | In place SURCSIRT p. 159 | None reported Not a Party or invited to accede CoE list |
| Trinidad and Tobago | In place Computer Misuse Act 2000; Cybercrime Bill 2017 under consideration p. 164 | In place | In place 2012 strategy, not overhauled p. 164 | In place TT-CSIRT, established 2015 p. 164 | In progress Invited to accede to the Convention CoE list |
How to read this. Entries come from the country chapters of the OAS–IDB 2025 Cybersecurity Report, with page numbers. Where a later or fuller source differs from the report, the entry cites that source instead, and a Budapest Convention entry is checked against the Council of Europe’s list. Guyana’s laws also link to the Parliament of Guyana. † marks a secondary source. “Not stated” means the report does not say, not that the item does not exist. Laws change, so check the source. Updated 2026-10-03.
Budapest Convention context
Grenada deposited its instrument of accession to the Budapest Convention on 22 April 2024, and the Council of Europe said this may set an example for other Caribbean countries (Council of Europe). For the current list of parties, start from the Council of Europe’s page on the Convention, which links to the Treaty Office. As of the Council of Europe’s list of Parties and invitees (checked 3 October 2026), the Dominican Republic and Grenada are Parties, Antigua and Barbuda and Trinidad and Tobago are invited to accede, and none of the other countries in this tracker appears. Countries that align their laws with the Convention without acceding, such as the Bahamas and Belize, are shown separately from those invited.