Trend · 2 September 2025

Why Jamaican MSMEs keep stalling on data protection

The JBDC has pushed MSMEs towards Data Protection Act compliance. Small firms aren't resisting the rules — they're stuck on cost, ownership and paperwork.

The Jamaica Business Development Corporation has repeatedly urged micro, small and medium enterprises to become compliant with the Data Protection Act. The message has landed; the execution has not. Three obstacles come up in almost every MSME conversation.

First, ownership. The Act expects a Data Protection Officer, and in a twelve-person company that role lands on whoever is least able to refuse it. Outsourced DPO retainers exist precisely for this, and for most small Jamaican firms they cost less than the internal time they replace.

Second, evidence. Compliance is not a state of mind, it is a folder: a processing register, consent records, a breach log, signed processor agreements and dated training records. Most MSMEs already do the right things and can prove none of it.

Third, price anchoring. Business owners hear 'compliance consultant' and assume Big Four fees. Local specialists routinely deliver MSME readiness for a fraction of that, and the gap between the two markets is the single most useful thing a buyer can understand before requesting quotes.

Firms mentioned

Sources