Data Protection Act, 2020 | Version 1.6 | June 2026
The Auditor General’s Department (hereinafter referred to as “AuGD” or “the Department”) is Jamaica’s Supreme Audit Institution, established under the Constitution of Jamaica and the Financial Administration and Audit (FAA) Act. The AuGD conducts independent audits of all Ministries, Departments, Agencies, Local Authorities, and Statutory Bodies of the Government of Jamaica and reports its findings to the Houses of Parliament.
The AuGD is committed to responsible stewardship of personal information and to full compliance with the Data Protection Act, 2020 (“the Act” or “DPA 2020”). This Privacy Notice explains how the AuGD collects, uses, stores, shares, and protects personal data in the course of fulfilling its statutory mandate and managing its internal operations. It applies to personal information provided directly to the AuGD, collected in the conduct of audit and oversight functions, and obtained from other lawful sources.
This Notice does not apply to third-party websites linked to or referenced in AuGD publications. Readers are encouraged to review those sites’ privacy notices independently.
This Notice is published at www.auditorgeneral.gov.jm and will be updated as legislation, operations, or regulatory guidance changes.
The Auditor General’s Department is required to maintain registration as a data controller under Part III of the Data Protection Act, 2020. The AuGD will maintain current registration particulars with the Office of the Information Commissioner as required by sections 15 and 16 of the Act.
A. What Is Personal Data?
Under the Data Protection Act, 2020, “personal data” means any information relating to an identified or identifiable living individual, or an individual who has been deceased for fewer than thirty (30) years. This includes any expression of opinion about an individual and any indication of the intentions of the data controller in respect of that individual.
“Sensitive personal data” is subject to heightened protection and includes data relating to: genetic or biometric data (including fingerprints, facial images, iris scans); racial or ethnic origin; political opinions; philosophical, religious, or similar beliefs; trade union membership; physical or mental health or condition; sex life; and any alleged offences or criminal proceedings involving the data subject.
B. What Personal Data Does AuGD Collect?
The AuGD collects personal data across two broad operational contexts:
(i) Audit and Oversight Functions
In discharging its statutory mandate, the AuGD may collect personal data when conducting financial audits, performance audits, compliance audits, and special investigations of public entities. Data collected in this context may include:
Identity and contact details of public officials and employees of audited entities (names, job titles, work addresses, email addresses, and telephone numbers)
Financial and procurement records that identify or are attributable to named individuals, including authorisation trails, payment records, and contract documentation
Personnel-related information in audited entities, including payroll records, HR files, and disciplinary decisions, accessed under statutory audit authority
Interview notes, witness accounts, and correspondence obtained during audit fieldwork
Information provided by complainants, persons making disclosures under the Protected Disclosures Act, 2011, or third parties in connection with audit investigations
Data obtained from Government of Jamaica (GoJ) platforms accessed in the course of audit work, including GFMS, MyHR+, PEPAS, and GOJEP
Management responses to draft audit findings submitted by officers of audited entities, which may contain personal data about named individuals
(ii) Internal Operations
In managing its human resources, procurement, and corporate functions, the AuGD collects personal data including:
Staff and applicant data: names, contact details, identification documents, employment history, academic qualifications, bank account details for payroll, performance evaluations, and disciplinary records
Vendor and contractor data: names, business registration details, contact persons, Tax Registration Numbers (TRN), and bank account details for payment
Visitor data: names, contact details, identification documents, and CCTV footage captured at AuGD premises
Website and digital interaction data: IP addresses, browser types, device identifiers, and interaction logs for users of AuGD digital services, including persons who subscribe to AuGD website updates (email address and notification preferences). The AuGD website may use cookies and web analytics tools (such as session or functional cookies) to support the operation of the site. Where such technologies are used, information will be provided at the point of collection through a cookie notice on the website. Users may manage cookie preferences through their browser settings.
Sensitive personal data: where required by law or with your express consent, including health information for occupational purposes or security vetting for specific roles
C. How Does AuGD Obtain Your Personal Data?
Direct Collection
The AuGD collects personal data directly from individuals through:
Completion of employment, vendor, accreditation, or service request forms
Correspondence by email, letter, telephone, or in-person interaction
Participation in interviews, surveys, consultations, or audit fieldwork enquiries
Submission of audit evidence, representations, or management responses by officers of audited entities
Complaints and disclosures submitted through the AuGD’s “Tell Us” channels, including those made under the Protected Disclosures Act, 2011
Information provided by members of the public in response to the AuGD’s “Audits in Progress” public listing, which invites citizens and whistleblowers to contribute information relevant to active audits
Subscription to AuGD website notifications
Indirect Collection
The AuGD may also receive personal data indirectly through:
Records and documents obtained from audited entities in the exercise of statutory audit access rights under the FAA Act
GoJ shared platforms and databases accessed in the course of audit work
Closed-circuit television (CCTV) surveillance systems at AuGD offices
Publicly available sources, including company registries, the National Land Agency, and published government reports
D. Legal Bases for Processing Personal Data
The AuGD processes personal data only where at least one of the conditions for lawful processing set out in section 23(1) of the Data Protection Act, 2020 is satisfied. Where sensitive personal data is processed, at least one of the additional conditions in section 24(1) must also be met.
The conditions under section 23(1) most relevant to the AuGD’s processing activities are:
s.23(1)(a) — Consent: The data subject has given informed, specific, unequivocal, and freely given consent to the processing and has not withdrawn it.
s.23(1)(b) — Contract: Processing is necessary for the performance of a contract to which the data subject is a party, or for steps taken at the data subject’s request with a view to entering into a contract. Applied to employment, service, and vendor relationships.
s.23(1)(c) — Legal Obligation: Processing is necessary for compliance with a legal obligation to which the AuGD is subject, other than an obligation imposed by contract. Applied to obligations under the FAA Act, the Corruption (Prevention) Act, the Public Bodies Management and Accountability Act, and related legislation.
s.23(1)(e) — Exercise of Public Functions: Processing is necessary for the administration of justice, for the exercise of functions conferred by or under any enactment, or for the exercise of other functions of a public nature carried out in the public interest. This is the primary condition underpinning all audit-related processing, including the collection of evidence during fieldwork and the publication and dissemination of audit reports.
s.23(1)(f) — Legitimate Interests: Processing is necessary for the purposes of the legitimate interests pursued by the AuGD or by any third party to whom personal data are disclosed, except where the processing is unwarranted in any particular case by reason of prejudice to the rights and freedoms or legitimate interests of the data subject (section 23(1)(f) DPA 2020). Applied to the AuGD’s operational security, asset protection, and ICT management functions.
For sensitive personal data, the AuGD relies principally on the conditions at section 24(1)(b) (legal obligations in connection with employment or social security), section 24(1)(f) (processing necessary for legal proceedings or establishing legal rights), and section 24(1)(g) (exercise of functions conferred by enactment).
E. How Does AuGD Use Your Personal Data?
The AuGD uses personal data for the following purposes:
Conducting financial, performance, compliance, and special audits of public entities in accordance with its statutory mandate and in conformity with International Standards of Supreme Audit Institutions (ISSAI)
Preparing, drafting, and issuing audit reports — a process which includes sending draft findings to audited entities for management responses prior to publication
Publishing and disseminating completed audit reports on the AuGD website and to Parliament, the Public Accounts Committee, the media, and the general public, in fulfilment of the AuGD’s constitutional reporting mandate. Published reports may identify named public officials and contain personal data relating to the exercise of their public functions
Listing audits in progress on the AuGD website and soliciting public input to assist active audit investigations
Investigating complaints, protected disclosures, fraud allegations, or irregularities referred to the AuGD
Recruiting, managing, and developing staff, including payroll administration and occupational health management
Managing contracts, procurement processes, and vendor relationships in compliance with the Public Procurement Act, 2015
Maintaining physical and information security, including CCTV monitoring, access control, and cybersecurity operations
Sending website update notifications to subscribers who have consented
Responding to requests under the Access to Information Act, 2002, where applicable
Sharing audit findings, methodologies, or reports with international oversight bodies, peer Supreme Audit Institutions, and development partners as part of the AuGD’s international cooperation activities
Fulfilling any other legal, regulatory, or institutional obligation
The AuGD does not ordinarily make decisions producing legal or similarly significant effects on individuals based solely on automated processing of personal data. Where any automated decision-making that may significantly affect a data subject is considered, the AuGD will ensure compliance with section 12 of the DPA 2020.
F. Disclosure of Personal Data
The AuGD does not sell, trade, or rent personal data. Disclosure is limited to circumstances that are lawfully required or operationally necessary, including:
The Houses of Parliament and Parliamentary Committees, including the Public Accounts Committee, to whom audit reports are submitted prior to public release
The general public, through publication of completed audit reports on the AuGD’s public website (www.auditorgeneral.gov.jm). Published audit reports are accessible globally and may contain the names and professional details of public officials and officers of audited entities
The media, upon tabling of audit reports in Parliament, in accordance with the AuGD’s public communications mandate
The relevant Minister and the Ministry of Finance and the Public Service, where required by the FAA Act or related legislation
The Jamaica Constabulary Force, the Major Organised Crime and Anti-Corruption Agency (MOCA), the Director of Public Prosecutions, or other law enforcement and regulatory authorities, where disclosure is required by law or ordered by a court
The Office of the Information Commissioner (OIC), in connection with data protection supervision, investigations, or complaints
International oversight bodies, peer Supreme Audit Institutions, INTOSAI, and development partners, where audit reports or methodologies are shared as part of the AuGD’s international cooperation activities
Third-party service providers engaged by the AuGD under data processing agreements, who assist in delivering ICT, archiving, or administrative services, subject to appropriate contractual protections and due diligence
External oversight bodies conducting reviews of the AuGD’s own operations
Where disclosure involves cross-border transfer of personal data, the AuGD will comply with section 31 of the DPA 2020. Transfers will be made only where the recipient jurisdiction provides an adequate level of protection in accordance with section 31(2) of the DPA 2020, having regard to the factors specified in that section, or where one of the permissible transfer conditions in section 31(4) is satisfied. Where adequacy is uncertain, the AuGD will seek a determination by the Commissioner under section 31(7) before proceeding.
G. How Does AuGD Store and Protect Your Data?
The AuGD employs technical and organisational security measures proportionate to the nature of the personal data held, including:
Access controls and role-based permissions on information systems
Encryption of data in transit and at rest across key platforms
Endpoint detection and response (EDR) capabilities on workstations
Network security controls, including next-generation firewall and intrusion prevention systems
Regular security patch management and vulnerability remediation programmes
Off-site and cloud-based data backup and disaster recovery arrangements
Information security policies, staff training, and awareness programmes aligned to the AuGD’s Information Security Management System
Secure physical storage and controlled access to paper records, managed by the Records and Information Management Unit
Physical security measures, including CCTV, access control, and secure storage for physical records, are maintained at all AuGD premises.
The AuGD periodically reviews and tests its technical and organisational security measures to ensure they remain effective, in accordance with the seventh data protection standard at section 30(6)(d) of the DPA 2020. Where a new or significantly changed processing activity may pose elevated risk, these safeguards are informed by Data Protection Impact Assessments as described in Section K of this Notice.
In the event of a personal data breach, the AuGD will act in accordance with its obligations under sections 21(3)(b) and 21(5) of the DPA 2020, including: reporting the breach to the Office of the Information Commissioner within the period prescribed by the Data Protection Act, 2020 (s.21(3)(b)); notifying affected data subjects of the nature of the breach and the measures being taken (s.21(5)); and providing such further information to any data subject as the Commissioner may direct (s.21(6)).
H. How Long Does AuGD Retain Your Personal Data?
Personal data will not be retained longer than is necessary for the purpose for which it was collected. The following retention principles apply:
Audit working papers and records are retained in accordance with the retention schedules established under the FAA Act and the AuGD’s Records and Information Management System (RIMS) manual. Statutory FAA Act retention obligations take precedence over DPA 2020 disposal rights in respect of audit working papers.
Published audit reports are permanent public records tabled in Parliament and are not subject to time-limited retention or deletion.
Employee records are retained for the duration of employment and for such further period as required by applicable employment legislation and the National Insurance Act.
Procurement and vendor records are retained in accordance with the Public Procurement Act, 2015, GoJ financial instructions, and the AuGD’s retention schedule.
CCTV footage is ordinarily retained for a maximum of thirty (30) days unless required for an ongoing investigation or legal proceedings.
Website subscription data is retained for as long as the subscription is active. Subscribers may unsubscribe at any time.
Personal data processed for other purposes will be disposed of securely once no longer required, in accordance with the AuGD’s data retention and disposal schedule.
I. Your Rights as a Data Subject
Subject to the provisions of the Data Protection Act, 2020, you have the following rights in respect of your personal data held by the AuGD:
Right to be Informed (s.22 DPA 2020): The first data protection standard requires the AuGD to provide you with information about how your personal data is processed. This Privacy Notice is the primary means by which the AuGD discharges that obligation, and is published at www.auditorgeneral.gov.jm.
Right of Access (s.6 DPA 2020): You may submit a Data Subject Access Request (DSAR) to receive a copy of the personal data the AuGD holds about you and a description of the purposes for which it is processed. The AuGD will respond within thirty (30) days. Where technically feasible and on payment of the prescribed fee, you may also request that your personal data be transmitted in a structured, commonly used, and machine-readable format to another data controller you specify (s.6(2)(c)(ii)).
Right to Rectification (s.13 DPA 2020): You may request that the AuGD rectify any inaccuracy in personal data it holds about you. Under section 13, ‘rectify’ means amend, block, erase, or destroy the data to the extent required to correct an inaccuracy. Note: (a) this right does not confer a general right to have accurate personal data deleted because you no longer wish it to be held; and (b) it may be limited or restricted in relation to personal data in audit reports formally tabled in Parliament, where exemptions under Part V of the DPA 2020 or parliamentary privilege under section 40 apply, which are parliamentary records that the AuGD cannot unilaterally alter. Concerns about the accuracy of published findings should be raised through the management response process before publication.
Right to Prevent Processing (s.11 DPA 2020): You may require the AuGD to cease, or not to begin, processing your personal data on any of the following grounds: (a) the processing is causing or is likely to cause substantial and unwarranted damage or distress to you or another person; (b) the personal data is incomplete or irrelevant having regard to the purpose of the processing; (c) the processing is prohibited under any law; or (d) the personal data has been retained beyond the period permitted by law. This right does not apply where the processing falls within the conditions in section 23(1) of the DPA 2020, including processing necessary for compliance with a legal obligation or for the exercise of official authority. Where processing is carried out in exercise of functions conferred by the FAA Act or other enactments, or falls within the statutory functions exemption under section 34 or 35 of the DPA 2020, this right may be limited or may not be available in full.
Rights in Relation to Automated Decision-Taking (s.12 DPA 2020): You may require the AuGD to ensure that no decision which significantly affects you is based solely on automated processing of your personal data for the purpose of evaluating matters relating to you (such as performance, creditworthiness, reliability, or conduct). Where such a decision has already been taken, you are entitled to be informed and may require the AuGD to reconsider the decision or make a new decision on a non-automated basis. Note: the AuGD does not ordinarily make decisions producing legal or similarly significant effects on individuals based solely on automated processing of personal data.
Right to Withdraw Consent (s.9 DPA 2020): Where processing is based on your consent, you may withdraw that consent at any time in the same manner in which it was given, without affecting the lawfulness of processing carried out before withdrawal.
If you believe the AuGD has failed to comply with any of your rights under the Data Protection Act, 2020, you may submit a complaint to the Office of the Information Commissioner (OIC), which has authority under the Act to investigate complaints and order compliance. Contact details for the OIC are provided in Section L below.
To exercise any of the rights set out above, please submit a written request to the Data Protection Officer or the Data Protection Leader using the contact details in Section L below. The AuGD will respond within the applicable statutory timeframe (which varies by right: thirty days for access and rectification requests under sections 6 and 13; twenty-one days for notices under section 11).
J. Personal Data in Published Audit Reports
This section specifically addresses the processing of personal data in the context of the AuGD’s audit report publication and dissemination activities, which is the most significant category of data processing carried out by the AuGD.
What personal data may appear in published audit reports
Completed audit reports published by the AuGD may contain personal data relating to public officials and officers of audited entities, including:
Names and job titles of public officials in connection with their exercise of public functions (e.g., authorisation of expenditure, contract approvals, or management decisions)
Details of financial transactions, procurement decisions, or operational failures attributed to named or identifiable individuals
Findings relating to disciplinary matters, non-compliance, or irregularities in the conduct of public duties
In certain performance audits (e.g., audits of social benefit programmes), anonymised or aggregated data relating to programme beneficiaries. Where sensitive personal data is involved, the AuGD will apply appropriate anonymisation or redaction measures before publication
Legal basis for publishing personal data in audit reports
The AuGD’s authority to publish personal data in audit reports derives from its constitutional mandate and statutory obligations under the FAA Act. The applicable condition for lawful processing is section 23(1)(e) of the Data Protection Act, 2020 (exercise of functions conferred by or under an enactment and other functions of a public nature carried out in the public interest). The publication of audit findings is a necessary and proportionate exercise of the AuGD’s public oversight role in the interest of accountability, transparency, and sound public financial management.
The draft report and management response process
Before any audit report is finalised and submitted to Parliament, the AuGD follows a structured process that affords affected parties an opportunity to respond:
Draft findings are communicated to the management of the audited entity for review and comment
Management responses received are considered by the AuGD and, where appropriate, incorporated into or appended to the final report
This process represents the primary mechanism through which persons whose personal data may appear in a published report may raise concerns about factual accuracy before publication
The management response process does not constitute a waiver of the AuGD’s authority to publish findings. It is the appropriate channel for contesting the accuracy of audit findings prior to publication. Requests to exercise DPA rectification rights in relation to draft or published reports must be assessed against the AuGD’s statutory obligations and will generally be addressed through this process.
Notification of individuals named in audit reports
Where personal data is collected indirectly (such as from records held by an audited entity), the DPA 2020 ordinarily requires the data controller to notify affected data subjects. In the context of the AuGD’s audit functions, this obligation is modified as follows:
Public officials of audited entities are generally notified of audit findings through the formal management response process described above
Where notification would prejudice an ongoing investigation, compromise the integrity of the audit process, or prevent the AuGD from fulfilling its statutory mandate, the AuGD may defer or disapply notification obligations in accordance with applicable exemptions under the DPA 2020
Publication of the audit report on the AuGD website and tabling in Parliament serves as general notice that audit findings are in the public domain
Anonymisation and redaction
The AuGD applies anonymisation or redaction in published reports where:
Individuals are beneficiaries of social welfare, health, or other programmes, and their personal identity is not relevant to the audit findings
Publication of identifying details would involve sensitive personal data categories and is not necessary to the public interest purpose of the report
Operational security, witness protection, or other overriding considerations require it
Where anonymisation is applied, it is designed to ensure that the anonymised individual cannot be re-identified from the information remaining in the published report.
Limitations of data subject rights in relation to published reports
As noted in Section I, data subject rights may be limited or restricted in relation to personal data contained in audit reports tabled in Parliament or published on the AuGD website, by virtue of the exemptions in Part V of the DPA 2020 and other applicable legislation. In particular, these reports are:
Created in exercise of the AuGD’s constitutional and statutory mandate
Parliamentary documents once tabled, and subject to parliamentary privilege
Permanent public records not subject to unilateral alteration by the AuGD
Potentially subject to public access under the Access to Information Act, 2002, independent of DPA rights
Downstream processing by third parties
Once published, audit reports are accessible to any member of the public, the media, academic researchers, Parliament, and international bodies. The AuGD has no control over the further processing of personal data by those parties and is not responsible for such downstream use. Individuals who have concerns about the use of their personal data by third parties in the context of published audit reports should direct those concerns to the relevant third party.
K. Data Protection Impact Assessments
The AuGD conducts Data Protection Impact Assessments (DPIAs) for any new or significantly changed processing activity that may pose a high risk to the rights of data subjects. This includes new audit methodologies involving large-scale processing of personal data or the use of new analytical tools. DPIAs are coordinated by the Data Protection Leader, in consultation with the Data Protection Officer, and where appropriate, the Executive Management Committee. The outcome of each DPIA is documented and informs the design and implementation of data protection safeguards.
L. How to Contact the AuGD
Questions, requests, or complaints regarding this Privacy Notice or the AuGD’s data protection practices should be directed to:
Data Protection Officer
Auditor General’s Department
40 Knutsford Boulevard, P.O. Box 455, Kingston 10, Jamaica W.I.
Telephone: (876) 926-8309 / 926-5963 / 926-5846
Fax: (876) 968-4690
Email: [email protected]
Website: www.auditorgeneral.gov.jm
Note: The Data Protection Leader is the first operational point of contact for day-to-day data protection enquiries and Data Subject Access Requests. Formal complaints and statutory matters are directed to the Data Protection Officer.
Office of the Information Commissioner (OIC)
If you are dissatisfied with the AuGD’s handling of your personal data, you may lodge a complaint with the OIC:
Website: www.oic.gov.jm | Email: [email protected]
Address: 3rd Floor, Harbour View Plaza, Kingston 10, Jamaica
M. Changes to This Privacy Notice
The AuGD reserves the right to amend this Privacy Notice in response to changes in legislation, operational practice, or regulatory guidance. Material changes will be communicated through the AuGD website. The date of the most recent revision is indicated in the document footer.
This Privacy Notice was last updated June 2026
Reference: AuGD/DPO/PN-001 | Version 1.6 | Classification: PUBLIC
To be read in conjunction with: AuGD Data Protection Policy | Information Security Policy | Incident Management Policy | RIMS Manual
Version: 1.6 |
Classification: PUBLIC
This Privacy Notice was last updated June 2026.
LinkedIn
Twitter
Youtube