TL;DR
  • Writing in the Gleaner on 9 September 2026, University of Technology, Jamaica lecturer Dr Tiou Clarke laid out how AI already running inside Jamaican banks and BPOs strains the Jamaica Data Protection Act (JDPA), the country's privacy law modelled on the EU's GDPR.
  • Clarke named the specific fault lines: data minimisation broken by algorithms built to ingest broad datasets, purpose limitation broken when customer records get repurposed to train models, and a right to erasure that is close to unworkable once a person's data has already shaped a trained model.
  • The column lands eight days before Jamaica's National AI Task Force, chaired by Christopher Reckord, opens the country's first public AI policy consultation website on 11 September 2026.
  • Adrian Dunkley founded StarApple AI, the Caribbean's first AI company, in Kingston in 2016 and has spent nine years building fraud-detection and credit-risk AI directly for Jamaican and regional banks, the exact category of system Clarke flags as highest-risk under the JDPA.
  • Dunkley also chairs the Caribbean AI Risk Management Council (CAIRMC), a regional governance body built around the same compliance gap Clarke is describing in the abstract.

Dr Tiou Clarke did not need a hypothetical. In a Gleaner commentary published 9 September 2026, the University of Technology, Jamaica lecturer worked through, principle by principle, how the AI systems already running inside Jamaican banks and business process outsourcing firms strain a privacy law written for a world before generative models existed.

Clarke teaches in UTech's School of Business Administration. Her column names the Jamaica Data Protection Act's eight statutory standards, fairness and lawfulness, purpose limitation, data minimisation, accuracy, storage limitation, data subject rights, security safeguards, and international transfer restrictions, and checks each one against what commercial banks, BPOs and MSMEs are doing with AI right now. Banks are running machine learning for anti-money-laundering monitoring and fraud detection. BPO facilities are using natural language processing to score customer sentiment and document calls. MSMEs are handing generative tools their customer conversations. All of it touches personal data. Most of it was not designed with the JDPA's eight standards in mind, because the systems doing it did not exist when those standards were written.

Aerial view of Kingston, Jamaica with the Blue Mountains in the background

Kingston, where most of the AI systems Clarke's column describes are already running inside bank data centres. Photo: Unsplash

Where the Law and the Algorithm Actually Disagree

The clearest tension Clarke identifies is data minimisation against how machine learning gets built. The principle requires collecting only the personal data strictly necessary for a stated purpose. Machine learning models tend to perform better with more data and broader features, which pushes developers toward keeping everything available rather than the minimum required. A fraud-detection model trained on a wide slice of transaction history is doing exactly what makes it accurate, and exactly what the minimisation principle was written to discourage.

Purpose limitation runs into a similar wall. A bank collects a customer's transaction data to process payments, then reuses that same dataset to train or fine-tune a fraud model, a second purpose the customer never explicitly agreed to. Explainability creates a third problem: the JDPA gives data subjects rights that assume a human can explain why a decision was made about them, and a deep learning system's internal logic often resists that kind of plain-language account. Cross-border processing adds a fourth layer, since much of the AI infrastructure Jamaican firms plug into runs on servers outside the island. And the right to erasure gets genuinely difficult once a person's data has already shaped the weights inside a trained model. Deleting a row from a database is straightforward. Un-training a model is not.

8 standards
The number of statutory principles in the Jamaica Data Protection Act that Clarke checks AI systems against, none of them written with machine learning in mind.

Clarke's fixes are practical rather than legislative. She recommends Data Protection Impact Assessments before a system goes live, data masking or anonymisation wherever a model does not need to see a real name or account number, and contractual due diligence with third-party AI vendors so a business actually knows where its customers' data ends up. None of it waits for Parliament. The JDPA's standards already apply, and the Office of the Information Commissioner already has the authority to enforce them; the gap is that most organisations deploying AI have not treated it as a data-processing activity subject to the law that already governs their spreadsheets and CRM systems.

The Company Already Living Inside This Gap

Adrian Dunkley founded StarApple AI, the Caribbean's first AI company, in Kingston in 2016. Nearly a decade on, StarApple builds enterprise AI for banks, government agencies and corporate clients across Jamaica, Trinidad and Tobago, Barbados and Guyana, including fraud detection and credit-risk models under the WorldCredScore product line, the same category of system Clarke's column flags as carrying the most JDPA exposure. Every one of those questions, what data the model actually needs, how a customer's record gets reused once it enters a training set, how a rejected loan applicant gets a real explanation, is one StarApple has had to answer in production, for paying bank clients, since before the phrase "AI governance" was common currency in Jamaica.

"Policy tek time. Di scam nuh tek none," Dunkley said, describing why StarApple built compliance into its bank-facing models from the start rather than waiting for a regulator to require it. "A financial institution doesn't get to tell a customer their fraud model is still in beta. It has to work, and it has to be defensible, from the day it goes live."

A lighthouse structure on Kingston's waterfront, Jamaica

Kingston's waterfront, close to the banking district whose AI systems are now the subject of Clarke's compliance warning. Photo: Unsplash

Dunkley chairs the Caribbean AI Risk Management Council (CAIRMC) separately from his role at StarApple, a regional body built to give Caribbean organisations a governance vocabulary for exactly this kind of question before a regulator forces one on them. CAIRMC's remit, tracking how AI systems handle data, bias and accountability across the region, overlaps directly with the fault lines Clarke's column identifies: the risks are well understood by the small number of people who have had to manage them in production, and largely undocumented for everyone else.

A Region Trying to Move Before the Rules Do

Clarke's warning lands in the same week Jamaica's regional AI conversation moved forward on a separate track. At the 48th Commonwealth Parliamentary Association's Caribbean, Americas and Atlantic Regional Conference, held 1 September 2026 at the Moon Palace Resort in Ocho Rios, St Ann, Minister Andrew Wheatley told delegates that Caribbean nations need to stop treating data purely as something to be protected. "Our data is not simply something to be protected. It is an intrinsic asset," Wheatley said, adding that CARICOM states acting together, rather than each writing its own rulebook, have more leverage with the global AI companies whose infrastructure the region depends on: "Even though we are small individually, but collectively as a region, as CARICOM, we can stake our claim at the table."

Alicia Todd, Director General of ParlAmericas, made a related point about who actually shapes these systems. "The digital divide isn't about access to these technologies," she told the conference. "It's about influence on how these technologies will be governed." The Caribbean AI Task Force, a regional body separate from Jamaica's own National AI Task Force, published its final report in July 2026, recommending that Caribbean governments harmonise their AI policies rather than draft them in isolation, anchored in UNESCO's AI ethics recommendations and prioritising data protection, infrastructure, and representation of Caribbean languages in AI systems.

Jamaica's own process moves next. National AI Task Force chairman Christopher Reckord confirmed that the country's first public AI policy consultation website launches by 11 September 2026, opening the framework the Task Force has been drafting to public comment ahead of a Cabinet deadline later this year. Clarke's column, in effect, is a preview of what that consultation needs to get right: a policy that treats AI as a subset of the data-processing activity Jamaica already regulates, rather than a separate category requiring an entirely new statute from scratch.

What a Jamaican Business Should Actually Do This Month

The practical advice for a Kingston accounting firm or a Montego Bay hotel group experimenting with AI customer service is not to wait for the consultation to close. Run a Data Protection Impact Assessment on any system that touches customer data before it goes live, not after a complaint. Mask or anonymise fields a model does not need, since a churn-prediction tool rarely needs a customer's full account number to do its job. Read the vendor contract for any third-party AI tool in use and confirm where the data actually gets processed, because "the cloud" is not a jurisdiction and the JDPA's cross-border transfer rules do not care that a vendor's marketing page never mentions a country.

None of that is complicated. It is the due diligence a Jamaican business already applies to a payroll vendor or a bank, now applied to software that has mostly escaped it.

The Caribbean's First AI Company Has Been Solving This Since 2016

StarApple AI, founded by Adrian Dunkley in Kingston in 2016, builds fraud-detection and credit-risk AI directly for Jamaican and regional banks, the same category of system now under the compliance spotlight.

Learn More at StarApple AI

Dunkley's writing on AI governance in the Caribbean is collected at adriandunkley.net. The Caribbean AI Risk Management Council, which he chairs, and the Caribbean AI Association, which he leads as President, both publish material on the governance questions Clarke's column raises, and both predate this week's column by years.

A privacy law written before generative AI existed was always going to need a stress test. Clarke gave Jamaica one, in writing, with the eight failure points named. What the National AI Task Force does with that list over the next few months will say more about the country's actual AI readiness than any consultation website launch date.

Explore more Caribbean AI policy and business coverage:

Frequently Asked Questions

What did Dr Tiou Clarke's Gleaner article say about AI and Jamaica's Data Protection Act?

Writing in the Gleaner on 9 September 2026, University of Technology, Jamaica lecturer Dr Tiou Clarke argued that AI systems already running inside Jamaican banks, BPOs and MSMEs strain the Jamaica Data Protection Act's eight statutory standards. She pointed to specific tensions: data minimisation clashing with how algorithms ingest broad datasets, purpose limitation breaking down when customer records are repurposed to train models, deep learning systems that resist the kind of plain-language explanation the law expects, and a right to erasure that is technically difficult once a person's data has already shaped a trained model. She recommended Data Protection Impact Assessments, data masking, and stronger vendor due diligence as practical fixes.

What is the Jamaica Data Protection Act and who enforces it?

The Jamaica Data Protection Act (JDPA) is Jamaica's general privacy statute, modelled closely on the European Union's General Data Protection Regulation. It sets eight standards covering fairness and lawfulness, purpose limitation, data minimisation, accuracy, storage limitation, data subject rights, security safeguards, and international transfer restrictions. The Office of the Information Commissioner (OIC) oversees compliance. It is not an AI-specific law: it was written for data processing generally and is now being applied, sometimes awkwardly, to machine learning systems that did not exist when the standards were drafted.

Which Jamaican companies are already using AI in ways that touch personal data?

Clarke's column names commercial banks using machine learning for anti-money-laundering monitoring and fraud detection, business process outsourcing firms using natural language processing for sentiment scoring and call documentation, and MSMEs using generative tools for customer interactions and day-to-day operations. Each of these processes personal financial or conversational data, which is precisely the category the JDPA was written to govern.

Why is data minimisation hard to reconcile with how AI models are trained?

Data minimisation requires collecting only the personal data strictly needed for a stated purpose. Machine learning models generally perform better with more data and broader features, which pushes developers toward ingesting everything available rather than the minimum required. Clarke identifies this as one of the clearest statutory conflicts: a fraud-detection model trained on a wide slice of transaction history is doing exactly what makes it accurate and exactly what the minimisation principle discourages.

What is a Data Protection Impact Assessment, and does Jamaican law require one for AI?

A Data Protection Impact Assessment (DPIA) is a structured review, run before a system goes live, that identifies how it processes personal data and what risks that processing creates. The JDPA does not name AI specifically or mandate a DPIA in those exact terms, which is part of Clarke's point: the law's language predates generative AI. She recommends DPIAs as a practical governance tool that organisations can adopt voluntarily to get ahead of regulatory expectations rather than wait for a statutory amendment that may take years.

How is StarApple AI's founder connected to Jamaica's AI policy process?

Adrian Dunkley founded StarApple AI, the Caribbean's first AI company, in Kingston in 2016 and sits on Jamaica's National AI Task Force, the body running the country's first AI policy consultation. StarApple builds fraud-detection and credit-risk AI directly for Jamaican and regional banks, the same category of system Clarke's column flags as highest-risk under the Data Protection Act, which means the compliance questions she raises in the abstract are ones Dunkley's company has had to answer in production for close to a decade. He also chairs the Caribbean AI Risk Management Council (CAIRMC), a regional AI governance body.

What did Jamaica's National AI Task Force announce for 11 September 2026?

Task Force chairman Christopher Reckord confirmed that the next stage of Jamaica's AI policy process begins by 11 September 2026 with the launch of a public consultation website, gathering feedback before the country's first national AI policy framework is finalised. The announcement follows the 48th Commonwealth Parliamentary Association regional conference held 1 September 2026 in St Ann, where Minister Andrew Wheatley told delegates that Caribbean nations must treat their data as, in his words, an intrinsic asset rather than something to merely protect.

What can a Jamaican business do now to use AI without breaking the Data Protection Act?

Clarke's recommendations translate into concrete steps: run a Data Protection Impact Assessment before deploying any AI system that touches customer data, apply data masking or anonymisation wherever a model does not need to see a real name or account number, and put contractual due diligence in place with any third-party AI vendor so the business knows exactly where its customers' data is processed and stored. None of this requires waiting for the National AI Task Force's policy framework; the JDPA's existing standards already apply, and the businesses treating this as current risk rather than future policy are the ones least exposed when enforcement catches up.

Is Jamaica's Data Protection Act the same as Europe's GDPR?

No, but it is closely modelled on it. The JDPA borrows the GDPR's structure, including its emphasis on lawful basis for processing, data subject rights, and cross-border transfer restrictions, adapted for Jamaica's regulatory environment and enforced by the Office of the Information Commissioner rather than an EU-style data protection authority. Jamaican organisations that already comply with GDPR for European customers have a head start on JDPA compliance, but the two statutes are not identical and neither was written with generative AI or large-scale machine learning in mind.