Skip to main content

Privacy

Privacy

Privacy Mission Statement

To integrate privacy practices into all aspects of our planning and environmental management efforts, to achieve sustainability in Jamaica’s natural and built environment.

 

Privacy Vision Statement

To create a sustainable future where Jamaicans can confidently share their data, knowing it is protected, while enhancing the natural and built environment for the benefit of current and future generations.

Policies

PRIVACY POLICY

National Environment and Planning Agency Privacy Policy

Policy Owner

National Environment and Planning Agency

Policy Approver(s)

Chief Executive Officer

Key Related Policies and Procedures

 

Created by

Privacy & Legal Management Consultants Limited

Storage Locations

 

Effective Date

 

Next Review Date

 

 

INTRODUCTION

The National Environment and Planning Agency (hereinafter “NEPA” or “the Agency”) is a Data Controller by virtue of the Data Protection Act, 2020 (the Act). Data Controllers have an obligation to Process Personal Data in accordance with the standards outlined in the Act. This Policy sets forth the core Principles governing the Processing of Personal Data by NEPA. This Policy is intended to ensure consistent practices are aligned with recognized local and international standards, for the processing of Personal Data by the Agency.

 

DEFINITIONS

Applicable Laws: means the Jamaica Data Protection Act, 2020 (JDPA), the Constitution, and any other related legislation and regulations governing the processing of personal data.

Data Controller: Any person or public authority, who, either alone or jointly or in common with other persons determines the purposes for which and the manner in which any Personal Data are, or are to be, Processed.

Data Processor: Any person, other than an employee of the Data Controller, who Processes the Personal Data on behalf of the Data Controller.

Data Subject: A named or otherwise identifiable individual who is the subject of Personal Data.

Personal Data: Information (however stored) relating to a living individual or an individual who has been deceased for less than thirty years, who can be identified from that information alone or from that information and other information in the possession of the Data Controller.

Processing (or “Process” or “Processes” or “Processed"): Any operation or set of operations, automated or not, which is performed on Personal Data, including but not limited to collection, storage, use, transmission, disclosure, or deletion.

Sensitive Personal Data: Personal Data consisting of any of the following information in respect of a Data Subject: genetic data or biometric data, filiation, or racial or ethnic origin, political opinions, philosophical beliefs, religious beliefs or other beliefs of a similar nature, membership in any trade union, physical or mental health or condition, sex life, the alleged commission of any offence by the Data Subject or any proceedings for any offence alleged to have been committed by the Data Subject.

 

PURPOSE

NEPA recognizes that as part of our operations we must collect and process personal data. The purpose of this policy is to describe how personal data must be collected, handled and stored to meet NEPA’s data protection standards, comply with governing privacy and data protection laws, and respect individual rights. The purpose of this policy is to:

  • Comply with the Data Protection Act, 2020 and follow best practices;
  • Protect the rights of employees, customers and any related data subjects as guaranteed by the Charter of Fundamental Rights and Freedoms; and
  • Ensure transparency around how NEPA collects, stores and processes individuals’ data.

 

SCOPE

This Data Protection Policy applies to all business processes, information systems and components, personnel, and physical areas of NEPA. This Policy applies to the collection, processing, storage, and handling of personal data and any other procedures related to personal data of any individual in both electronic and manual format.

Individuals or groups this policy applies to include, but are not limited to:

·        Executives and directors;

·        All employees, whether employed on a full-time or part-time basis, by NEPA;

·        All previous employees, whether employed on a full-time or part-time basis, by NEPA;

·        All job applicants of positions at NEPA;

·        All contractors, suppliers and other people including but not limited to agents and subcontractors working on behalf of NEPA;

·        All customers of NEPA; and

·        Any other data subjects identified through the regular course of business by NEPA.

 

OUR APPROACH TO HANDLING PERSONAL DATA

 

NEPA’s approach to handling personal data is aligned with the JDPA. In particular, NEPA:

a.     may collect your personal data where this is reasonably necessary for, or directly related to, one or more of its functions or activities;

b.     may collect your sensitive personal data where you consent, where the collection is authorised or required by law, or the collection is otherwise allowed under the JDPA;

c.      will only use and disclose your personal information for the purposes for which it was collected, or otherwise in accordance with the JDPA; and

d.     will notify you of the purpose that your personal data is being collected, either at the time of collection, or as soon as practicable afterwards.

 

INFORMATION COLLECTED FROM YOU

NEPA will collect personal information directly from you.

a.     NEPA and associated users or partners will collect personal data in a manner that is fully transparent with data subjects and in accordance with the law.

b.     Users will refrain from knowingly collecting the personal data of any data subject without authorization from a Direct Manager or Data Protection Officer.

c.      If personal data is collected from someone other than the data subject, the data subject will be informed of the collection unless one of the following criteria apply:

                           i.          The data subject has received the required information by other means.

                          ii.          The information must remain confidential due to a professional secrecy obligation.

                         iii.          A national law expressly provides for the collection, processing, or transfer of the personal data.

d.     When necessary, NEPA will obtain consent from data subjects in accordance with the Consent Policy and through the authorization of the Data Protection Officer.

e.     Consent from the data subject will be provided in writing.

f.       Consent obtained orally from a data subject will be reviewed by the Data Protection Officer.

DATA ACCURACY

NEPA will take reasonable measures to ensure that personal data remains accurate across the Agency.

All data users at NEPA will take reasonable steps to ensure personal data is kept as accurate and up to date as possible.

 

STORING YOUR PERSONAL DATA

NEPA will secure your personal data where it:

a.     physically possesses a record containing your personal information (including storage on servers owned and operated by the Department); or

b.     has the right or power to deal with the information, even if it does not physically possess it (such as where the personal information is stored on servers owned or operated by a third party, to which the Agency has access to, or in archived files).

The Agency holds personal information in a range of audio-visual such as CCTV Data, paper and electronic based records (including in cloud-based applications and services). The Agency complies with the GOJ ICT Policy for protecting departmental resources (including information) from harm or unauthorised access. Personal data is held in accordance with the collection and security requirements of the ISO 270001 Framework and NIST CSF, the department’s policies and procedures, and the JDPA.

If personal data held by us is lost, or subject to unauthorised access or disclosure, the Agency will respond in line with the JDPA and Data Protection (Data Controller) Regulations 2024.  

 

DATA RETENTION

Personal Data should be reviewed at least once annually, against the Records Retention Schedule. If no longer required, data should be disposed of. Refer to Records Retention Policy and Schedule for further detail.

 

DISCLOSURE TO THIRD-PARTIES

We may disclose your personal data to third parties, where this is permitted under the JDPA. Those third parties include the entities or persons identified on the List of Third Parties document., located on the NEPA Website.  

If NEPA discloses your personal data to a third party, it will take reasonable steps to ensure that the third party handles your personal data in the same manner as NEPA and in accordance with the JDPA. NEPA imposes privacy obligations on all contracting parties, including in its funding deeds, service contracts, data sharing arrangements and commercial agreements.

 

 

Cross Border Transfers

NEPA may disclose personal data to overseas recipients in limited circumstances, where this is reasonably necessary, or directly related to, our work. This may include, for example, disclosure to peer reviewers anywhere in the world where appropriate scientific expertise exists, or to a foreign government or agency.

If it is likely that your personal data will be disclosed to an overseas recipient, we will take reasonable steps to notify you, and we will only disclose the information as permitted under the JDPA to the overseas recipient. We will also take reasonable steps to ensure the overseas recipient treats your personal data in accordance with the applicable provisions under the JDPA, such as through our standard contractual clauses, Data Processing Agreements, binding corporate rules, where applicable.

PRIVACY RIGHTS AND CHOICE

Data Subjects have rights under the Act. These include:

Your Right to

What does this mean?

Be Informed

You have the right to know whether we process your personal data

Access

You have the right to request all Personal Data we have collected about you, if any

Data Portability

You have the right to request the transfer of your Personal Data in a commonly used machine-readable format to another data controller that determines the purposes and means for which Personal Data is processed

Consent

You have the right consent to the processing of your personal data. Where you have provided us with your consent, you also have the right to withdraw such consent at any time

Prevent Processing

You can tell us when you do not want your Personal data to be on our grounds for legitimate interest, unless our reasons for undertaking that processing outweighs any prejudice to your data protection rights

Automated Decision Making

You have the right to ensure that no decision having significant impact on you, the data subject, is made solely by automated means

Rectification

You have the right to change any errors or omissions in the Personal Data we have collected about you

 

ACCOUNTABILITY AND REVIEW

This Privacy Policy is reviewed and updated annually. Any updated version will be available on NEPA’s website. NEPA must develop mechanisms to:

a.     oversee compliance with this Policy; and

b.     provide individuals with a method, subject to reasonable limitations and conditions, to:

                           i.          request information regarding the individual’s Personal Data Processed by NEPA; and

                          ii.          seek redress if the individual reasonably believes that the individual’s Personal Data has been Processed in violation of this Policy.

 

EFFECTIVE DATE

This policy is effective as of September 2025.

 

RELATED DOCUMENTS

a. Data Subject Access Request Policy

b. Incident Response Policy

c.  IT and Acceptable Use Policy

d. IT Remote Access Policy

 

QUESTIONS ABOUT POLICY

Questions regarding this Policy should be addressed to the Data protection officer via email at Dataprotection@nepa.gov.jm.

History of Changes

Revision Date

Revision Number

Changes

Revised By

 

 

 

National Environment and Planning Agency

 

 

 

 

 

CONSENT MANAGEMENT POLICY |

National Environment and Planning Agency Consent Management Policy

 

Policy Owner

National Environment and Planning Agency

Policy Approver(s)

Chief Executive Officer

Key Related Policies and Procedures

Privacy Policy, [Consent Notice, Information Security Policy]

Created by:

Privacy & Legal Management Consultants Limited

Storage Location

 

Effective Date

 

Next Review Date

 

 

Purpose

This Policy establishes guidelines for obtaining, managing, and revoking consent for the processing of Personal Data. It aims to ensure the National Environment and Planning Agency’s (NEPA) compliance with applicable data protection laws, including the Data Protection Act, 2020 (JDPA), and incorporates best practices from privacy frameworks while upholding ethical data practices.

 

Scope

This Policy applies to all employees, temporary workers, and Data Processors that process Personal Data on behalf of NEPA.

 

Definitions

  • Personal Data: Any information relating to an identified or identifiable natural person.
  • Consent: Freely given, specific, informed, and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.
  • Contractors: a person or company contracted to perform services for or on behalf of NEPA, including interns or temporary staff.
  • Processing: Any operation performed on personal data, including collection, recording, storage, use, or deletion.
  • Data Subject: An individual whose personal data is processed by NEPA.
  • Sensitive Personal Data: Data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, health, biometric, or genetic data.
  • Explicit Consent: Consent given through a clear affirmative action, such as ticking a box or clicking a button.
  • Implicit Consent: Consent inferred from the data subject's behavior, such as continuing to use a website after being presented with a privacy notice.
  • Withdrawal of Consent: The right of a data subject to revoke previously given consent at any time.
  • Data Controller: NEPA, which determines the purposes and means of processing personal data.
  • Data Processor: A third party that processes personal data on behalf of NEPA.
  • Children: persons considered as minors in the context of the JDPA or the applicable age of consent in the relevant jurisdiction.

 

Policy Principles

NEPA adheres to the following principles to ensure that consent is obtained and managed ethically and transparently:

1.           Consent must be freely given, informed, specific, and unambiguous.

2.           The process of obtaining consent must be transparent, using clear and plain language.

3.           Consent must be recorded and documented to ensure traceability and auditability.

4.           Individuals must be able to withdraw consent easily and at any time.

5.           Consent will not be a precondition for providing services unless necessary for the processing involved.

 

Obtaining Consent

NEPA adheres strictly to the guidelines outlined in the Data Protection Act, 2020 and supporting regulations for obtaining consent. The following practices are required to ensure compliance:

  1. Transparency and Clarity:
    • Provide individuals with clear, concise, and easily understandable information about the purposes of processing their personal data.
    • Ensure that consent requests are separate from other terms and conditions and presented in a way that allows individuals to make an informed decision.
  2. Active and Explicit Agreement:
    • Consent must involve an affirmative action by the individual, such as ticking a box, signing a form, or providing verbal agreement that is recorded.
    • Silence, pre-ticked boxes, or inactivity do not constitute valid consent.
  3. Purpose-Specific Consent:
    • Obtain separate consents for different data processing purposes, ensuring that individuals can opt-in selectively for each purpose (e.g. public education and marketing).
  4. Accessibility:
    • Present consent requests in a manner that is accessible to all individuals, including those with disabilities or limited literacy, in compliance with accessibility standards.
  5. Right to Refuse or Withdraw:
    • Clearly inform individuals of their right to refuse consent without detriment and their ability to withdraw consent at any time.
    • Provide mechanisms for individuals to easily exercise these rights, such as an online form or a dedicated contact point.

 

Obtaining Consent from Minors

The right of consent of a minor is to be exercised by a parent or legal guardian of the minor or by the minor in any case where the law recognises the capacity of the minor to act in the matter to which the personal data relates.

NEPA will make reasonable efforts to verify in such cases that consent is given or authorised by the holder of parental responsibility over the minor.

 

Processing Special Categories of Data

NEPA complies with the requirements outlined in the Data Protection Act, 2020, and related regulations for processing special categories of data (e.g., health, biometric, or financial data). The following principles and documentation practices are strictly followed:

  1. Explicit Consent:
    • Special categories of data require explicit consent from the data subject. This consent must be obtained through a clear and affirmative action, such as a signed document or an electronically recorded agreement.
    • The request for consent must clearly specify why the sensitive data is being collected, how it will be used, and the duration of its storage.
  2. Purpose-Specific Agreement:
    • The purpose of processing must be stated explicitly and separately from general consent for other data types.
    • Separate consent forms or sections in a consent request are required for special categories of data.
  3. Records of Consent:
    • Maintain detailed records that document:
      • The identity of the data subject;
      • The nature and purpose of the special category data being processed;
      • The method of obtaining explicit consent (e.g., signed form, digital signature); and
      • The date and time consent was given.
    • Ensure that any privacy notices or explanatory materials provided to the data subject are also retained as part of the consent record.

 

  1. Minimization and Security:
    • Ensure that only the minimum necessary amount of sensitive data is processed and that it is protected by robust security measures, including encryption and access controls.

 

Documenting Consent

NEPA ensures compliance with the Data Protection Act, 2020, and related regulations by documenting consent in a manner that is traceable, auditable, and transparent. According to the regulations, the following practices are required for documenting consent:

  1. Record-Keeping Requirements:
    • Maintain records of the identity of the individual providing consent;
    • Include the date, time, and method by which consent was obtained (e.g., electronic form, verbal agreement recorded in writing); and
    • Specify the purposes for which consent was provided, ensuring that these are clear and aligned with the explanations given at the time of obtaining consent.
  2. Format of Documentation:
    • Use systems that ensure consent records are easily retrievable (e.g., electronic databases, secure storage for physical forms); and
    • Ensure that the consent documentation includes any relevant privacy notices or disclosures provided to the individual at the time of consent.
  3. Updates and Renewals:

Where consent is obtained for long-term data processing, periodic reviews should ensure the continued validity of consent and update the records accordingly.

  1. Withdrawal of Consent:
    • Clearly record and maintain evidence of any withdrawal of consent, including the date and time of the withdrawal and the specific actions taken in response (e.g., data deletion, cessation of processing); and
    • Include a mechanism to record and process withdrawals of consent specifically for special categories of data.
  2. Audit-Readiness:

Ensure that all consent records are maintained in a way that they can be provided to regulatory authorities during audits or investigations to demonstrate compliance with consent requirements.

Managing Consent

NEPA manages consent throughout the data lifecycle by:

  • Periodic review of consent to ensure its ongoing validity;
  • Implementing mechanisms for withdrawing consent, ensuring requests are processed within a reasonable timeframe; and
  • Notifying data subjects of any significant changes to the processing purposes and obtaining renewed consent when necessary.

 

Compliance with Data Protection Laws

NEPA complies with the Data Protection Act, 2020, and related regulations, ensuring that consent practices align with legal requirements. The Agency respects the rights of data subjects, including their right to access and rectify personal data.

 

Alignment with International Standards

NEPA follows the best practices outlined in  ISO/IEC 27001 to integrate data privacy into its Information Security Management System (ISMS). This includes establishing robust policies, procedures, and training programs to maintain compliance and protect personal data.

 

Training and Awareness

All NEPA employees and contractors are required to complete data protection training, emphasizing the importance of consent and privacy rights. Ongoing training ensures that staff remain aware of changes to laws and best practices.

 

Policy Review and Updates

This Consent Policy will be reviewed annually or whenever significant changes occur in legislation, business operations, or industry standards. Updates will be communicated promptly to all relevant stakeholders.

 

History of Changes

Revision Date

Revision Number

Changes

Revised By

 

 

 

 

 

 

 

 

 

 

 

 

 

 

A logo of a map

AI-generated content may be incorrect.

 

 

Data Subject Access Request Policy

 

2026

 

 

 


 

1. Introduction

This Data Subject Access Request (“Policy”) is a sub-policy of the Privacy Policy of the National Environment and Planning Agency (“NEPA”). This Policy sets out the responsibilities and expected conduct of all staff of NEPA in respecting and upholding the rights of data subjects as outlined in the Jamaica Data Protection Act.

2. Purpose

The purpose of this Policy is to provide guidance to staff members (primarily staff members who are authorized to handle data subject access requests) on how data subject access requests should be handled.

3. Definitions

“Inaccuracies” mean any error or omission;

“Rectification” means amend, block, erase or destroy, as may be required to correct the inaccuracy; and

Third party (an 'agent') acting on behalf of a data subject may include the data subject’s parents, guardians, legal representatives and those acting under a power of attorney or other legal authority. The agent must provide sufficient evidence that he/she is authorised to act on behalf of the data subject.

 

4. Scope

This Policy applies to all NEPA staff and authorised users of NEPA who receive and/or will handle data subject access requests in the following manner:

All staff:

i. must direct the data subject in writing to fill out the (DSAR) Webform on NEPA’s website after receipt of a data subject access request by letter, e-mail or telephone, and

ii. must not take any other action in relation to the data subject access request.

 

Authorised users:

                               i.          The Data Protection Officer, the Human Resource Management & Development Branch, and the Information Communication Technology Branch are authorised to handle data subject access requests;

                                            ii.               The Data Protection Officer will make key decisions in relation to DSARs and will oversee the process; 

iii.             The Human Resource Management & Development Branch handles all customer and employee requests; and

iv.              The Information Communication Technology Branch will ensure that data can be accessed from multiple systems or applications in order to fulfill requests.

 

5. Data Subject Requests that Should be Considered (All Staff)

A Data Subject Access Request (DSAR) is any request from a data subject (or from a third-party acting on behalf of a data subject):

i.                         to confirm whether NEPA processes personal data about him or her;

ii.                       for a description of his/her personal data, the purposes for which it is being processed or the recipients to whom the personal data have been disclosed;

iii.                    for access to a copy of that personal data;

iv.                    for information on the source that provided their personal data;

v.                       for information on the period for which personal data will be stored;

ii.                       to object to the processing of his/her personal data;

vi.                    for his/her information be transmitted elsewhere; and

vii.                  for ascertaining whether NEPA makes automated decision based on his/her personal data, and if so, the logic involve.

A DSAR must be made in writing. In general, verbal requests for information held about an individual are not valid DSARs. In the event a Data Subject Access Request is made verbally, the data subject must be directed in writing to fill out the DSAR Webform on NEPA’s website for processing.

 

6. The Rights of a Data Subject

Under the JDPA, data subjects enjoy the following rights:

a.       Right to be informed and to request access to Personal Data A data subject is entitled to make a written request to NEPA to be informed whether their Personal Data is being processed by NEPA. If their Personal Data is being processed by NEPA, the data subject is entitled to be provided with a description of:

                                                i.               the Personal Data;

                                             ii.               the purpose(s) for which the Personal Data is or is to be processed; and

                                           iii.               the recipients or categories of recipients of the Personal Data.


 A data subject may also upon payment of the prescribed fee of $100.00 per page or $1,000.00 for audio or video, request a copy of their data in a clear and concise format as well as the source of that Personal Data.

b.      Right to data portability - A data subject is also entitled to request that their Personal Data be shared with another data controller. The data subject is not required to pay a fee if the personal data is shared electronically with another data controller.

 

c.       Right to be informed about automated decision making - Where Personal Data is processed by automated means to determine issues regarding a data subject, such as credit-worthiness or work performance, and constitutes or is likely to constitute the sole basis for such decisions, the data subject is entitled to be informed of the logic involved in the decision-making process. NEPA may request that the data subject pays a prescribed fee of $1,000.00,. A data subject may also request in writing that decisions made solely on the basis of automated processing be reconsidered with human involvement. The data subject may also request that no decision regarding their Personal Data is made solely by automatic means.

 

d.      Right to prevent processing - The data subject is entitled to make a written request to NEPA to cease or not to begin processing their Personal Data in a specific manner or for a specific purpose. The grounds on which a data subject may make this request are that:

                                 i.               the processing of the Personal Data is causing or is likely to cause substantial damage or distress to the data subject or another and the damage or distress is unwarranted;

                              ii.               the Personal Data is incomplete, or irrelevant, having regard to the purpose of the processing;

                            iii.               the processing of the Personal Data, or the processing of the Personal Data for that purpose or in that manner, is prohibited under any law; or

                            iv.               Personal Data has been retained by the data controller for longer than the period of time for which it may be retained by the data controller under any law.

 

e.       Right to rectification - A data subject may request that inaccuracies in their Personal Data be rectified. Upon receipt of the request, it must be determined whether rectification is required. If the Data Protection Officer or other relevant personnel are of the view that rectification is not required, this should be noted in the Personal Data and communicated to the data subject within thirty (30) days of receiving the request. Where rectification is required, the data subject must be notified of the rectification within thirty (30) days. Notification of the rectification must also be sent to every other person or entity to whom the Personal Data was disclosed within twelve months prior to the request.

 

f.         Right to consent – A data subject may consent to the processing of their Personal Data. Where a data subject has previously provided NEPA with his/her consent to such processing, the data subject is entitled to make a request to withdraw that consent at any time.

 

7. Conditions for responding to a valid request (Authorised staff)

The Data Protection Officer should be notified about all requests for personal data. Additionally, the Director of the Human Resource Management & Development Branch should be notified about all customer and employees or prospective employees requests.

Where a large quantity of information about any data subject is processed, NEPA may need to ask him/her to specify the information or processing activities to which the request relates. Requests are more likely to be successful when they are specific and targeted at particular information (e.g. by referring to a specific department), the period in which the information was generated or processed and being specific about the nature of the data sought (e.g. a copy of a particular form or email records from within a particular department). Only information that is reasonably required to locate the Personal Data should be requested from the data subject.

A reasonable fee (based on the administrative cost of providing the information) for responding to a request may be charged for:

i. personal data to be communicated in an intelligible format;

ii. information relating to the source that disclosed data to NEPA;

iii. information on the logic used to make automated decisions; and

iv. additional copies of the same information.

 

       8. The DSAR Process

The procedure is presented as a flow chart in the DSAR Protocol Appendix to this document.

a.       Request

To enable NEPA to respond to a DSAR promptly, the data subject should submit his/her request using the Application for Access to Personal Data Form (Form 2 of the Regulations) or the Delegation Form (Form 1A of the Regulations) where the data subject has authorized his/her legal representative to act on their behalf.  

Upon receipt of a DSAR, the Data Protection Officer will acknowledge such a request, if the mentioned form was not used the acknowledgment of the request must include a request for the data subject to complete the Form to better enable NEPA to locate the relevant information.

 

b.      Identifying the data subject (Authorised Staff)

Before responding to a request, authorised staff must take reasonable steps to verify the identity of the data subject. If there are doubts as to the identity of the data subject, additional information must be requested to confirm his or her identity. If the individual’s identity still cannot be verified, staff must refuse to act on that request.

Where the Data Protection Officer is reasonably satisfied with the information presented by the person who received the request, the Data Protection Officer will notify the requestor that his/her DSAR will be responded to within thirty days of receiving the request. The thirty-day period begins from the date that the required documents are received. The requestor will be informed by the Data Protection Officer in writing if there will be any deviation from the thirty-day time frame due to other intervening events or the volume of personal data requested or the complexity of the request.

 

c.       Review of information

The Data Protection Officer will contact and ask the relevant department(s) for the required information as requested in the DSAR. This may also involve an initial meeting with the relevant department to go through the request if required. The department which holds the information must return the required information by the deadline imposed by the Data Protection Officer and/or a further meeting is arranged with the department to review the information. The Data Protection Officer will determine whether there is any information that may be subject to an exemption under the JDPA and/or if consent is required to be provided from a third party.

The Data Protection Officer must ensure that the information is reviewed/received by the imposed deadline to ensure the thirty-day (30) timeframe is not breached.

 

d.      Response to Access Requests

The Data Protection Officer will provide the finalized response together with the information retrieved from the department(s) and/or a statement that NEPA does not hold the information requested, or that an exemption applies. The Data Protection Officer will ensure that a written response is sent back to the requestor. This will be via email, unless the requestor has specified another method by which they wish to receive the response (e.g. post). NEPA will only provide information via channels that are secure. When hard copies of information are posted, they will be sealed securely and sent by recorded delivery.

e.       Archiving

After the response has been sent to the requestor, the DSAR will be considered closed and archived by the Data Protection Officer in accordance with NEPA’s Data Retention Policy and any applicable laws.

 

9. Refusing to respond to a request (Authorised Staff)

Authorised staff may refuse to act on a data subject access request where:

                         i.               even after requesting further information, the individual has not complied with the request for further information. NEPA is not required to respond to requests for information unless it is provided with sufficient details to enable the location to be identified, and to satisfy itself as to the identity of the data subject making the request;

 

                       ii.               a subsequent identical or similar request was made by the individual, unless a reasonable interval has elapsed between compliance with the previous request and the making of the subsequent request. When determining what is a “reasonable interval”, regard should be had to the nature of the personal data, the purpose for which the personal data are processed and the frequency with which the personal data are altered;

 

                    iii.               the information relates to another individual that can be readily identified unless:

a.        the other individual consents to the disclosure of the information; or

 

b.       it is reasonable in all the circumstances to comply with the request without the consent of the other individual and NEPA has notified that other individual of its intention to comply with the request. Reasonableness considers (i) the type of information that would be disclosed, (ii) any duty of confidentiality owed to the other individual, (iii) any steps taken by NEPA with a view to seeking the consent of the other individual, (iv) whether the other individual is capable of giving consent and (v) any express refusal of consent by the other individual.

 

                    iv.               where an exemption(s) applies.

 

                       v.                where NEPA is not in custody of the requested information.

 

                    vi.               Where the information already exists in the public domain.

 

If authorised staff intends to refuse to act on a data subject access request, the data subject must be informed of the reason(s) no later than thirty (30) days from the receipt of the request or the date of payment, and the Data Protection Officer must be notified of the intended refusal before same is communicated to the Data Subject

 

10. Time limit for responding to a request (Authorised Staff)

Once a data subject access request is received, authorised staff must provide a response within thirty (30) days. Where payment is being charged for the request, a response must be provided to the data subject within thirty (30) days from the date of payment. If a data subject access request is complex due to the size or nature of the Personal Data, NEPA:

i.  may extend the period of compliance by an additional forty-five (45) days ; and

ii. must inform the data subject of the extension within one month of the receipt of the request and explain why the extension is necessary.

 

11. Exemptions to the right of access (Authorised Staff Only)

In certain circumstances, NEPA may be exempt from providing some or all of the personal data requested. These exemptions are described below and should only be applied on a case-by-case basis after a careful consideration of all the facts:

i. Law enforcement/taxation/statutory functions: NEPA does not have to disclose any personal data which it is processing for the purposes of preventing or detecting crime; apprehending or prosecuting offenders; or assessing or collecting any tax or duty.

ii. Protection of the rights of others: NEPA does not have to disclose personal data if it would involve disclosing information relating to another individual that can be identified from the information, unless:

·   that other individual has consented in writing to the disclosure of the information to the individual making the request; or

 

·   it is reasonable to disclose the information to the individual making the request without the other individual’s consent, having regard to –

 

(a)     the type of information that would be disclosed;

(b)    any duty of confidentiality owed to the other individual;

(c)    any steps taken by NEPA with a view to seeking the consent of the other individual; and

(d)    whether the other individual is capable of giving consent and any express refusal of consent by the other individual.

iii. Disclosures required by law or by the Court: NEPA may disclose personal data where the disclosure is necessary for the purpose of, or in connection with, any legal proceedings (including prospective legal proceedings); or for the purpose of obtaining legal advice, or is otherwise necessary for the purposes of establishing, exercising or defending legal rights.

Any data subject dissatisfied with the outcome of his/her Data Subject Access Request is entitled to make a request to the Data Protection Officer to review the outcome. Any data subject who is dissatisfied with the manner in which their request was handled is entitled to seek assistance from the Office of the Information Commissioner (OIC) by calling (876)929-8990-9/ (876)960-1623 or visiting their offices at The PCJ Building, 36 Trafalgar Road Kingston 10, Jamaica.

 

12. Non-Compliance

Violations of this Policy will be subject to NEPA’s standard disciplinary procedures as outlined in the Human Resources Policies and Procedures Manual.

 

13. Relevant Policies & Procedures

·   Privacy Policy

  Information Security Policy

 

14. Review of the Policy

This Policy will be reviewed annually by the Data Protection Officer, or more frequently as required by virtue of changes in the operating environment or applicable laws.

 

 

14.1 Revision History

Revision Date 

Revision Number 

Changes Made 

Revised By 

 

 

 

 

 

 

 

 

 

                           

 

APPENDIX A

                                                                                    FORM 2                                                            (Regulation 3)

THE DATA PROTECTION ACT, 2020

APPLICATION FOR ACCESS TO PERSONAL DATA

(under section 6(2) of the Act)

Reference No:

(For Internal Use Only)

1. Name and address of data controller: . . . . . . . . . . . . . . . . . . . . . . . .(Please state the name and address of the data controller to whom

the application is being directed).

 

2. Name of data subject:

(Print)

Last . . . . . . . . . . . . . . . . . First . . . . . . . . . . . . . . Middle . . . . . . . . . . . .

 

3. Name of applicant: (If different from data subject)

(Print)

Last . . . . . . . . . . . . . . . . . First . . . . . . . . . . . . . . Middle . . . . . . . . . . . .

 

4. Date of birth of data subject . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

 

5. Sex of data subject Male Female

 

6. Address:(Please indicate the address to which correspondence related to your application should be sent).

Home: . . . . . . . . . . . . . . . . . . . . . . .       Mailing: . . . . . . . . . . . . . . . . . . . . . .

 . . . . . . . . . . . . . . . . . . . . . . . . . . . . .       . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

 . . . . . . . . . . . . . . . . . . . . . . . . . . . . .       . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Tel: . . . . . . . . . . . . . . . . . . . . . . . . . .      Tel: . . . . . . . . . . . . . . . . . . . . . . . . . .

Email: . . . . . . . . . . . . . . . . . . . . . . . .      Other: . . . . . . . . . . . . . . . . . . . . . . . .

 

7. I would like to: (Please check the relevant box(es)

be informed whether the personal data of the abovenamed data subject is being processed by you or on your behalf;

be given a description of the:

personal data of the abovenamed data subject which is being processed;

purpose(s) for which the data are being, or are to be, processed; and

recipients or classes of recipients to whom the data are or may be disclosed;

have the personal data of the abovenamed data subject made available to me and to be advised of the source of the data (if known);

be informed of the logic involved in the automated decision which was taken regarding the abovenamed data subject;

have the personal data of the abovenamed data subject transmitted to the following data controller(s):

Name of data controller: . . . . . . . . . . . . . . . . . . . . . . . . . . .

Address of data controller: . . . . . . . . . . . . . . . . . . . . . . . . .

Telephone number: . . . . . . . . . . . . Email: . . . . . . . . . . . .

 

 

8. I would like to have the personal data of the abovenamed data subject made available in the following format:

photocopy

electronically

other (please specify) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

 

Note: Where a fee is applicable, payment will be required before the personal data are, or the logic involved in an automated decision is, made available or the personal data are transmitted to another data controller.

 

. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Signature of data subject/applicant

 

 

. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Date

INTERNAL USE

Accepted

Rejected  

Reason for Rejection (if applicable)

_______________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________

Signature DPO                                                                                             Date

 

……………………………………………………..                                                     …………………………………………….

APPENDIX B

                                                        FORM 1A                                  (Regulation 2)

THE DATA PROTECTION ACT, 2020

DELEGATION FORM

(under section 5(b)(ii) of the Act)

I . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . of  (Insert full name of data subject) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .  . . . . . . . .  hereby (Insert address of data subject) authorise . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .  . . . . . of (Insert name of person being issued authorisation to act) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .  . . . . . . . .  . . . . . .  to: (Insert address of person being issued authorisation to act)

exercise my right [strike out the items that do not apply]:

of access to my personal data

to prevent processing of my personal data

in relation to automated decision taking

to rectify any inaccuracy in my personal data.

This authorisation is given in respect of personal data being processed by [strike out the item that does not apply]:

all data controllers

a specific data controller (specify details of the data controller):

Name: . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Address: . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Phone number: . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Email: . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

and shall be valid for . . . . . . . . . . . . . . . . . . . . . . from the date hereof.

                                    (insert period of validity)

. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Signature of data subject

. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Date

. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Signature of Justice of the Peace/Notary Public or Consular Officer [as the case requires]

. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Date

 

Please see the link to the DSAR form  Application for Access to Personal Data.pdf

 

 

INFORMATION SECURITY POLICY

National Environment and Planning Agency Information Security Policy

Policy Owner

National Environment and Planning Agency

Policy Approver(s)

Chief Executive Officer

Related Policies and Procedures

 

Created by

Privacy &Legal Management Consultants Limited

Storage Locations

 

Effective Date

 

Next Review Date

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

INTRODUCTION

National Environment & Planning Agency (“NEPA”) recognises the importance of protecting its Information Assets from unauthorised access, use, disclosure, disruption, modification, or destruction, and created an Information Security Policy.

 

This Information Security Policy (“Policy”) provides management direction and support for information security and outlines the responsibilities and required behaviours of all users of NEPA’s facilities. This Policy, along with its component sub-policies, constitutes NEPA’s Information Security framework.

PURPOSE

This Policy establishes the framework for ensuring the security, confidentiality, integrity, and availability of information managed by NEPA. The objectives of this Policy are to:

i.       Ensure that all users are aware of and comply with this Policy including sub-policies and the Jamaica Data Protection Act, 2020, its amendments, and regulations;

ii.      Provide a safe and secure information systems environment for users by minimising the risk of security incidents and data breaches;

iii.     Ensure that all users understand their own responsibilities for protecting the confidentiality and integrity of the personal data that they handle; and

iv.     Adequately guide the staff in order to protect NEPA from liability or damage through the misuse of information or information systems.

 

SCOPE

This Policy applies to all individuals and entities accessing, processing, or managing information assets within NEPA, including:

·    Staff;

·    Contractors, Consultants and Third-Party Vendors; and

·    Any other authorised user of NEPA systems and networks.

 

This Policy covers all Information Assets, regardless of format (electronic, physical, or verbal), and all systems, networks, and premises used to store, process, or transmit information.

DEFINITIONS

“Access Control” means the process of controlling access to systems, networks, and information based on business and security requirements.

 

Applicable Laws” means the Jamaica Data Protection Act, the Cybercrimes Act and any other relevant legislation and regulations.

 

Business Case” means the demonstration by a Client of the existence of a legitimate business or regulatory requirement to warrant provision of Restricted Access data and information. The primary considerations for assessing a Business Case are, interests in planning or decision making or a high likelihood the distribution of data and information will ultimately serve conservation and recovery; and the existence of appropriate controls to minimize risk or misuse of the data.

 

Client” means a consumer of element data and information. For the purposes of these policies and procedures a client specifically refers to an individual, or representative of an agency or organization who has requested access to data and information. A client who has requested access to Restricted Access data and information will be required to demonstrate a Business Case and abide by specified obligations associated with that access.

 

Confidentiality Agreement” means a signed agreement which prescribes the terms of Client access, constraints to the use of, and redistribution of Sensitive Personal Data and Information Assets. Confidentiality agreements are a means by which the NEPA implements controls on the Client’s use of Sensitive Personal Data. Confidentiality agreements are considered instruments of the NEPA.

 

Critical Data” means information that is essential to NEPA’s operations, financial stability, legal compliance, or reputation.

Information Assets” means all hardware, software, data, and network resources of NEPA, including but not limited to computer networks, systems, servers, workstations, portable devices such as laptops and mobile devices, network infrastructure, software applications, databases, and electronic communication systems such as email and Wi-Fi networks.

 

“Personal Data” means any information, however stored, relating to a living individual or an individual who has been deceased for less than thirty years, who can be identified from that information alone or from that information and other information in the possession of, or likely to come into the possession of, the data controller. This includes any expression of opinion about that individual and any indication of the intentions of the data controller or any other person in respect of that individual.

Sensitive Personal Data” means information relating to an individual’s (a) racial origin, (b) ethnic origin, (c) filiation, (d) beliefs such as political opinion and religious beliefs, (e) trade union membership, (f) health records, (g) sex life, (h) criminal history or legal proceedings or physical, physiological, or behavioural characteristics such as pictures, fingerprint, iris scan, blood type, height, vein pattern, gait, signature, voice.

 

“Ecological Data and Information” means data and information of a biological or geographical nature pertaining to Elements as defined in this policy.

 

Element” means an identifiable and recognized unit of natural biological diversity. Elements represent species and infraspecific taxa, natural communities, or other nontaxonomic biological entities (e.g., migratory species aggregation areas).

 

Elements of Conservation Concern” means ecologically definable entities for which there are legitimate concerns for conservation, survival and/or persistence due to inherent and external threats. These may be identified by NEPA in a variety of means including conservation status rank (e.g., S1, S2, S3) or similar status labels (e.g. Vulnerable, Threatened, Endangered and Critically Endangered) or by other appropriate means.

 

 

 

POLICY STATEMENTS

NEPA supports the development and maintenance of Information Security in accordance with business, legal, and privacy requirements. The following principles underpin this Policy:

       i.          All Information Assets must be used solely for authorised business activities;

      ii.          Critical Information Assets must be accessible to authorised users when needed;

     iii.          Access to Information Assets, both physical and remote, must be controlled through robust authentication and authorisation mechanisms and restricted to authorised personnel;

    iv.          Users interacting with Information Assets must receive appropriate security training;

      v.          Information security controls must be automated where feasible;

  1. Portable Information Assets require heightened security measures, including encryption to prevent loss or theft;

   vii.          Security incidents, including loss, theft, or damage to Information Assets, must be reported immediately to the Incident Response Team promptly;

  viii.          During the investigation of a  security incident, the Incident Response Team (IRT) is authorized to monitor relevant NEPA resources, access communications and other pertinent records associated with specific users;

    ix.          Element data and information must be made as freely and openly available as possible, consistent with the philosophies and context of Open Data frameworks and, where applicable, relevant Open Data and Information Policies;

      x.          Access to Sensitive Ecological Data must be routinely provided where the Client has demonstrated an appropriate Business Case and where NEPA has the relevant authorities to distribute those data; and

    xi.          Access to Sensitive Ecological Data must be provided subject to relevant guidelines, restrictions, and agreements as necessary to maintain the integrity of that data (e.g., Confidentiality and Non-Distribution Agreements, Data Sharing Agreements, Training Requirements).

 

ROLES & RESPONSIBILITIES

Information Technology Department:

·    Responsible for overseeing information security operations;

·    Implements and maintains security controls;

·    Manages user accounts and access privileges;

·    Patches and updates systems and software;

·    Monitors system logs and security alerts; and

·    Performs backups and disaster recovery.

Senior Management Team:

·    Ensures compliance with this Policy within their respective divisions and branches.

 

Staff & Authorised Users:

·    Adheres to this Policy and reports security incidents; and

·    Protects passwords and access credentials.

 

INFORMATION CLASSIFICATION AND HANDLING

Information classification is required to determine the relative sensitivity and criticality of Information Assets, which provide the basis for protection efforts and access control. All Personal Data will be classified into the following categories:

1. Restricted: Highly confidential information whose unauthorised disclosure, compromise, or destruction would result in severe damage to NEPA, its staff, or other individuals. This information includes data restricted to personnel such as the members of the Chief Executive Office, Human Resources Management and Development Branch and Legal Services Branch.

2. Confidential: Information whose unauthorised disclosure, compromise, or destruction would result in severe damage to NEPA, its staff, or other individuals. This includes customer lists, financial information, permit and application records, legal documents, payment histories, and any personal information deemed as Sensitive Personal Data. This data is highly sensitive, and access is restricted to authorised personnel with a need-to know.

3. Internal Use: Information intended for internal use within NEPA. This information includes internal reports, internal memos, company policies, operational documentation, and employee communications. Access is restricted to authorised individuals.

4. Public: Information intended for public dissemination, such as marketing materials, public website content, or general business information.

 

 

ACCESS CONTROL

             i.          All users shall be required to have a unique login ID to enable granular access control based on the principle of least privilege. The Managers for ICT Security and Infrastructure and Technical Services will configure and manage access levels to ensure that employees have access only to the information necessary for their roles.

            ii.          Access must only be granted to those with a legitimate business need.

          iii.          Robust mechanisms must be implemented to verify user identity and grant appropriate permissions. All users must authenticate using secure methods such as strong passwords and multi-factor authentication. All user passwords are to be kept confidential and must not be shared with anyone or stored using the “Remember Me” feature on web browsers or applications. Where there is a reason to believe that a password has been compromised, it must be reported to the Manager of ICT Security and the password changed.

          iv.          The Information Communication and Technology Branch must be immediately notified of changes in a user’s employment.  

           v.          Quarterly reviews must be conducted, ensuring that access privileges remain aligned with current job requirements and unauthorised or inappropriate access is identified.

 

 

PHYSICAL SECURITY

The protection of physical assets, including computers, servers, and sensitive documents, is

essential to maintaining the confidentiality, integrity, and availability of NEPA’s information

systems and data. It therefore follows that:

i.    All staff and visitors must present valid identification upon entering the premises. Access to the building will be monitored through security personnel and/or electronic access control systems such as locks, keypads, or PIN codes. These systems will be used to control entry to sensitive areas such as storage areas for physical records, and management offices.

ii.  Access to sensitive areas will be restricted to authorised personnel only.

iii.               A visitor log will be maintained, recording the name, purpose of visit, date, and time of entry and exit for all external visitors. This log will be kept for a minimum of seven (7) years for audit and security purposes.

iv.Video surveillance will be used to deter unauthorised access and monitor access to areas at NEPA. Video recordings will be retained for a defined period, and access to these recordings will be restricted to authorised personnel.

v.  NEPA will engage security personnel to conduct regular patrols of the premises, especially during non-business hours, to deter unauthorised access and ensure the physical security of the building.

 

NETWORK/SERVER SECURITY

The most recent security patches must be installed on all systems, and automatic updates, enabled whenever possible.

 

Servers should be physically located in an access-controlled environment or a cloud infrastructure environment with an IT infrastructure provider that has achieved and maintains a high level of compliance with IT standards, i.e. the ISO 270001 Standard CIS (Center for Internet Security) Benchmarks. Servers are specifically prohibited from being operated from locations without appropriate physical access controls.

 

SERVER MALWARE PROTECTION

All servers must be equipped with up-to-date antivirus/anti-malware software that provides real-time scanning and protection and must be subjected to regularly scheduled scans to detect and remove existing malware. Servers must be protected by properly configured firewalls to block unauthorised network traffic and prevent malware from entering the server environment.

 

SOFTWARE INSTALLATION

Staff are prohibited from installing software on NEPA’s Information Systems without authorisation from the Director of the Information and Communication Technology Branch. Personal or other licensed software must not be used for NEPA related business purposes unless authorised by the Director of the Information and Communication Technology Branch. Staff are also prohibited from removing, deleting, uninstalling, or deactivating any software installed by NEPA onto these devices.

 

ENCRYPTION

All encryptions must be performed using industry-standard encryption algorithms. The use of weak or outdated encryption algorithms is prohibited. Secure communication channels shall be used for transmitting sensitive data between internal systems. Sensitive data stored on devices (e.g., laptops, desktops, mobile devices) shall be encrypted using full disk encryption or file/folder encryption.

 

REMOTE ACCESS

Remote access shall be granted only to authorised individuals with a legitimate business need. A formal approval process shall be in place for granting remote access privileges. Authorised individuals must use a Virtual Private Network (VPN) or other secure communication protocols approved by the Director of the Information and Communication Technology Branch for secure remote access to NEPA’s network and systems. Devices used for remote access shall meet minimum security requirements, including up-to-date operating systems, access controls, encryption, and anti-malware software.

 

LOGGING, AUDITING AND MONITORING

To ensure the confidentiality, integrity, and availability of NEPA’s Information Assets, detect security incidents, and demonstrate compliance with applicable laws and regulations, the following requirements apply:

i.       All relevant system and application events must be logged and monitored in real-time, including login attempts, file access, system changes, and network activity. Logged data must be retained for only as long as is necessary and protected from unauthorised access, modification, and deletion.

ii.      Access to log data and auditing tools must be restricted to authorised personnel on a need-to-know basis.

iii.     Real-time monitoring tools and techniques must be implemented to detect suspicious activity, unauthorised access attempts, and security incidents.

iv.    Regular security audits, covering system configuration, access controls, and personal data handling procedures, must be conducted at least annually or more frequently based on risks or changes in the operating environment.

 

BACK UP

NEPA must maintain a comprehensive backup program to protect the data and systems of the organisation. The Manager of Infrastructure and Technical Services is to define which information and which machines are to be backed up, the frequency of backup, and the method of backup:

i.       All digital systems containing data critical to NEPA’s operations must be backed up daily.

ii.      All digital systems containing sensitive personal information must be backed up regularly and encrypted.

iii.     A full system backup shall be performed monthly.

iv.    The Information Communication Technology Branch is responsible for backing up information contained on the local drive of their assigned computers to NEPA’s network or cloud locations.

v.      All physical records and documents containing critical or sensitive information must be stored securely and included in a documented disaster recovery plan. Regular physical backups, such as copies or scanned digital versions of essential documents, should be maintained in a separate secure location to prevent loss due to damage, theft, or disaster.

 

STAFF AWARENESS AND TRAINING

All staff and authorised users of NEPA’s facilities will complete mandatory information security training after onboarding, which will be tracked by the designated personnel in the Information Communication and Technology Branch. All staff and authorised users of NEPA’s facilities will be provided with security awareness updates quarterly.

INFORMATION SECURITY RISK ASSESSMENT

The Manager of ICT Security and the Chief Privacy Officer have the authority to periodically conduct risk assessments to identify any vulnerabilities within NEPA’s information systems. Identified vulnerabilities are to be assessed critically by necessary parties, including the Incident Response Team.

 

NON-COMPLIANCE

Violations of this Policy will be subject to NEPA’s standard disciplinary procedures which may include, but are not limited to, the following:

 

i. Minor violations may result in disciplinary actions such as verbal or written warnings.

ii. Repeated or more serious violations may result in disciplinary actions such as suspension or demotion.

iii. Severe violations may result in termination of employment, subject to a disciplinary hearing.

iv. Legal action may be pursued according to applicable laws and contractual agreements.

 

RELEVANT POLICIES & PROCEDURES

·    Data Protection Policy

·    Acceptable Use Policy

·    Data Retention Policy and Schedule

·    Data Subject Access Request Policy

·    Incident Response Policy and Plan

 

POLICY REVIEW

This Policy shall be reviewed at least annually or more frequently as required by changes in the operating environment or applicable laws. Authorised personnel from the Information Communication and Technology Branch and Human Resource Management and Development Branch are responsible for reviewing this Policy.

Revision History

Revision Date 

Revision Number 

Changes Made 

Revised By 

 

 

 

 

 

 

 







National Environment and Planning Agency

Incident Response Policy

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Prepared by: Privacy & Legal Management Consultants Limited

 

 

1.    INTRODUCTION

The purpose of this Incident Response Policy is to establish a framework for identifying, managing and responding to security incidents that may compromise the confidentiality, integrity or availability of the National Environment & Planning Agency (“NEPA”)’s information assets. This policy ensures compliance with the Jamaica Data Protection Act (JDPA) and relevant regulations, safeguarding the personal and financial information of NEPA’s members.

 

This Policy applies to all NEPA’s officers, directors, employees, agents, affiliates, contractors, consultants, advisors or service providers that may collect, process, or have access to data (including personal data and / or sensitive personal data). It is the responsibility of all the above to familiarise themselves with this Policy and ensure adequate compliance with it.

 

2.    OBJECTIVES

 

This Policy aims to:

·       Protect the confidentiality, integrity and availability of NEPA’s information assets;

·       Minimize risks to data subjects’ personal data and NEPA from security incidents;

·       Ensure compliance with the JDPA and other applicable regulations;

·       Facilitate prompt and effective responses to security incidents to minimize harm; and

·       Support continuous improvement of security measures by learning from security incidents.

 

3.    DEFINITIONS

Data Breach: Any breach of security leading to the accidental, unauthorized or unlawful destruction, loss, alteration, disclosure of or access to NEPA’s Personal Data.

Incident: Any event that compromises or threatens the confidentiality, integrity or availability of NEPA information or systems. Examples of incidents are outlined in Appendix A.

Incident Response Team (IRT): NEPA’s designated group responsible for managing incidents. The Roles and Responsibilities of each member are outlined in this Incident Response Policy.

Personal Data: Information (however stored) relating to a living individual or an individual who has been deceased for less than thirty years, who can be identified from that information alone or from that information and other information in the possession of the Data Controller.

NEPA’s Personal Data:  Any Personal Data processed by NEPA on behalf of data subjects. 

 

4.    SCOPE

 

The objective of this Policy is to ensure a consistent and effective approach to the management of NEPA’s Personal data, including the protection of all NEPA’s Personal Data, whether in electronic or physical form. This policy also applies to the information systems, networks, and devices used to process NEPA’s Personal Data, including those managed by third-party vendors. It covers all personnel, contractors, and third-party service providers who handle NEPA’s Personal data, as well as incidents occurring at any location where NEPA’s Personal Data is processed or stored, including remote and cloud environments.

 

5.    ROLES AND RESPONSIBILITIES

 

5.1 All Personnel

All NEPA personnel mentioned above must be knowledgeable of what data breaches and incidents are, and must carry out the following deliverables:

·       Promptly report suspected or actual security incidents to the IRT, even if they have contributed in some way to the event or incident. Reports are to be made to the Data Protection Officer dataprotection@nepa.gov.jm; or Manager of ICT Security; at security@nepa.gov.jm];and

·       Comply with the incident response procedures and other related policies, and must not interfere, obstruct, prevent, retaliate against, or dissuade others from reporting an incident or cooperating with an investigation.

 

5.2 Data Protection Officer

NEPA’s Data Protection Officer must:

 

·       Impart his/ her knowledge on the life cycle of data vulnerabilities, the JDPA and data protection best practices to the IRT; and

 

·       Collaborate with the IRT to ensure each member is knowledgeable of their role should a data breach/ incident occur. 

 

 

5.3 Incident Response Team (IRT)

 

The IRT is tasked with carrying out the following:

·       Developing an effective Incident Response Plan. This Plan must be tested and used to prevent or to mitigate against possible data breaches/ incidents;

·       Coordinating staff training sessions and table-top exercises to ensure that all employees, contractors, temporary workers, third-party service providers and any other authorized personnel who handle NEPA’s Personal data can recognize and report breaches or incidents;

·       Leading the incident response process, including identification, containment, eradication, recovery and lessons learned;

·       Maintaining a central record of reported incidents and actions taken; and

·       Providing regular updates to senior management and stakeholders.

The specific duties of the team members include;

o   Data Protection Officer-  duties are outlined at 5.2.

o   Legal Services Branch - Assist the Data Protection Officer to validate breach determination and scope out the legally required breach notifications to regulatory bodies such as providing notifications to individuals, media, law enforcement, government agencies, amongst others.

o   Information & Communication Technology Branch – Provide guidance regarding detection, isolation, removal and preservation of affected systems. This department is also to address data compromises and carry out forensic investigations, where a data breach or incident has occurred.

o   Human Resource Management & Development Department- Serve as an information conduit to employees, and other authorized personnel where a data breach or incident has occurred.

o   Public Education & Corporate Communication Branch - Advise the team about managing its relationship with data subjects during the creation of the incident response plan. Also offer insight on data subject’s behaviour to the team and  establishes and maintain a positive and consistent message to disseminate where a breach or incident has occurred. This department must also handle breach-related call traffic in the event of a data breach or incident

o   Finance & Accounting Branch- Calculate and manage the costs associated with containing and correcting a data breach or incident.

 

5.4 Data Protection Officer (DPO)

The DPO ensures compliance with the JDPA and manages notifications to regulatory authorities and affected individuals as required.

 

5.5 IT Security Specialists

The IT Security Specialists are tasked with investigating and mitigating technical aspects of security incidents, and providing recommendations for strengthening security measures.

 

5.6  Third-Party Vendors

Third-Party Vendors are obliged to notify NEPA of any security incidents affecting their systems that process NEPA Personal Data. Also, they are tasked with cooperating fully with the IRT during investigations and remediation efforts.

 

 

 

 

 

 

6.    POLICY STATEMENTS

 

Incident Reporting

All personnel must report suspected or actual security incidents immediately to the IRT via email or hotline based on the severity of the incident.  Reports must include relevant details such as the date, time, nature of the incident and any observed impact.

 

Incident Response Process

The IRT will follow these steps to manage incidents:

·      Identification: Detect and confirm the occurrence of an incident.

·       Containment: Limit the spread or impact of the incident.

·       Eradication: Eliminate the root cause of the incident.

·       Recovery: Restore systems and operations to normal functionality.

·       Lessons Learned: Conduct a post-incident review to prevent future occurrences.

 

During the conduct of a security event investigation, the IRT is authorized to monitor relevant NEPA resources and retrieve communications and other relevant records of specific users of the resources, including login session data and the content of individual communications without notice or further approval from the user or management.

 

Regulatory Compliance

All data breaches must be reported to the Office of the Information Commissioner (OIC) within seventy-two (72) hours of becoming aware of a data breach involving personal data, as required by the JDPA. This report must include:

·       The facts surrounding the breach;

·       A description of the nature of the breach, including the categories, number of data subjects concerned, and the type and number of personal data concerned;

·       The measures taken or proposed to be taken to mitigate or address the possible adverse effects of the breach;

·       The consequences of the breach; and

·       The name, address and other relevant contact information of the Data Protection Officer.

NEPA also has a statutory requirement to inform affected data subjects about a data breach that affects their personal data, after becoming aware of said breach, or after it has reason to become aware of the breach. The notification should include:

·       the nature of the security breach

·       the measures taken or proposed to be taken to mitigate or address the possible adverse effects of the breach; and

·       the name, address and other relevant contact information of the Data Protection Officer.

 

Communication and Transparency

NEPA should maintain open and transparent communication with stakeholders during and after incidents. In keeping with this, public statements will be coordinated by the Director of the  Corporate Management Division to ensure accuracy and consistency.

Any external disclosure of information regarding security events must be reviewed and approved by the IRT in consultation with the Data Protection Officer and other stakeholders as appropriate.

 

Record-Keeping

A detailed record of all reported incidents, including the actions taken, outcomes and lessons learned shall be maintained. The record shall be kept in accordance with the Agency’s Records Retention Policy.

 

 

7.    TRAINING AND AWARENESS

 

All personnel will undergo regular training to ensure they are equipped to recognize, report, and respond appropriately to security incidents. Specialized training will be provided to members of the Incident Response Team (IRT) to enhance their capabilities in advanced incident management techniques. Furthermore, incident response protocols will be incorporated into the onboarding process for new employees and contractors, ensuring that they are familiar with the organization’s approach to security incidents from the outset.

 

 

 

8.    COMPLIANCE AND LEGAL CONSIDERATIONS

 

All applicable laws and regulations, including the Jamaica Data Protection Act (JDPA) and other privacy standards, must be adhered to. Contracts with third-party vendors will include provisions for incident reporting and cooperation. The confidentiality of incident-related information will be maintained throughout investigations to ensure compliance with legal and regulatory requirements.

 

 

9.    REVIEW AND MAINTENANCE

This Policy will be reviewed at least annually to ensure its effectiveness. Updates to this Policy will be made to reflect changes in regulations, organizational operations, or security technologies.

10. ENFORCEMENT

Violations of this Policy will be subject to NEPA’s standard disciplinary procedures which may include, but are not limited to, the following:

 i.          Minor violations may result in disciplinary actions such as verbal or written warnings.

ii.          Repeated or more serious violations may result in disciplinary actions such as suspension or demotion.

iii.          Severe violations may result in termination of employment.

iv.          Legal action may be pursued according to applicable laws and contractual agreements.

 

 

11. CONTACT INFORMATION

 

For questions or to report an incident, contact:

 

·       Data Protection Officer: dataprotection@nepa.gov.jm, (876)618-0215

 

·       Manager, ICT Security: security@nepa.gov.jm, (876)443-0042

 

·       Incident Response Team Email: IncidentResponseTeam@nepa.gov.jm

 

 

12. APPROVAL

 

This Incident Response Policy has been reviewed and approved by the Chief Executive Officer. By implementing this IRP, NEPA demonstrates its commitment to protecting sensitive information, ensuring compliance with the JDPA and safeguarding the interests of its members and stakeholders.

 

13.  HISTORY OF CHANGES

 

Revision Date

Revision number

Changes

Revised by:

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

CLOSED CIRCUIT TELEVISION (CCTV) POLICY

National Environment and Planning Agency CCTV Policy

 

1. Background

This document outlines the policy governing the use of Closed-Circuit Television (CCTV) systems at National Environment and Planning Agency (hereinafter referred to as ‘NEPA’ or “the Agency”). It is designed to support the security infrastructure while adhering to local and international data protection laws, ensuring that all monitoring activities are conducted legally, ethically, and responsibly. 

2. DEFINITIONS

CCTV (Closed-Circuit Television): Refers to the use of video cameras to transmit signals to a specific, limited set of monitors, positioned in strategic locations to monitor areas for security and operational purposes. 

Recorded Footage/Footage: images or video of individuals, activities, and events occurring in the monitored areas within the NEPA’s premises or surrounding property.

 

2. Purpose of Policy

NEPA leverages CCTV systems to deter criminal activities and enhance the safety of employees and visitors, while ensuring that the management of these systems respects individuals’ privacy rights. Additionally, the system acts as a verification tool for the Agency’s automated time and attendance systems to ensure the accuracy of payroll records and prevent fraudulent clocking activities. NEPA processes personal data in accordance with our Data Protection Policy and we are dedicated to aligning our CCTV operations with the requirements under the Data Protection Act, 2020, ISO/IEC standards, and other relevant regulations. This enables us to strike a balance between effective security measures and the protection of personal data.

 

3. Scope of Policy

This Policy will enable the NEPA to comply with legal obligations, provide better customer care, improve transparency, and increase the level of trust by being open with data subjects about the information that is held about them in regard to all CCTV systems installed and operated within the premises of and controlled by NEPA including all external and internal cameras. The data collected by CCTV includes video footage and time stamps.

This Policy applies to all NEPA’s staff and other personnel who have access or authority to access the CCTV systems, including the Data Protection Officer.  

 

4. Reference documents

a. Data Protection Act, 2020;

b. NEPA Privacy Policy;

 

5. Legal Framework

Jamaica Data Protection Act, 2020 (“JDPA”): Outlines the overarching legal standards for the processing of personal data, to include fairness and lawfulness, limiting the collection to the specified purpose and retaining the data only for as long as necessary.

ISO/IEC 27001:2013 and ISO/IEC 27701:2013: Establishes guidelines for managing information security management systems.

 

6. Legal Basis for using CCTV

NEPA uses personal data captured through CCTV for the purposes of the Agency’s legitimate interests. CCTV footage is used to enhance the security and safety of employees and customers, and the property of NEPA. NEPA processes CCTV data for:

a.     Prevention and detection of crime (security): CCTV is used to deter and record any criminal activity or security incidents on the premises, ensuring the protection of both NEPA’s assets and individuals within its premises;

b.     Protection of employees and customers: NEPA has a responsibility to provide a safe environment for its employees and customers, and the use of CCTV is an essential measure in preventing or responding to security threats or safety incidents;

c.      Safeguarding property: NEPA is committed to protecting its physical assets, premises, and infrastructure from vandalism, theft, or any other malicious activities; and

d.     Verification of Attendance and Punctuality and Support Related Processes: NEPA has a legitimate interest in ensuring that public funds are utilized correctly by verifying that employees are physically present when clocking in or out. Processing this data is necessary to prevent 'buddy punching' (one employee clocking in for another) and to resolve time-keeping disputes.

 

7. Responsibility for the Management of the System

The Information & Communications Technology Division has overall responsibility for the maintenance of the CCTV system. They will periodically check the equipment and arrange for the suppliers to carry out periodic maintenance checks.

The ICT Security Officer will ensure that Footage are processed in accordance with NEPA’s Data Retention Policy and will have access to the Recorded Footage during the maintenance of the systems but will only view footage according to established procedural guidelines. Under the direction of the Data Protection Officer, the Facilities Management & Operations Manager shall submit routine reports to the Records and Information (RIM) Committee and the Data Protection Oversight Committee to confirm compliance with the above requirements.

Members of the Information & Communications Technology Division will be trained in the operation of the CCTV system and will be aware of the data protection compliance requirements under the JDPA, 2020.

The Data Protection Officer is to ensure that data subjects are informed that they may be recorded through CCTV signage in visible areas around the premises. Additionally, NEPA is to provide information, through these mediums, on how to contact the Data Protection Officer or Information & Communications Technology Division for any inquiries regarding the CCTV system.

 

8. Auditing the System’s Operation and Working Practices

The Data Protection Oversight Committee is responsible for ensuring that this policy and its implementation is compliant with the JDPA. Where a risk or potential risk is identified, the matter may be referred to the relevant audit body for review and further action.

 

9. Monitoring of CCTV Footage

The CCTV system shall be monitored on a twenty-four (24) hour basis by designated Security Officers. Monitoring shall occur continuously across all shifts to ensure the timely identification and escalation of incidents.

Security Officers assigned to each shift shall prepare and submit a written monitoring report at the end of their respective shift. Such reports shall document any incidents observed, actions taken, system irregularities, and any other relevant occurrences during the monitoring period.

To ensure accountability and accuracy of reporting, the Security Coordinator shall conduct periodic random checks of monitoring activities and submitted reports. These checks shall serve to verify that monitoring is being properly conducted and that reports accurately reflect recorded events and observations.

 

10. Access to and Disclosure of Images

CCTV footage may be disclosed internally for investigations to include security incidents, policy violations, or employee safety.

Disclosure to external parties, including law enforcement, is permitted under the following conditions:

·        A formal request is received, specifying the nature and purpose of the request.

·        A valid legal basis is provided, such as a warrant or subpoena, or as part of an ongoing investigation.

·        The request is reviewed and approved by the Data Protection Officer.

Requests made by data subjects for access to images will be reviewed on a case-by-case basis and will be addressed in accordance with NEPA’s Data Subject Access Request Policy.

Reviewing the footage captured by cameras specifically designated for Time & Attendance verification is restricted to authorized Human Resources personnel. This access is granted solely for the purpose of verifying attendance records. This footage shall not be used for general performance monitoring (e.g., monitoring work pace or social interactions).

All disclosures of CCTV footage must be documented, including the date and purpose of the request, the requesting party and any legal justification. This documentation will be maintained for record-keeping and auditing purposes.

11. Secure Storage and Retention of Recorded Footage

CCTV footage is retained only for as long as necessary for the legitimate purposes for which it was captured and will be retained only for the duration specified in the Retention Schedule. The Information & Communications Technology Division and the Security Coordinator has the responsibility for ensuring that the equipment is up-to-date and Recorded Footage is protected by strict access controls and data encryption measures.

Where footage has been retained for an investigation the Security Coordinator in conjunction with the Information & Communications Technology Division will take responsibility for the secure storage of those footage. This will be done in liaison with the Director, Corporate Management Division.

 

12. Validity and Document Management

This document is valid as of  February       2026.

 

The owner of this document is the Data Protection Officer, who must check and, if necessary, update the document at least once a year.

 

Questions regarding this Policy should be addressed to:

 

Data Protection Officer

DataProtection@nepa.gov.jm

(876) 754-7540 ext. 4400

Change history 

Date 

Version 

Created by 

Description of change 

dd.mm.yyyy 

 

 

 

 

 

 

 

 

 

Policy Owner

National Environment and Planning Agency

Policy Approver(s)

 

Related Policies

Retention Policy and Schedule, Privacy Policy

Related Procedures

 

Storage Locations

 

Effective Date

 

Next Review Date

 

 

 

 

 

 

 

 

 

 

 

 

APPENDIX A- LOCATION OF ALL CCTV CAMERAS

The following areas have CCTVs installed:

11 Caledonia Avenue, Kingston 5 – First Floor

Area

Precise Location

CCTV

Inventory Area

Pointing to the entrance of the inventory room

1 CCTV Camera

Inventory Area

In the Inventory Room

2 CCTV Cameras

 

 

 

 

 

 

 

 

 

11 Caledonia Avenue, Kingston 5 – Second Floor

Area

Precise Location

CCTV

Hallway

Rear Stairwell Area

1 CCTV camera

 

 

 

 

 

 

 

 

 

 

 

 

Contact email: DataProtection@nepa.gov.jm