A procurement officer asks an overseas supplier a reasonable question: which data protection law will govern this engagement? For most jurisdictions the answer is a statute and a section number. For Saint Helena the honest answer is that no local data protection legislation is currently in force, and that this makes the question harder rather than easier.
Suppliers hear that and relax. That is the wrong reaction, and it is the reason this article exists. An absent statute does not mean an absent obligation. It means the obligations arrive from other directions, that there is no local default to fall back on when something goes wrong, and that the government you are selling to has already worked all of this out and written down its own position.
What follows is an orientation, not legal advice. Nobody writing this is admitted to practise in a British Overseas Territory, and anything involving personal data belonging to residents of one should be reviewed by qualified counsel. With that said, the public record is unusually clear, and a supplier who reads it will be several steps ahead of one who assumes.
What is in force, and what is not
Four facts establish the position, and each is documented.
There is no Data Protection Ordinance in force on the island. A Data Protection Policy was developed and put out for consultation in 2024, with a policy approved in October of that year, and legislative work has not since produced a commenced Ordinance. Annexes published in June 2026 alongside a wider memorandum of understanding record a commitment to introduce one, with an anticipated lead-in period of two years after enactment before obligations bite. Read that carefully: two years after enactment, and enactment has not happened. This is a medium-term horizon, not an imminent deadline.
UK data protection law does not extend to the territory. The Information Commissioner's Office states plainly that United Kingdom data protection law applies in England, Northern Ireland, Scotland and Wales. British Overseas Territories are not included. The UK GDPR and the Data Protection Act 2018 are not local law on Saint Helena, and a supplier who assumes otherwise has misread the constitutional position.
The government has published its own position, and it is stricter than the law requires. The St Helena Government privacy policy, effective from September 2025, states directly that the Data Protection Act 2018 and UK GDPR do not yet apply on St Helena Island, and that the organisation abides by the spirit of the principles regardless. That sentence is the single most useful thing in this entire article, because it tells a supplier exactly what standard the buyer expects to be met voluntarily.
Adjacent legislation exists and does not fill the gap. A Communications Ordinance was taken forward in 2025 and carries confidentiality and subscriber-data provisions applying to communications licensees. That is sector-specific regulation of telecommunications operators. It is not a general data protection framework, and it does not govern a marketing supplier's handling of personal data.
Four Layers, and Only Two of Them Bind You
The gap in the middle is what makes this jurisdiction awkward. There is no local statute to point at, and no local regulator to complain to.
A local Data Protection Ordinance
A policy was consulted on and approved in 2024. No Ordinance has commenced. Annexes published June 2026 record a commitment to introduce one with an anticipated two-year lead-in after enactment.
UK GDPR and Data Protection Act 2018
The Information Commissioner's Office confirms UK data protection law applies in England, Northern Ireland, Scotland and Wales only. British Overseas Territories are outside its territorial scope.
Extraterritorial routes
A government information paper from 2019 identified two: activity through the territory's representative office in the United Kingdom, and monitoring the behaviour of data subjects in Europe. Terminology predates Brexit and should be read with care.
The buyer's own published standard
The government privacy policy, effective September 2025, states that UK instruments do not yet apply locally and that it abides by the spirit of the principles anyway. That is the standard a supplier will be measured against.
And one that is often mistaken for a fourth layer
A Communications Ordinance carrying confidentiality and subscriber-data provisions for communications licensees is sector regulation of telecoms operators. It is not a general data protection framework and it does not govern how a marketing supplier handles personal data.
Sources: SHG privacy policy effective September 2025 • SHG Data Protection Policy consultation, 2024 • Publication of Annexes to the BIOT Memorandum of Understanding, 24 June 2026 • ICO guidance on territorial scope • SHG Chief Secretary Information Paper, 13 November 2019
Created by Arfadia • arfadia.com/blog
Why an absent statute is harder than a strict one
Suppliers who work in heavily regulated markets develop a habit: find the rule, follow the rule, document that you followed it. The rule provides certainty and, crucially, it provides a defence. Saint Helena removes both.
Consider what is missing. There is no local definition of personal data to work from, so the boundaries of the obligation are whatever the parties agree they are. There is no statutory lawful basis to rely on, so consent and legitimate interests become contractual constructs rather than legal ones. There is no local supervisory authority, which means no guidance to follow, no approved codes, and no forum for resolving a dispute short of the courts. There is no statutory breach notification timetable, so what counts as prompt is a matter of negotiation before an incident rather than after.
What replaces all of that is the contract, and the buyer's expectations. That is a weaker foundation for a supplier than a statute, because a statute is at least predictable. In a vacuum, the standard applied after something goes wrong tends to be the one the aggrieved party thinks is reasonable.
The practical consequence is straightforward. Write the data-handling position down before it is asked for, pitch it at the level the government itself has published, and put it in the proposal rather than the appendix.
Adequacy, and which direction it runs
A related question gets asked and misunderstood: does the territory have a UK adequacy decision?
It does not. Saint Helena does not appear on the United Kingdom's list of countries and territories covered by adequacy regulations. Among the British Overseas Territories, Gibraltar is the one that holds adequacy, which surprises people who assume constitutional relationship implies data-flow recognition. It does not.
The consequence matters most in the direction people forget. If a UK-based organisation transfers personal data to Saint Helena, that is a restricted transfer requiring an appropriate safeguard, typically the International Data Transfer Agreement or the UK addendum, supported by a transfer risk assessment. The absence of local legislation is exactly what makes that assessment awkward, because one of the things it asks about is the legal protection available in the destination.
Run the same logic for a supplier based elsewhere and the picture is the same in structure. There is no reciprocal recognition to rely on, so safeguards are contractual, and the documentation has to be assembled rather than cited.
The routes that do reach you
Three, and they are the ones a supplier should be able to discuss without notice.
Through the United Kingdom presence. A government information paper from 2019 identified that the territory's representative office in London brings certain processing within European rules of the time. The terminology in that paper predates Brexit, so the current shape of that argument would need checking, but the underlying point survives: activity routed through a UK establishment does not sit in the same legal position as activity confined to the territory.
Through monitoring behaviour. The same paper identified monitoring of data subjects in Europe as a trigger. For a marketing supplier this is the live one. Analytics, remarketing audiences, engagement scoring and behavioural tracking aimed at prospective visitors in the United Kingdom or the European Union are precisely the activity that extraterritorial provisions were written to catch. The location of the island is irrelevant to that analysis. The location of the person being tracked is what matters.
Through the supplier's home jurisdiction. An overseas supplier carries its own law with it. For an Indonesian provider, the Personal Data Protection Law imposes obligations on cross-border transfer that apply regardless of what the destination territory does or does not have on its statute book. A supplier who says the destination has no law and therefore no obligation has answered only half the question, and the wrong half.
Exposure by activity
Not all marketing work carries the same risk, and the differences are large enough to shape a scope. Citation auditing and entity work sit at the low end, which is worth knowing before a proposal is written.
| Activity | Exposure | Control that actually helps |
|---|---|---|
| Auditing public pages and AI answers | Low | Use standardised research accounts and keep real names out of prompts |
| Entity and structured-data work | Low | No personal data involved. Say so explicitly in the proposal rather than leaving it implied |
| Aggregate reporting on visibility | Low | Aggregate by default, and exclude session identifiers from reports |
| Analytics access on the client's property | Medium | A processing agreement, defined retention, and a named list of who has access |
| Press and trade contact databases | Medium | Document source, purpose, access and retention before the list is built, not after |
| Remarketing and audience building in source markets | Medium to high | This is behavioural monitoring of people in the UK and EU. Treat it under their rules, not the territory's |
| Handling enquiry or booking records | High | A controller and processor agreement with a safeguard for the transfer, plus a transfer risk assessment |
| Putting client records into an AI tool | High | Prohibit by default. Where permitted, contract training off, with retention and deletion controls documented |
Read the top three rows again, because they carry a commercial point. The work most useful in this market, auditing how the territory is described and fixing the entity signals, happens to be the work with the lowest personal-data exposure. That is a genuine advantage for a remote supplier, and it should be stated in the proposal rather than discovered in a security review.
Seven Things a Buyer Here Will Eventually Ask For
None of these is expensive to prepare. All of them are expensive to improvise in an evaluation window.
A controller and processor agreement drafted to UK GDPR standards
Voluntarily, since nothing local compels it. This mirrors the standard the government has already published for itself and removes an entire conversation.
A transfer mechanism and a transfer risk assessment
The territory holds no UK adequacy decision, so transfers are restricted transfers. The assessment has to grapple with the absence of local law, which is precisely why it should be written in advance.
A named subprocessor list with locations
Every analytics platform, hosting provider and AI tool in the chain, with the country each sits in. Vague answers here read as unpreparedness.
Retention periods, per data category
Not a single blanket figure. Prompt logs, report archives, contact records and access credentials all justify different periods.
An incident notification commitment, in hours
There is no statutory timetable to inherit. Offer one anyway, and make it a number rather than a promise to act promptly.
A written position on AI tool usage
Which tools are used, whether provider training is contractually disabled, and what may never be pasted into one. Increasingly the first question a security reviewer asks.
A minimisation statement for the specific scope
For audit and entity work, the honest statement is that almost no personal data is processed at all. Say it explicitly. It is the strongest answer available and suppliers routinely forget to give it.
One thing not to do
Do not claim that UK GDPR applies on Saint Helena. At least one indexed third-party page asserts exactly that, and the government's own privacy policy contradicts it in plain words. Repeating the error in a bid document signals that the source was a blog rather than the buyer's own publications.
Compiled from SHG privacy policy effective September 2025, ICO territorial scope and international transfer guidance, and the UK list of adequacy regulations, as at August 2026 • Not legal advice
Created by Arfadia • arfadia.com/blog
The supplier's own side of the transfer
An Indonesian supplier carries Indonesian obligations, and the cross-border provisions of the Personal Data Protection Law apply on their own terms. In outline, a transfer out requires that the receiving jurisdiction offers an adequate level of protection, or failing that, adequate and binding safeguards, or failing that, the consent of the data subject.
Apply that to a territory with no data protection statute and the first limb is difficult to argue. Which leaves the second, contractual safeguards, as the workable route, and reinforces the point made above: the agreement is doing all the work here, so it needs to be drafted properly rather than adapted from a template written for a different situation.
Two practical consequences follow. Keep personal data out of the engagement wherever the deliverable does not require it, because a scope that processes nothing needs no transfer analysis at all. And where personal data is unavoidable, document the safeguard, the assessment and the subprocessor chain at the outset rather than assembling it if somebody asks.
What to watch
Three developments would change the picture, and a supplier working here should track them rather than assume the position is static.
Enactment of a local Data Protection Ordinance is the obvious one. Watch for commencement, and remember that the anticipated two-year lead-in means the practical date is later than the legislative one.
Any move toward a UK adequacy decision covering the territory would simplify transfers considerably. Nothing published suggests that is imminent.
And any establishment of a local supervisory function would change the enforcement landscape from contractual to regulatory. At present there is nobody to complain to locally, which cuts both ways and mostly cuts against the party with less bargaining power.
Limits of this piece
Everything above describes the public position as at August 2026, drawn from government publications, regulator guidance and published policy. It is orientation for scoping and proposal work.
It is not legal advice, and three areas in particular need qualified input rather than a summary. Whether a specific processing activity falls within an extraterritorial provision is a legal analysis, not a checklist outcome. Whether a particular transfer safeguard is adequate for a particular data set depends on the data. And the position on the ground can change with a single commencement notice, which is why every claim here carries a date. How this feeds into scoping is set out on our GEO service page for Saint Helena, and the search-side equivalent on the companion SEO page.
Frequently Asked Questions
Does UK GDPR apply on Saint Helena?
No. The Information Commissioner's Office states that United Kingdom data protection law applies in England, Northern Ireland, Scotland and Wales, and British Overseas Territories are outside that scope. The St Helena Government's own privacy policy, effective September 2025, says the same thing in plain terms: the Data Protection Act 2018 and UK GDPR do not yet apply on St Helena Island. Third-party pages asserting that they do apply locally are incorrect, and repeating that claim in a bid document is a visible error.
Is there any local data protection law?
Not currently in force. A Data Protection Policy was consulted on and approved in 2024, and annexes published in June 2026 record a commitment to introduce a Data Protection Ordinance with an anticipated lead-in period of two years after enactment. Since enactment has not occurred, the practical horizon is medium-term. A Communications Ordinance carrying confidentiality and subscriber-data provisions applies to communications licensees and is not a general data protection framework.
Does Saint Helena have a UK adequacy decision?
No. Saint Helena does not appear on the United Kingdom's list of countries and territories covered by adequacy regulations. Gibraltar is the British Overseas Territory that holds adequacy, which surprises people who assume the constitutional relationship implies data-flow recognition. Transfers to Saint Helena from the UK are therefore restricted transfers requiring an appropriate safeguard and a transfer risk assessment.
If nothing applies locally, is a data processing agreement still needed?
Yes, and more so rather than less. With no local statute there is no definition of personal data to work from, no statutory lawful basis, no supervisory authority to issue guidance, and no statutory breach notification timetable. The contract carries all of that weight. In the absence of a rule, the standard applied after an incident tends to be whatever the aggrieved party considers reasonable, which is a poor position for a supplier.
Which marketing activities carry the highest exposure?
Handling enquiry or booking records, and putting client records into an AI tool. Remarketing and audience building in the source markets also sits high, because it is behavioural monitoring of people in the United Kingdom and European Union and falls under their rules regardless of where the island sits. The lowest exposure sits with auditing public pages and AI answers, entity and structured-data work, and aggregate visibility reporting, none of which requires personal data at all.
What obligations does an Indonesian supplier carry?
Its own. The Indonesian Personal Data Protection Law imposes cross-border transfer requirements that apply irrespective of what the destination territory has on its statute book, in outline requiring an adequate level of protection in the receiving jurisdiction, or adequate and binding safeguards, or the data subject's consent. Because the first limb is hard to argue for a territory with no data protection statute, contractual safeguards become the practical route, which again puts the weight on the agreement.
What standard should a supplier volunteer?
The one the buyer has already published for itself. The government states that it abides by the spirit of UK data protection principles despite them not applying locally. A supplier contracting to UK GDPR standards voluntarily, with a named transfer mechanism, a documented subprocessor list, per-category retention periods and a stated incident notification window in hours, is meeting the buyer where the buyer already stands.
What should be watched for changes?
Three things. Commencement of a local Data Protection Ordinance, bearing in mind that the anticipated two-year lead-in makes the practical date later than the legislative one. Any movement toward a UK adequacy decision covering the territory, which nothing published currently suggests is imminent. And the establishment of any local supervisory function, which would shift enforcement from contractual to regulatory.
Sources & References:
- Buyer position: St Helena Government privacy policy, effective September 2025, stating that the Data Protection Act 2018 and UK GDPR do not yet apply on St Helena Island and that the organisation abides by the spirit of the principles. The same policy references standard contractual clauses and data bridge arrangements in relation to analytics transfers.
- Local legislation status: St Helena Government Data Protection Policy, consultation draft version 3.2.0, August 2024, with policy approved October 2024. No Data Protection Ordinance has commenced as at August 2026. Publication of Annexes to the BIOT Memorandum of Understanding, 24 June 2026, recording a commitment to introduce a Data Protection Ordinance with an anticipated lead-in period of two years following enactment. The lead-in is a stated expectation rather than a statutory deadline.
- Territorial scope of UK law: Information Commissioner's Office guidance confirming that United Kingdom data protection law applies in England, Northern Ireland, Scotland and Wales, and does not extend to the British Overseas Territories.
- Adequacy: Saint Helena does not appear on the United Kingdom list of countries and territories covered by adequacy regulations. Gibraltar is the British Overseas Territory covered by UK adequacy. Transfers from the UK to Saint Helena are therefore restricted transfers requiring an appropriate safeguard, such as the International Data Transfer Agreement or the UK addendum to standard contractual clauses, supported by a transfer risk assessment.
- Extraterritorial routes: St Helena Government Chief Secretary Information Paper, 13 November 2019, identifying the territory's United Kingdom representative office and the monitoring of behaviour of data subjects in Europe as routes by which European data protection rules of the time could reach activity connected to the territory. Terminology in that paper predates the United Kingdom's departure from the European Union and the current position should be verified with counsel.
- Sector legislation: Communications Ordinance taken forward in 2025, containing confidentiality and subscriber-data provisions applying to communications licensees. Sector-specific and not a general data protection framework.
- Supplier-side obligations: Indonesian Personal Data Protection Law, Law No. 27 of 2022, cross-border transfer provisions requiring an adequate level of protection in the receiving jurisdiction, or adequate and binding safeguards, or the consent of the data subject. Described in outline only.
- Documented third-party error: at least one indexed cybersecurity commentary page asserts that Saint Helena has data protection laws based on the UK Data Protection Act 2018 and UK GDPR. This is contradicted directly by the St Helena Government privacy policy and by ICO guidance on territorial scope.
- This article is orientation for scoping and proposal work as at August 2026. It is not legal advice. Whether a specific processing activity falls within an extraterritorial provision, and whether a particular safeguard is adequate for a particular data set, are legal questions requiring qualified counsel. Positions described here can change with a single commencement notice, and every claim above is dated for that reason.