Tonga's Privacy Act 2025 was passed by the Legislative Assembly on 6 August 2025 and assented by King Tupou VI on 16 December 2025 as Act 34 of 2025. Section 1(2) states that it comes into force on a date proclaimed by Cabinet. As at August 2026 we found no proclamation and no appointed Privacy Commissioner.
So it is law, and it is not yet operative. Those are different things, and quite a lot of published commentary has merged them.
That distinction is the first reason to read this now rather than later. The second is more practical: one clause in this Act reaches agencies that have never set foot in Tonga, and another clause quietly resolves a question that answer-engine monitoring has been arguing about for two years. Neither appeared in any of the eight research documents compiled for this project. Both come from reading the statute.
Gazetted is not commenced
In January 2026, Tongan press reported the gazettal of the 2025 legislative package under a headline describing the reforms as coming into force. Read as journalism that is fair shorthand, since the Acts had completed their passage. Read as a compliance statement it is wrong, because section 1(2) is explicit that commencement waits on a Cabinet proclamation.
The practical position for a business today is therefore specific, and it is neither of the two positions people usually take. It is not "Tonga has no privacy law," which was the position before December 2025 and which at least one AI research source still asserted during this project, running roughly eight months behind. It is also not "the Privacy Act is in force," which the gazettal headlines imply.
It is: the Act exists in final form, its obligations are knowable today, and the commencement date has not been set. Which is a good position to prepare in, and a bad position to be surprised by.
Six Sections That Matter to a Marketing Team
Act 34 of 2025. Passed 6 August 2025, assented 16 December 2025, commencement awaiting Cabinet proclamation.
Reaches processors established anywhere
Applies where processing relates to targeted offering of goods or services to a data subject in the Kingdom, or monitoring of their behaviour as far as it takes place within the Kingdom. Having no office in Tonga is not a defence.
Already-published information sits outside the Act
The Act does not apply to collection or processing of personal information published in a generally available publication. This is the clause that answers the public-answer monitoring question.
Cross-border transfer, with an adequacy test
Transfer out of the Kingdom needs Commission approval or an adequate safeguard: binding corporate rules, contractual clauses, a code of conduct or certification. Section 40(5) states that no determination implies neither adequacy nor inadequacy.
Direct marketing and automated decisions
A right to require processing for direct marketing to stop, actioned within 30 days, and a right not to be subject to decisions made solely by automated means.
Breach notification is deferred two years
The 72-hour notification duty to the Commission does not apply until the second anniversary of the commencement date. A grace period inside an Act that has not commenced.
Penalties, court-determined
Individuals: up to 5,000 first contravention, then the greater of 30,000 or three times the benefit obtained. Organisations and public authorities: up to 30,000 first, up to 100,000 subsequent. Stated in the Act with a currency symbol and no code.
Source: Privacy Act 2025 (Act 34 of 2025), primary text via the Attorney General's Office of Tonga, read August 2026. General information, not legal advice.
Created by Arfadia • arfadia.com/blog
The clause that reaches offshore agencies
Section 5(1)(c) is the one that changes procurement conversations.
The Act applies to a data controller or processor wherever it is established, if the processing relates to the targeted offering of goods or services to a data subject in the Kingdom, or to the monitoring of the behaviour of a data subject as far as that behaviour takes place within the Kingdom.
Run an advertising campaign targeting people in Tonga and you are inside that. Operate analytics or remarketing that tracks the behaviour of people in Tonga and you are inside it as well. It does not matter whether your servers are in Jakarta, Sydney or Frankfurt.
This structure will look familiar to anyone who has worked with European or Korean privacy law, and that is the point: Tonga has adopted a recognisable international model rather than something idiosyncratic. The practical consequence is that a provider who says "we are not in Tonga so this does not apply to us" is either unfamiliar with the statute or hoping you are.
For a Tongan business hiring an overseas agency, this is straightforwardly useful. It means the obligations follow the processing rather than the passport, so the right procurement question is about data flows and contracts rather than about where anyone's office happens to be.
The clause that makes answer monitoring workable
Section 48(1)(a) provides that the Act does not apply to the collection or processing of personal information that is already published in a generally available publication.
That is a narrow-sounding clause with a specific consequence for answer-engine work. Monitoring what an assistant says about a business, recording which public sources it cites, and tracking whether the facts are accurate involves reading material that is already published to the world. On the face of section 48(1)(a), that activity sits outside the Act's scope.
Two qualifications, both real.
First, the exemption attaches to the already-published nature of the information, not to the monitoring activity as a category. If a monitoring workflow starts storing personal details that were not in the public material, or enriching public records with private data, the exemption stops covering that part. The discipline is to keep the analytics layer free of personal identifiers rather than to collect them and rely on an exemption to excuse it afterwards.
Second, section 5(1)(c) still applies to everything else you do. An agency running both public-answer monitoring and a targeted campaign is exempt on the first and squarely in scope on the second. The exemption is clause-specific, not a general shelter.
Cross-border transfer, and a claim nobody can make
Sections 39 and 40 govern moving personal information out of Tonga. Transfer requires either the Commission's written approval or an adequate safeguard, and the Act lists the familiar mechanisms: recipient legal protections, binding corporate rules, contractual clauses, a code of conduct, a certification mechanism.
Section 40(5) is the sentence worth memorising. The absence of a determination by the Commission implies neither adequacy nor inadequacy.
So nobody can currently claim that Indonesia, or Australia, or anywhere else, has been found adequate for transfers from Tonga. There is no Commission to make such a finding, because the Act has not commenced. Anyone asserting a settled adequacy position is asserting something that does not exist. Equally, nobody can claim a country has been found inadequate. The correct position is that the safeguard route is the available one, and the contract should be written accordingly.
| Marketing activity | Position under the Act | Control that helps |
|---|---|---|
| Monitoring public AI answers and citation sets | Outside scope on the face of s48(1)(a), already-published information | Keep personal identifiers out of the analytics layer entirely |
| Publishing dated operational facts about your own business | Low exposure, generally no personal information involved | Avoid naming staff or guests without a lawful basis |
| Advertising targeted at people in Tonga | In scope under s5(1)(c) regardless of where the agency is based | Documented lawful basis, defined retention, processing agreement |
| Behavioural analytics and remarketing on Tongan visitors | In scope, monitoring behaviour within the Kingdom | Consent architecture, retention limits, transfer safeguard |
| Email marketing to a customer list | In scope. s43 gives a right to require direct marketing processing to stop | Working unsubscribe, honoured within 30 days, logged |
| Automated lead scoring or pricing decisions | s44 gives a right not to be subject to solely automated decisions | Keep a human review step and be able to evidence it |
| Sending customer data to an overseas agency or tool | s39 and s40. Adequacy or a listed safeguard. s40(5): no determination means neither adequate nor inadequate | Contractual clauses now, rather than waiting for a Commission that does not exist yet |
Penalties, and how to quote them honestly
Section 54(4) sets pecuniary penalties determined by a court. For an individual, up to 5,000 for a first contravention, and for a subsequent contravention the greater of 30,000 or three times the benefit obtained. For an organisation or public authority, up to 30,000 for a first contravention and up to 100,000 for a subsequent one.
Two honest caveats. The Act states these with a currency symbol and no currency code. Tongan legislation conventionally denominates in pa'anga, but the section itself does not say so, and we have not converted the figures or attached a code they do not carry. Separately, there is no enforcement record at all, because the Act has not commenced. Nobody can tell you how a Tongan court will approach these in practice, and any provider offering a confident view of enforcement posture is speculating.
These are also, by international comparison, modest numbers. That is worth saying rather than inflating, because the reason to prepare is not fear of a large fine. It is that the operational work required, knowing where data sits, why you hold it, how long you keep it and where it flows, is work that improves a marketing operation regardless of any regulator.
The companion legislation, and one correction
The Privacy Act arrived inside a broader package. Verified as part of the 2025 reforms: the Cybersecurity Act 2025, also awaiting Cabinet proclamation; the Personal Health Information Protection Act 2025; the Whistleblower Protection Act 2025; the Civil Registration and Digital Identification Act 2025; the Money Laundering and Proceeds of Crime Act 2025; the Consumer Protection Act 2025; and the Ocean Management Act 2025.
A correction worth recording. One research source compiled for this project listed an Electronic Transactions Act 2025 and a Computer Crimes Act 2025 as part of the package. Neither was confirmed during verification, while the Civil Registration and Digital Identification Act 2025, which that source did not mention, was. We list only what we could verify, and we are noting the discrepancy rather than quietly dropping it.
The Consumer Protection Act 2025 deserves a marketing team's attention alongside the privacy statute, since advertising claims and substantiation sit under consumer law rather than privacy law in most jurisdictions.
Five Things to Do Before Commencement
None of these require a lawyer to start, and all of them improve a marketing operation regardless of any regulator.
Map what personal data your marketing actually touches
Customer lists, booking records, enquiry forms, analytics identifiers, remarketing audiences, review responses. Most teams have never written this down, and cannot answer the first question a regulator or a client would ask.
Write down where each of those flows
Which tool, which country, under whose contract. Sections 39 and 40 turn on this, and so does any serious procurement questionnaire.
Put contractual safeguards in place now
There is no Commission to grant approval or make an adequacy determination, and s40(5) confirms silence means neither. Contractual clauses are the route that exists today.
Make unsubscribe work and log it
Section 43 creates a right to require direct marketing processing to stop, actioned within 30 days. A broken unsubscribe link is the easiest possible contravention to demonstrate.
Keep a human in any automated decision
Section 44 gives a right not to be subject to decisions made solely by automated means. Automated lead scoring or pricing needs a documented review step you can actually evidence.
Source: Privacy Act 2025 (Act 34 of 2025), primary text. Operational sequencing is Arfadia guidance. General information, not legal advice; Tongan counsel should review anything contractual.
Created by Arfadia • arfadia.com/blog
Why this sits between the search work and the answer work
Data governance is usually filed as a legal matter and then forgotten by the people generating most of the data.
Search programmes collect enquiry data, run analytics, build remarketing audiences and handle customer records. Answer-engine programmes monitor public sources, track citations and correct entity information. The first is squarely inside the Act once it commences. The second sits largely outside it under section 48(1)(a). Knowing which is which lets you scope both accurately, and it lets a Tongan business ask an overseas provider a question with a right answer.
That question is not "are you compliant with Tonga's Privacy Act." Nobody is compliant with an Act that has not commenced. The question is: which of our activities will fall inside section 5(1)(c), where does our data flow, and what safeguard are you putting in the contract. A provider who can answer those three has read the statute. One who cannot has read a summary of it.
Tessar Napitupulu writes about building visibility programmes that survive regulatory scrutiny across jurisdictions in Cited or Silent, available as a free gated edition.
Frequently Asked Questions
Is Tonga's Privacy Act 2025 in force?
Not on the evidence we could verify. Act 34 of 2025 passed the Legislative Assembly on 6 August 2025, was assented by King Tupou VI on 16 December 2025, and was gazetted with the wider 2025 reform package. Section 1(2) states it comes into force on a date proclaimed by Cabinet, and as at August 2026 we found no proclamation and no appointed Privacy Commissioner. Press coverage describing the package as in force is using journalistic shorthand for gazettal.
Does the Act apply to an agency based outside Tonga?
It can. Section 5(1)(c) applies the Act to a data controller or processor wherever established, where the processing relates to the targeted offering of goods or services to a data subject in the Kingdom, or to monitoring their behaviour as far as it takes place within the Kingdom. Running campaigns aimed at people in Tonga, or analytics tracking them, brings an overseas provider into scope regardless of where its servers sit.
Can we monitor AI answers and citations under this Act?
On the face of section 48(1)(a), yes, because the Act does not apply to collection or processing of personal information already published in a generally available publication. Two qualifications apply: the exemption attaches to the already-published nature of the information rather than to monitoring as an activity, so a workflow that starts storing personal details not present in the public material loses the cover; and section 5(1)(c) still applies to everything else you do.
What are the penalties?
Section 54(4) sets court-determined pecuniary penalties. For an individual, up to 5,000 for a first contravention, then the greater of 30,000 or three times the benefit obtained. For an organisation or public authority, up to 30,000 first and up to 100,000 subsequent. The Act states these with a currency symbol and no code; Tongan legislation conventionally denominates in pa'anga but the section does not say so, and no conversion is applied here. There is no enforcement record, because the Act has not commenced.
Has Indonesia been found adequate for data transfers from Tonga?
No, and neither has anywhere else. Sections 39 and 40 require either Commission approval or an adequate safeguard such as binding corporate rules, contractual clauses, a code of conduct or a certification mechanism. Section 40(5) states that the absence of a determination implies neither adequacy nor inadequacy. There is no Commission yet to make one, so anyone claiming a settled adequacy position is asserting something that does not exist.
When do breach notification duties start?
Section 37(11) provides that the 72-hour notification duty to the Commission does not apply until the second anniversary of the commencement date. Since commencement has not yet been proclaimed, that is a deferral inside an Act that is not yet operative. Building the incident response process earlier is still sensible, because the process takes longer to establish than the deadline allows for.
What other 2025 laws should marketing teams know about?
Verified as part of the package: the Cybersecurity Act 2025, also awaiting Cabinet proclamation, the Personal Health Information Protection Act 2025, the Whistleblower Protection Act 2025, the Civil Registration and Digital Identification Act 2025, the Money Laundering and Proceeds of Crime Act 2025, the Consumer Protection Act 2025 and the Ocean Management Act 2025. The Consumer Protection Act deserves attention alongside privacy, since advertising claims and substantiation usually sit under consumer law.
What should we do before commencement?
Map what personal data your marketing touches, write down where each item flows and under whose contract, put contractual transfer safeguards in place rather than waiting for a Commission that does not exist yet, make unsubscribe work and log it against the 30-day requirement in section 43, and keep a documented human review step in any automated decision under section 44. All of that improves a marketing operation whether or not the proclamation ever lands.
Sources & References:
- Primary source: Privacy Act 2025 (Act 34 of 2025), Kingdom of Tonga. Full text obtained from the Attorney General's Office of Tonga and read in August 2026. Passed by the Legislative Assembly 6 August 2025; assented by King Tupou VI 16 December 2025; section 1(2) provides for commencement on a date proclaimed by Cabinet.
- Commencement status: no Cabinet proclamation and no appointment of a Privacy Commissioner was located as at August 2026. Tongan press reporting in January 2026 described the gazettal of the 2025 legislative package using language suggesting the laws were in force, which conflates gazettal with commencement.
- Section 5(1)(c): applies the Act to a data controller or processor wherever established where processing relates to the targeted offering of goods or services to a data subject in the Kingdom, or the monitoring of the behaviour of a data subject as far as that behaviour takes place within the Kingdom.
- Section 48(1)(a): the Act does not apply to the collection or processing of personal information published in a generally available publication. Section 49(1)(c) provides a media organisation journalism exemption.
- Sections 39 and 40: cross-border transfer requires the Commission's written approval or an adequate safeguard, including recipient legal protections, binding corporate rules, contractual clauses, a code of conduct or a certification mechanism. Section 40(5) provides that the absence of a determination implies neither adequacy nor inadequacy.
- Section 43: right to require processing for direct marketing purposes to stop, with compliance within 30 days. Section 32(2): sensitive personal information may not be processed for direct marketing without consent. Section 44: right not to be subject to a decision made solely by automated means.
- Section 37(11): the 72-hour breach notification duty to the Commission does not apply until the second anniversary of the commencement date.
- Section 54(4): pecuniary penalties determined by a court. Individual, maximum 5,000 for a first contravention and the greater of 30,000 or three times the benefit obtained for a subsequent contravention. Organisation or public authority, maximum 30,000 first contravention and 100,000 subsequent. The Act states these figures with a currency symbol and no currency code; no conversion or code is applied here. Section 53 sets a six-year limitation. Sections 7, 10 and 11 establish the Privacy Commission and Commissioner. Sections 68 and 69 cover regulations and transitional arrangements, with the Attorney General ensuring compliance until a Commissioner is appointed.
- Companion legislation verified as part of the 2025 package: Cybersecurity Act 2025 (Act 14 of 2025, also awaiting Cabinet proclamation), Personal Health Information Protection Act 2025, Whistleblower Protection Act 2025 (Act 32 of 2025), Civil Registration and Digital Identification Act 2025, Money Laundering and Proceeds of Crime Act 2025, Consumer Protection Act 2025, Ocean Management Act 2025.
- Correction recorded: one research source compiled for this project listed an Electronic Transactions Act 2025 and a Computer Crimes Act 2025 within the package. Neither was confirmed during verification. The Civil Registration and Digital Identification Act 2025, which that source did not list, was confirmed. A separate research source asserted that Tonga has no comprehensive privacy statute and identified the Computer Crimes Act 2003 as the primary mechanism, a position roughly eight months out of date.
- This article is a compliance orientation based on the primary statutory text, not Tongan legal advice. Any contractual or operational decision involving personal data of people in Tonga should be reviewed by qualified Tongan counsel.