Skip to main content
All insights
Security5 min readUpdated August 30, 2026

Customer Data Privacy Basics for Small Businesses in Guyana

The short answer

Customer data privacy starts with collecting only what you need, explaining why you need it, storing it securely, limiting who can access it, not sharing it casually, and deleting it when it is no longer needed. Guyana has its own law on this, the Data Protection Act, Act No. 18 of 2023, which sets out that personal data must be processed lawfully, fairly, and transparently, collected for specified purposes, kept accurate, and held securely. As of May 2026, the most recent public confirmation, the Act had not been brought into force, because the commencement order had not been issued, although a Data Protection Commissioner took up the post in January 2026. This is not legal advice, and regulated businesses should get professional guidance, but these habits reduce risk and build customer trust.

By Timothy Indarsingh, Founder & CEO, Firelinkx

As more Guyanese businesses move enquiries, forms, bookings, payments, and customer records online, they collect more information than before. Names, phone numbers, addresses, ID copies, health details, payment records, job photos, and messages can all become sensitive depending on the business. Privacy is a trust topic as much as a legal one.

This is general guidance

This article is not legal advice. If you handle health, financial, legal, children's, employee, or cross-border customer data, confirm your obligations with a qualified professional. The practical habits below are still a sensible starting point for most small businesses.

Guyana's Data Protection Act 2023

Guyana has its own data protection law on the books. The National Assembly passed it on 9 August 2023 and it was gazetted on 16 August 2023 as the Data Protection Act, Act No. 18 of 2023. The Act regulates how personal data is collected, kept, processed, used, and shared, and it defines personal data as information relating to an identified or identifiable person.

The status matters for how you plan. As of April 2026 the Act had not been brought into force, because the commencement order that would activate it had not been issued. A Data Protection Commissioner, Aneal Giddings, took up the post with effect from January 2026, and in May 2026 the Commissioner wrote that the Data Protection Office was still being formally established, which is the most recent public confirmation. So the law exists and the office is being stood up, but the date enforcement begins is still to be set. Check the current position before you rely on it.

The principles in the Act are already clear enough to design around. Section 4 of the Act as gazetted sets out that personal data must be processed lawfully, fairly, and in a transparent manner, collected for specified, explicit, and legitimate purposes, limited to what is necessary for those purposes, kept accurate and up to date, kept in a form that identifies people no longer than those purposes need, and processed with appropriate security. The Act defines consent as a freely given, specific, informed, and unambiguous indication of the person's wishes, and section 7 gives that person the right to withdraw it at any time. Section 4 also makes a failure to meet its requirements an offence.

The habits below are the same principles in working form. Collecting less, explaining what data is for, storing it securely, limiting access, and deleting what you no longer need line up with what the Act asks. Building them now protects your customers today and shortens the work when the commencement order arrives. If you handle sensitive categories of data or process it on behalf of a public body, get the detail confirmed against the Act itself by a qualified professional.

Collect less

The safest data is the data you never collect. Do not ask for ID numbers, addresses, dates of birth, or documents unless you actually need them for the service. A contact form for a simple enquiry may only need a name, contact method, and message. Every extra field creates another thing to protect.

Explain what the data is for

Customers should not be surprised by how their information is used. If you collect a phone number to confirm an appointment, use it for that purpose. If you plan to send marketing messages later, say so and give people a way to opt out. Plain explanations build more trust than long legal pages nobody understands.

Store it somewhere safer than chat

WhatsApp and email are convenient, but they are poor long-term filing systems for sensitive customer data. Important records should live in a system with access controls, backups, and a clear owner. That might be a CRM, booking system, client portal, or secure shared drive, depending on the business.

Limit access

  • Give staff access only to the information they need for their role.
  • Remove access when someone leaves or changes role.
  • Use strong passwords and two-factor authentication on important accounts.
  • Avoid sharing one login across the whole team.
  • Keep customer files out of personal phones and personal email where possible.

Have a deletion habit

Many small businesses keep customer data forever because nobody decided when to delete it. Set a simple rule: keep what you need for service, warranty, accounting, or legal reasons, then delete or archive what no longer has a purpose. Old files are still a risk if they leak.

Where this meets cybersecurity

Privacy and security are different, but they overlap. Privacy is about what information you collect and how you use it. Security is about protecting it from being lost, stolen, or misused. A business that collects less, controls access, keeps backups, and trains staff is already ahead of many problems. For the technical side, read cybersecurity basics for small businesses.

Frequently asked questions

Does Guyana have a data protection law?

Yes. The Data Protection Act, Act No. 18 of 2023, was passed by the National Assembly on 9 August 2023 and gazetted on 16 August 2023. It regulates how personal data is collected, kept, processed, used, and shared, sets conditions for consent, and creates a Data Protection Office headed by a Commissioner. As of May 2026, the most recent public confirmation, the Act had not been brought into force, because the commencement order had not been issued. A Data Protection Commissioner took up the post with effect from January 2026 and the office was still being established, so confirm the current position before relying on it.

What customer data should a small business avoid collecting?

Avoid collecting anything you do not need to provide the service: unnecessary ID numbers, home addresses, dates of birth, sensitive documents, or personal details. If a simpler contact field will do, use the simpler field. Less data means less risk.

Is WhatsApp safe for customer information?

WhatsApp is useful for conversation, but it should not be your only filing system for important or sensitive customer records. Move important details into a controlled business system, CRM, booking tool, portal, or secure storage with proper access and backups.

Do I need a privacy policy on my website?

If your website collects personal information through forms, bookings, payments, analytics, or accounts, a privacy policy is sensible. It should explain what you collect, why, how people can contact you, and how the information is handled. For regulated or sensitive data, get professional guidance.

Want your security gaps checked?

Firelinkx helps businesses collect customer information in cleaner, safer ways instead of leaving it scattered across messages and spreadsheets.

WhatsApp Us