Barbados Wants to Secure the Region’s Data. It Can’t Yet Secure Its Own.
Barbados Policy Pulse — Part 3 of 3: The Greenland Data Centre
Barbados Wants to Store the Region’s Data. It Can’t Yet Secure Its Own.
This is the third piece in a series examining the government’s plan to build a national data and green power centre in Greenland, St Andrew. The first looked at water and cooling. The second looked at pollutants and human health. This one asks the most basic question of all: can the government that will run this facility currently keep data safe?
The public record suggests the honest answer, right now, is no.
The breaches on file
In December 2022, the Queen Elizabeth Hospital suffered a cyberattack that knocked out internet-dependent services across the facility. Digitised records, lab systems, and radiology scheduling were pushed back to manual processes for weeks while the hospital’s IT team worked with outside experts to contain it (DataBreaches.net).
Almost two years later, in September and October 2024, the Barbados Revenue Authority was breached. A threat actor going by “Pryx” gained access to roughly 230 gigabytes of data, including vehicle registration records, property tax records, driver’s licences, passport numbers, phone numbers, and email addresses, some of it later listed for sale on a Russian-language hacking forum (Barbados Today). One leaked file reportedly belonged to a South Carolina driver’s licence holder, raising the possibility the exposure reached beyond Barbadian citizens. Then-Minister Marsha Caddle told the public there was no evidence the stolen data had been used for fraud, and that an incident response team drawn from the National Cybersecurity Unit and the Barbados Defence Force Cyber Unit had contained and hardened the affected systems.
Two major breaches of government-held data, at a hospital and a revenue authority, inside two years, plus an earlier mass exposure of the entire electoral register, is the baseline the Greenland data centre proposal is being built against.
The warnings that went unanswered
Niel Harper is not a bystander to this story. Barbadian-born, with roughly two decades in digital trust and cybersecurity governance at organisations including INTERPOL, the European Commission, the World Economic Forum, and the ITU, he holds a World Economic Forum Young Global Leader designation and the ISC2 Global Achievement Award (2024). He is also, by his own account and reporting in Barbados Today, someone the government has had direct access to and largely not used.
During the BRA breach, Harper said he wrote directly to Attorney General Dale Marshall and then-Minister Caddle with urgent recommendations on containment and disclosure, and separately reached out to Prime Minister Mia Mottley. He has stated he received no reply from any of the three (DataBreaches.net).
This was not the first time his input had gone nowhere. In 2023, Harper submitted detailed, structured feedback on the draft Cybercrime Bill, flagging vague offence definitions that could sweep up legitimate security researchers, and the absence of independent oversight over expanded police powers. The Attorney General publicly dismissed the concerns, telling local media the government had already considered them (Niel Harper). It’s worth noting the government did later send the Bill to a Joint Select Committee for further public input, so the criticism was not entirely without effect, even if Harper’s specific engagement wasn’t acknowledged.
In a 2024 post responding to the launch of GovTech Barbados, Harper went further, questioning the credibility of the government’s own Tier 3 National Data Centre ambitions, given that a single monopoly electricity provider serves the entire island, which he argued makes the redundancy a Tier 3 facility requires difficult to achieve cost-effectively. He also pointed to Barbados’s weak showing in the ITU’s 2024 Global Cybersecurity Index relative to other developing nations, and noted that a previously funded Barbados Computer Emergency Response Team had been staffed with equipment and office space but never actually made operational (Niel Harper).
The one that predates all of this
There’s an earlier incident that belongs in this timeline, because it shows the pattern didn’t start with the BRA or the QEH. On December 29, 2021, days after a snap election was called, the Electoral and Boundaries Commission published the full Register of Electors on the open internet: a 5,520-page document containing the name, national registration number, date of birth, gender, address, constituency, and polling station of more than 264,000 eligible voters (ISSA Barbados Chapter). It was downloadable by anyone, anywhere, not just people in Barbados. Within days it had been copied, shared on WhatsApp, and reposted to platforms like Reddit. The EBC took it down shortly after, but by then the file was already circulating well beyond its control.
Harper flagged this one too, in real time, criticising the EBC for failing to apply basic data minimisation. There was no requirement to include national registration numbers or dates of birth in a public register; the underlying law only required publication of the register itself, not every field the EBC chose to attach to it. He raised this with the EBC directly and later said the response was to be ignored, while claiming Bajan identities were subsequently being used for fraud abroad, evidenced by banks blocking Barbadian cards internationally.
The EBC’s formal position, restated more than a year later, is that this was not a data breach at all: the Representation of the People Act requires the register to be published, and the Commission argues it was simply following that legal mandate in electronic form. It also stated it had no reports or evidence of any resulting identity theft, pointing to the absence of fraud reports through the Bankers Association’s Anti-Fraud Committee and the Central Bank.
Both of those positions are worth holding up to scrutiny rather than taking at face value. First, if publishing the list truly wasn’t a problem, there was no reason to pull it down within days, an action that is hard to reconcile with the claim that nothing improper had occurred. Second, the “no evidence of identity theft” claim rests entirely on one reporting channel: fraud that gets reported to a Barbadian bank and gets traced back to this specific leak. It says nothing about identity theft committed abroad using a stolen NRN and birth date that never passes through a Barbadian financial institution at all. Absence of evidence through a single narrow channel is a considerably weaker claim than “we investigated and found nothing,” and the EBC’s public messaging did not draw that distinction.
What the government has built in response
To be fair to the administration, it has not done nothing. A National Cybersecurity Unit, co-led with the Barbados Defence Force Cyber Unit, was mobilised for the BRA incident and credited with containing and hardening the breached systems. The government has also funded a national cyber and information security awareness programme following the breach, and is running a cybersecurity training initiative aimed at placing Barbadians in cybersecurity jobs internationally, though Harper has separately criticised the terms of that programme as unrealistic given the loan structure involved.
The gap Harper’s writing keeps returning to isn’t effort. It’s follow-through: a cybersecurity working group stood up and later shut down without clear public accounting of what it learned, a CERT funded and equipped but never staffed to operate, and now a Tier 3 data centre ambition layered on top of a Cybercrime Bill process that outside experts say still needs independent oversight mechanisms.
The actual question for Greenland
None of this means Barbados cannot build a secure data centre. Physical and cyber security for a purpose-built facility is a different problem than securing decades of legacy government IT systems, and it’s entirely possible to get one right while the other remains a work in progress. New infrastructure, built with security requirements specified from day one, is generally easier to secure than retrofitting old systems.
But that is exactly the case the government hasn’t yet made publicly. What we have on the record is three significant data incidents across four years, a documented pattern of ignoring input from the most credentialed Barbadian voice in the field, on the legislation, the electoral list, and the BRA breach itself, and skepticism from that same expert about whether a Tier 3 data centre is realistic given the island’s existing power and cybersecurity infrastructure. If the government wants the public to trust it with a facility meant to hold not just its own data but potentially regional and private-sector data too, the credible next step is to show, specifically, how this project’s security architecture and oversight will differ from what failed at the BRA and the QEH, not simply assert that it will.
