- Nine government phones discarded still contained confidential official data.
- 479 ICT devices across three entities lacked proper disposal records.
- eGovJa’s 265 devices had no documented sanitization before disposal.
- PTD disposed of 171 devices without maintaining any security records.
- No government-wide policy existed for secure ICT equipment disposal.
- All three entities accepted audit recommendations and pledged corrective action.
Read the full audit report from the Auditor General’s Department →
An audit by Jamaica’s Auditor General has found that three public sector bodies discarded hundreds of computers, servers, and mobile phones without adequately removing the sensitive data stored on them — raising the prospect that confidential government information, and potentially personal details of ordinary Jamaicans, could fall into unauthorized hands. The findings expose a systemic failure stretching across the Ministry of Science, Energy and Technology, the government’s own IT services company, and the Post and Telecommunications Department, and reveal that no government-wide policy existed to prevent it.
When a government office upgrades its computers or retires an old mobile phone, the expectation — and the legal and ethical obligation — is that any sensitive data stored on those devices is securely erased before the equipment leaves official custody. That expectation, the Auditor General of Jamaica has found, was not being met at three significant public sector entities. The result was a systemic exposure of confidential government information at the point where ICT equipment met the disposal bin.
The Information Technology audit, published in December 2018, examined disposal practices at the Ministry of Science, Energy and Technology (MSET), eGov Jamaica Limited (eGovJa), and the Post and Telecommunications Department (PTD). Across all three, auditors identified a combined 479 devices — laptops, desktops, servers, networking equipment, and mobile phones — that were marked for or had been disposed of without adequate controls to protect the data they once held. At the heart of every finding was the same failure: government bodies were releasing physical hardware without being able to demonstrate, through any documented evidence, that the information stored on it had been removed.
The most vivid illustration of what that failure means in practice came at MSET. Among 30 mobile phones identified for disposal, 15 received no form of data sanitization at all. Of those 15, nine were examined and found to still contain confidential data — official emails, messages, contact lists, images, and videos. A further six phones could not be examined at all because they had been locked by third-party applications, meaning their contents remained unknown and unverifiable. In plain terms: government phones carrying real official information were on their way out of secure custody without anyone having wiped them.
For ordinary Jamaicans, the significance of that finding depends on what those phones carried. Official emails between ministry staff and members of the public, for instance, can include personal details — names, addresses, identification numbers, the substance of complaints or requests. Images and videos on government devices may record site visits, inspections, or meetings where sensitive policy discussions took place. The audit does not specify precisely what categories of citizen data appeared on those nine phones, but the nature of ministry work means the risk of personal exposure was real and should not be dismissed as abstract.
Beyond the phones, MSET also had 43 laptops and desktops flagged for disposal with no documented disposal or data sanitization records to account for them. When auditors looked at the ministry’s broader access control practices, they found compounding vulnerabilities: active user accounts and administrator accounts operated without any requirement to change passwords periodically, and users were free to reuse old passwords or create weak ones that failed basic security standards. These are not minor administrative oversights. They are the building blocks of a security culture that treats digital information as less valuable than the physical property it is stored on.
eGov Jamaica Limited presents a different but equally serious dimension of the problem. As the government’s designated IT services provider — the entity tasked with delivering e-government platforms that Jamaicans interact with — eGovJa’s own internal security practices carry a particular weight. Yet auditors found that 265 devices, spanning laptops, desktops, servers, and networking equipment, lacked documented disposal procedures. Servers and networking equipment are not ordinary office tools. They can hold databases, application logs, authentication credentials, and the transactional records of systems that government and citizens rely upon daily. The absence of documentation means there is no assurance, and no audit trail, confirming that the data those machines once processed was ever neutralized.
eGovJa’s password policy failures reinforced the picture. Password complexity controls were disabled entirely, and minimum password length requirements sat below what industry standards demand. For an organization whose core mandate is the security and delivery of digital government services, that is a striking gap between institutional purpose and institutional practice. The entity responsible for helping Jamaica build a modern, secure digital government was itself operating without some of the most basic security configurations in place.
At the Post and Telecommunications Department, 171 devices were identified as having been disposed of without maintained security records or any documented evidence of data sanitization. PTD’s role in managing postal and telecommunications services means it handles information relating to correspondence, licensing, and regulated services — data with both commercial sensitivity and potential personal implications. The scale of the lapse at PTD, 171 devices, is the largest of the three entities by raw number, and the absence of any maintained security records makes it impossible to reconstruct what those devices contained or where they ended up.
The Auditor General identified a set of structural causes that cut across all three entities. None of them had formal written procedures for ICT equipment disposal. None maintained systems for independent verification that residual data had been removed before equipment left official control. In some cases, entities relied on unverified assurances that a low-level format had been performed — without documentation, and without understanding that a low-level format does not meet the standard required for secure data destruction. In the wrong hands, improperly formatted storage media can be recovered with freely available tools.
Underpinning all of this was a structural vacuum at the highest level of government: there was no overarching government-wide policy governing how public sector entities should securely dispose of ICT equipment. Each entity was, in effect, left to develop its own approach — and where approaches existed at all, they were demonstrably inadequate. That absence of central policy guidance is not a technical failure. It is a governance failure. When government does not set clear standards, entities default to whatever is convenient, and convenience rarely aligns with security.
The implications reach beyond data security in the narrow technical sense. Jamaica’s public institutions handle information that shapes the everyday lives of its citizens — records of land transactions and housing applications, health data from clinic systems, the personal particulars submitted with business licences, the details of tax filings, the contents of correspondence routed through postal services. The government’s own IT systems connect these services. When the entities responsible for running or supporting those systems cannot demonstrate that decommissioned equipment was securely sanitized, every person whose information ever passed through those systems has a legitimate reason to ask whether their data remained protected.
Businesses operating in Jamaica should also take note. Government IT entities are the custodians of procurement records, licensing databases, and commercial correspondence. Entrepreneurs, contractors, and investors who have transacted with government agencies expect that their commercial information is handled with care — not inadvertently released on a discarded hard drive or forgotten on an unlocked phone.
The audit also has implications for Jamaica’s broader ambitions around digital transformation and e-government. Public trust in digital government services depends, in part, on public confidence that the institutions running those services take data protection seriously. Findings of this nature — published by an independent constitutional body — can erode that trust in ways that are difficult to rebuild, particularly when the entity with the most direct responsibility for digital government infrastructure is among those found deficient.
The Auditor General recommended that all three entities implement formal, documented data sanitization procedures; maintain evidence of sanitization activities as a matter of routine; configure access control and password management systems in line with established security policy standards; and establish independent verification mechanisms for the disposal process. The recommendations are grounded in widely accepted information security practice and do not require extraordinary resources — they require discipline, documentation, and institutional will.
All three entities accepted the recommendations in full and committed to implementing corrective measures, improving their documentation practices, and configuring their systems to comply with security policy standards. That acceptance is a necessary first step. Whether the commitments translate into durable institutional change is a question that subsequent audits, and continued public scrutiny, will need to answer.
What the audit ultimately demonstrates is that Jamaica’s public sector has been managing the end-of-life of its digital assets with the same informality that might characterize disposing of old furniture. Hardware carries data. Data carries risk. The routine decommissioning of government computers and phones is not a clerical afterthought — it is the final stage of a data lifecycle that began the moment a public servant logged in for the first time. Treating it as anything less creates the conditions for exactly the kind of exposure the Auditor General found.
The case for a government-wide ICT disposal policy is made plainly by these findings. Without central standards, individual entities will continue to develop patchwork approaches that leave gaps. A national framework setting mandatory sanitization methods, documentation requirements, independent verification steps, and consequences for non-compliance would address the structural vacuum that allowed these failures to develop across three separate institutions simultaneously. Until such a framework exists and is actively enforced, the risk of government data leaving official custody on insufficiently sanitized hardware will remain a feature, not an aberration, of how Jamaica manages its public sector ICT estate.
Jamaica Accountability Watch is an independent editorial series by Jamaica Homes News examining what government audit reports reveal about the management of public money. Source: Auditor General’s Department of Jamaica.
Follow Jamaica Homes on Youtube @jamaicahomes and Instagram @jamaica_homes and on Facebook @jamaicahomesnews Send us a message or email us at onlinefeedback@jamaica-homes.com or editor@jamaica-homes.com
Support independent Jamaican journalism.
- 1Our journalists cover housing, politics and community — stories that directly affect Jamaican lives.
- 2We have no billionaire owner and no advertisers calling the shots. Every story is decided by our editors.
- 3It costs less than a cup of coffee a week, and takes less time to subscribe than it took to read this article.
Support Jamaica Homes News today.
- Save 17% compared to monthly
- All articles unlocked
- Weekly newsletter
- Priority support
By subscribing you agree to our Privacy Policy and Terms.


Visit our YouTube Community ↗