Country guide · Fiji

Cyber security compliance in Fiji

Fiji has no general cybersecurity statute for private organisations, and no data protection law. The binding cyber requirements that do exist come from the Reserve Bank of Fiji, which has issued detailed cybersecurity risk rules for the financial sector. A national strategy for 2026 to 2031 and a national CERT now sit alongside them. This page sets out what applies and to whom.

At a glance
  • Frameworks listed6
  • Issuing bodies4
  • Framework pages1
  • Platform languagesEnglish and Arabic
  • DeploymentSaaS, private cloud or on-premises
FijiChecked Sep 2026
What applies

Cybersecurity and data protection frameworks in Fiji

Who issues each one and who must comply. Open a framework for its structure, obligations and how GRCLens runs it.

Reserve Bank of Fiji

PSPS No. 2: Minimum Requirements for the Management of Cybersecurity Risk

Banks, credit institutions, insurers and brokers, the securities exchange, fund managers, stockbrokers, FNPF and FDB. Material cyber incidents within 24 hours

Reserve Bank of Fiji

BSPS No. 16: Minimum Requirements for the Management of Operational Risk

Licensed financial institutions, including IT, business continuity and outsourcing

Reserve Bank of Fiji

PSP SPS No. 1: Risk Management Frameworks of Licensed Payment Service Providers

Licensed payment service providers, from 31 March 2025, including penetration testing at least every three years

Parliament of Fiji

Cybercrime Act 2021

Everyone. Reported in force since November 2022

Ministry of Policing and Communications

National Cybersecurity and Resilience Strategy 2026-2031

National policy, reported as endorsed by Cabinet in February 2026. It does not itself impose obligations on businesses

ISO and IEC

ISO/IEC 27001

The reference standard most organisations in Fiji use to structure a security programme

Open the framework page →

Which cybersecurity rules apply in Fiji?

For the financial sector, the Reserve Bank of Fiji's supervision policy statements. For everyone, the Cybercrime Act 2021. There is no statute imposing cybersecurity controls on other private organisations, so most businesses outside finance structure their programme on an international standard such as ISO/IEC 27001, often because a customer or an overseas parent requires it.

What does the Reserve Bank of Fiji require?

PSPS No. 2, effective 31 March 2023, requires supervised entities to have a board-approved cyber risk management framework, a chief information security officer, a cyber strategy and policies reviewed each year. Contracts with third parties must let the Reserve Bank inspect, and material cyber incidents must be notified within 24 hours, with a quarterly incident report.

Payment service providers are not covered by PSPS No. 2. Their requirements sit in PSP SPS No. 1, issued under the National Payment System Act 2021 and effective 31 March 2025, which requires a cybersecurity strategy, penetration testing at least every three years and Reserve Bank approval before outsourcing.

Does Fiji have a data protection law?

No. The Constitution protects the right to privacy, and the National Digital Strategy commits to developing a data protection framework, but no statute has been passed. Claims of a Fijian Privacy Act 2021 are wrong. A draft National Identification Bill went to public consultation in March 2026.

Who handles cyber incidents nationally?

Fiji CERT, under the Ministry of Policing and Communications, monitors and responds to nationally significant incidents, publishes alerts and takes incident reports. Fiji also became a Party to the Budapest Convention on Cybercrime in June 2024, which supports cross-border cooperation on investigations.

How GRCLens supports organisations in Fiji

GRCLens implements the Reserve Bank's cyber risk requirements alongside ISO/IEC 27001 on one control model, so a bank or insurer evidences governance, incident handling and third-party controls once. The 24-hour notification and quarterly reporting are tracked as indicators. Organisations with an Australian or New Zealand parent can run the parent's frameworks in the same tenant. GRCLens can be hosted in the region or fully on-premises.

Questions

Cyber compliance in Fiji: common questions

Does Fiji have a data protection law?

No. The Constitution protects privacy and the government has committed to developing a framework, but no data protection statute has been enacted.

How fast must a Fiji financial institution report a cyber incident?

Within 24 hours for a material cyber incident, under the Reserve Bank of Fiji's PSPS No. 2, with a quarterly incident report.

Does APRA CPS 234 apply in Fiji?

Not as Fijian law. It reaches Fiji operations only through the obligations of an Australian parent group. Fijian requirements come from the Reserve Bank of Fiji.

Is Fiji a party to the Budapest Convention?

Yes, since June 2024.

Sources

Checked against the issuing bodies' own publications in September 2026. Regulations change, so confirm current requirements with the relevant regulator before relying on them.

Run Fiji's frameworks on one platform

See GRCLens with your own frameworks loaded. Need hands-on help? Cyber security services in Fiji and the Pacific from Security Solution Consultants.