Form

Data Protection - Breach Notification Form

Cayman Islands Office of the Ombudsman (OMBUDSMAN) · Cayman Islands

Status not confirmed

Published: 2021-10-18

Current version last checked: 2026-07-30

Summary

This is the standard form issued by the Office of the Ombudsman for reporting personal data breaches under section 16 of the Data Protection Act (2021 Revision). Data controllers use it to notify the Ombudsman of a breach, describe its scope and cause, assess risk to affected individuals, and record mitigation steps taken or proposed.

  • Contact and risk details: Requires organisation and contact information, plus details of when the breach occurred, when it was discovered, and how.
  • Impact assessment: Requires the nature and cause of the breach, number and categories of data subjects affected, categories of personal data involved, and likely consequences for those individuals.
  • Mitigation: Requires description of measures already taken and further measures proposed to address the breach, and measures recommended to affected data subjects.
  • Data subject notification: Requires confirmation of whether affected data subjects have been notified in accordance with section 16(1)(a)-(d) of the Act, with a copy of that notification, or an explanation if not yet done.

The guidance notes accompanying the form state that data controllers must submit this breach notification to the Ombudsman, and notify affected data subjects, no later than 5 calendar days after they should, with due diligence, have become aware of the breach. If full details are not yet available, the controller must explain this and indicate when further information will follow.

Key obligations

  • Data controllers must submit a personal data breach notification to the Ombudsman no later than 5 calendar days after they should, with due diligence, have become aware of the breach
  • Data controllers must notify affected data subjects of the breach in accordance with section 16(1)(a)-(d) of the Data Protection Act (2021 Revision)
  • If full details of the breach cannot yet be provided, the controller must explain why and indicate when further information will be submitted
  • Controllers must provide a copy of the notification given to affected data subjects, and any other supporting documentation, with the form

Applies to

data controllers

Deadlines

  • 5 (calendar) days after you should, with the exercise of due diligence, have been aware of the breach: Deadline for a data controller to submit the personal data breach notification to the Ombudsman and affected data subjects under section 16(1) of the Data Protection Act (2021 Revision)

Topics

Version history

2026-07-30

source file (current)