Statement of Guidance

Data Protection Act (2021 Revision) - Guidance on Monetary Penalty Orders

Cayman Islands Office of the Ombudsman (OMBUDSMAN) · Cayman Islands

Status not confirmed

Published: 2019-11-07

Current version last checked: 2026-07-30

Summary

This is guidance issued by the Ombudsman under section 56 of the Data Protection Act (2021 Revision), explaining when the Ombudsman will consider imposing a Monetary Penalty Order (MPO) on a data controller and how the amount of any penalty will be determined. It does not create new powers but clarifies how existing powers under sections 44-47 and 55 of the DPA will be exercised.

  • Trigger for an MPO: The Ombudsman may issue an MPO where satisfied, on the balance of probabilities, that a data controller has seriously contravened the DPA and the contravention was likely to cause substantial damage or distress to a data subject.
  • Penalty cap: An MPO cannot exceed $250,000 and is paid into general government revenue; payment must be made within the period stated in the order.
  • Pre-order process: Before issuing an MPO, the Ombudsman must serve a notice of intent, giving the data controller 21 calendar days to make representations on whether an MPO should be imposed and on the proposed amount.
  • Aggravating factors: Factors making an MPO more likely include the seriousness, intentionality or negligence of the breach, prior infringements, financial gain from the breach, and whether the breach should have been apparent to a reasonably prudent controller.
  • Mitigating factors: Factors making an MPO less likely include circumstances outside the controller's control, prior compliance, cooperation with the Ombudsman, self-reporting, adherence to approved codes of practice, and mitigating action taken.
  • Penalty amount factors: In setting the amount, the Ombudsman will weigh the nature and number of individuals affected, whether vulnerable individuals were involved, duration and repetition of the breach, steps taken to prevent or remedy it, cooperation, sector and resources of the controller, and evidence of genuine financial hardship.
  • Non-compliance consequence: A data controller who fails to comply with an MPO (absent a successful judicial review) commits an offence, punishable on conviction by a fine of $100,000, imprisonment of up to five years, or both.
  • Judicial review: A data controller may seek judicial review of an MPO within 45 days of receiving it.

The guidance is aimed at data controllers subject to the DPA and sets expectations for how enforcement discretion will be exercised, rather than imposing new substantive compliance requirements beyond those already in the Act.

Key obligations

  • A data controller served with a notice of intent must make any representations on the proposed MPO and its amount within 21 calendar days.
  • A data controller subject to an MPO must pay the penalty within the period specified in the order.
  • A data controller who wishes to challenge an MPO must seek judicial review within 45 days of receipt.
  • Failure to comply with an MPO (without successful judicial review) exposes the data controller to prosecution, with a fine of up to $100,000 and/or imprisonment of up to five years.

Applies to

data controllers

Deadlines

  • 21 calendar days: Period within which a data controller must make representations after receiving a notice of intent to issue an MPO.
  • 45 days: Period within which a data controller may seek judicial review of an MPO after receiving it.

Topics

Version history

2026-07-30

source file (current)