Statement of Guidance

Data Protection Act (2021 Revision) - Guide for Data Controllers (v1.05)

Cayman Islands Office of the Ombudsman (OMBUDSMAN) · Cayman Islands

In force

Published: 2023-05-05

Current version last checked: 2026-07-30

Summary

This is a lengthy, non-binding guidance document issued by the Office of the Ombudsman (Cayman Islands' data protection supervisory authority) explaining how it interprets the Data Protection Act (2021 Revision). It is aimed at data controllers and walks through key definitions, the eight data protection principles, data subject rights, and the roles and obligations of data controllers and data processors.

  • Scope: Explains who counts as a data controller or data processor, what personal data and sensitive personal data are, and when the DPA applies (including need for a local representative).
  • Eight data protection principles: Covers fair and lawful processing, purpose limitation, data minimisation, accuracy, storage limitation, respect for individuals' rights, security (integrity and confidentiality), and international transfers.
  • Data subject rights: Describes the right to be informed, right of access, rectification, restriction of processing, objection to direct marketing, rights around automated decision-making, and the right to complain and seek compensation.
  • Processor obligations: Sets out what should be in data processing agreements and the direct statutory responsibilities of data processors, including acting only on documented instructions, security, cooperation with the Ombudsman, record-keeping, and breach notification to the controller.
  • International transfers: Explains restrictions on transferring personal data outside jurisdictions with adequate protection and what safeguards or authorisations the Ombudsman will accept.

As guidance, the document itself is not legally binding but is issued under sections 34(1) and 41 of the DPA to explain how the Ombudsman will likely interpret and apply the Act's provisions; the underlying obligations derive from the DPA itself. The current version (v1.05, May 2023) removed a previously stated threshold for reporting personal data breaches so that guidance aligns with section 16 of the DPA.

Key obligations

  • Data controllers must comply with the eight data protection principles (fair and lawful processing, purpose limitation, data minimisation, accuracy, storage limitation, respect for individuals' rights, security, and international transfer restrictions).
  • Data controllers must have a written contract with any data processor that includes terms required by Schedule 1, Part 2, paragraph 3 of the DPA, addressing matters such as confidentiality of staff, sub-processor approval, assistance with data subject rights, breach notification and deletion/return of data at contract end.
  • Data processors must act only on the documented instructions of the data controller and must not use a sub-processor without the controller's prior written authorisation.
  • Data processors must cooperate with the Office of the Ombudsman, ensure the security of their processing, document their processing activities, and notify personal data breaches to the data controller without delay.
  • Data controllers must be able to demonstrate compliance with the security (integrity and confidentiality) principle, including appropriate technical and organisational measures.
  • Data controllers must respond to data subjects exercising rights such as access, rectification, restriction of processing, and objection to direct marketing.
  • Data controllers must ensure any international transfer of personal data outside jurisdictions with adequate protection is supported by approved safeguards or an Ombudsman authorisation.

Applies to

data controllers, data processors, public authorities, private organisations processing personal data

Topics

Version history

2026-07-30

source file (current)