Statement of Guidance
Data Protection - Guidance on Monetary Penalty Order Methodology
Status not confirmedView on OMBUDSMAN's website Source document
Summary
This guidance from the Cayman Islands Office of the Ombudsman explains the internal methodology and tools used to decide whether to issue a Monetary Penalty Order (MPO) under section 55 of the Data Protection Act (2021 Revision), and how the amount of any penalty (up to $250,000) is calculated. It supplements the broader Guidance on Monetary Penalty Orders issued under section 56 of the DPA and describes two calculation tools used by the Ombudsman.
- Breach Severity Assessment Tool: A spreadsheet based on ENISA methodology that scores a breach on type of data, ease of identification of individuals, and circumstances of the breach, producing a Low, Medium, High or Very High severity rating that informs (but does not automatically determine) the Ombudsman's decision.
- Matrix for Monetary Penalty Calculation: A matrix based on the UK ICO's methodology that combines the seriousness of the contravention (from the severity score) with the data controller's level of culpability (none/low, negligent, intentional) to set a starting penalty amount, ranging from $5,000 to $225,000.
- Aggravating and mitigating adjustments: The starting penalty is then adjusted using factors such as whether vulnerable individuals or children were affected, whether the breach was a one-off or repeated, its duration, remedial steps taken, willingness to offer compensation, and cooperation with the Ombudsman, plus discretionary factors like the controller's size, resources, and financial hardship.
- Threshold for penalties: Only breaches scoring high or very high severity (3.0 or above) are likely to attract a monetary penalty, though exceptions may occur depending on context.
- Notice of Intent: The specific factors and scoring applied to a given infringement are set out in the Notice of Intent sent to the data controller under sections 55(5) to (7) of the DPA.
The document is explanatory rather than obligation-creating: it does not itself impose new duties on data controllers, but clarifies how existing DPA enforcement powers will be exercised, including that a data controller will be held accountable for the actions of any data processor it has engaged.
Applies to
data controllers