Statement of Guidance

Data Protection - Guidance on Monetary Penalty Order Methodology

Cayman Islands Office of the Ombudsman (OMBUDSMAN) · Cayman Islands

Status not confirmed

Published: 2021-09-03

Current version last checked: 2026-07-30

Summary

This guidance from the Cayman Islands Office of the Ombudsman explains the internal methodology and tools used to decide whether to issue a Monetary Penalty Order (MPO) under section 55 of the Data Protection Act (2021 Revision), and how the amount of any penalty (up to $250,000) is calculated. It supplements the broader Guidance on Monetary Penalty Orders issued under section 56 of the DPA and describes two calculation tools used by the Ombudsman.

  • Breach Severity Assessment Tool: A spreadsheet based on ENISA methodology that scores a breach on type of data, ease of identification of individuals, and circumstances of the breach, producing a Low, Medium, High or Very High severity rating that informs (but does not automatically determine) the Ombudsman's decision.
  • Matrix for Monetary Penalty Calculation: A matrix based on the UK ICO's methodology that combines the seriousness of the contravention (from the severity score) with the data controller's level of culpability (none/low, negligent, intentional) to set a starting penalty amount, ranging from $5,000 to $225,000.
  • Aggravating and mitigating adjustments: The starting penalty is then adjusted using factors such as whether vulnerable individuals or children were affected, whether the breach was a one-off or repeated, its duration, remedial steps taken, willingness to offer compensation, and cooperation with the Ombudsman, plus discretionary factors like the controller's size, resources, and financial hardship.
  • Threshold for penalties: Only breaches scoring high or very high severity (3.0 or above) are likely to attract a monetary penalty, though exceptions may occur depending on context.
  • Notice of Intent: The specific factors and scoring applied to a given infringement are set out in the Notice of Intent sent to the data controller under sections 55(5) to (7) of the DPA.

The document is explanatory rather than obligation-creating: it does not itself impose new duties on data controllers, but clarifies how existing DPA enforcement powers will be exercised, including that a data controller will be held accountable for the actions of any data processor it has engaged.

Applies to

data controllers

Topics

Version history

2026-07-30

source file (current)