Statement of Guidance
Guidance on Employee Vaccination Status (October 2021)
Status not confirmedView on OMBUDSMAN's website Source document
Summary
This is a data protection guidance note from the Cayman Islands Ombudsman explaining how employers should handle checks of employee COVID-19 vaccination status under the Data Protection Act (DPA). It applies to any employer considering or conducting vaccination status checks, including in connection with mandatory checks for work permit holders. The guidance sets out how the eight data protection principles apply to this type of processing, focusing on legal basis, sensitive personal data conditions, purpose limitation and data minimization.
- Written policy: Employers considering vaccination status checks should create a written policy explaining how checks will be conducted and what the data will be used for, and should also consider employment law, health and safety requirements, and equality and human rights implications.
- Legal basis: Employers must identify a lawful basis under Schedule 2 of the DPA before processing vaccination status data; for work permit purposes this is likely a legal obligation basis, but employers have no automatic right to reuse this data for their own purposes.
- Sensitive personal data condition: Because vaccination status is sensitive personal data, employers must also satisfy a Schedule 3 condition (such as a legal obligation connected with employment); if no such condition can be met, the data cannot be collected. Consent is generally unlikely to be valid given the employment power imbalance.
- Purpose limitation: Data collected for one purpose (e.g. work permit applications) must not be used for an incompatible purpose without proper justification and disclosure in a privacy notice.
- Data minimization: Employers should first consider alternatives to collecting personal data (e.g. social distancing, PPE, remote work) and, if collection is necessary, gather only the minimum data required (e.g. recording that a check occurred rather than retaining a vaccine certificate copy).
- Other data handling principles: Any vaccination status data collected must be kept accurate and up to date, stored securely, kept confidential with limited access, and retained only as long as necessary.
The note is explanatory guidance rather than binding legislation itself, but it reiterates existing obligations under the Data Protection Act that apply whenever employers process employee vaccination status information.
Key obligations
- Employers who check employee vaccination status must comply with all eight data protection principles under the DPA.
- Employers must establish a lawful basis under Schedule 2 of the DPA before processing vaccination status data.
- Employers must satisfy a Schedule 3 condition for processing sensitive personal data before collecting vaccination status information, and must not collect it if no condition can be met.
- Employers must provide employees with a written privacy notice or similar communication specifying the purpose of collecting vaccination status data.
- Employers must not use vaccination status data collected for one purpose (e.g. work permit applications) for an incompatible purpose.
- Employers must apply data minimization, collecting only the minimum vaccination status data necessary and considering alternatives before collecting personal data.
- Employers must keep collected vaccination status data accurate, securely stored, confidential with limited access, and retained only as long as necessary.
Applies to
employers