Cayman Islands

data protection

128 Cayman Islands regulatory document(s) tagged data protection.

Practice-note overview · reflects instruments as at 2026-07-30. Generated from the indexed documents below and human-reviewed — not legal advice.

Who is caught

The Data Protection Act (2021 Revision), supplemented by the Data Protection Regulations 2018, is the Cayman Islands' primary data protection regime, administered and enforced by the Office of the Ombudsman. It applies principally to data controllers, but imposes direct duties on processors and reaches organisations established outside the Islands in defined circumstances.

Who is caught

  • Local controllers: Data controllers established in the Cayman Islands whose processing of personal data occurs in that context.
  • Overseas controllers: Data controllers established elsewhere but processing personal data in the Islands, other than personal data merely transiting through.
  • Local representative: An overseas controller processing personal data in the Islands must nominate a local representative, who bears all obligations under the Act as if it were the controller itself.
  • Data processors: The Ombudsman's guidance describes direct statutory responsibilities on processors, including acting only on documented instructions, security, record-keeping and breach notification to the controller.
  • Public authorities: Public authorities process personal data as controllers and, under section 40, must consult the Ombudsman before adopting measures or rules affecting personal data processing.

Data protection obligations also recur across CIMA-regulated sectors. Company management licensees must process records-related personal data in accordance with the Data Protection Act, the Cybersecurity Rule requires data protection to be built into an entity's cyber framework, and virtual asset service providers are expected to protect customer data. Employers processing employee data (for example vaccination status) are likewise subject to the Act.

Sources: Freedom of Information (General) Regulations (2021 Revision) · Statement of Principles – Conduct of Virtual Asset Services (February 2021) · Rule - Cybersecurity for Regulated Entities (April 2023) · Rule and Statement of Guidance - Nature, Accessibility, and Retention of Records for Licensees Conducting the Business of Company Management · Rule and Statement of Guidance – Nature, Accessibility, and Retention of Records for Licensees Conducting the Business of Company Management · Rule - Virtual Asset Custodians and Virtual Asset Trading Platforms (December 2024) · Data Protection Act (2021 Revision) · Data Protection Regulations, 2018 (SL 17 of 2019) · Data Protection Act (2021 Revision) - Guide for Data Controllers (v1.05) · Data Protection Act (2021 Revision) – Section 40 Guidelines · Guidance on Employee Vaccination Status (October 2021)


Key duties

The core continuing duty is compliance with the data protection principles for all personal data processed, together with specific, deadline-bound obligations on subject rights and breach handling. The duties below lead with those that recur across the enforcement record and carry fixed timeframes.

Data protection principles

  • Eight principles: Controllers must comply with, and ensure compliance by those processing on their behalf with, the data protection principles: fair and lawful processing, purpose limitation, data minimisation, accuracy, storage limitation, respect for individuals' rights, security, and international transfer restrictions.
  • Privacy notice: Controllers must inform individuals of the controller's identity and the purposes of processing, generally via a privacy notice at the point of collection.

Subject access and other rights

  • Access requests: Controllers must respond to a written subject access request within 30 days, subject to identity verification, and generally free of charge.
  • Time extension: The response time may be extended by up to 30 days in specified circumstances, and beyond 30 days only with the Ombudsman's permission; the data subject must be told the reason and when a final response will be given.
  • Fees and refusals: A reasonable fee may be charged, or a request refused with reasons, only where it is manifestly unfounded or excessive; the controller bears the burden of proving this.
  • Complaint rights: On receiving a section 8 request, the controller must tell the data subject of their right to complain to the Ombudsman.
  • Stop processing: Controllers must comply with a valid request to cease processing, including an absolute right to stop direct marketing, unless they apply to the Ombudsman within 21 days of a cessation request and obtain approval not to comply.
  • Correction and erasure: Controllers must comply with rectification, blocking, erasure or destruction requests.

Breach notification

  • Section 16 notification: Controllers must notify the Ombudsman and affected data subjects of a personal data breach without undue delay and, per the enforcement orders indexed here, no later than five days after becoming aware of it.

Processor contracts and transfers

  • Processor agreements: Controllers must have a written contract with any data processor containing the terms required by Schedule 1, Part 2, paragraph 3 of the Act, covering matters such as staff confidentiality, sub-processor approval, breach notification and return or deletion of data.
  • International transfers: Transfers of personal data outside the Islands must satisfy a Schedule 4 exception or otherwise comply with the eighth data protection principle, supported by approved safeguards or an Ombudsman authorisation.

Public authority consultation

  • Section 40: Public authorities must consult the Ombudsman on the content of new or amended legislation, codes of conduct or practice affecting personal data processing before those measures come into force, using the section 40 consultation form.

Sources: Data Protection Act (2021 Revision) · Data Protection Regulations, 2018 (SL 17 of 2019) · Data Protection Act (2021 Revision) - Guide for Data Controllers (v1.05) · Data Protection Act (2021 Revision) - Guide for Data Subjects · Data Protection Act (2021 Revision) – Section 40 Guidelines · Enforcement Order - Ministry of Planning, Agriculture, Housing, Infrastructure, Transport and Development (2024-11-01) · Enforcement Order 202100222 - Betty Boo Real Estate Sales (2023-04-27) · Credit Union sends invitation without using BCC (2022-06-28) · Direct marketing by hotel (2021-05-12) · Enforcement Order 201900212 (2021-03-18)


Exemptions and carve-outs

The Act and Regulations provide a range of subject-matter exemptions, and case outcomes confirm territorial limits on the Ombudsman's reach.

  • Statutory exemptions: The Act sets out specific exemptions for national security, crime and government fees, health, education and social work, journalism, literature and art, research and statistics, legal proceedings, corporate finance, negotiations, legal professional privilege and trusts, and others set by regulation.
  • Health records: Personal data whose release could cause mental or physical harm are exempt from subject information provisions, subject to consultation with an appropriate health professional where the controller is not one.
  • Educational records: Educational records are exempt from section 8 disclosure in certain circumstances, including risk of serious harm, certain parental requests, abuse-risk information, and exam questions within twelve months.
  • Social work: Personal data processed by public authorities or courts in specified social work, welfare, housing or family and child proceedings contexts are exempt where disclosure could cause serious harm or was given in confidence.
  • International cooperation transfers: Transfers between intelligence or regulatory agencies for international cooperation are limited to disclosures permitted or required under a Cayman Islands enactment or a Grand Court order.
  • Territorial limits: Where data is not processed in the Cayman Islands and the controller is not established there, the matter falls outside the Ombudsman's jurisdiction.

Sources: Data Protection Act (2021 Revision) · Data Protection Regulations, 2018 (SL 17 of 2019) · Artist's Profile on Art Website (2019-12-05)


Enforcement and penalties

The Ombudsman holds the investigative and enforcement powers under the Act. Enforcement in the indexed orders has combined corrective directions with, in serious cases, monetary penalties, and non-compliance can amount to a criminal offence.

Ombudsman powers

  • Orders and search: The Ombudsman can receive complaints, issue information orders and enforcement orders (for example requiring policies, training, remediation or cessation of a practice), and enter and search premises under warrant.
  • Monetary penalty orders: The Ombudsman may impose a Monetary Penalty Order of up to CI$250,000, payable into general government revenue, where satisfied on the balance of probabilities that a controller has seriously contravened the Act and the contravention was likely to cause substantial damage or distress.
  • Severity threshold: Ombudsman guidance indicates that only breaches scoring high or very high severity are likely to attract a monetary penalty, with a matrix producing starting amounts ranging from $5,000 to $225,000 before aggravating and mitigating adjustments.
  • Notice of intent: Before issuing a penalty the Ombudsman must serve a notice of intent, giving the controller 21 calendar days to make representations on whether a penalty should be imposed and on the amount.

Offences and review

  • Failure to comply: A controller who fails to comply with a Monetary Penalty Order, absent successful judicial review, commits an offence punishable by a fine of up to $100,000, imprisonment of up to five years, or both.
  • Other offences: Unlawful obtaining or disclosure of personal data, and failure to comply with warrants or orders, are offences under the Act.
  • Judicial review: A recipient of an enforcement order or a Monetary Penalty Order may seek judicial review in the Grand Court within 45 days of receipt, on notice to the Ombudsman.

For the CIMA rules touching data protection (records for company management, cybersecurity, and virtual asset service providers), breach is addressed through CIMA's Enforcement Manual and its powers under the relevant regulatory Acts and the Monetary Authority Act, rather than under the Data Protection Act's penalty regime.

Sources: Rule - Cybersecurity for Regulated Entities (April 2023) · Rule and Statement of Guidance - Nature, Accessibility, and Retention of Records for Licensees Conducting the Business of Company Management · Rule and Statement of Guidance – Nature, Accessibility, and Retention of Records for Licensees Conducting the Business of Company Management · Rule - Virtual Asset Custodians and Virtual Asset Trading Platforms (December 2024) · Data Protection Act (2021 Revision) · Data Protection Act (2021 Revision) - Guide for Data Subjects · Data Protection Act (2021 Revision) - Guidance on Monetary Penalty Orders · Data Protection - Guidance on Monetary Penalty Order Methodology · Enforcement Order 202400591, 202400592 & 202400716 - WORC (2024-12-04) · Enforcement Order 202100222 - Betty Boo Real Estate Sales (2023-04-27) · Enforcement Order 202000583 - Gain Global Markets Inc. (2022-08-02) · Enforcement Order 201900212 (2021-03-18)

Documents

CitationRegulatorType
A Bank Uses Social Media to Find Out How to Contact an Individual (2020-11-02)OMBUDSMANNotice
A healthcare provider suffers phishing attack from former employee emails (2023-05-29)OMBUDSMANNotice
Abuse of Utility Customer Profile (2020-09-02)OMBUDSMANNotice
Access to One's Own Personal Data (2020-10-30)OMBUDSMANNotice
Accidental disposal of documents outside courts building (2021-04-09)OMBUDSMANNotice
Artist's Profile on Art Website (2019-12-05)OMBUDSMANNotice
Bank card statement (2019-10-18)OMBUDSMANNotice
Bank inadvertently sends existing clients’ data to new applicants (2022-02-21)OMBUDSMANNotice
Breach at local telecommunications company (2023-01-12)OMBUDSMANNotice
Civil servant claims unlawful access to travel history (2023-07-21)OMBUDSMANNotice
Coding error causes data breach (2020-10-27)OMBUDSMANNotice
Common Regulatory and Thematic Issues Pt 1 (2016-02-01)CIMACircular
Confirmation of job applications by Cabinet Office (2021-06-23)OMBUDSMANNotice
Contested debt in bank records (2021-01-12)OMBUDSMANNotice
Courts and expunging criminal records outside our jurisdiction (2022-07-25)OMBUDSMANNotice
Credit Union sends invitation without using BCC (2022-06-28)OMBUDSMANNotice
Cybersecurity Circular (2017-10-17)CIMACircular
Data Protection - Breach Notification FormOMBUDSMANForm
Data Protection - Compliance Audit Sample QuestionnaireOMBUDSMANForm
Data Protection - DPL Exemptions OverviewOMBUDSMANForm
Data Protection - Guidance on Monetary Penalty Order MethodologyOMBUDSMANStatement of Guidance
Data Protection - Record of Processing Activities (RoPA) Model TemplateOMBUDSMANForm
Data Protection - Subject Access Request Model FormOMBUDSMANForm
Data Protection Act (2021 Revision)OMBUDSMANAct
Data Protection Act (2021 Revision) - Guidance on Monetary Penalty OrdersOMBUDSMANStatement of Guidance
Data Protection Act (2021 Revision) - Guide for Data Controllers (v1.05)OMBUDSMANStatement of Guidance
Data Protection Act (2021 Revision) - Guide for Data SubjectsOMBUDSMANStatement of Guidance
Data Protection Act (2021 Revision) - Section 40 Consultation FormOMBUDSMANForm
Data Protection Act (2021 Revision) – Section 40 GuidelinesOMBUDSMANStatement of Guidance
Data Protection Complaint FormOMBUDSMANForm
Data Protection Regulations, 2018 (SL 17 of 2019)OMBUDSMANRegulation
Direct marketing by hotel (2021-05-12)OMBUDSMANNotice
Employee image in directory does not violate the DPA (2023-05-22)OMBUDSMANNotice
Employee of an insurance company reveals sensitive personal data (2022-07-20)OMBUDSMANNotice
Enforcement Order - Department of Agriculture (2021-07-12)OMBUDSMANNotice
Enforcement Order - Department of Children and Family Services (2022-02-14)OMBUDSMANNotice
Enforcement Order - Ministry of Planning, Agriculture, Housing, Infrastructure, Transport and Development (2024-11-01)OMBUDSMANNotice
Enforcement Order 201900212 (2021-03-18)OMBUDSMANNotice
Enforcement Order 202000507 (2020-08-07)OMBUDSMANNotice
Enforcement Order 202000583 - Gain Global Markets Inc. (2022-08-02)OMBUDSMANNotice
Enforcement Order 202000820 (2021-03-18)OMBUDSMANNotice
Enforcement Order 202100204 (2021-09-22)OMBUDSMANNotice
Enforcement Order 202100222 - Betty Boo Real Estate Sales (2023-04-27)OMBUDSMANNotice
Enforcement Order 202100552-553 (2023-03-21)OMBUDSMANNotice
Enforcement Order 202300267 (2023-07-25)OMBUDSMANNotice
Enforcement Order 202300268 (2023-11-09)OMBUDSMANNotice
Enforcement Order 202400056 (2024-10-25)OMBUDSMANNotice
Enforcement Order 202400056-2 (2024-12-12)OMBUDSMANNotice
Enforcement Order 202400591, 202400592 & 202400716 - WORC (2024-12-04)OMBUDSMANNotice
Enhanced due diligence by a financial services provider (2021-06-23)OMBUDSMANNotice
Erroneous group email sent by financial service provider (2019-11-26)OMBUDSMANNotice
Error in HR system causes breach at PoCS (2022-08-04)OMBUDSMANNotice
Excessive data collected by jobs portal (2021-06-08)OMBUDSMANNotice
Excessive data gathering for beach weddings - Public Lands Commission (2023-11-09)OMBUDSMANNotice
Financial regulator inadvertently discloses personal data (2022-03-10)OMBUDSMANNotice
Financial service provider neglects to update their paper files (2022-01-31)OMBUDSMANNotice
Freedom of Information (General) Regulations (2021 Revision)CIMARegulation
Fund administrator system sends a report containing financial details to an unintended recipient (2023-09-04)OMBUDSMANNotice
Government Department E-Services Website Breach (2020-03-25)OMBUDSMANNotice
Government E-services website (2019-11-15)OMBUDSMANNotice
Guidance on Employee Vaccination Status (October 2021)OMBUDSMANStatement of Guidance
HR system reports are sent to incorrect Ministry (2023-05-23)OMBUDSMANNotice
HSA discloses PCR results to wrong person (2022-03-28)OMBUDSMANNotice
Health Clinic Gathers Credit Card Data in Contravention of Data Security Standards (2020-11-02)OMBUDSMANNotice
Health Insurance Form Asking About Applicants' Sex Lives (2020-10-12)OMBUDSMANNotice
Immigration service provider locates missing documents (2023-10-18)OMBUDSMANNotice
Inadvertent leak of personal data by financial services company (2019-11-25)OMBUDSMANNotice
Incorrect Access Controls in Utility Company’s Recruitment Software (2020-01-21)OMBUDSMANNotice
Individual’s details discussed in Parliament (2021-11-11)OMBUDSMANNotice
Information Circular - Cybersecurity (2017-10-30)CIMACircular
Information sharing between HM Prison, RCIPS and the Courts (2022-03-24)OMBUDSMANNotice
Investor personal data leaked on the dark web (2023-09-25)OMBUDSMANNotice
Job references not held (2022-10-25)OMBUDSMANNotice
Legal analysis not personal data accessible under section 8 - Cabinet Office (2022-06-28)OMBUDSMANNotice
Limitations to the right to access one’s own data (2022-03-29)OMBUDSMANNotice
Local hospital sends patient COVID-19 results to unintended recipient (2023-09-13)OMBUDSMANNotice
Local law firm made aware of personal data breach (2023-03-16)OMBUDSMANNotice
Malware attack on electronic payment system (2021-08-31)OMBUDSMANNotice
Medical clinic inadvertently sends health records to the Health Practice Board (2023-06-08)OMBUDSMANNotice
Member of the public requests removal from Election Register (2023-04-20)OMBUDSMANNotice
Misdirected Email with Account Information (2020-02-14)OMBUDSMANNotice
Missing exhibit book and entries (2023-10-19)OMBUDSMANNotice
Newspaper links to personal data of football players (2021-06-23)OMBUDSMANNotice
No personal data held by local law firm (2023-08-18)OMBUDSMANNotice
No personal data on reissued SIM cards (2022-05-02)OMBUDSMANNotice
Overseas fund administrator suffers ransomware attack (2021-09-16)OMBUDSMANNotice
Performance Assessment Sent to Wrong Person (2020-02-18)OMBUDSMANNotice
Personal Data of Former Employees on Company Website (2019-12-17)OMBUDSMANNotice
Personal data transferred from company laptop (2020-10-12)OMBUDSMANNotice
Pharmacy gives prescription medicine to the wrong patient (2021-04-14)OMBUDSMANNotice
Pharmacy suffers ransomware attack (2021-12-02)OMBUDSMANNotice
Phishing Attack at Financial Services Company (2020-02-11)OMBUDSMANNotice
Phishing attack at professional association (2021-06-07)OMBUDSMANNotice
Processor employees fall victim to a smishing attack allowing access to customer information (2023-08-15)OMBUDSMANNotice
Proof of vaccination had no legal basis and was excessive - CIBC FCIB (Cayman) (2023-03-21)OMBUDSMANNotice
Public sector entity incurs unreasonable delays in responding to a subject access request (2022-07-20)OMBUDSMANNotice
RCIPS inadvertently release third party personal data in collision report (2022-10-04)OMBUDSMANNotice
RCIPS loses bail book and finds it again (2022-08-12)OMBUDSMANNotice
RCIPS sends misdirected data on firearms owner (2022-03-18)OMBUDSMANNotice
Ransomware attack at overseas financial services provider (2020-09-14)OMBUDSMANNotice
Request for Rectification of Financial Data (2020-10-20)OMBUDSMANNotice
Restructuring Administrator security incident results in a non-jurisdictional breach (2023-12-08)OMBUDSMANNotice
Retail Store Asking Customers for their Phone Numbers (2020-12-04)OMBUDSMANNotice
Retail bank reveals overdrawn account (2021-11-29)OMBUDSMANNotice
Retail bank’s lack of response to a subject access request (2021-06-03)OMBUDSMANNotice
Reuse of pre-paid mobile number (2021-06-15)OMBUDSMANNotice
Right to one’s own personal data despite FOI exemptions (2023-02-10)OMBUDSMANNotice
Risk management entity sends misdirected shareholder data (2023-02-02)OMBUDSMANNotice
Rule - Cybersecurity for Regulated Entities (April 2023)CIMARule
Rule - Virtual Asset Custodians and Virtual Asset Trading Platforms (December 2024)CIMARule
Rule and Statement of Guidance - Nature, Accessibility, and Retention of Records for Licensees Conducting the Business of Company ManagementCIMARule
Rule and Statement of Guidance – Nature, Accessibility, and Retention of Records for Licensees Conducting the Business of Company ManagementCIMARule
Search for beach access records was reasonable (2023-04-28)OMBUDSMANNotice
Serious data breach at real estate company - Betty Boo Real Estate Sales (2023-04-27)OMBUDSMANNotice
Spreadsheet data tool causes utility emails to be sent to wrong customers (2021-07-15)OMBUDSMANNotice
Statement of Principles – Conduct of Virtual Asset Services (February 2021)CIMAStatement of Principles
Supervisory Issues & Information Circular (2017-10-17)CIMACircular
The right to access one’s own personal data - Department of Education Services (2023-07-25)OMBUDSMANNotice
Tourism sponsorship business cases and agreements to be disclosed (2023-09-14)OMBUDSMANNotice
Transparency and accountability for salary increase process (2023-11-30)OMBUDSMANNotice
Unauthorized use of third-party website leads to data breach (2022-01-21)OMBUDSMANNotice
Unprotected Food Delivery Website (2020-07-08)OMBUDSMANNotice
Unsubscribing from an IT service provider (2021-08-05)OMBUDSMANNotice
Use of a Sign-in Book and CCTV Cameras (2020-11-20)OMBUDSMANNotice
Verification of employment letter by retail bank (2021-03-05)OMBUDSMANNotice
Videos of court proceeding are part of the judicial functions of a court (2023-06-22)OMBUDSMANNotice
WORC sends bulk emails without using BCC (2022-06-22)OMBUDSMANNotice
“White hat hacker” informs bank of security breach (2020-03-26)OMBUDSMANNotice