Cayman Islands
data protection
128 Cayman Islands regulatory document(s) tagged data protection.
Who is caught
The Data Protection Act (2021 Revision), supplemented by the Data Protection Regulations 2018, is the Cayman Islands' primary data protection regime, administered and enforced by the Office of the Ombudsman. It applies principally to data controllers, but imposes direct duties on processors and reaches organisations established outside the Islands in defined circumstances.
Who is caught
- Local controllers: Data controllers established in the Cayman Islands whose processing of personal data occurs in that context.
- Overseas controllers: Data controllers established elsewhere but processing personal data in the Islands, other than personal data merely transiting through.
- Local representative: An overseas controller processing personal data in the Islands must nominate a local representative, who bears all obligations under the Act as if it were the controller itself.
- Data processors: The Ombudsman's guidance describes direct statutory responsibilities on processors, including acting only on documented instructions, security, record-keeping and breach notification to the controller.
- Public authorities: Public authorities process personal data as controllers and, under section 40, must consult the Ombudsman before adopting measures or rules affecting personal data processing.
Data protection obligations also recur across CIMA-regulated sectors. Company management licensees must process records-related personal data in accordance with the Data Protection Act, the Cybersecurity Rule requires data protection to be built into an entity's cyber framework, and virtual asset service providers are expected to protect customer data. Employers processing employee data (for example vaccination status) are likewise subject to the Act.
Sources: Freedom of Information (General) Regulations (2021 Revision) · Statement of Principles – Conduct of Virtual Asset Services (February 2021) · Rule - Cybersecurity for Regulated Entities (April 2023) · Rule and Statement of Guidance - Nature, Accessibility, and Retention of Records for Licensees Conducting the Business of Company Management · Rule and Statement of Guidance – Nature, Accessibility, and Retention of Records for Licensees Conducting the Business of Company Management · Rule - Virtual Asset Custodians and Virtual Asset Trading Platforms (December 2024) · Data Protection Act (2021 Revision) · Data Protection Regulations, 2018 (SL 17 of 2019) · Data Protection Act (2021 Revision) - Guide for Data Controllers (v1.05) · Data Protection Act (2021 Revision) – Section 40 Guidelines · Guidance on Employee Vaccination Status (October 2021)
Key duties
The core continuing duty is compliance with the data protection principles for all personal data processed, together with specific, deadline-bound obligations on subject rights and breach handling. The duties below lead with those that recur across the enforcement record and carry fixed timeframes.
Data protection principles
- Eight principles: Controllers must comply with, and ensure compliance by those processing on their behalf with, the data protection principles: fair and lawful processing, purpose limitation, data minimisation, accuracy, storage limitation, respect for individuals' rights, security, and international transfer restrictions.
- Privacy notice: Controllers must inform individuals of the controller's identity and the purposes of processing, generally via a privacy notice at the point of collection.
Subject access and other rights
- Access requests: Controllers must respond to a written subject access request within 30 days, subject to identity verification, and generally free of charge.
- Time extension: The response time may be extended by up to 30 days in specified circumstances, and beyond 30 days only with the Ombudsman's permission; the data subject must be told the reason and when a final response will be given.
- Fees and refusals: A reasonable fee may be charged, or a request refused with reasons, only where it is manifestly unfounded or excessive; the controller bears the burden of proving this.
- Complaint rights: On receiving a section 8 request, the controller must tell the data subject of their right to complain to the Ombudsman.
- Stop processing: Controllers must comply with a valid request to cease processing, including an absolute right to stop direct marketing, unless they apply to the Ombudsman within 21 days of a cessation request and obtain approval not to comply.
- Correction and erasure: Controllers must comply with rectification, blocking, erasure or destruction requests.
Breach notification
- Section 16 notification: Controllers must notify the Ombudsman and affected data subjects of a personal data breach without undue delay and, per the enforcement orders indexed here, no later than five days after becoming aware of it.
Processor contracts and transfers
- Processor agreements: Controllers must have a written contract with any data processor containing the terms required by Schedule 1, Part 2, paragraph 3 of the Act, covering matters such as staff confidentiality, sub-processor approval, breach notification and return or deletion of data.
- International transfers: Transfers of personal data outside the Islands must satisfy a Schedule 4 exception or otherwise comply with the eighth data protection principle, supported by approved safeguards or an Ombudsman authorisation.
Public authority consultation
- Section 40: Public authorities must consult the Ombudsman on the content of new or amended legislation, codes of conduct or practice affecting personal data processing before those measures come into force, using the section 40 consultation form.
Sources: Data Protection Act (2021 Revision) · Data Protection Regulations, 2018 (SL 17 of 2019) · Data Protection Act (2021 Revision) - Guide for Data Controllers (v1.05) · Data Protection Act (2021 Revision) - Guide for Data Subjects · Data Protection Act (2021 Revision) – Section 40 Guidelines · Enforcement Order - Ministry of Planning, Agriculture, Housing, Infrastructure, Transport and Development (2024-11-01) · Enforcement Order 202100222 - Betty Boo Real Estate Sales (2023-04-27) · Credit Union sends invitation without using BCC (2022-06-28) · Direct marketing by hotel (2021-05-12) · Enforcement Order 201900212 (2021-03-18)
Exemptions and carve-outs
The Act and Regulations provide a range of subject-matter exemptions, and case outcomes confirm territorial limits on the Ombudsman's reach.
- Statutory exemptions: The Act sets out specific exemptions for national security, crime and government fees, health, education and social work, journalism, literature and art, research and statistics, legal proceedings, corporate finance, negotiations, legal professional privilege and trusts, and others set by regulation.
- Health records: Personal data whose release could cause mental or physical harm are exempt from subject information provisions, subject to consultation with an appropriate health professional where the controller is not one.
- Educational records: Educational records are exempt from section 8 disclosure in certain circumstances, including risk of serious harm, certain parental requests, abuse-risk information, and exam questions within twelve months.
- Social work: Personal data processed by public authorities or courts in specified social work, welfare, housing or family and child proceedings contexts are exempt where disclosure could cause serious harm or was given in confidence.
- International cooperation transfers: Transfers between intelligence or regulatory agencies for international cooperation are limited to disclosures permitted or required under a Cayman Islands enactment or a Grand Court order.
- Territorial limits: Where data is not processed in the Cayman Islands and the controller is not established there, the matter falls outside the Ombudsman's jurisdiction.
Sources: Data Protection Act (2021 Revision) · Data Protection Regulations, 2018 (SL 17 of 2019) · Artist's Profile on Art Website (2019-12-05)
Enforcement and penalties
The Ombudsman holds the investigative and enforcement powers under the Act. Enforcement in the indexed orders has combined corrective directions with, in serious cases, monetary penalties, and non-compliance can amount to a criminal offence.
Ombudsman powers
- Orders and search: The Ombudsman can receive complaints, issue information orders and enforcement orders (for example requiring policies, training, remediation or cessation of a practice), and enter and search premises under warrant.
- Monetary penalty orders: The Ombudsman may impose a Monetary Penalty Order of up to CI$250,000, payable into general government revenue, where satisfied on the balance of probabilities that a controller has seriously contravened the Act and the contravention was likely to cause substantial damage or distress.
- Severity threshold: Ombudsman guidance indicates that only breaches scoring high or very high severity are likely to attract a monetary penalty, with a matrix producing starting amounts ranging from $5,000 to $225,000 before aggravating and mitigating adjustments.
- Notice of intent: Before issuing a penalty the Ombudsman must serve a notice of intent, giving the controller 21 calendar days to make representations on whether a penalty should be imposed and on the amount.
Offences and review
- Failure to comply: A controller who fails to comply with a Monetary Penalty Order, absent successful judicial review, commits an offence punishable by a fine of up to $100,000, imprisonment of up to five years, or both.
- Other offences: Unlawful obtaining or disclosure of personal data, and failure to comply with warrants or orders, are offences under the Act.
- Judicial review: A recipient of an enforcement order or a Monetary Penalty Order may seek judicial review in the Grand Court within 45 days of receipt, on notice to the Ombudsman.
For the CIMA rules touching data protection (records for company management, cybersecurity, and virtual asset service providers), breach is addressed through CIMA's Enforcement Manual and its powers under the relevant regulatory Acts and the Monetary Authority Act, rather than under the Data Protection Act's penalty regime.
Sources: Rule - Cybersecurity for Regulated Entities (April 2023) · Rule and Statement of Guidance - Nature, Accessibility, and Retention of Records for Licensees Conducting the Business of Company Management · Rule and Statement of Guidance – Nature, Accessibility, and Retention of Records for Licensees Conducting the Business of Company Management · Rule - Virtual Asset Custodians and Virtual Asset Trading Platforms (December 2024) · Data Protection Act (2021 Revision) · Data Protection Act (2021 Revision) - Guide for Data Subjects · Data Protection Act (2021 Revision) - Guidance on Monetary Penalty Orders · Data Protection - Guidance on Monetary Penalty Order Methodology · Enforcement Order 202400591, 202400592 & 202400716 - WORC (2024-12-04) · Enforcement Order 202100222 - Betty Boo Real Estate Sales (2023-04-27) · Enforcement Order 202000583 - Gain Global Markets Inc. (2022-08-02) · Enforcement Order 201900212 (2021-03-18)