Cayman’s Data Protection Law in force from September 2019

Published: 19 Nov 2018
Type: Insight

The Cayman Islands Data Protection Law, 2017 (“DPL”), which was expected to come into force on 29 January 2019, will now come into force in September 2019.


The DPL will regulate the future processing of all personal data in the Cayman Islands. Drafted around a set of internationally recognised privacy principles, the new law provides a framework of rights and duties designed to give individuals greater control over their personal data, and will stand as the most comprehensive data protection law in the region.

With the implementation date now set, organisations should take steps now to ensure they understand their obligations under the new law, have in place policies and procedures to ensure the proper protection of all personal data under their control and create an effective governance regime for approving, overseeing, implementing and reviewing those policies. Organisations in Cayman need to get it right – reputations and criminal liability will soon be at stake.

Overview of the DPL

The DPL provides a framework of rights and duties designed to give individuals greater control over their personal data. Importantly, the new law supports a growing expectation from international businesses and their clients that organisations operating in offshore jurisdictions have comprehensive data protection compliance requirements backed up by robust data privacy legislation. Personal data is defined widely under the law to include any data relating to a living individual. Personal data must be processed fairly and lawfully and used for a legitimate purpose that has been notified to the individual data subject in advance.

Personal data holdings should not be excessive in relation to the purposes for which they are collected and should be securely purged once those purposes have been fulfilled. If personal data is processed for any new purposes, this processing can only be undertaken if fresh consent is obtained. Data subjects must also be informed of any countries or territories outside the Cayman Islands to which their personal data may be transferred.

Achieving compliance

The DPL gives individuals the right to access personal data held about them and to request that any inaccurate data is corrected or deleted. Organisations will need to have policies and procedures in place to manage these requests. The law also obliges businesses to cease processing personal data once the purposes for which that data has been collected have been exhausted.

Prescribed data retention periods are not set out in the DPL but analysis will need to be undertaken to determine how long data should be kept for. Similarly, it will be important to evaluate how personal data can be securely deleted once the purposes for holding it have been fulfilled.

Implementing a data protection compliance programme involves engaging with the right stakeholders across the organisation and creating an effective governance regime for approving, overseeing, implementing and reviewing the various policies. A coordinated chain of command should be developed, together with written reporting procedures, authority levels and protocols including seeking and complying with legal advice. The appointment of official roles such as a Data Protection Officer is also recommended.

The Office of the Ombudsman, which will have responsibility for enforcing the new law, has issued a Guide for Data Controllers to assist the implementation process.

Breaches of the DPL could result in fines of up to Cl$100,000 per breach, imprisonment for a term of up to 5 years, or both. Other monetary penalties of up to Cl$250,000 are also possible under the law.

Share
More publications
Appleby-Website-Dispute-Resolution-Practice
11 Feb 2026

When the Court intervenes… and when it does not: Grand Court Reaffirms Limited Curial Intervention in Support of Foreign Arbitrations

The Financial Services Division of the Grand Court’s judgment in In the matter of A v B & C (FSD 270 of 2025) provides a timely reminder of the proper boundaries between national courts and international arbitration tribunals in respect of the grant of interim relief. The decision underscores the Cayman Islands' commitment to the principle of limited curial intervention and confirms that the Court’s powers under section 54 of the Arbitration Act 2012 are ancillary to the arbitral process and are only to be exercised when the tribunal cannot provide effective relief itself. The judgment helpfully sets out clear parameters for those seeking ancillary relief and highlights that the Cayman courts will support arbitration proceedings without supplanting them.

Website-Code-Cayman-2
5 Feb 2026

Recusal For Apparent Bias Is Not A New Frontier

In Re New Frontier Health Corporation,[1] Justice Doyle decided to recuse himself, such that he would not hear the trial listed to commence weeks later, on the basis that he made findings in his recent Re 51job Inc judgment, as to the reliability and credibility of the same two experts who would give evidence at the New Frontier trial. The New Frontier judgment represents a further endorsement by the Cayman courts of the fundamental maxim that justice must not only be done, but must be seen to be done.

Appleby-Website-Corporate-Practice
4 Feb 2026

The New Crypto-Asset Reporting Framework – Relevance for Cayman Investment Funds

The Tax Information Authority (International Tax Compliance) (Crypto-Asset Reporting Framework) Regulations, 2025 (CARF Regulations) came into effect on 1 January 2026 and provide for the collection, reporting and automatic exchange of information on transactions in crypto-assets.  The CARF Regulations will operate in a similar fashion to the existing Cayman Common Reporting Standard (CRS) regime which facilitates the automatic exchange of financial account information.  For information on recent changes to the CRS, please see our December advisory here.

Appleby-Website-Regulatory-Practice
27 Jan 2026

CIMA Launches Prudential Information Survey for SIBA Registered Persons

The Cayman Islands Monetary Authority (CIMA) has published a General Industry Notice launching a new Prudential Information Survey for Registered Persons under the Securities Investment Business Act (SIBA) of the Cayman Islands.

Appleby-Website-Dispute-Resolution-Practice
15 Dec 2025

Aquapoint LP v Fan: Privy Council Confirms Equitable Constraints Can Override Strict Contractual Rights in Cayman ELP Winding Up

In its recent judgment in Aquapoint LP (in Official Liquidation) v Fan,[1] the Privy Council upheld the judgments of the Grand Court and Cayman Islands Court of Appeal (CICA). The ruling confirms that the exercise of strict legal rights under a limited partnership agreement – even one containing detailed contractual terms and “entire agreement” clauses – can nevertheless be subject to equitable considerations in certain circumstances. Where those equitable considerations arise, they may justify the winding up of an exempted limited partnership on the “just and equitable” basis. Appleby acts for the joint official liquidators of Aquapoint; for further details on the background of this case, see Appleby’s previous article here.