The DPL will regulate the future processing of all personal data in the Cayman Islands. Drafted around a set of internationally recognised privacy principles, the new law provides a framework of rights and duties designed to give individuals greater control over their personal data, and will stand as the most comprehensive data protection law in the region.

With the implementation date now set, organisations should take steps now to ensure they understand their obligations under the new law, have in place policies and procedures to ensure the proper protection of all personal data under their control and create an effective governance regime for approving, overseeing, implementing and reviewing those policies. Organisations in Cayman need to get it right – reputations and criminal liability will soon be at stake.

Overview of the DPL

The DPL provides a framework of rights and duties designed to give individuals greater control over their personal data. Importantly, the new law supports a growing expectation from international businesses and their clients that organisations operating in offshore jurisdictions have comprehensive data protection compliance requirements backed up by robust data privacy legislation. Personal data is defined widely under the law to include any data relating to a living individual. Personal data must be processed fairly and lawfully and used for a legitimate purpose that has been notified to the individual data subject in advance.

Personal data holdings should not be excessive in relation to the purposes for which they are collected and should be securely purged once those purposes have been fulfilled. If personal data is processed for any new purposes, this processing can only be undertaken if fresh consent is obtained. Data subjects must also be informed of any countries or territories outside the Cayman Islands to which their personal data may be transferred.

Achieving compliance

The DPL gives individuals the right to access personal data held about them and to request that any inaccurate data is corrected or deleted. Organisations will need to have policies and procedures in place to manage these requests. The law also obliges businesses to cease processing personal data once the purposes for which that data has been collected have been exhausted.

Prescribed data retention periods are not set out in the DPL but analysis will need to be undertaken to determine how long data should be kept for. Similarly, it will be important to evaluate how personal data can be securely deleted once the purposes for holding it have been fulfilled.

Implementing a data protection compliance programme involves engaging with the right stakeholders across the organisation and creating an effective governance regime for approving, overseeing, implementing and reviewing the various policies. A coordinated chain of command should be developed, together with written reporting procedures, authority levels and protocols including seeking and complying with legal advice. The appointment of official roles such as a Data Protection Officer is also recommended.

The Office of the Ombudsman, which will have responsibility for enforcing the new law, has issued a Guide for Data Controllers to assist the implementation process.

Breaches of the DPL could result in fines of up to Cl$100,000 per breach, imprisonment for a term of up to 5 years, or both. Other monetary penalties of up to Cl$250,000 are also possible under the law.

Share
Twitter LinkedIn Email Save as PDF
More Publications
18 May 2023

The 2023 Cayman Islands Real Estate Guide

The Real Estate 2023 guide provides the latest legal information on the impact of disruptive technol...

Contributors: Norman Klein
26 Apr 2023

(RE)INSURANCE - THE ABC’S OF SPC’S

Segregated portfolio companies (SPC’s) are frequently used in Cayman Islands (re)insurance structu...

13 Feb 2023

Offshore AML Regulation and Enforcement in the Cayman Islands

In the February 2023 edition of Financier Worldwide, Miriam Smyth answers questions about AML Regula...

3 Feb 2023

Offshore Private Funds and Offshore Managers: Divergent Regimes in the Cayman Islands and the British Virgin Islands

Consideration should be given and appropriate advice should be sought as to what would be the most a...

Contributors: Grace Yeung
1 Feb 2023

Fund Finance Laws and Regulations 2023 – Cayman Islands

The Cayman Islands fund finance market has continued to see plenty of activity over the past 12 mont...

Contributors: Georgina Pullinger
27 Sep 2022

Similar but Different

While the basic features of the trust remain, there are some notable differences in how trusts can b...

30 Aug 2022

The Cayman Islands restructuring officer regime comes into force on 31 August 2022

These new proceedings will significantly enhance the Cayman Islands restructuring regime.

4 Aug 2022

Norwich Pharmacal orders: the right medicine for third party disclosure of information and documents in the Cayman Islands

A Norwich Pharmacal order (NPO) is a disclosure order available in the Cayman Islands to compel a th...

Contributors: Susan Fallan
4 May 2022

Aircraft financing - a brief guide to Cayman

Legal and administrative service providers in the Cayman Islands such as Appleby can offer aircraft ...

Contributors: Alexandra Simpson
28 Apr 2022

Restructuring the offshore debt of Chinese Real Estate Developers

This article sets out how the current regimes in the Cayman Islands and the BVI can assist with rest...

Contributors: Crystal Au-Yeung