Don’t do SECURITY. Do business SECURELY.

Cayman Islands Data Protection Law comes into force

The Cayman Islands’ GDPR-style Data Protection Law takes effect.

The Cayman Islands’ Data Protection Law comes into force today, introducing a GDPR-style regime overseen by the Ombudsman and applying to controllers established in, or processing data in, the Islands.

Key points

  • Appropriate technical and organisational measures are required.
  • Breaches must be notified to the Ombudsman and data subjects within 5 days.
  • Applies to controllers established in, or processing data in, the Cayman Islands.
  • Transfers are restricted.

UK organisations using Cayman Islands funds, administrators or service providers should review their data protection arrangements, including contracts and incident procedures, given the short 5-day breach notification window.

Source: Cayman Islands Data Protection Law, 2017 (Cayman Islands Legislation)

Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights