The Cayman Islands’ Data Protection Law comes into force today, introducing a GDPR-style regime overseen by the Ombudsman and applying to controllers established in, or processing data in, the Islands.
Key points
- Appropriate technical and organisational measures are required.
- Breaches must be notified to the Ombudsman and data subjects within 5 days.
- Applies to controllers established in, or processing data in, the Cayman Islands.
- Transfers are restricted.
UK organisations using Cayman Islands funds, administrators or service providers should review their data protection arrangements, including contracts and incident procedures, given the short 5-day breach notification window.
Source: Cayman Islands Data Protection Law, 2017 (Cayman Islands Legislation)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.