Short answer: create one evidence file
A privacy policy by itself does not show how a business handles personal data. Use one controlled operating file to connect the data map, purpose and legal-basis questions, notices, rights requests, retention, security, processors, transfers, incidents, owners, and review dates. The checklist prepares evidence and professional questions; it does not certify compliance or decide a legal issue.
- Assign an accountable internal owner even though the Data Protection Act does not itself require every organisation to appoint a formal data protection officer.
- Map actual practices before rewriting policies; a polished notice cannot fix an unknown spreadsheet, inbox, camera, device, or vendor flow.
- Separate confirmed facts, current controls, missing evidence, and questions for the Ombudsman or Cayman counsel.
- Reopen the file when a purpose, system, vendor, location, security risk, retention rule, or affected group changes.
Run the scope screen
The Cayman Data Protection Act applies to personal-data processing by public and private organisations within its scope. Start with the organisation, activity, people, and systems—not the document name. A controller determines why and how data is processed; a processor handles it on a controller's behalf. Personal or household activity has a different boundary, so mixed landlord, consultancy, founder, or family records deserve careful review.
| Scope question | Evidence to record | Escalate when |
|---|---|---|
| Which legal entity or person runs the activity? | Entity name, trading names, contacts, locations, and accountable owner. | Several entities, a foreign head office, or personal and business activity overlap. |
| Whose data is involved? | Customers, staff, applicants, tenants, children, visitors, suppliers, and website users. | Sensitive data, minors, monitoring, or vulnerable people are involved. |
| Where does processing happen? | Paper files, devices, email, cloud tools, cameras, websites, payroll, and archives. | A vendor or recipient is overseas or the storage location is unclear. |
| Who decides purpose and method? | Decision owner, instructions, contracts, and actual control for each activity. | Two parties share decisions or a vendor acts beyond written instructions. |
Build the data-flow register
Inventory one processing purpose at a time. The register should follow data from collection through access, use, disclosure, storage, transfer, archive, and deletion. This exposes duplicate collection, stale files, shadow systems, and vendors that a policy review often misses.
| Collection point | Personal data and people | Purpose and destination | Delete/review trigger |
|---|---|---|---|
| Website, enquiry, or booking | Contact details, message, device or analytics data. | Lead response, service delivery, CRM, email, or analytics provider. | Purpose ends, consent/objection changes, or retention review is due. |
| Employment or recruitment | Identity, CV, immigration, payroll, benefits, performance, or health records. | Hiring, employment administration, advisers, insurers, payroll, or government processes. | Candidate/employee milestone plus applicable legal and dispute needs. |
| Customer, tenant, or supplier file | Contracts, ID, payment, address, correspondence, access, or incident records. | Contract, KYC, billing, support, property access, or dispute handling. | Contract and claim lifecycle plus sourced retention review. |
| Cameras, access logs, or devices | Images, entry records, location, identifiers, or communications. | Security, safety, operations, investigation, or device management. | Short documented review tied to the actual risk and purpose. |
Record purpose, legal basis, and sensitive-data questions
Each purpose needs at least one applicable Schedule 2 legal basis. The six broad bases described by the Ombudsman are consent, contract, legal obligation, vital interests, public functions, and legitimate interests. Sensitive personal data needs an additional Schedule 3 condition. Do not default to consent or choose a basis from this checklist; record the facts and ask for advice where the fit is uncertain.
| Purpose | Candidate source to review | Sensitive-data flag | Decision evidence |
|---|---|---|---|
| Deliver a requested service | Contract terms, pre-contract request, and necessary processing facts. | Check for health, financial, identity, or other sensitive fields. | Owner, reviewed basis, data minimum, source link, and review date. |
| Meet an obligation | Exact Cayman or other applicable legal requirement. | Record any additional Schedule 3 question. | Legal source, affected records, retention source, and adviser note. |
| Marketing, analytics, or improvement | Consent or legitimate-interest facts, expectations, impact, and objection route. | Avoid unnecessary profiling or sensitive inference. | Assessment, notice, preference record, and suppression evidence. |
Create the privacy-information workflow
Privacy information should be given as soon as reasonably practicable, usually when data is collected. Distinguish the statutory minimum—such as controller identity and purpose—from the Ombudsman's broader recommended transparency about categories, sources, recipients, transfers, retention, rights, complaints, and automated decisions. Review notices when purposes or flows change.
- List every collection point: web form, phone, email, contract, application, camera area, referral, imported list, and in-person intake.
- Name the notice shown at each point, its version, owner, date, delivery method, and evidence that it was available.
- Create a change trigger for new data, purpose, recipient, vendor, country, retention rule, or automated decision.
- Use layered or audience-specific information where one dense notice would hide the decision a person needs to understand.
Set up individual-rights intake
The Act includes rights relating to information, access, correction, stopping or restricting processing, direct marketing, automated decisions, complaints, and compensation. Subject access requests normally have a 30-day response period, subject to identity, scope, extension, exemption, mixed-data, and exceptional-fee boundaries. Log first receipt immediately and escalate rather than promising an outcome from memory.
| Log field | Operational owner | Evidence to preserve |
|---|---|---|
| First receipt and channel | Front desk, inbox, or system owner | Original request, timestamp, acknowledgement, and deadline calculation. |
| Identity, authority, and scope | Privacy owner with counsel where needed | Checks, clarifications, authorised representative, and search terms. |
| Search and review | System/data owners | Locations searched, processor support, results, third-party data, exemptions, and redactions. |
| Decision and response | Accountable owner | Advice, extension/fee basis if any, disclosure method, response, and closure date. |
Build a purpose-led retention and deletion schedule
The storage-limitation principle requires personal data to be kept no longer than needed. The DPA does not create one universal retention period for every record, and other legal, regulatory, contractual, insurance, tax, employment, or dispute requirements may matter. Source each period, review it, and record whether data is deleted, securely destroyed, or genuinely anonymised.
| Record class | Purpose and other-law source | Review event | End action and proof |
|---|---|---|---|
| Enquiries and unsuccessful applications | Operational need, complaint risk, and applicable advice. | Purpose ends or scheduled review. | Delete/anonymise decision plus system and backup handling. |
| Active customer, tenant, supplier, or staff file | Current relationship and exact legal/contractual needs. | Change, termination, dispute, or statutory milestone. | Archive only what remains justified; restrict access and record disposal. |
| Security, access, camera, or incident records | Risk, investigation, claims, and regulator/counsel advice. | Short recurring review and event closure. | Secure deletion or documented hold with owner and expiry. |
Maintain the security and access-control register
Appropriate security is risk-based and includes organisational, physical, and technical measures. Record the confidentiality, integrity, availability, and recovery risks around people, premises, paper, devices, accounts, vendors, backups, and incidents. Encryption or a vendor badge alone does not prove that controls are adequate.
| Risk area | Evidence to keep | Review trigger |
|---|---|---|
| People and access | Role-based access, joiner/mover/leaver log, training, confidentiality, and privileged-account review. | Hire, role change, departure, error, complaint, or access anomaly. |
| Devices, systems, and premises | Inventory, updates, authentication, secure storage, disposal, visitor and physical controls. | New system/site, lost device, vulnerability, or control failure. |
| Availability and recovery | Backup scope, restore test, continuity owner, vendor dependency, and recovery evidence. | Material change, failed test, outage, or incident lesson. |
| Governance | Risk register, decisions, accepted residual risk, reviews, and escalation contacts. | Quarterly review and any new high-impact processing. |
Control processors and subprocessors
A controller using a processor needs written terms and remains responsible for its own compliance. Build a vendor file covering documented instructions, confidentiality, security, subprocessors, rights support, incident support, deletion or return, audit information, service exit, and the actual chain of access. This is a due-diligence checklist, not contract language or a finding that an agreement is valid.
| Processor record | Question | Evidence |
|---|---|---|
| Service and role | What data, people, purpose, systems, and decisions are involved? | Scope, flow map, role note, owner, and minimisation check. |
| Written terms | Do the terms address instructions, security, confidentiality, support, subprocessors, and end-of-service data? | Signed version, schedules, changes, and legal review. |
| Service chain | Who else can access data and from which countries? | Subprocessor list, notifications, locations, objections, and transfer review. |
| Exit and incident readiness | Can data be returned/deleted and evidence produced quickly? | Export test, deletion path, incident contact, response times, and closure proof. |
Gate overseas transfers
Sending or making personal data accessible overseas requires an adequacy or other permitted-condition or safeguard analysis. A cloud region, EU contract, standard-clause label, consent tick-box, certification, or well-known vendor does not approve every transfer by itself. Keep the destination, recipient role, data, purpose, onward-transfer chain, proposed route, and review evidence together.
| Destination/recipient | Data and purpose | Transfer path and onward access | Safeguard/condition and reviewer |
|---|---|---|---|
| Cloud, email, CRM, analytics, payroll, or support | Exact fields, people, frequency, and necessity. | Hosting, remote support, backup, affiliates, and subprocessors. | Documented legal analysis, contract evidence, security review, owner, and date. |
| Foreign adviser, head office, client, or referral partner | Why disclosure or access is needed and what can be minimised. | Direct send, portal, shared system, or continuing access. | Permitted route, recipient controls, notice, retention, and escalation. |
Prepare the incident and breach-response file
Treat every suspected loss, unauthorised access, disclosure, alteration, destruction, or availability failure as an immediate evidence and escalation event. The statutory reporting clock can be five days from when the controller should, with due diligence, have been aware. Current Ombudsman materials contain important reporting nuance, so do not make a report/no-report decision from a template; preserve the first-awareness time and seek prompt Ombudsman or Cayman legal guidance.
- Require processors to escalate suspected incidents without waiting for a complete investigation.
- Do not destroy or overwrite the logs and records needed to understand what happened.
- Separate containment, recovery, notification analysis, individual communication, and long-term remediation owners.
| Timeline field | Evidence to capture | Owner/escalation |
|---|---|---|
| First signal and awareness | Reporter, time, system, facts known, screenshots/logs, and who was told. | Incident lead and accountable controller owner. |
| Containment and preservation | Access changes, isolation, recovery, preserved logs/devices, and business-continuity action. | Security/operations plus processor contacts. |
| Impact assessment | Data, people, volume, sensitivity, consequences, geography, and mitigation. | Cayman counsel and Ombudsman guidance promptly. |
| Decision and follow-through | Advice, notifications, communications, measures, reasons, dates, and lessons. | Named approver, affected owners, and scheduled control review. |
Use the first 30 days to make it operational
The goal is a maintained system, not a one-time binder. Finish the first month with named owners, evidence locations, unresolved questions, and review triggers that fit the business's actual risk and scale.
- Week 1: assign the accountable owner, complete the scope screen, list systems and vendors, and open a questions log.
- Week 2: map the main data flows, roles, purposes, candidate legal bases, sensitive-data flags, notices, and rights intake.
- Week 3: build retention, access/security, processor, subprocessor, and overseas-transfer registers; fix obvious orphaned access and stale data safely.
- Week 4: run a tabletop rights request and incident exercise, confirm regulator/counsel contacts, approve priorities, and schedule the next review.
- Quarterly and on material change: review new purposes, fields, people, notices, vendors, countries, retention sources, access, incidents, complaints, and control tests.
Trust note
Last updated August 2026. This guide is written for relocation planning and should be verified with licensed Cayman professionals for legal, tax, immigration, medical, insurance, or financial decisions.
Reference points: Office of the Ombudsman — Data Protection for Organizations, Office of the Ombudsman — Who does the DPA apply to?, Office of the Ombudsman — Legal basis for processing, Office of the Ombudsman — The right to be informed, Office of the Ombudsman — The right of access, Office of the Ombudsman — Storage limitation, Office of the Ombudsman — Security, integrity and confidentiality, Office of the Ombudsman — Controller and processor contracts, Office of the Ombudsman — International transfers, Office of the Ombudsman — Personal data breaches, Cayman Islands Data Protection Act (2021 Revision).
