Privacy Policy
1. SCOPE
The Cayman Islands General Registry (GR) respects your privacy and is committed to protecting the personal information you provide while using our website. This Privacy Notice outlines how we collect, use, disclose, and protect your personal information. Personal information collected via the Corporate Administration Platform, Cayman Business Portal, Vital Statistics Birth, Death & Marriages Portal, Company Search Portal and Cayman Online Registry Information System (CORIS) are not covered within this policy.
2. WHAT PERSONAL DATA WE COLLECT
When you use the GR website, contact us via email or online forms or leave comments and questions on our web forms, GR collects relevant personal data.
The scope of data we collect is limited to what is necessary for our operations. Within this Privacy Notice, ‘personal data’ references any information tied to an identified or potentially identifiable living individual. The personal data that we collect includes:
- Identifiers: This includes details like your first name, last name, usernames, other unique identifiers, and email addresses.
- Visual Identifiers: Photos or images that you provide to us, whether mandated by our services or uploaded voluntarily to our systems.
- Technical Data: Details such as your IP address, the device, and the browser version you utilise to access our services. This category also accounts for information like email headers, usage patterns, and more.
- Contact Information: Beyond the email addresses highlighted above, this categoryencompasses telephone numbers and any other contact details you may provide.
- Support and Interaction Details: Data provided during support requests, which may include the identifiers and contact information listed above. Depending on the nature of your support request, other personal details like employment status might also be revealed, whether through emails, online form submissions, online chat conversations, or phone calls.Additionally, this category captures records of your interactions with our customer support channels, noting which support portal articles you’ve accessed or were referred to for assistance.
3. HOW WE USE YOUR PERSONAL DATA
GR via its website, may use your personal data for the following purposes:
- Policy Implementation: Implementing policies, providing services and programmes, and managing your relationship with us.
- User Facilitation: Facilitating your use of our services.
- Inquiries and Support: Responding to your inquiries, providing general or service‐specific support, and sending important notifications and updates.
- Identity Verification: Verifying your identity to ensure the security of your data and our platforms.
- Enhanced Experience: Enhancing your experience interacting with our services and communicating with visitors to our online services.
- Service Interactions: Measuring interactions with GR’s website and continually improving our communication and support channels, including through the use of aggregated data from cookies.
- Fraud Prevention: Managing and protecting our resources by preventing fraud.
- Reporting: Compiling statistical reports for internal use and other reporting, both internally and externally.
- Legal Purposes: Seeking legal advice, exercising or defending legal rights, and complying with our legal obligations, including all legislation applicable across the public sector.
4. HOW WE SHARE YOUR PERSONAL DATA
GR may share your personal data as required, including under applicable legislation, with recipients that include joint data controllers, our data processors, and third parties. We will only share your personal data as permitted by the Cayman Islands Data Protection Act. Your personal data may be shared with the following recipients that support our public functions and operations:
Other public authorities: Personal data may be shared with other public authorities. ‘Public Authorities’ includes Ministries, Portfolios, Offices, Departments, Statutory Authorities, Statutory Bodies, and Government Companies. For instance, article containing information about you or include your personal information may be shared with the other platforms such as the CIG Hub for publication.
External data processors: Personal data may be shared with individuals providing services to GR as data processors in compliance with the DPA. These service providers can only use the data per our instructions. This can encompass:
- Information Technology;
- Records and Information Management, including storage;
- Communications;
- Security operations and fraud prevention;
- Providing service‐specific customer support;
Legal advisors and other persons if required by law or in relation to legal proceedings or rights: Personal data may be disclosed as legally required, for the purpose of or in connection with proceedings under the law, if necessary to obtain legal advice, or if the disclosure is otherwise necessary to establish, exercise or defend legal rights. This may include disclosing your personal data for the following purposes:
- Seeking legal advice;
- Exercising or defending legal rights;
- Complying with internal and external audits or investigations by competent authorities;
- Complying with information security policies or requirements.
5. OUR LEGAL BASES FOR PROCESSING YOUR PERSONAL DATA
Depending on applicable laws and other circumstances, GR will rely on specific legal bases, or “conditions of processing”, under the DPA to process your personal data. These may include:
- Legal Obligation: GR is subject to various legal obligations, including compliance with obligations under the Procurement Act (2023 Revision) and Procurement Regulations (2022 Revision), the Public Management and Finance Act (2020 Revision) and Financial Regulations (2022 Revision), the Public Service Management Act (2018 Revision) and Personnel Regulations (2022 Revision), and the National Archive and Public Records Act (2015 Revision).
- Public Functions: To exercise public functions, including GR’s roles of communicating with staff members and responding to support inquiries.
- Protecting Vital Interests: To protect your vital interests.
- Consent: In certain circumstances where we seek your explicit agreement, such as sharing your data with a third party, gathering analytics for an online service’s usage, or administering surveys.
- Legitimate Interests: When pursued by GR or a third party to whom the personal data may be disclosed. An example includes disclosing records containing third‐party personal data in response to a request submitted under the Freedom of Information Act (2021 Revision).
For the processing of sensitive personal data, a secondary legal basis will also be met, which may encompass:
- Exercising our public functions.
- Engaging in legal proceedings, including seeking legal advice and establishing, exercising, or
- defending legal rights.
6. CHILDREN’S PERSONAL DATA
GR collects personal data relating to children under the age of 18 to enable us to deliver public services and programmes and carry out our functions. We may collect and further process children’s personal data for the purposes set out in this Privacy Notice.
7. SECURITY AND INTERNATIONAL TRANSFERS
GR has ensured that its hosting partners have implemented suitable technical, physical, and organisational measures to ensure your personal data remains secure. To preserve the confidentiality, integrity, and accessibility of your personal data, these precautions include:
- Strong Password Protection: Access to our platforms is fortified using robust, unique passwords. Our password guidelines mandate periodic password modifications and uphold minimum length and complexity requisites to minimize unauthorised access threats.
- Pseudonymisation: Whenever possible, Personal Data on our platforms is pseudonymised, substituting identifiable data components with pseudonyms to reduce the risk of Data Subjects’ identification by unauthorized individuals in the event of a data breach.
- Access Control: Access to Personal Data is restricted to a need‐to‐know basis, supported by role‐based access controls.
- Data Backup and Recovery: We routinely back up Personal Data, which is stored securely to facilitate swift recovery in scenarios of data loss, corruption, or system breakdowns.
- Security Assessments: GR conducts periodic evaluations and audits to pinpoint and remedy potential vulnerabilities within our platforms.
GR will not transfer personal data to organisations, countries or territories failing to ensure an adequate protection level for personal data. Your personal data may be transmitted to:
- Ireland and other EU nations for secure hosting and website analytics purposes.
- Other countries, for providing customer support for specific government functions.
Data transfers will only occur if the organisation, country, or territory guarantees an appropriate protection degree for your rights and freedoms related to your personal data processing, unless the DPA provides a relevant exception or exemption. Such exceptions might encompass your consent or suitable safeguards, like standard contractual clauses.
8. HOW LONG WE KEEP YOUR PERSONAL DATA
GR may store your personal data for as long as we need it in order to fulfil the purpose(s) for which we collected your personal data, and in line with any applicable laws and the agency’s operational and administrative disposal authorities.
10. YOUR RIGHTS
GR will respect and honour your rights in relation to your personal data and implement measures that allow you to exercise your rights under the DPA and other applicable legislation. In accordance with the DPA, your rights in relation to your own personal data include:
- The right to be informed and the right of access: The right to request access to all personal data the GR maintains about you as well as supplementary information about why and how we are processing your personal data. This is commonly known as a Subject Access Request and certain supplementary information about our processing is contained within this Privacy Notice.
- Rights in relation to inaccurate data: The right to request the rectification, blocking, erasure or destruction of any inaccurate personal data GR maintains on you. We will ensure, through all reasonable measures, that your personal data is accurate, complete and, where necessary, up–to–date, especially if it is to be used in a decision‐making process.
- The right to stop or restrict Processing: The right to restrict or stop how GR uses your personal data in certain circumstances.
- The right to stop direct marketing: GR does not currently carry out any direct marketing activities. However, we will update this Privacy Notice and we will also notify you in writing as required if this position changes.
- Rights in relation to automated decision making: The right to obtain information about and object to the use of automated decision making by GR using your personal data. GR does not currently use automated means to make decisions about you. However, we will update this Privacy Notice as required if this position changes.
- The right to complain: The right to complain to the Ombudsman about any perceived violation of the DPA by GR.
- The right to seek compensation: The right to seek compensation in the Court if you suffer damage due to a contravention of the DPA by GR.
You may contact GR, using the contact details listed below, to access and review your personal data or to exercise any other rights provided to you under the DPA. GR will take into consideration circumstances where, under the DPA or other applicable legislation, your rights may be limited or subject to conditions, exemptions or exceptions. Upon contacting GR, we may need to verify your identity prior to fulfilling a request and may request additional information as required. In accordance with the DPA, GR may also charge a reasonable fee in relation to your request if it is unfounded or excessive in nature, or GR may reserve the right not to comply with the request at all.
To learn more about your rights, visit www.ombudsman.ky.
11. DATA PROTECTION PRINCIPLES
When processing your personal data, GR will comply with the eight Data Protection Principlesdefined within the DPA:
- Fair and lawful processing: Personal data shall be processed fairly. In addition, personal data may be processed only if certain conditions are met, for example the data controller is subject to a legal obligation that requires the processing or the processing is necessary for exercise of public functions.
- Purpose limitation: Personal data shall be obtained only for one or more specified, explicit and legitimate purposes, and not processed further in any manner incompatible with that purpose or those purposes.
- Data minimisation: Personal data shall be adequate, relevant and not excessive in relation to the purpose or purposes for which they are collected or processed.
- Data accuracy: Personal data shall be accurate and, where necessary, kept up‐to‐date.
- Storage limitation: Personal data processed for any purpose shall not be kept for longer than is necessary for that purpose.
- Respect for the individual’s rights: Personal data shall be processed in accordance with the rights of data subjects under the DPA, including subject access.
- Security: confidentiality, integrity and availability: Appropriate technical and organisational measures shall be taken against unauthorised or unlawful processing of personal data and against accidental loss or destruction of, or damage to, personal data.
- International transfers: Personal data shall not be transferred to a country or territory unless that country or territory ensures an adequate level of protection for the rights and freedoms of data subjects in relation to the processing of personal data.
12. HOW TO CONTACT US
GR has appointed a Data Protection Leader. If you have any questions about this Privacy Notice or how your personal data is handled, or if you wish to make a complaint, please contact:
Name: Mellisa Layne, Senior Information Manager
Telephone number: +1 (345) 244‐3691
Email Address: Mellisa.layne2@gov.ky
Address: Government Administration Building, 133 Elgin Avenue, Grand Cayman, KY1‐9000
GR aims to resolve inquiries and complaints in a respectful and timely manner.
13. CHANGES TO THIS PRIVACY NOTICE
GR reserves the right to update this Privacy Notice at any time and will publish a new Privacy Notice when we make any substantial updates. From time to time, GR may also notify you about the processing of your personal data in other ways, including by email or through our publications.
This Privacy Notice was created on 11th October, 2024.