Protecting Personal Data – the New Normal

Published: 30 Jun 2020
Type: Insight

One unanticipated consequence of the COVID pandemic has been the huge increase in the collection of personal data.

With much of the world’s population working remotely for extended periods, people have had to quickly sign up to digital tools and communications platforms often without fully understanding how those tools may be collecting their personal data, or worse, knowing that the companies behind those platforms will harvest their data, but having no alternative but to accept. At the same time, their smart home devices are capable of recording confidential conversations and their phones are able to track their movements with increasingly accurate precision. Should these workers venture outside their temporary home offices, new surveillance and tracking measures to monitor “lockdowns” and public health authorities are increasingly sharing medical data, all in an attempt to keep the virus under control.


The invasiveness of these measures varies from jurisdiction to jurisdiction. While governments may be able to rely on national security or public interest exemptions under local data protection laws to collect and share personal data during times of crisis, individuals are increasingly concerned about how their personal data may be used, with whom it may be shared and the impact on their rights. The spectre of stigmatisation has already been evident. There is also a longer-term concern around how some of these increased collection measures will be “rolled back” once the crisis ends or if they will be reduced at all.

Data Protection Rights and Obligations

Under Cayman’s Data Protection Law (DPL), personal data must be processed fairly and lawfully and used for a legitimate purpose that has been notified to the individual. Personal data holdings should not be excessive in relation to the purposes for which they are collected and should be securely purged once those purposes have been fulfilled. If personal data is processed for any new purposes, this processing can only be undertaken if there is a legitimate purpose for doing so which has been notified to the affected individual.

The DPL gives individuals the right to access personal data held about them and to request that any inaccurate data is corrected or deleted. Businesses are obliged to cease processing personal data once the purposes for which that data has been collected have been exhausted. Data retention periods are not prescriptive but each data controller must determine for how long data should be kept and ascertain how it might be securely deleted once the purposes for holding it have been satisfied, in this case, once the crisis ends.

Where personal data is shared between parties, contractual or other provisions should be put in place between the data controller and the third party processor to ensure that any personal data is processed only for authorised purposes, that all data is stored and transmitted securely and that incident response plans are in place in the event of a data breach. Use of subcontractors by the service provider should be prohibited without the prior approval of the data controller, particularly where international transfers of data are involved.

Post-Lockdown Considerations

As lockdown restrictions are eased and workplaces and other locations begin to reopen, employers and organisations will need to put appropriate measures in place to keep people safe. Those measures are likely to further impact the use of personal data. Some of the most frequently asked scenarios are considered below.

Can I use temperature checks or thermal cameras to monitor staff and members of the public for symptoms?

The DPL does not prevent you from taking steps to keep your employees and the public safe but it does require you to be responsible with people’s personal data and ensure it is handled with care. As you will be processing information that relates to an identified or identifiable individual, you need to comply with the DPL. Personal data that relates to health is classed as ‘sensitive personal data’ so it must be even more carefully protected.

When considering the use of more intrusive technologies, especially for capturing health information, you need to give thought to the purpose and context of its use and be able to make the case for using it. Any monitoring of employees needs to be necessary and proportionate, and in keeping with their reasonable expectations. You should also think about whether you can achieve the same results through other less privacy intrusive means. If so, then the monitoring may not be considered proportionate.

Protecting legitimate business interests and providing a safe working environment for employees are likely to be appropriate legal grounds for carrying out testing as long as you are not collecting or sharing irrelevant or unnecessary data.

How often should I check for symptoms?

This will depend on the social distancing and other measures that your organisation needs to put in place. Any testing of your staff, and subsequent processing of their health information, should be reasonable and proportionate to the circumstances including their role.

As an employer, and a data controller for your employees’ health information, you will need to decide the appropriate timescale between tests. For front line staff who interact with the public, more regular testing may be appropriate.

You also have a responsibility to ensure that you hold accurate personal data. The health status of an individual may change over time, so if you record the test results, you should ensure those records are accurate by including the date and time of the result. Any decisions to send staff home or otherwise impact their employment should be based on factually accurate information.

Can I keep lists of employees who have symptoms or have been tested as positive?

Yes. If you need to collect specific health data about employees, you need to ensure the use of the data is actually necessary and relevant for your stated purpose. You should also ensure that the data processing is secure, and consider any duty of confidentiality owed to employees.

As an employer, you must also ensure that such lists do not result in any unfair or harmful treatment of employees. For example, this could be due to inaccurate information being recorded, or a failure to acknowledge an individual’s health status changing over time.

These lists should only be retained for a short period and should not be used for any other purposes.

How do I ensure I don’t collect too much data?

For sensitive personal data, such as health data, it is particularly important to only collect and retain the minimum amount of information you need to fulfil your purpose.

In order to not collect too much data, you must ensure that it is:

  • enough to properly fulfil your stated purpose;
  • relevant and has a sensible link to that stated purpose; and
  • limited to what is necessary – you should not hold more data than you need to fulfil that purpose.

Can I use recorded CCTV footage to assist with contact tracing?

The analysis of CCTV footage could assist with contact tracing. You should assess whether this is necessary in the specific circumstances and consider speaking to the individuals who would be affected and to provide advice on appropriate measures such as self-isolation. Analysis of CCTV footage could reveal sensitive aspects of an individual’s behaviours and relationships. Employees have legitimate expectations that they can keep their personal lives private. This approach for employees should therefore be considered in the context of your existing employee monitoring policy.

Privacy should not be a casualty

As a result of the coronavirus, most people accept and appreciate the need for extraordinary measures to protect the vulnerable. The measures being developed in response to the virus must take privacy issues into account, have one eye on the long term use of the data being collected, and ensure privacy is not another casualty of the crisis.

Appleby will launch its Offshore Data Protection Guide on July 8th, providing a detailed overview of the data protection and cyber security regimes in eight of the world’s largest offshore jurisdictions. As the first dedicated offshore data protection publication, this guide will provide quick linked answers to some of the most business critical issues. For more information on the guide, or to be added to the distribution list, contact us.

Share
More publications
Appleby-Website-Banking-and-Asset-Finance
13 Jul 2026

Guide to Loans & Secured Financing in the Cayman Islands 2026

This guide provides local insights into the legal and regulatory framework governing bank lending and finance. It covers key topics including bank loans versus debt securities, common forms of bank loan facilities, bridge financing, the roles of agents, trustees and lenders, and governing laws. It also examines the regulatory landscape, including capital, liquidity and disclosure requirements, the use of loan proceeds, cross-border lending, and interest rate and currency restrictions. In addition, the guide explores security interests and guarantees, the impact of fraudulent conveyance and similar doctrines on bank loan financing structures, intercreditor arrangements, loan terms and structures, and recent market developments.

Appleby-Website-Insolvency-and-Restructuring
9 Jul 2026

A Warning to Litigants Seeking Funding: English High Court Clarifies the Limits of Litigation Privilege

Important for Cayman litigants, funders and attorneys given the growing use of third-party funding in disputes.

Appleby-Website-Fraud-and-Asset-Tracing
8 Jul 2026

A Cautionary Tale in Interim Injunctive Relief: Lessons from Dixon v Seymour

In a recent judgment of Chief Justice Ramsay-Hale, the Cayman Grand Court provided guidance on the necessary components of an application for interim injunctive relief. The ruling illustrates how an ex parte application may fail to satisfy the American Cyanamid test when unsupported by proper evidence.

Appleby-Website-Regulatory-Practice
7 Jul 2026

CIMA’s 2026 Reinsurance Thematic Review: Focus Points for Boards

The Cayman Islands Monetary Authority (CIMA) has published its 2026 Thematic Review of Reinsurance Companies (Thematic Review). This reflects fieldwork conducted by CIMA between mid-2025 and Q1 2026 at selected Class B(iii) and Class D licensed reinsurers. The focus being on compliance with the Insurance Act (as revised) and other applicable legislation, regulations, rules and statements of guidance as issued by CIMA centering around stress-testing, cash flow testing frameworks, capital and collateral adequacy management, and corporate governance. Corporate governance weaknesses account for 68% of all findings with the remaining 32% spread across stress-testing, cash flow testing capital and collateral adequacy. Notwithstanding these findings, CIMA has noted several good practices across all areas including, importantly, comprehensive risk management frameworks covering key risk areas and strong capital and collateral adequacy monitoring processes. With Cayman’s reinsurance sector having grown to an institutional scale, and over 110 licensed reinsurers writing in the order of US$30 billion in annual premiums against over US$100 billion in assets, this latest Thematic Review demonstrates development in CIMA’s supervisory expectations of Cayman’s licensed reinsurers. It represents a reflection of the jurisdiction’s increasingly sophisticated and maturing reinsurance market and reinforces that CIMA’s expectations align closely with the standards that onshore counterparty cedants, rating agencies and US state regulators already expect. We take this opportunity to review certain of the key findings alongside CIMA’s cross-sectoral 2026 Thematic Review on Outsourcing, note some of the good practices highlighted by CIMA and make some associated recommendations for Cayman reinsurers.

Appleby-Website-Regulatory-Practice
25 Jun 2026

CIMA Enforcement Action in Focus: Reminders and Recommendations

The Cayman Islands Monetary Authority (CIMA) has recently published a number of Enforcement Notices that provide helpful context for regulated entities, including Licensees and Registered Persons under the Securities Investment Business Act (Revised) (SIBA), seeking to understand and meet their ongoing regulatory obligations in the Cayman Islands. In early June 2026, CIMA exercised its enforcement powers under SIBA Section 17 to cancel the registrations of several SIBA Registered Persons on the basis that it had reasonable grounds to believe that such Registered Persons had failed to meet certain key regulatory obligations. The Appleby Team takes this opportunity to review the relevant findings and CIMA enforcement action; and to highlight certain key obligations that attach to regulated entities in the Cayman Islands.

Appleby-Website-Regulatory-Practice
23 Jun 2026

Important Cayman Islands Industry Advisory: Common Reporting Standard 2.0 and Economic Substance Updates

Further to the introduction of the Tax Information Authority (International Tax Compliance) (Common Reporting Standard) (Amendment) Regulations, 2025 (the CRS Amendment Regulations or CRS 2.0), the Cayman Islands Department for International Tax Cooperation (DITC) has issued an Industry Advisory flagging certain key updates in respect of Common Reporting Standard (CRS) and Economic Substance (ES) reporting in the Cayman Islands. Cayman Financial Institutions will be required file 2025 CRS Returns and Declarations by 31 July 2026, ahead of the online DITC Portal’s closure to facilitate its transition to XML Schema v3.0. ES courtesy reminders (which have historically been sent by email to designated Responsible Persons in advance of annual ES reporting deadlines) will no longer be issued such that Relevant Entities will need to independently track such deadlines themselves. Updated Individual and Entity CRS Self-Certification forms, aligned with CRS 2.0, are now available online via the DITC website.

JPLs, Directors and Arbitration: Grand Court Clarifies the Scope of Provisional Liquidators' Powers
18 Jun 2026

JPLs, Directors and Arbitration: Grand Court Clarifies the Scope of Provisional Liquidators' Powers

In Peakwave Investment Management Ltd v Energy Evolution GP Ltd [2026] CIGC (FSD) 22, the Grand Court clarified the scope of joint provisional liquidators' powers following their appointment. In particular, the Court confirmed that the appointment of provisional liquidators does not automatically displace existing directors.

Appleby-Website-Cayman2
17 Jun 2026

Property, Fairness and the Constitution: The Grand Court Marks the Boundaries of Freedom of Information

The Grand Court of the Cayman Islands has overturned a decision of the Ombudsman in a successful judicial review brought by Caribbean Utilities Company, Ltd. (CUC), represented by Appleby.

JPLs, Directors and Arbitration: Grand Court Clarifies the Scope of Provisional Liquidators' Powers
28 Apr 2026

The Interplay Between Supervision Applications and Winding Up on the Just and Equitable Ground: Re Atlas Capital Markets LLC

In its recent judgment in Re Atlas Capital Markets LLC [2026] CIGC (FSD) 19, the Grand Court considered itself bound to make a supervision order pursuant to s.131(b) of the Companies Act, notwithstanding that the company was the subject of a pending just and equitable winding up (J&E) petition when its voluntary liquidation was commenced; and rejected an attack on the joint voluntary liquidators’ (JVLs) independence, which was principally based on a misreading of the JVLs’ evidence and lacked any objective foundation. The authors, who successfully represented the JVLs in obtaining the supervision order, discuss this important judgment further below – which is believed to be the first decision on the interplay between supervision applications and J&E proceedings under the Companies Act – and offer their views on the guidance that shareholders petitioning on the just and equitable ground may derive from it in future cases.  The challenge to the JVLs’ independence was rejected on the well-established principles which Doyle J discussed in Re Global Fidelity Bank [2021] 2 CILR 361, and is not discussed in further detail below.