TerraLex Cross-Border Guide to Global Crisis Management Regulatory Guide

Welcome to the TerraLex global crisis management regulatory guide

When a crisis hits your organisation, you need to take action quickly. What practical steps can you and your team take to minimize the impact on your business? What are your reporting requirements in the relevant jurisdiction(s)? What legislation applies there?

Our guide provides you with the answers to these questions in relation to key jurisdictions and it supports your understanding of the relevant local legal framework. It also provides high level practical guidance for those crucial first 72 hours, together with contact details of the local TerraLex firm for when you need specialist advice.

A crisis, by its nature, is both serious and unexpected and your response and actions within the first 72 hours will most likely define its impact on your organisation.

It is therefore important to have in place robust procedures that, if followed, will help minimize the adverse consequences.

The crisis checklist below includes next steps which are common across all jurisdictions. Please refer to the chapter for the relevant jurisdiction for more detailed guidance on your obligations in that country.

How to Use: You can use the tools below to create bespoke reports for the jurisdiction(s) and topic(s) covered. Click into single jurisdiction for one location or use the compare tool to compare multiple jurisdictions. Select the jurisdictions and topics of interest to create your unique report. You also have the option to print or download using the ellipsis button in the top right corner.

Cayman Islands Global Crisis Management Regulatory Guide Guide

Date posted:
07/10/2022
Last update:
08/10/2022

Data breach

On discovering a data breach, which regulators or other government agencies should be notified?

List: - Under the Data Protection Act (2021 Revision) (DPA), which came into effect on 30 September 2019, the relevant designated authority is the Ombudsman appointed under section 3 of the Ombudsman Act (2021 Revision).

  • In the case of a personal data breach, the DPA provides that the data controller is required to notify the data subject and the Ombudsman of the breach, without undue delay, but no longer than five days after the data controller should, with the exercise of reasonable diligence, have been aware of the breach. Failure to do so is an offence for which the fine is US$120,000 on conviction.

  • Notification of the breach should include the nature of the breach, the consequences of the breach, the measures proposed or taken by the data controller to address the breach and the measures recommended by the data controller to the data subject of the personal data in question to mitigate the possible adverse effects of the breach.

What legislation, relating to both criminal offences and civil wrongs, covers such a breach?

The legislation is the Data Protection Act (2021 Revision). The DPA covers civil and criminal offences, and provides a cause of action for compensation to a person who suffers damage by reason of a contravention of the DPA by a data controller. The offences are punishable by a fine of up to US$120,000 and imprisonment for a term up to five years.

The Ombudsman also has the power to serve a data controller with a monetary penalty order in an amount of up to US$300,000 if he is satisfied on a balance of probabilities that (a) there has been a serious contravention of the DPA by the data controller; and (b) the contravention was of a kind likely to cause substantial damage or substantial distress to the data subject.

"Dawn" raids

What agencies have the power to conduct dawn raids on private sector companies? What legislation gives those agencies the power to undertake those inspections?

List: - Cayman Islands Monetary Authority: Banks and Trust Companies Act (2021 Revision), Companies Management Act (2021 Revision), Monetary Authority Act (2020 Revision), Securities Investment Business Act (2020 Revision)

  • The Police: Police Act (2021 Revision), Proceeds of Crime Act (2020 Revision)

  • HM Customs: Customs Act (2017 Revision), Proceeds of Crime Act (2020 Revision)

On what bases, including privilege and/or confidentiality, may organisations refuse to permit the seizure of documents?

List: - A company may ordinarily refuse to hand over documents which are legally privileged. Confidentiality alone will not normally be sufficient grounds to avoid disclosure.

  • The terms of any warrant or similar authority for the search should be carefully checked to ensure that any document sought to be seized falls within its terms (as to date, subject matter etc).

Whistleblowing

What are the circumstances under which an employee is entitled to protection when reporting an alleged wrongdoing?

List: - The Whistleblower Protection Act (2015 Revision) provides protection for whistleblowers who make known information which is in the public interest.

  • Under this legislation, persons may disclose to the designated authority any information that they have a reasonable belief shows or tends to show that improper conduct has occurred, is occurring or is likely to occur.

What legislative protection does that employee enjoy?

List: - These protections include safeguards against “detrimental action”, such as intimidation, discrimination, adverse treatment or retaliation by employers or other employees. Detrimental action is defined in the law as including:

- action causing injury, loss or damage
- intimidation or harassment
- unlawful discrimination, disadvantage or adverse treatment in relation to a person’s employment, family life, career, profession, trade or business, including the taking of disciplinary action
- preventing, restraining or restricting an employee from making a protected disclosure, and
- inducing any person by threats, promises or otherwise to contravene this Law.
  • If any such detrimental action is taken by an employer against a whistleblower it will be deemed an offence punishable by a fine of up to US$24,000 and imprisonment for a term of up to five years.

  • There will be no protection offered under the law for frivolous or vexatious complaints intending only to humiliate employers, nor will it be offered if the reporting of the information is in itself an offense or the information being reported is legally privileged, and will only gain the protection offered if they are made in the public’s interest.

  • An employer can be held liable for the actions taken by their other employees against any employee who reports suspected wrongdoing and suffers “detrimental action” as a result.

  • A person who takes detrimental action against an employee in reprisal for the employee making a protected disclosure is liable in damages for any injury, loss or damage to that employee.

Anti-bribery and corruption

What are the main anti-corruption laws and regulations in your jurisdiction?

The Anti-Corruption Act (2019 Revision) sets out a number of corruption offenses including bribery (of public officers, members of the Legislative Assembly and foreign public officer), frauds on the government, breach of trust (by public officer or member of the Legislative Assembly); influencing or negotiating appointments or dealing in offices; false claims by public officers; abuse of office; contractor subscribing to election fund, secret commissions, facilitation payments, false statements to the Anti-Corruption Commission, conflict of interests.

Does the legislation have extra-territorial effect?

Yes. Section 39 (1)(b) of the Anti-Corruption Act (2019 Revision) provides that an offense may be committed where the conduct constituting the alleged offense occurs wholly outside the Cayman Islands and at the time of the alleged offense the person committing the offense has Caymanian status, is a resident of the Cayman Islands, or is a body corporate incorporated by or under a law of the Cayman Islands.

What are the main enforcement bodies?

List: - The Anti-Corruption Commission (the “Commission”) – is the designated anti-corruption authority which is comprised of persons appointed by the Governor to receive and investigate any reports of corruption. Where the Commission has reason to suspect the commission of an offense under the Anti- Corruption Act (2019 Revision), following a report being made, the Commission is empowered to carry out an investigation with all the power of investigation provided under Anti-Corruption Act (2019 Revision) and the Criminal Procedure Code (2021 Revision) (including the power of arrest without a warrant). If following its investigation, the Commission determines that a corruption offense has been committed it will refer the matter to the Director of Public Prosecution.

  • Royal Cayman Islands Police – supports the Commission in its investigations.

  • The Director of Public Prosecutions (DPP) – will assist the Commission in determining whether to decline to carry out investigations into a report or to proceed with further investigations. In addition to prosecuting, the DPP will assist the Commission in obtaining Grand Court orders and warrants necessary for the purposes of an investigation.

Internal investigations

Is there any duty to report the issue, for example to a regulator?

List: - The requirement to report will depend on the nature of the company’s business, whether it is subject to regulation and the seriousness of the issue identified by the investigation. In the case of a regulated entity, the duty to report is a matter which must be kept under constant review as and when further information becomes known.

  • If there is a suspicion of money laundering a Suspicious Activity Report should be made immediately to the Cayman Islands Monetary Authority (“CIMA”). Other circumstances such as fraud which could have a detrimental effect on investors also give rise to an obligation to report to CIMA.

What is the protection from disclosure for documents generated as part of the investigation (for example, privilege)?

Documents generated as part of the investigation will generally not be disclosable if they are privileged. There are two relevant types of privilege under Common law:

  • Legal advice privilege protects all communications between a lawyer and client created in the context of seeking legal advice. Where the client is a company, the protection only applies to communications with the individuals authorized to seek legal advice on behalf of the company in relation to the investigation.

  • Litigation privilege may protect documents/communications if they are created for the dominant purpose of litigation and that litigation is reasonably in contemplation at the time the document is created. Litigation privilege applies to communications between relevant employees of the company, third parties and/or legal advisors.

Is the advice given by an in-house lawyer in relation to the investigation privileged and/or confidential?

Generally, advice given by an in-house lawyer regarding an investigation is confidential and privileged, if structured correctly. At the outset of an investigation, it is most likely that legal advice privilege will apply (see above).

However, if litigation becomes likely as the investigation develops, then litigation privilege will also be likely to apply.

Disclaimer: This guide contains summaries of general principles of law. It is not a substitute for specific legal advice and should not be relied upon in relation to the application of the law or subject matter covered.