Effective date: 2 September 2026
Cayman Islands Data Protection Act (2021 Revision)

This Data Protection Policy explains how The Cayman Islands Directors Association Ltd. (“CIDA”, “the Association”, “we”, “us” or “our”) collects, uses, stores, shares and protects personal data. It is published so that members, applicants, event attendees, website visitors and other individuals can understand how their personal data is handled, and how they may exercise their rights.

CIDA is a company limited by guarantee, established as a self-regulating professional association of individuals resident in the Cayman Islands who hold office as directors of one or more Cayman Islands registered companies. We process personal data as a data controller under the Data Protection Act (2021 Revision) and the Data Protection Regulations, 2018 (together, the “DPA”).

1. Who we are

The data controller is:

The Cayman Islands Directors Association Ltd.
c/o 2D Landmark Square, 64 Earth Close
P.O. Box 30116, Grand Cayman KY1-1201
Cayman Islands
Email for data protection enquiries and requests: membership@cida.ky
Website: https://cida.ky

CIDA is administered by a volunteer Executive Committee. We have not appointed a statutory data protection officer. Day-to-day data protection queries should be sent to membership@cida.ky and will be handled by the Secretary or another officer designated by the Executive Committee.

2. Scope and legal framework

This Policy applies to personal data processed by CIDA in connection with:

  • membership applications, admission, renewal, resignation and records;
  • the public and internal member directory;
  • events, education and accreditation (including the Directors’ Education and Accreditation Program (“DEAP”), educational half-days, the Annual General Meeting and other meetings);
  • invoicing and collection of application and subscription fees;
  • professional communications with members and interested persons;
  • the website at cida.ky and related online forms; and
  • correspondence, complaints and governance of the Association.

The DPA requires personal data to be processed in accordance with eight data protection principles. In summary, personal data must be:

  1. processed fairly and lawfully;
  2. obtained only for one or more specified lawful purposes, and not further processed in a manner incompatible with those purposes;
  3. adequate, relevant and not excessive in relation to those purposes;
  4. accurate and, where necessary, kept up to date;
  5. not kept for longer than is necessary for those purposes;
  6. processed in accordance with the rights of data subjects under the DPA;
  7. protected by appropriate technical and organisational security measures; and
  8. not transferred outside the Cayman Islands unless an adequate level of protection is ensured, or a permitted condition for transfer applies.

CIDA is established in the Cayman Islands and this Policy is issued under the DPA. If we process personal data of individuals in the United Kingdom or the European Economic Area, we will have regard to the UK GDPR or EU GDPR to the extent those laws apply. The governing law of this Policy is the law of the Cayman Islands.

3. Personal data we collect

The categories of personal data we process depend on how you deal with CIDA. They typically include the following.

3.1 Members and applicants

  • Identity and contact details: full name, postal address, email address, telephone number and preferred correspondence details.
  • Professional and eligibility details: directorships of Cayman Islands companies; employer name and CIMA licence status (where applying under Form A); education and professional qualifications; names of sponsoring members (Form B); and confirmation of Cayman Islands residency (Caymanian, permanent resident or work permit, and residence in the Islands for at least six months of the year, as required by the membership criteria).
  • Date of birth: collected on the membership application for internal verification of identity only. Date of birth is not published in the member directory.
  • Membership administration: application status, admission date, subscription year, fee payment status, committee roles, proxies and attendance at general meetings, and declarations that the applicant will abide by the Articles of Association and the CIDA Code of Conduct and will contribute to the Association’s assets up to CI$1.

3.2 Event attendees (members and non-members)

  • Name, organisation, email address, telephone number and dietary or accessibility requirements.
  • Registration status, attendance records and, where relevant, payment of event fees.
  • For DEAP participants, information necessary to enrol you with the Chartered Governance Institute of Canada (or any successor education provider) and to record completion of the programme.

3.3 Website visitors and correspondents

  • Information you submit through website forms or by email (for example enquiries, event check-in, proxy appointments or updates to contact details).
  • Limited technical data such as IP address, browser type, device information and pages visited, generated by the website and any analytics or email-delivery tools we use.

3.4 Sensitive personal data

The DPA gives extra protection to “sensitive personal data”, which includes health information and certain other specified categories. CIDA does not routinely collect sensitive personal data and does not seek criminal, political, religious or similar data as a condition of membership. We may receive limited health or accessibility information if you volunteer it so that we can accommodate you at an event (for example a dietary restriction or mobility requirement). That information is processed on the basis of your consent and is used only for that event. Residency and immigration status is collected solely to assess membership eligibility and is not published.

4. How we collect personal data

We collect personal data:

  • directly from you, when you complete Form A or Form B, register for an event or DEAP, update your details, appoint a proxy, email us, or use the website;
  • from the two CIDA members who sponsor a Form B application, to the extent they confirm your eligibility;
  • from your employer, where a Form A application is supported by a CIMA-licensed firm;
  • from the Executive Committee and event organisers in the ordinary administration of the Association; and
  • automatically, through the website and our email platform, as described in section 10.

You are not obliged to provide personal data to CIDA. However, if you do not provide the information required for membership or an event, we may be unable to process your application, admit you as a member, or complete your registration.

5. Purposes and lawful conditions for processing

Under Schedule 2 of the DPA, personal data may be processed only if a specified condition is met. CIDA relies on the following conditions, depending on the purpose.

Purpose Lawful condition
Membership applications, eligibility checks, billing of the application and annual subscription fees (currently CI$50 application and CI$125 annual subscription), and administration of membership Necessary for a contract with you, or for steps at your request prior to entering that contract (Schedule 2, paragraph 2)
Member directory, events, educational programmes including DEAP, AGM and proxies, industry advocacy, and member communications about CIDA activities Legitimate interests of a professional membership association, balanced against your rights (Schedule 2, paragraph 6)
Photographs or recordings at events; optional promotional or third-party communications that are not reasonably necessary for membership or a booked event Consent, which you may withdraw
Compliance with applicable law, court orders, or requests of competent authorities including the Ombudsman Legal obligation (Schedule 2, paragraph 3)
Dietary, accessibility or similar event information Explicit consent

Members of a professional directors’ association reasonably expect their names to appear in a member directory and to receive operational communications about events, governance and industry matters. You may object to processing based on legitimate interests. We will consider any objection and stop the processing unless we have a compelling ground to continue or the processing is needed for legal claims.

The public directory at https://cida.ky/members/ currently lists member names. Email addresses of Executive Committee officers are published on the Contact Us page and, in some cases, in the directory. If you wish your directory listing to be limited (for example, name only, or removal of an email address), please email membership@cida.ky.

Consent must be freely given, specific, informed and unambiguous. You may withdraw consent at any time by emailing membership@cida.ky. Withdrawal does not affect processing already carried out, and it does not affect processing that CIDA may continue on another lawful condition (for example, membership administration).

6. Who we share personal data with

CIDA does not sell personal data. We disclose personal data only where necessary for the purposes described above, including to:

  • the Executive Committee and authorised volunteers who administer membership, events, finance and communications;
  • event venues and catering providers in Grand Cayman (name, attendance and any dietary or accessibility information you have given us);
  • the Chartered Governance Institute of Canada (and any successor DEAP provider) for enrolment, materials, assessment and accreditation;
  • email, website and IT service providers who host cida.ky, store files or send bulk email on our behalf (our current membership-email platform is operated via Mailchimp / The Rocket Science Group, part of Intuit, which processes data in the United States);
  • professional advisers, banks and payment channels used to invoice and receive fees. CIDA does not collect or store full credit or debit card numbers on membership application forms;
  • Cayman Finance and other industry bodies only where you have agreed to be identified in connection with a joint event or publication, or where disclosure is otherwise lawful; and
  • regulators, the Ombudsman, law enforcement or the courts where we are required or permitted by law to do so.

Where a third party processes personal data on CIDA’s behalf, it is a data processor. The DPA requires us to choose processors that provide sufficient guarantees of security and to put in place a written contract containing appropriate data-protection obligations. CIDA remains responsible for personal data processed on its behalf.

7. International transfers

The eighth data protection principle restricts transfers of personal data outside the Cayman Islands unless the destination ensures an adequate level of protection, or a condition in Schedule 4 of the DPA applies.

In the ordinary course of CIDA’s activities, personal data may be transferred to, or accessed from:

  • Canada, in connection with DEAP and the Chartered Governance Institute of Canada;
  • the United States, in connection with our email platform (Mailchimp) and any US-hosted website, file-storage or payment tools; and
  • the United Kingdom or other jurisdictions, where an officer, adviser, venue group or service provider is located there, or where a member corresponds with us while travelling.

Where we transfer personal data outside the Cayman Islands we will take appropriate steps to protect it. Those steps may include contractual clauses with the recipient, transferring only what is necessary, and relying on a Schedule 4 condition where applicable (including that the transfer is necessary for the performance of a contract with you, such as DEAP enrolment, or that you have consented to the transfer).

8. Retention

The fifth data protection principle requires that personal data is not kept for longer than is necessary for the purpose for which it is processed. CIDA applies the following indicative periods, which may be extended where a complaint, claim, audit or legal obligation requires it:

  • Membership records: for the duration of membership and for seven years after membership ends, so that we can administer the Association, evidence eligibility and meet ordinary limitation periods.
  • Unsuccessful applications: generally up to twenty-four months after the decision, unless you ask us to keep a record with a view to a later application.
  • Event and DEAP records: generally up to seven years after the event or after completion of the programme (accreditation records may be kept longer where needed to confirm that a person completed DEAP).
  • Financial records: generally seven years.
  • Website logs and email analytics: for the shortest period the relevant service requires for security and operation, typically not more than twenty-four months.
  • Dietary or accessibility information: deleted after the relevant event unless you ask us to retain it for future events.

When personal data is no longer required we will delete or irreversibly anonymise it, or (in the case of back-ups) isolate it until the back-up cycle expires.

9. Security

The seventh data protection principle requires appropriate technical and organisational measures against unauthorised or unlawful processing and against accidental loss, destruction or damage. Taking account of CIDA’s size as a volunteer professional association, we:

  • limit access to personal data to Executive Committee members and service providers who need it;
  • use password-protected email, cloud storage and the Association’s website tools;
  • do not collect full payment-card data on application forms;
  • treat date of birth and residency status as internal verification information and do not publish them; and
  • require processors to give contractual security assurances.

No method of electronic transmission or storage is completely secure. If you have reason to believe that your interaction with us is no longer secure, please notify membership@cida.ky immediately.

10. Website, cookies and email tools

The website at https://cida.ky is used to publish Association information, the member directory, event notices and membership application forms. The site and our email tools may set cookies or similar technologies that are necessary for the site to function, that remember preferences, or that provide aggregate usage statistics.

Membership contact-detail updates and certain bulk emails are sent through Mailchimp (cida.us17.list-manage.com). Mailchimp’s own privacy notice applies to its processing as a provider. You may unsubscribe from non-essential mailing lists using the link in those emails, or by writing to membership@cida.ky. Operational messages about your membership, fees, meetings and events you have booked may still be sent.

cida.ky may contain links to third-party sites (for example Cayman Finance, event venues or the Chartered Governance Institute of Canada). CIDA is not responsible for the privacy practices of those sites.

11. Your rights under the DPA

Subject to the exemptions in the DPA, you have the following rights.

  • Right to be informed. You are entitled to be told who is processing your personal data and for what purpose. This Policy is intended to meet that requirement.
  • Right of access. You may request in writing confirmation of whether CIDA processes your personal data, a copy of that data, and certain supplementary information (including purposes, categories of data, recipients, any overseas transfers, and your right to complain to the Ombudsman). We will respond as soon as reasonably practicable and generally within thirty days of receiving a valid written request. We may need to verify your identity. Access requests are free of charge. A reasonable fee may be charged, or a request refused, only if the request is manifestly unfounded or excessive (for example repetitive or fraudulent), as provided in the Data Protection Regulations, 2018.
  • Accuracy and rectification. We must keep personal data accurate and, where necessary, up to date. Please tell us if your details change. If data is inaccurate, you may require it to be corrected. If we do not agree that it is inaccurate, you may complain to the Ombudsman, who can order rectification, blocking, erasure or destruction.
  • Right to stop or restrict processing. You may require CIDA to cease, or not to begin, processing your personal data where the processing is causing or is likely to cause unwarranted substantial damage or distress. Statutory exemptions apply.
  • Direct marketing. You may require CIDA at any time to stop, or not to begin, processing your personal data for the purpose of direct marketing. Operational membership and event messages are not treated as direct marketing.
  • Automated decision-taking. You have rights where a decision significantly affecting you is taken solely by automated means. CIDA does not take membership or event decisions solely by automated means.
  • Complaint and compensation. You may complain to the Office of the Ombudsman and, in appropriate cases, seek compensation for damage caused by a contravention of the DPA.

The DPA does not confer a general “right to erasure” or a “right to data portability” of the kind found in the EU GDPR. CIDA will nevertheless delete or anonymise personal data when it is no longer needed, in accordance with the fifth data protection principle and section 8 of this Policy.

Please make access and other rights requests in writing to membership@cida.ky. Describe the right you wish to exercise and provide enough information for us to identify you and locate the relevant records.

12. Personal data breaches

If CIDA becomes aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data, we will notify the Ombudsman and the affected individual(s) without undue delay and in any event within five days after we should, with the exercise of due diligence, have been aware of the breach, as required by section 16 of the DPA. The notification will describe the nature and consequences of the breach and the measures we have taken or propose to take.

13. How to contact CIDA

For questions about this Policy, to update your details, to limit your directory listing, to withdraw consent, or to exercise any right under the DPA:

The Cayman Islands Directors Association Ltd.
c/o 2D Landmark Square, 64 Earth Close
P.O. Box 30116, Grand Cayman KY1-1201, Cayman Islands
Email: membership@cida.ky
Website: https://cida.ky

14. How to complain to the Ombudsman

If you are not satisfied with our response, or if you believe CIDA has not processed your personal data in accordance with the DPA, you may complain to the Cayman Islands supervisory authority:

Office of the Ombudsman
5th Floor, Anderson Square, 64 Shedden Road, George Town, Grand Cayman
P.O. Box 2252, Grand Cayman KY1-1107, Cayman Islands
Email: info@ombudsman.ky
Telephone: +1 345 946 6283
Website: https://ombudsman.ky

Complaint forms are available on the Ombudsman’s website. You may also be able to seek a civil remedy in the Grand Court of the Cayman Islands.

15. Changes to this Policy

The Executive Committee may revise this Policy from time to time to reflect changes in law, guidance from the Ombudsman, or CIDA’s operations. The current version will be published on this page. The effective date at the head of the Policy will be updated when a revision is issued. Material changes will be drawn to members’ attention by email where practicable.

This Policy does not form part of any contract except to the extent it describes how CIDA will handle personal data in connection with membership and events. Nothing in this Policy limits any right you have under the DPA.

Approved for publication by the Executive Committee
The Cayman Islands Directors Association Ltd. — 2 September 2026