Ministry of Health External Privacy Notice
Applies to | External Customers to the Ministry of Health | ||||||
Responsibility | Data Protection Leader (“DPL”) | Revision Description | Author | Maria Brown-Lewis | |||
Version | 1 | Initial Document release | Date | November 8, 2023 | |||
2 | Ministry reassignment of subject matters | Date | December 3,2024 |
Version Control Notice:
This document is a controlled document that supersedes all previous versions. Please discard any previous copies of this document dated prior to the version and publication date noted above this page.
Anyone who obtains an electronic or printed version of this document is responsible for ensuring that they have the latest version. The latest version of this document is available on https://www.gov.ky/health-wellness and can also be obtained by email on request to healthandwellness@gov.ky
The Cayman Islands Government Ministry of Health, MoH or “The Ministry” respects your privacy and takes care in protecting your personal data. As a data controller, we comply with the Cayman Islands Data Protection Act (2021 Revision) (the “DPA”). This privacy notice (“Privacy Notice”) demonstrates our commitment to ensuring your personal data is handled responsibly and applies to the Ministry of Health.
This Privacy Notice does not apply to MoH when we are processing personal data relating to our employees, who are covered under our Employee Privacy Notice. For the avoidance of doubt, personal data collected by the Department of Health Regulatory Services, the Mosquito Research and Control Unit and the Health Services Authority are covered under those entities’ respective privacy notice(s).
The Ministry collects personal data, including sensitive personal data, directly from you and may also collect your personal data indirectly from third party sources. Personal data collected by the Ministry is limited to what is necessary for our processing activities. In this Privacy Notice, personal data includes any data relating to an identified or identifiable living individual and includes: contact details, medical history, complaint details and recruitment data.
Personal data we collect directly from you
The Ministry may collect the following information directly from you:
a. Personal data you provide through our website(s), such as:
i.personal data provided within comments and questions, including your name and/or email address if you provide these details in our web form. If you ask questions about our public services and programmes or provide information about your relationship with us, this may also reveal other personal data, e.g. your employment status and health information.
b. Personal data you provide when you visit our offices and other locations, contact us by email or telephone, or access our programmes and services.
c. Personal data that you provide when you inquire about or apply for a job with the Ministry
d. Any information you choose to provide when interacting with the Ministry on social media platforms, including our Facebook page, Cayman Islands Government (CIG)’s YouTube or Instagram channels; and
e. Any other personal data where the collection is necessary to achieve our lawful purpose(s).
Personal data collected from other sources
The Ministry of Health may collect the following personal data from other sources:
a.We may collect data from third parties that verify Personal Data you provide and third parties that share employment and related information (e.g. references, background checks for prospective employees and CVs that may be provided by third party recruiters). We may also collect data from the Economics and Statistics Office (ESO) to help us to assess the health of the population and to provide necessary health programmes, policies and interventions of national interest.
b. Any other personal data where the collection is necessary to achieve our lawful purpose(s).
The purpose of the Civil Service is to make the lives of those we serve better. We are dedicated to supporting the elected government by delivering caring, modern and customer-centred public services and programmes, which deliver value for money. The Ministry may use your personal data for the following purposes:
a. Implementing policies, providing services and programmes, and managing your relationship with us;
b. Responding to your inquiries;
c. Verifying your identity;
d. Measuring how users interact with our website and continually improving our communications channels (including by aggregating personal data collected using cookies);
e. Communicating and interacting with website visitors;
f. Communications and public relations activities;
g. Managing accounts payable and receivable, preventing fraud, and protecting public funds;
h. Statistical and other reporting, both internally and externally;
i. Seeking legal advice, and exercising or defending legal rights;
j. Complying with our legal obligations, including all legislation that applies across the public sector;
k. Communicating and interacting with job applicants and related third parties (e.g. referees) and carrying out recruitment and selection processes.
The Ministry of Health may share your personal data as required, including under applicable legislation, with recipients that include joint data controllers, our data processors, and third parties. We will only share your personal data as permitted by the Cayman Islands DPA.
Your personal data may be shared with the following recipients that support our public functions and operations:
a. With other public authorities: Personal data may be shared with other public authorities – here, “public authorities” means Ministries, Portfolios, Offices, Departments, Statutory Authorities, Statutory Bodies and Government Companies – for the purposes set out in this Privacy Notice.
b. With data processors external to the CIG: Personal data may be shared with persons providing services to The Ministry of Health as a data processor in compliance with the Cayman Islands DPA. When they are acting as data processors, these service providers are only able to use personal data under our instructions. We engage data processors for a variety of processing activities, which may include:
i. Webhosting;
ii. Information Technology;
iii. Records and Information Management, including storage facilities;
iv. Communications;
v. Marketing and campaigns;
vi. Events management; and
vii. Security operations and fraud prevention.
In limited circumstances, service providers who act as data processors for MoH may also act as a separate data controller in relation to their own purposes for processing your personal data, e.g. to provide customer support, or for analytics or machine learning in order to improve their services. These are unrelated to the purposes for which The Ministry processes your personal data and should be clearly and directly disclosed to you by the service provider through their own separate privacy notice. However, you may contact us to ask about our current service providers and specific instances, if any, that we are aware of where your personal data may be processed for a service provider’s own purposes.
c. With legal advisors and other persons if required by law or in relation to legal proceedings or rights:
Personal data may be disclosed as legally required, for the purpose of or in connection with proceedings under the law, if necessary to obtain legal advice, or if the disclosure is otherwise necessary to establish, exercise or defend legal rights. This may include disclosing your personal data for the following purposes:
i. Seeking legal advice;
ii. Exercising or defending legal rights;
iii. Complying with internal and external audits or investigations by competent authorities;
iv. Complying with information security policies or requirements.
Depending on applicable laws and other circumstances, The Ministry will rely on specific legal bases, or “conditions of processing”, under the Cayman Islands DPA to process your personal data. These may include:
a. A legal obligation to which The Ministry of Health is subject, for example under:
▪ The Procurement Act, (2023 Revision) and Procurement Regulations (2022 Revision),
▪ The Public Management and Finance Act (2020 Revision) and Financial Regulations (2022 Revision),
▪ The Public Service Management Act (2018 Revision) and Personnel Regulations (2022 Revision)
▪ National Archive and Public Records Act (2015 Revision);
▪ Public Authority Act (2020),
▪ Standards in Public Life Act (2021)
b. To exercise public functions, including the functions of The Ministry of Health to empower people in the Cayman Islands to achieve optimal well-being through strategic policies, innovative programmes and proactive services, governed by the highest principles of justice, personal and public integrity, and excellence of standards and functions under various enactments such as the Public Health Act (2021 Revision) and the Mental Health Act (2021 Revision).
c. To perform or enter into a contract with you.
d.To protect your vital interests, e.g. medical referrals and decisions
e. Consent, e.g. to administer surveys and polls;
f. For the purposes of legitimate interests pursued by The Ministry or by a third party or parties to whom the personal data may be disclosed, e.g. when disclosing records containing third party personal data in response to a request submitted under the Freedom of Information Act (2021 Revision).
Where we process your sensitive personal data, we will also meet a second legal basis. These may include:
a. To exercise our public functions e.g. To assess the health status of the population and to develop national health policies
b. In relation to legal proceedings, including obtaining legal advice and otherwise establishing, exercising or defending legal rights; and
c. For medical purposes, including the management of healthcare services
d. For vital interests, including emergency medical treatment and decisions
The Ministry of Health may collect personal data relating to children under the age of 18 to enable us to deliver public services and programmes and carry out our functions or for any of the purposes set out in section 3 of this Privacy Notice.
The Ministry of Health has put in place appropriate technical, physical and organisational measures in order to keep your personal data secure. These safeguards to maintain the confidentiality, integrity and availability of your personal data may include the below and any other controls implemented by the Cybersecurity and Computer Services department.
• Role-based controls e.g. we will only provide the level of system access required for a particular role
• User access management
• Technical controls e g. penetration tests to ensure the robustness of our systems
The Ministry of Health will not transfer personal data to countries or territories that do not ensure an adequate level of protection for personal data.
We will only transfer your personal data to a country or territory that ensures an adequate level of protection for your rights and freedoms in relation to the processing of your personal data, unless there is a relevant exemption or exception under the Cayman Islands DPA. Exceptions may include your consent or appropriate safeguards.
MoH may store your personal data for as long as we need it in order to fulfil the purpose(s) for which we collected your personal data, and in line with any applicable laws. This includes the National Archive and Public Records Act (2015 Revision), which governs the creation, maintenance and disposal of all public records. Sometimes, we may anonymise your personal data so that it is no longer associated with you.
The Ministry of Health will respect and honour your rights in relation to your personal data and implement measures that allow you to exercise your rights under the DPA and other applicable legislation.
In accordance with the DPA, your rights in relation to your own personal data include:
a. The right to be informed and the right of access: The right to request access to all personal data the Ministry maintains about you as well as supplementary information about why and how we are processing your personal data. This is commonly known as a Data Subject Access Request (DSAR) and certain supplementary information about our processing is contained within this Privacy Notice.
b. Rights in relation to inaccurate data: The right to request the rectification, blocking, erasure or destruction of any inaccurate personal data the Ministry maintains on you. We will ensure, through all reasonable measures, that your personal data is accurate, complete and, where necessary, up‑to‑date, especially if it is to be used in a decision-making process.
c. The right to stop or restrict Processing: The right to restrict or stop how The Ministry uses your personal data in certain circumstances.
d. Rights in relation to automated decision making: The right to obtain information about and object to the use of automated decision making by the Ministry using your personal data. The Ministry does not currently use automated means to make decisions about you. However, we will update this Privacy Notice and we will also notify you in writing as required if this position changes.
e. The right to complain: The right to complain to the Ombudsman about any perceived violation of the DPA by the Ministry.
f. The right to seek compensation: The right to seek compensation in the Court if you suffer damage due to a contravention of the DPA by the Ministry.
You may contact the Ministry, using the contact details listed below, to access and review your personal data or to exercise any other rights provided to you under the DPA. The Ministry will take into consideration circumstances where, under the DPA or other applicable legislation, your rights may be limited or subject to conditions, exemptions or exceptions.
Upon contacting the Ministry, we may need to verify your identity prior to fulfilling a request and may request additional information as required. In accordance with the DPA, The Ministry may also charge a reasonable fee in relation to your request if it is unfounded or excessive in nature, or The Ministry may reserve the right not to comply with the request at all.
To learn more about your rights, visit https:www.ombudsman.ky.
When processing your personal data, the Ministry will comply with the eight Data Protection Principles defined within the Cayman Islands DPA:
a. Fair and lawful processing: Personal data shall be processed fairly. In addition, personal data may be processed only if certain conditions are met, for example the Ministry is subject to a legal obligation that requires the processing or the processing is necessary for exercise of public functions.
b. Purpose limitation: Personal data shall be obtained only for one or more specified, explicit and legitimate purposes, and not processed further in any manner incompatible with that purpose or those purposes.
c. Data minimisation: Personal data shall be adequate, relevant and not excessive in relation to the purpose or purposes for which they are collected or processed.
d. Data accuracy: Personal data shall be accurate and, where necessary, kept up-to-date.
e. Storage limitation: Personal data processed for any purpose shall not be kept for longer than is necessary for that purpose.
f. Respect for the individual’s rights: Personal data shall be processed in accordance with the rights of data subjects under the DPA, including subject access.
g. Security – confidentiality, integrity and availability: Appropriate technical and organisational measures shall be taken against unauthorised or unlawful processing of personal data and against accidental loss or destruction of, or damage to, personal data.
h. International transfers: Personal data shall not be transferred to a country or territory unless that country or territory ensures an adequate level of protection for the rights and freedoms of data subjects in relation to the processing of personal data.
If you have any questions about this Privacy Notice or how your personal data is handled, or if you wish to make a complaint, please contact:
Carolina Ferreira, Information and Communications Manager
Telephone number: (345) 244-3142
Email Address: Carolina.Ferreira@gov.ky
Address: 5th Floor, Ministry of Health, 133 Elgin Avenue, George Town
Or
Maria Brown-Lewis, Data Protection Leader
Telephone number: (345) 244-3162
Email Address: maria.brown-lewis@gov.ky
Address: 5th Floor, Ministry of Health, 133 Elgin Avenue, George Town
The Ministry aims to resolve inquiries and complaints in a respectful and timely manner.
The Ministry of Health reserves the right to update this Privacy Notice at any time and will publish a new Privacy Notice when we make any substantial updates. From time to time, The Ministry of Health may also notify you about the processing of your personal data in other ways, including by email or through our publications.