Privacy Notice - WORC
The Cayman Islands Government Workforce Opportunities & Residency Cayman, “WORC”, respects your privacy and takes care in protecting your personal data. As a data controller, we comply with the Cayman Islands Data Protection Act (2021 Revision) (the “DPA”). This privacy notice (“Privacy Notice”) demonstrates our commitment to ensuring your personal data is handled responsibly and applies to WORC.
On this page:
What Personal Data we collect
- Personal data we collect directly from you
- How we use your Personal Data
- How we share your Personal Data
- Our legal bases for processing your Personal Data
- Children’s Personal Data
- Security and international transfers
- How long we keep your Personal Data
- Your rights
- Data Protection Principles
- How to contact us
- Changes to this Privacy Notice
WORC provides online services, such as JobsCayman. When you engage with these platforms, whether it's by utilising them directly, contacting us via email, online forms, or phone, or even when leaving comments and questions on our web forms, WORC collects relevant personal data.
The scope of data we collect is limited to what is necessary for our operations. Within this Privacy Notice, 'personal data' references any information tied to an identified or potentially identifiable living individual. The personal data that we collect includes:
- Identifiers: This includes details like your first name, last name, usernames, other unique identifiers, and email addresses.
- Visual Identifiers: Photos or images that you provide to us, whether mandated by our services or uploaded voluntarily to our systems.
- Technical Data: Details such as your IP address, the device, and the browser version you utilise to access our services. This category also accounts for information like email headers, caller ID data, usage patterns, and more. For further insights into some related data collection practices, like cookies, you can refer to our Cookie Notice.
- Contact Information: Beyond the email addresses highlighted above, this category encompasses telephone numbers and any other contact details you may provide.
- Support and Interaction Details: Data provided during support requests, which may include the identifiers and contact information listed above. Depending on the nature of your support request, other personal details like employment status or property ownership might also be revealed, whether through emails, online form submissions, online chat conversations, or phone calls. Additionally, this category captures records of your interactions with our customer support channels, noting which support portal articles you've accessed or were referred to for assistance.
WORC collects the following information directly from you:
- Personal data provided by you when using online systems provided by WORC;
- Personal data that you provide when you contact us or our delegates by email, online form or telephone;
- Personal data that is provided on documents or images, such as your photo, that you provide to WORC, send to us by email, or upload to our servers;
- Personal data that is provided within comments and questions, including your name and/or email address if you provide these details in our web forms. If you ask questions about our public services and programmes or provide information about your relationship with us, this may also reveal other personal data, e.g. your personal preferences; and
- Your Internet Protocol (“IP”) address, details of which device or version of web browser you used to access our website content, and other information about how you used our website; (see our Cookie Notice for more information - https://qa-my.egov.ky/web/worc/privacy-notice).
The purpose of the Civil Service is to make the lives of those we serve better. We are dedicated to supporting the elected government by delivering caring, modern, and customer-centric public services and programmes, which deliver value for money. WORC, through its various platforms and services, may use your personal data for the following purposes:
- Policy Implementation: Implementing policies, providing services and programmes, and managing your relationship with us.
- User Facilitation: Facilitating your use of our services.
- Inquiries and Support: Responding to your inquiries, providing general or service-specific support, and sending important notifications and updates.
- Identity Verification: Verifying your identity to ensure the security of your data and our platforms.
- Enhanced Experience: Enhancing your experience interacting with our services and communicating with visitors to our online services.
- Service Interactions: Measuring interactions with WORC’s online services and continually improving our communication and support channels, including through the use of aggregated data from cookies.
- Fraud Prevention: Managing and protecting our resources by preventing fraud.
- Reporting: Compiling statistical reports for internal use and other reporting, both internally and externally.
- Legal Purposes: Seeking legal advice, exercising or defending legal rights, and complying with our legal obligations, including all legislation applicable across the public sector.
WORC may share your personal data as required, including under applicable legislation, with recipients that include joint data controllers, our data processors, and third parties. We will only share your personal data as permitted by the DPA.
Your personal data may be shared with the following recipients that support our public functions and operations:
- Other public authorities: Personal data may be shared with other public authorities. ‘Public Authorities’ includes Ministries, Portfolios, Offices, Departments, Statutory Authorities, Statutory Bodies, and Government Companies. We do this for purposes including verifying your identity and enhancing your interaction with our services.
- External data processors: Personal data may be shared with individuals providing services to WORC as data processors in compliance with the DPA. These service providers can only use the data per our instructions. This can encompass:
- Information Technology;Records and Information Management, including storage;
- Security operations and fraud prevention;
- Providing service-specific customer support;
- Legal advisors and other persons if required by law or in relation to legal proceedings or rights: Personal data may be disclosed as legally required, for the purpose of or in connection with proceedings under the law, if necessary to obtain legal advice, or if the disclosure is otherwise necessary to establish, exercise or defend legal rights. This may include disclosing your personal data for the following purposes:
- Seeking legal advice;
- Exercising or defending legal rights;
- Complying with internal and external audits or investigations by competent authorities;
- Complying with information security policies or requirements.
Depending on applicable laws and other circumstances, WORC will rely on specific legal bases, or “conditions of processing”, under the DPA to process your personal data. These may include:
- Legal Obligation: WORC is subject to various legal obligations, including compliance with obligations under the Procurement Act (2023 Revision) and Procurement Regulations (2022 Revision), the Public Management and Finance Act (2020 Revision) and Financial Regulations (2022 Revision), the Public Service Management Act (2018 Revision) and Personnel Regulations (2022 Revision), and the National Archive and Public Records Act (2015 Revision).
- Public Functions: To exercise public functions, including WORC’s roles in providing online services and responding to support inquiries.
- Contractual Necessity: To perform or enter into a contract with you.
- Protecting Vital Interests: To protect your vital interests.
- Consent: In certain circumstances where we seek your explicit agreement, such as sharing your data with a third party, gathering analytics for an online service’s usage, or administering surveys.
- Legitimate Interests: When pursued by WORC or a third party to whom the personal data may be disclosed. An example includes disclosing records containing third-party personal data in response to a request submitted under the Freedom of Information Act (2021 Revision).
- Exercising our public functions.
- Engaging in legal proceedings, including seeking legal advice and establishing, exercising, or defending legal rights.
- Strong Password Protection: Access to our platforms is fortified using robust, unique passwords. Our password guidelines mandate periodic password modifications and uphold minimum length and complexity requisites to minimize unauthorised access threats.
- Pseudonymisation: Whenever possible, Personal Data on our platforms is pseudonymised, substituting identifiable data components with pseudonyms to reduce the risk of Data Subjects' identification by unauthorized individuals in the event of a data breach.
- Multi-Factor Authentication (MFA): MFA is the standard for all administrative access to our platforms, fortifying security by obligating users to offer at least two identification forms before access.
- Access Control: Access to Personal Data is restricted to a need-to-know basis, supported by role-based access controls.
- Data Backup and Recovery: We routinely back up Personal Data, which is stored securely to facilitate swift recovery in scenarios of data loss, corruption, or system breakdowns.
- Security Assessments: WORC conducts periodic evaluations and audits to pinpoint and remedy potential vulnerabilities within our platforms.
- Ireland and other EU nations for secure hosting and website analytics purposes.
- Other countries, for providing customer support for specific government functions.
- The right to be informed and the right of access: The right to request access to all personal data the WORC maintains about you as well as supplementary information about why and how we are processing your personal data. This is commonly known as a Subject Access Request and certain supplementary information about our processing is contained within this Privacy Notice.
- Rights in relation to inaccurate data: The right to request the rectification, blocking, erasure or destruction of any inaccurate personal data WORC maintains on you. We will ensure, through all reasonable measures, that your personal data is accurate, complete and, where necessary, up to date, especially if it is to be used in a decision-making process.
- The right to stop or restrict Processing: : The right to restrict or stop how WORC uses your personal data in certain circumstances.
- The right to stop direct marketing: : WORC does not currently carry out any direct marketing activities. However, we will update this Privacy Notice and we will also notify you in writing as required if this position changes.
- Rights in relation to automated decision making: : The right to obtain information about and object to the use of automated decision making by WORC using your personal data. WORC does not currently use automated means to make decisions about you. However, we will update this Privacy Notice as required if this position changes.
- The right to complain: : The right to complain to the Ombudsman about any perceived violation of the DPA by WORC.
- The right to seek compensation: : The right to seek compensation in the Court if you suffer damage due to a contravention of the DPA by WORC.
- Fair and lawful processing: Personal data shall be processed fairly. In addition, personal data may be processed only if certain conditions are met, for example the data controller is subject to a legal obligation that requires the processing or the processing is necessary for exercise of public functions.
- Purpose limitation: Personal data shall be obtained only for one or more specified, explicit and legitimate purposes, and not processed further in any manner incompatible with that purpose or those purposes.
- Data minimisation: Personal data shall be adequate, relevant and not excessive in relation to the purpose or purposes for which they are collected or processed.
- Data accuracy: Personal data shall be accurate and, where necessary, kept up-to-date.
- Storage limitation: Personal data processed for any purpose shall not be kept for longer than is necessary for that purpose.
- Respect for the individual’s rights: Personal data shall be processed in accordance with the rights of data subjects under the DPA, including subject access.
- Security – confidentiality, integrity and availability: Appropriate technical and organisational measures shall be taken against unauthorised or unlawful processing of personal data and against accidental loss or destruction of, or damage to, personal data.
- International transfers: Personal data shall not be transferred to a country or territory unless that country or territory ensures an adequate level of protection for the rights and freedoms of data subjects in relation to the processing of personal data.
For the processing of sensitive personal data, a secondary legal basis will also be met, which may encompass:
WORC collects personal data relating to children under the age of 18 to enable us to deliver public services and programmes and carry out our functions. We may collect and further process children’s personal data for the purposes set out in this Privacy Notice.Security and International Transfers
WORC has implemented suitable technical, physical, and organisational measures to ensure your personal data remains secure. To preserve the confidentiality, integrity, and accessibility of your personal data, these precautions include:
WORC will not transfer personal data to organisations, countries or territories failing to ensure an adequate protection level for personal data. Your personal data may be transmitted to:
Data transfers will only occur if the organisation, country, or territory guarantees an appropriate protection degree for your rights and freedoms related to your personal data processing, unless the DPA provides a relevant exception or exemption. Such exceptions might encompass your consent or suitable safeguards, like standard contractual clauses.How Long We Keep Your Personal Data
WORC may store your personal data for as long as we need it in order to fulfil the purpose(s) for which we collected your personal data, and in line with any applicable laws. This includes the National Archive and Public Records Act (2015 Revision), which governs the creation, maintenance and disposal of all public records. Sometimes, we may choose to anonymise your personal data so that it is no longer associated with you.Cookies
Cookies, along with pixels, local storage objects, and similar technologies (hereafter collectively referred to as "Cookies" unless specified), are employed to distinguish between visitors to a website. When you access WORC websites or portals these small text-based files might be saved on your device (be it a computer, phone, tablet, or any other device) via your browser. These text files store information.
WORC will respect and honour your rights in relation to your personal data and implement measures that allow you to exercise your rights under the DPA and other applicable legislation.
In accordance with the DPA, your rights in relation to your own personal data include:
You may contact WORC, using the contact details listed below, to access and review your personal data or to exercise any other rights provided to you under the DPA. WORC will take into consideration circumstances where, under the DPA or other applicable legislation, your rights may be limited or subject to conditions, exemptions or exceptions.
Upon contacting WORC, we may need to verify your identity prior to fulfilling a request and may request additional information as required. In accordance with the DPA, WORC may also charge a reasonable fee in relation to your request if it is unfounded or excessive in nature, or WORC may reserve the right not to comply with the request at all.
To learn more about your rights, visit www.ombudsman.ky.
When processing your personal data, WORC will comply with the eight Data Protection Principles defined within the DPA:
WORC has appointed a Data Protection Leader. If you have any questions about this Privacy Notice or how your personal data is handled, or if you wish to make a complaint, please contact:
Name: Jeremy Scott, Director Workforce Opportunities & Residency Cayman
Telephone number: +1 (345) 945-9672
Email Address: email@example.com
Address: Apollo House West,87 Mary Street, George Town, Grand Cayman, KY1-9000
WORC aims to resolve inquiries and complaints in a respectful and timely manner.
WORC reserves the right to update this Privacy Notice at any time and will publish a new Privacy Notice when we make any substantial updates. From time to time, WORC may also notify you about the processing of your personal data in other ways, including by email or through our publications.Changes to this policy