1. Scope
The National Drug Council, (“NDC”), respects your privacy and takes care in protecting your personal data. As a data controller, we comply with the Cayman Islands Data Protection Act (2021 Revision) (the “DPA”). This privacy notice (“Privacy Notice”) demonstrates our commitment to ensuring your personal data is handled responsibly and applies to the NDC.
This Privacy Notice does not apply to the NDC when we are processing personal data relating to our employees, who are covered under our Employee Privacy Notice. This Privacy Notice also does not apply to:
- Employee Data: Personal data collected and processed in relation to NDC employees is covered under the separate Employee Privacy Notice and is not within the scope of this Privacy Notice.
- Data Processed by Other Public Authorities: This Privacy Notice does not apply to personal data processed by other public authorities or government agencies, even if such data is related to the services or programmes provided by the NDC. These entities may have their own privacy notices governing their data processing activities.
- Data Controlled by Third-Party Service Providers: Any personal data collected and processed by third-party service providers that the NDC engages with, where such providers act as independent data controllers, is outside the scope of this Privacy Notice. These third parties are responsible for their own privacy practices and notices.
- External Websites and Social Media Platforms: Personal data collected by external websites or social media platforms that may be linked from the NDC’s online presence is not covered by this Privacy Notice. Users are encouraged to review the privacy policies of these external platforms before sharing their personal data.
2. What Personal Data We Collect
The NDC collects personal data, directly from you and may also collect your personal data indirectly from third party sources. Personal data collected by the NDC is limited to what is necessary for our processing activities. In this Privacy Notice, personal data includes any data relating to an identified or identifiable living individual and includes: Your name, email address, school, and class name.
Personal data we collect directly from you1
The NDC may collect the following information directly from you:
- Personal data you provide through the NDC’s website(s), such as:
- Personal data provided within comments and questions, including your name and/or email address if you provide these details in our web form. If you ask questions about our public services and programmes or provide information about your relationship with us, this may also reveal other personal data, e.g. your employment status
- Your Internet Protocol (“IP”) address, details of which device or version of web browser you used to access our website content, and other information about how you used our website (see our Cookie Notice for more information;
- Personal data you provide when you visit the NDC offices and other locations; contact us by email, by telephone or through our social media channels; or access our programmes and services, including our online services such as our campaign websites;
- Personal data that you provide when you inquire about or apply for a job with the NDC;
- Any information you choose to provide when interacting with the NDC on social media platforms, including Facebook, Instagram, TikTok, or YouTube; and
- Any other personal data where the collection is necessary to achieve our lawful purpose(s).
Personal data collected from other sources
The NDC may collect the following personal data from other sources:
- Background Checks: For job applicants, personal data such as employment history, educational background, and criminal records may be collected from third parties conducting background checks or providing references.
- Service Providers: Personal data may be collected indirectly through service providers who assist the NDC in delivering its services. This may include contractors, consultants, or third-party platforms that gather and transmit personal data on behalf of the NDC.
- Publicly Available Sources: The NDC may also collect personal data from publicly accessible sources, such as social media platforms, public registries, or other publicly available databases, to verify information provided by you or for other lawful purposes.
- Any other personal data where the collection is necessary to achieve our lawful purpose(s).
3. How We Use Your Personal Data
The purpose of the NDC is to co-ordinate anti-drug measures in the Cayman Islands. We are dedicated to supporting our youth and the wider community through programming, research, and policy efforts that enhance prevention efforts against the harms of substance use.2 The NDC may use your personal data for the following purposes:
- Implementing policies, providing services and programmes, and managing your relationship with us;
- Responding to your inquiries;
- Verifying your identity;
- Measuring how users interact with the NDC’s website(s) and continually improving our communications channels (including by aggregating personal data collected using cookies);
- Communicating and interacting with website visitors;
- Communications and public relations activities;
- Statistical and other reporting, both internally and externally;
- Seeking legal advice, and exercising or defending legal rights;
- Complying with our legal obligations, including all legislation that applies across the public sector, e.g. legislation that provides for records and information management, procurement, human resource management, financial management, audit, and similar functions and activities;
- Communicating and interacting with job applicants and related third parties (e.g. references) and carrying out recruitment and selection processes; and
4. How We Share Your Personal Data
The NDC may share your personal data as required, including under applicable legislation, with recipients that include joint data controllers, our data processors, and third parties. We will only share your personal data as permitted by the DPA.
Your personal data may be shared with the following recipients that support our public functions and operations:
- With other public authorities: Personal data may be shared with other public authorities – here, “public authorities” means Ministries, Portfolios, Offices, Departments, Statutory Authorities, Statutory Bodies and Government Companies – for the purposes set out in this Privacy Notice.
- With data processors external to the CIG: Personal data may be shared with persons providing services to the NDC as a data processor in compliance with the DPA. When they are acting as data processors, these service providers are only able to use personal data under our instructions. We engage data processors for a variety of processing activities, which may include:
-
- iPower (Webhosting);
- RowemeDesign (Website management);
- Cayman Network Solutions (I.T. Management);
- JotForm (statistics for campaigns) ;
- Survey Monkey (statistical data);
In limited circumstances, service providers who act as data processors for the NDC may also act as a separate data controller in relation to their own purposes for processing your personal data, e.g. to provide customer support, or for analytics or machine learning in order to improve their services. These are unrelated to the purposes for which the NDC processes your personal data and should be clearly and directly disclosed to you by the service provider through their own separate privacy notice. However, you may contact us to ask about our current service providers and specific instances, if any, that we are aware of where your personal data may be processed for a service provider’s own purposes.
-
- With legal advisors and other persons if required by law or in relation to legal proceedings or rights: Personal data may be disclosed as legally required, for the purpose of or in connection with proceedings under the law, if necessary to obtain legal advice, or if the disclosure is otherwise necessary to establish, exercise or defend legal rights. This may include disclosing your personal data for the following purposes:
- Seeking legal advice;
- Exercising or defending legal rights;
- Complying with internal and external audits or investigations by competent authorities;
- Complying with information security policies or requirements;
- With other third parties: Personal data may be disclosed to other third-party recipients for the purposes set out in this Privacy Notice and in accordance with the DPA.
5. Our Legal Bases for Processing Your Personal Data
Depending on applicable laws and other circumstances, the NDC will rely on specific legal bases, or “conditions of processing”, under the DPA to process your personal data. These may include:
- A legal obligation to which the NDC is subject, e.g. National Drug Council Law (2010) and to comply with various obligations under the Procurement Act (2023 Revision) and Procurement Regulations (2022 Revision), the Public Management and Finance Act (2020 Revision) and Financial Regulations (2022 Revision), the Public Service Management Act (2018 Revision) and Personnel Regulations (2022 Revision), the Data Protection Act (2021 Revision) and Data Protection Regulations, 2018,
and the National Archive and Public Records Act (2015 Revision); - To exercise public functions, including the functions of the NDC to deliver and evaluation prevention programming and related-services;
- To perform or enter into a contract with you, e.g. <insert examples>;
- To protect your vital interests, e.g. <insert examples>;
- Consent, e.g. to send you marketing communications or to administer surveys and polls; and
- For the purposes of legitimate interests pursued by the NDC or by a third party or parties to whom the personal data may be disclosed, e.g. when disclosing records containing third party personal data in response to a request submitted under the Freedom of Information Act (2021 Revision).
6. Security and International Transfers
The NDC has put in place appropriate technical, physical and organisational measures in order to keep your personal data secure. These safeguards to maintain the confidentiality, integrity and availability of your personal data may include:
- Developing and maintaining written plans to identify, prevent, detect, respond to, and recover from security threats, events and incidents;
- Developing robust authentication procedures for accessing all systems that store Personal Data;
- Administrative and technical controls to restrict access to Personal Data on a “need to know” basis;
- Maintaining systems, software and applications, anti-virus software, firewalls, and other computer security safeguards, and appointing appropriate personnel to be responsible for keeping such safeguards up to date, including through actions such as patching, licence renewals/expiry monitoring, system health checks and account/user access management;
- Requiring Data Processors who Process Personal Data on behalf of [Insert Public Authority] to maintain appropriate security measures, including through MOUs, agreed Terms of Service or Data Processing Agreements;
- Maintaining appropriate records of access to and Processing of Personal Data;
- Ensuring employees are trained on security policies and measures that have been implemented;
- Auditing security measures implemented to safeguard Personal Data at regular intervals, including when changes have been made to systems or processes and when legislative changes impact the Processing of Personal Data, and recording the results of such audits;
- Using appropriate measures, such as encryption, pseudonymisation and chain of custody records, to protect Personal Data, including when stored on laptops, tablets, external hard drives, USB drives and other portable storage devices;
- Utilising appropriate and secure methods to destroy Personal Data as legally required; and
- Taking all other reasonable measures as required from time to time by legislation, rules and policies.
The NDC will not transfer personal data to countries or territories that do not ensure an adequate level of protection for personal data. We may transfer your personal data outside of the Cayman Islands to:
- Germany, where your data is securely stored by JotForm in accordance with our Data Processing Agreement.
We will only transfer your personal data to a country or territory that ensures an adequate level of protection for your rights and freedoms in relation to the processing of your personal data, unless there is a relevant exemption or exception under the DPA. Exceptions may include your consent or appropriate safeguards.
7. How Long We Keep Your Personal Data
The NDC may store your personal data for as long as we need it in order to fulfil the purpose(s) for which we collected your personal data, and in line with any applicable laws. This includes the National Archive and Public Records Act (2015 Revision), which governs the creation, maintenance and disposal of all public records. Sometimes, we may anonymise your personal data so that it is no longer associated with you.
8. Cookies
Cookies, in combination with pixels, local storage objects, and similar devices (collectively, “Cookies” unless otherwise noted), are used to distinguish between visitors to a website.
When you visit our website(s), small files known as Cookies may be stored on your computer, phone, tablet or any other device through your web browser. Information is stored in these text files.
Enabling Cookies may allow for a more tailored browsing experience and is required for certain website functionality. In the majority of cases, a Cookie does not provide us with any of your personal data.
Please see the website’s Cookie Notice for more information about the use of Cookies.
9. Your Rights
The NDC will respect and honour your rights in relation to your personal data and implement measures that allow you to exercise your rights under the DPA and other applicable legislation.
In accordance with the DPA, your rights in relation to your own personal data include:
- The right to be informed and the right of access: The right to request access to all personal data the NDC maintains about you as well as supplementary information about why and how we are processing your personal data. This is commonly known as a Data Subject Access Request and certain supplementary information about our processing is contained within this Privacy Notice.
- Rights in relation to inaccurate data: The right to request the rectification, blocking, erasure or destruction of any inaccurate personal data the NDC maintains on you. We will ensure, through all reasonable measures, that your personal data is accurate, complete and, where necessary, up‑to‑date, especially if it is to be used in a decision-making process.\
- The right to stop or restrict Processing: The right to restrict or stop how the NDC uses your personal data in certain circumstances.
- The right to stop direct marketing: The NDC does not currently carry out any direct marketing activities. However, we will update this Privacy Notice, and we will also notify you in writing as required if this position changes.
- Rights in relation to automated decision making: The NDC does not currently use automated means to make decisions about you. However, we will update this Privacy Notice and we will also notify you in writing as required if this position changes.
- The right to complain: The right to complain to the Ombudsman about any perceived violation of the DPA by the NDC.
- The right to seek compensation: The right to seek compensation in the Court if you suffer damage due to a contravention of the DPA by the NDC.
You may contact the NDC using the contact details listed below, to access and review your personal data or to exercise any other rights provided to you under the DPA. The NDC will take into consideration circumstances where, under the DPA or other applicable legislation, your rights may be limited or subject to conditions, exemptions or exceptions.
Upon contacting the NDC, we may need to verify your identity prior to fulfilling a request and may request additional information as required. In accordance with the DPA, the NDC may also charge a reasonable fee in relation to your request if it is unfounded or excessive in nature, or the NDC may reserve the right not to comply with the request at all.
To learn more about your rights, visit www.ombudsman.ky.
10. Data Protection Principles
When processing your personal data, the NDC will comply with the eight Data Protection Principles defined within the DPA:
- Fair and lawful processing: Personal data shall be processed fairly. In addition, personal data may be processed only if certain conditions are met, for example the data controller is subject to a legal obligation that requires the processing or the processing is necessary for exercise of public functions.
- Purpose limitation: Personal data shall be obtained only for one or more specified, explicit and legitimate purposes, and not processed further in any manner incompatible with that purpose or those purposes.
- Data minimisation: Personal data shall be adequate, relevant and not excessive in relation to the purpose or purposes for which they are collected or processed.
- Data accuracy: Personal data shall be accurate and, where necessary, kept up-to-date.
- Storage limitation: Personal data processed for any purpose shall not be kept for longer than is necessary for that purpose.
- Respect for the individual’s rights: Personal data shall be processed in accordance with the rights of data subjects under the DPA, including subject access.
- Security – confidentiality, integrity and availability: Appropriate technical and organisational measures shall be taken against unauthorised or unlawful processing of personal data and against accidental loss or destruction of, or damage to, personal data.
- International transfers: Personal data shall not be transferred to a country or territory unless that country or territory ensures an adequate level of protection for the rights and freedoms of data subjects in relation to the processing of personal data.
11. How to Contact Us
The NDC has appointed a Data Protection Leader. If you have any questions about this Privacy Notice or how your personal data is handled, or if you wish to make a complaint, please contact:
Name: Simon Miller – Data Protect Leader
National Drug Council Privacy Notice 7
Telephone number: 1-345-949-9000
Email Address: smiller@ndc.ky
Address: Units 17 & 18, Caymanian Village, P.O. Box 10007, Grand Cayman, KY1-1001, Cayman Islands
The NDC aims to resolve inquiries and complaints in a respectful and timely manner.
12. Changes to this Privacy Notice
The NDC reserves the right to update this Privacy Notice at any time and will publish a new Privacy Notice when we make any substantial updates. From time to time, the NDC may also notify you about the processing of your personal data in other ways, including by email or through our publications.
This Privacy Notice was last updated on August 29, 2024.