Notice
Breach at local telecommunications company (2023-01-12)
Issued 2023-01-12View on OMBUDSMAN's website Source document
Summary
This is a published case summary from the Cayman Islands Ombudsman describing the outcome of a data breach investigation involving a local telecommunications company. It is informational, documenting how the Ombudsman handled a specific complaint under the Data Protection Act (DPA) rather than creating new rules or ongoing requirements.
- What happened: An ex-employee of the telecommunications data controller unlawfully shared a customer's personal data with a police officer for personal use, prompting a data breach notification to the Ombudsman.
- Investigation scope: The Ombudsman reviewed the controller's data protection policies, training records, a confidentiality agreement, call logs, system audit logs, and witness statements to assess whether the controller contributed to the breach.
- Outcome: The Ombudsman found the data controller had adequate organizational and technical measures in place, so the data breach case against the controller was closed; the underlying issue of unlawful data sharing remains before the courts separately.
No new compliance obligations or deadlines arise from this notice for other entities; it illustrates the Ombudsman's approach to assessing controller accountability following an employee-caused breach under the DPA.
Applies to
data controllers, telecommunications service providers
Topics
Version history
2026-07-30