Notice
Enforcement Order 201900212 (2021-03-18)
Issued 2021-03-18View on OMBUDSMAN's website Source document
Summary
This is an enforcement order issued by the Cayman Islands Ombudsman against Jacques Scott Group Ltd. (JSG) following a ransomware attack that exposed personal data of about 150 individuals, including employees, shareholders and pension account members. The Ombudsman found JSG breached the seventh data protection principle of the Data Protection Law, 2017 (DPL) in two respects: inadequate technical and organizational security measures, and a data processing agreement that lacked mandatory DPL clauses.
- Binding requirement: JSG must ensure its current and future agreements with data processors include the mandatory terms required by paragraph 3, part 2, schedule 1 of the DPL (processor to act only on controller instructions and comply with equivalent security obligations).
- Security recommendations: The Ombudsman recommended JSG implement Deloitte's remediation report plus additional measures: information security policies, annual cybersecurity awareness training and phishing simulations, incident response training, data handling training, enabling logs on critical network devices, a 3-2-1 backup strategy, endpoint protection and UTM systems, patch management, and quarterly vulnerability assessments with annual penetration testing.
- Mitigating factors: The Ombudsman acknowledged JSG's prompt notification to the Ombudsman and affected data subjects, engagement of external investigators (Deloitte and SigNus Technologies), and that no exfiltration or serious ongoing harm to data subjects was found.
This order is specific to JSG's case but signals the Ombudsman's expectations for data controllers generally on processor contract terms and technical/organizational security safeguards under the DPL. A recipient of an enforcement order may seek judicial review of the order in the Grand Court within 45 days of receipt, under section 47 of the DPL.
Key obligations
- JSG must ensure that any current and future agreements with its data processors meet the requirements of paragraph 3, part 2, schedule 1 of the DPL (specifying the processor acts only on the controller's instructions and complies with equivalent security obligations).
- JSG should execute the security remediation recommendations from the Deloitte security and compromise assessment report.
- JSG is recommended to adopt a range of cybersecurity measures including policies and procedures, annual staff training, logging, backups, endpoint protection, patch management, and regular vulnerability/penetration testing.
Applies to
data controllers, data processors
Deadlines
- within 45 days of receipt: Deadline for a person who received an enforcement order under the DPL to seek judicial review of the order in the Grand Court, under section 47.