Notice
Enforcement Order 202000583 - Gain Global Markets Inc. (2022-08-02)
Issued 2022-08-02View on OMBUDSMAN's website Source document
Summary
This is an Enforcement Order issued by the Cayman Islands Ombudsman against Gain Global Markets Inc., a financial services company acting as a data controller, following a cybersecurity breach that exposed personal data of approximately 26,290 individuals. The Ombudsman found that inadequate security measures, such as unpatched systems, lack of vulnerability testing, and insufficient staff awareness, violated the seventh data protection principle of the Data Protection Act (2021 Revision).
- Breach and cause: A threat actor accessed or exfiltrated personal data of about 26,290 individuals due to a systems vulnerability; adequate security standards, patching, vulnerability testing, and staff awareness were lacking.
- Finding: The data controller breached the seventh data protection principle by failing to implement appropriate technical and organisational safeguards, though the breach did not meet the threshold for substantial damage since the data involved was not sensitive.
- Mitigating factor: The Ombudsman noted the data controller swiftly implemented remedial technical and organisational measures after the breach, improving its security posture.
- Ongoing requirement: The data controller must continue to carry out regular audits and reviews of its security posture, at least annually, to remain compliant with the seventh data protection principle.
- Right of review: Under section 47 of the DPA, the data controller may seek judicial review of the Order in the Grand Court within 45 days of receipt, upon notice to the Ombudsman.
This order is specific to Gain Global Markets Inc. but illustrates the Ombudsman's expectations for all data controllers regarding security obligations under the seventh data protection principle, including regular security reviews and prompt remediation following breaches.
Key obligations
- The data controller (Gain Global Markets Inc.) must continue to carry out regular audits and reviews of its security posture, at least on an annual basis, to remain compliant with the seventh data protection principle.
- Any person who receives an enforcement order under the DPA may seek judicial review of the Order in the Grand Court within 45 days of receipt, upon notice to the Ombudsman.
Applies to
data controllers, financial services company
Deadlines
- within 45 days of receipt: Period within which the data controller may seek judicial review of the enforcement order in the Grand Court, upon notice to the Ombudsman.
- at least annually: Recurring requirement for the data controller to conduct audits and reviews of its security posture.