Notice
Enforcement Order 202100222 - Betty Boo Real Estate Sales (2023-04-27)
Issued 2023-04-27View on OMBUDSMAN's website Source document
Summary
This is an Enforcement Order issued by the Cayman Islands Ombudsman against Betty Boo Real Estate Sales, a sole-operator real estate brokerage, following a personal data breach that led to a client being defrauded of KYD 22,680 via a spoofed email and fraudulent wire transfer instructions. The Ombudsman found the data controller breached three Data Protection Act (DPA) requirements: the seventh principle (security), section 16 (breach notification), and the first principle (fair processing/privacy notice).
- Seventh principle (security): The data controller lacked adequate technical measures (no MFA, weak email security) and organisational measures (no information security policy, no incident response policy, no staff/owner cyber-awareness training) to prevent or detect the email account compromise.
- Section 16 (breach notification): The data controller failed to investigate or formally notify affected data subjects and the Ombudsman without undue delay after first becoming aware of the breach in March 2021, only completing proper notifications months later after repeated prompting.
- First principle (fair processing): The data controller did not provide clients with a privacy notice identifying herself as data controller or explaining the purposes of processing, as required by schedule 1 of the DPA.
Under section 45 of the DPA, the Ombudsman ordered specific corrective steps to be completed within 30 days, covering email system upgrades, ongoing IT support, mandatory annual training, and development of data protection policies. The data controller (or any recipient of a DPA enforcement order) may seek judicial review of the order in the Grand Court within 45 days of receipt.
Key obligations
- Migrate to a business email solution supporting MFA, industry-standard malicious-email monitoring and filtering, administrative access to audit logs, and vendor support for breach investigations, within 30 days of the Order.
- Retain a reputable IT service provider to provide ongoing IT support to maintain compliance with the seventh data protection principle.
- Undertake cybersecurity awareness training at least annually and data protection awareness training annually.
- Develop appropriate policies and procedures to safeguard personal data and maintain DPA compliance.
- Notify the Ombudsman and affected data subjects of any personal data breach without undue delay and no later than five days after becoming aware of it, per section 16(1) of the DPA.
Applies to
data controllers, real estate brokerages/agents
Deadlines
- no later than 30 days after this Order is issued: Deadline for the data controller to complete the required corrective steps (email migration, IT support retention, training, policy development).
- within 45 days of receipt: Period within which the data controller may seek judicial review of the enforcement order in the Grand Court under section 47 of the DPA.
- no longer than five days after becoming aware of a breach: Statutory timeframe under section 16(1) of the DPA for notifying data subjects and the Ombudsman of a personal data breach.