Notice

Error in HR system causes breach at PoCS (2022-08-04)

Cayman Islands Office of the Ombudsman (OMBUDSMAN) · Cayman Islands

Issued 2022-08-04

Current version last checked: 2026-07-30

Summary

This is a published case summary from the Cayman Islands Ombudsman describing an informal resolution of a data protection breach at the Portfolio of the Civil Service (PoCS). A configuration error in a newly deployed Human Resource Management System (HRMS) gave some managers unauthorized access to personal data of employees who did not report to them.

  • Scope: 11 employee reports were affected by the workflow error, with two involving extensive personal data and an increased risk of harm.
  • Remediation: PoCS cancelled the open workflows, investigated the full scope of the breach, and reconfigured the workflow using a unique identifier to ensure reports route to the correct manager.
  • Notification: The two data subjects at increased risk of harm were notified in accordance with the Data Protection Act (DPA); the remaining group was not formally notified as the Ombudsman agreed the risk of harm was minimal given recipients' duty of confidentiality as government managers.
  • Outcome: The Ombudsman found PoCS's response appropriate and closed the case with no further concerns.

The document is informational and records the closure of a specific case; it does not itself create new binding rules but illustrates how the DPA's breach notification requirements are applied in practice.

Key obligations

  • Data controllers must notify affected data subjects of a personal data breach when there is an increased risk of harm to them, in accordance with the Data Protection Act.

Applies to

public authorities, government agencies, data controllers

Topics

Version history

2026-07-30

source file (current)