Notice
Financial regulator inadvertently discloses personal data (2022-03-10)
Issued 2022-03-10View on OMBUDSMAN's website Source document
Summary
This is a published case summary from the Cayman Islands Ombudsman describing an investigation into a data breach at an unnamed financial regulator. An employee mistakenly emailed a spreadsheet tab containing personal data of numerous individuals (director, officer and shareholder applicants) to an external party. The Ombudsman reviewed the regulator's response and remedial measures and concluded no further enforcement action was required.
- Nature of breach: Personal data (names, approval status, supervisor queries, fee payment details) intended for internal use was sent externally via email attachment.
- Remedial steps taken: The regulator attempted to recall the email, contacted recipients to request deletion, obtained confirmation of deletion, and had IT trace and remove the email from servers.
- Planned improvements: The regulator committed to introducing a data classification scheme, encrypting outgoing emails, replacing email with secure file-sharing for confidential data, adding review/approval workflow steps, and staff training.
- Compliance shortfall noted: Affected individuals were not notified within the statutory notification period, in some cases more than two months late, partly due to the large number of affected individuals and incomplete contact information.
- Outcome: The Ombudsman closed the matter with no further action, citing the regulator's swift response, while flagging the late notification issue.
This notice is informational and case-specific; it does not itself impose new rules, but it illustrates the Ombudsman's expectations around timely breach notification and data-handling safeguards for organisations holding personal data, including financial regulators and other data controllers.
Key obligations
- Data controllers must notify affected individuals of a personal data breach within the period allowed by law (the Ombudsman noted a failure to do so in this case).
Applies to
financial regulators, data controllers