Notice

Financial service provider neglects to update their paper files (2022-01-31)

Cayman Islands Office of the Ombudsman (OMBUDSMAN) · Cayman Islands

Issued 2022-01-31

Current version last checked: 2026-07-30

Summary

This is a published case summary from the Cayman Islands Ombudsman describing an informally resolved data protection complaint against a financial service provider acting as a data controller. It illustrates how a mismatch between updated electronic records and outdated paper files led to a personal data breach, and sets out the corrective steps the Ombudsman recommended.

  • What happened: A data controller updated its electronic records after one joint account holder sold his interest to the other, but failed to update the corresponding paper file; a new staff member relied on the outdated paper file and disclosed personal data to the wrong (previous) account owner, causing a breach.
  • Recommendation 1: Implement better controls to ensure data held across all filing systems (paper and electronic) is kept up to date and consistent.
  • Recommendation 2: Ensure all employees routinely receive data protection training relevant to their specific job functions.
  • Recommendation 3: Publish an internal written policy or procedure governing how staff process personal data during investment portfolio reviews.

As a case outcome rather than a rule of general application, the recommendations were directed at the specific data controller involved, but they signal the standards the Ombudsman expects financial service providers handling personal data to meet under Cayman's data protection framework.

Key obligations

  • Keep personal data consistent and up to date across all filing systems, including both paper-based and electronic records
  • Provide employees with routine data protection training relevant to their job functions
  • Maintain a written internal policy or procedure describing how staff should process personal data during investment portfolio reviews

Applies to

financial service providers, data controllers

Topics

Version history

2026-07-30

source file (current)