Notice
Fund administrator system sends a report containing financial details to an unintended recipient (2023-09-04)
Issued 2023-09-04View on OMBUDSMAN's website Source document
Summary
This is a published case summary from the Cayman Islands Ombudsman describing a data protection breach investigation and its outcome, not a rule or regulatory instrument. It recounts an incident where a fund administrator's system misdirected a report containing investor financial details to the wrong recipient, and the corrective steps taken.
- Incident: A fund administrator's system sent an order acknowledgment containing two investors' data, via a transfer agency, to an unintended fund manager due to a system fault.
- Response: The transfer agency identified and escalated the error; the administrator obtained confirmation the data was deleted the same day and notified impacted parties to watch for suspicious contact.
- Remediation: The administrator adjusted the report run time scheduler, fixed the underlying system bug, conducted testing, and introduced a manual control to verify reports and intended recipients before sending.
- Ombudsman finding: The Ombudsman reviewed the breach and was satisfied with the steps taken to address it, closing the matter without further action noted.
As a case outcome summary, this document does not itself impose new rules; it illustrates the Ombudsman's expectations for breach response (containment, notification, root-cause fix, and preventive controls) that fund administrators and similar data controllers may look to when handling comparable incidents.
Applies to
fund administrators
Topics
Version history
2026-07-30