Notice

Fund administrator system sends a report containing financial details to an unintended recipient (2023-09-04)

Cayman Islands Office of the Ombudsman (OMBUDSMAN) · Cayman Islands

Issued 2023-09-04

Current version last checked: 2026-07-30

Summary

This is a published case summary from the Cayman Islands Ombudsman describing a data protection breach investigation and its outcome, not a rule or regulatory instrument. It recounts an incident where a fund administrator's system misdirected a report containing investor financial details to the wrong recipient, and the corrective steps taken.

  • Incident: A fund administrator's system sent an order acknowledgment containing two investors' data, via a transfer agency, to an unintended fund manager due to a system fault.
  • Response: The transfer agency identified and escalated the error; the administrator obtained confirmation the data was deleted the same day and notified impacted parties to watch for suspicious contact.
  • Remediation: The administrator adjusted the report run time scheduler, fixed the underlying system bug, conducted testing, and introduced a manual control to verify reports and intended recipients before sending.
  • Ombudsman finding: The Ombudsman reviewed the breach and was satisfied with the steps taken to address it, closing the matter without further action noted.

As a case outcome summary, this document does not itself impose new rules; it illustrates the Ombudsman's expectations for breach response (containment, notification, root-cause fix, and preventive controls) that fund administrators and similar data controllers may look to when handling comparable incidents.

Applies to

fund administrators

Topics

Version history

2026-07-30

source file (current)