Notice
HR system reports are sent to incorrect Ministry (2023-05-23)
Issued 2023-05-23View on OMBUDSMAN's website Source document
Summary
This is a published case summary from the Cayman Islands Ombudsman describing a data protection breach in which an automated Cayman Islands Government HR system report was sent to the wrong ministry. It illustrates how the Ombudsman applies the statutory breach notification timeframe under data protection law to a real incident.
- What happened: An HR system report containing personal data on 21 employees (with detailed information on 9 of them, including names, titles, departments, hourly rates and banked time liability) was automatically sent to the incorrect government ministry.
- Discovery and response: The receiving portfolio identified the error after a chief financial officer flagged an incorrect test report received as part of a pilot program, about 4 hours after it was generated; the technical issue was fixed within one day and the breach was reported to the Ombudsman.
- Ombudsman finding: The Ombudsman determined that the 9 employees whose detailed information was disclosed should have been notified within the statutory 5 day notification timeframe, and this had not been done.
- Outcome: The government portfolio was urged to ensure the statutory notification period is adhered to in future incidents.
This is an individual case outcome rather than a rule change, but it confirms the Ombudsman's expectation that data controllers notify affected individuals of a personal data breach within 5 days as required by law.
Key obligations
- Data controllers must notify individuals affected by a personal data breach within the statutory timeframe of 5 days.
Applies to
Cayman Islands Government ministries and portfolios (as data controllers)
Deadlines
- 5 days: Statutory timeframe within which affected individuals must be notified following a personal data breach.
Topics
Version history
2026-07-30