Notice

Inadvertent leak of personal data by financial services company (2019-11-25)

Cayman Islands Office of the Ombudsman (OMBUDSMAN) · Cayman Islands

Issued 2019-11-25

Current version last checked: 2026-07-30

Summary

This is a published case summary from the Cayman Islands Ombudsman describing an informal resolution of a data protection complaint, not a binding rule or guidance document. It illustrates how the Ombudsman handled a self-reported personal data breach by a financial services company.

  • What happened: A financial services company notified the Ombudsman that it had inadvertently published unredacted legal documents containing a client's personal data on its website instead of redacted versions.
  • Remediation: The company noticed the error the same day and replaced the documents with properly redacted versions.
  • Outcome: The Ombudsman conferred with the company, was satisfied with the corrective actions taken, found no evidence of prejudice to the data subject's rights, and closed the matter as an informal resolution with no further action or penalty.

The document is informational only, recording a past case outcome; it does not create new rules, obligations, or deadlines for regulated entities generally, though it illustrates the Ombudsman's expectations around prompt self-reporting and remediation of data leaks.

Applies to

financial services company

Topics

Version history

2026-07-30

source file (current)