Notice
Inadvertent leak of personal data by financial services company (2019-11-25)
Issued 2019-11-25View on OMBUDSMAN's website Source document
Summary
This is a published case summary from the Cayman Islands Ombudsman describing an informal resolution of a data protection complaint, not a binding rule or guidance document. It illustrates how the Ombudsman handled a self-reported personal data breach by a financial services company.
- What happened: A financial services company notified the Ombudsman that it had inadvertently published unredacted legal documents containing a client's personal data on its website instead of redacted versions.
- Remediation: The company noticed the error the same day and replaced the documents with properly redacted versions.
- Outcome: The Ombudsman conferred with the company, was satisfied with the corrective actions taken, found no evidence of prejudice to the data subject's rights, and closed the matter as an informal resolution with no further action or penalty.
The document is informational only, recording a past case outcome; it does not create new rules, obligations, or deadlines for regulated entities generally, though it illustrates the Ombudsman's expectations around prompt self-reporting and remediation of data leaks.
Applies to
financial services company
Topics
Version history
2026-07-30