Notice

Incorrect Access Controls in Utility Company’s Recruitment Software (2020-01-21)

Cayman Islands Office of the Ombudsman (OMBUDSMAN) · Cayman Islands

Issued 2020-01-21

Current version last checked: 2026-07-30

Summary

This is a published case summary from the Cayman Islands Ombudsman describing an informal resolution of a data breach notification made by a utility company. It illustrates how the Ombudsman handles self-reported access control failures under data protection rules rather than creating any new rule or requirement.

  • What happened: A utility provider's new recruitment software had incorrect access controls, allowing an employee to view job applications for positions they should not have had access to.
  • Company response: The employee reported the issue to HR, which reviewed and corrected the access control settings; no other unauthorized access was found.
  • Outcome: The Ombudsman verified the remedial steps, found no evidence of prejudice to individuals' rights, and closed the case informally without issuing a formal enforcement notice.

This notice is informational only, documenting a closed case, and does not itself impose new obligations on regulated entities beyond illustrating expected data breach response practices.

Applies to

data controllers, utility companies

Topics

Version history

2026-07-30

source file (current)