Notice
Local law firm made aware of personal data breach (2023-03-16)
Issued 2023-03-16View on OMBUDSMAN's website Source document
Summary
This is a published case summary from the Cayman Islands Ombudsman describing how a personal data breach at a local law firm was handled under the Data Protection Act. It illustrates the Ombudsman's approach to investigating breaches and assessing remedial action, rather than creating new rules.
- What happened: A law firm's IT service provider (acting as data processor) notified the firm of a business email compromise affecting a staff member, which appeared to expose personal data.
- Investigation: The law firm commissioned an independent third-party audit; the Ombudsman had to issue an Information Order to obtain the investigation reports.
- Outcome: A phishing attack had compromised an employee's email and an attempted fraudulent change to bank details was detected and stopped, resulting in no financial loss.
- Ombudsman's view: The Ombudsman found the firm's remedial measures (implementing all auditor recommendations) appropriate and recommended ongoing regular security reviews in line with best practices.
The document is informational and does not itself impose new statutory obligations; it serves as guidance on how similar breaches may be assessed and what remediation the Ombudsman regards as satisfactory.
Applies to
law firms, data controllers, data processors
Topics
Version history
2026-07-30