Notice

Local law firm made aware of personal data breach (2023-03-16)

Cayman Islands Office of the Ombudsman (OMBUDSMAN) · Cayman Islands

Issued 2023-03-16

Current version last checked: 2026-07-30

Summary

This is a published case summary from the Cayman Islands Ombudsman describing how a personal data breach at a local law firm was handled under the Data Protection Act. It illustrates the Ombudsman's approach to investigating breaches and assessing remedial action, rather than creating new rules.

  • What happened: A law firm's IT service provider (acting as data processor) notified the firm of a business email compromise affecting a staff member, which appeared to expose personal data.
  • Investigation: The law firm commissioned an independent third-party audit; the Ombudsman had to issue an Information Order to obtain the investigation reports.
  • Outcome: A phishing attack had compromised an employee's email and an attempted fraudulent change to bank details was detected and stopped, resulting in no financial loss.
  • Ombudsman's view: The Ombudsman found the firm's remedial measures (implementing all auditor recommendations) appropriate and recommended ongoing regular security reviews in line with best practices.

The document is informational and does not itself impose new statutory obligations; it serves as guidance on how similar breaches may be assessed and what remediation the Ombudsman regards as satisfactory.

Applies to

law firms, data controllers, data processors

Topics

Version history

2026-07-30

source file (current)