Notice

Overseas fund administrator suffers ransomware attack (2021-09-16)

Cayman Islands Office of the Ombudsman (OMBUDSMAN) · Cayman Islands

Issued 2021-09-16

Current version last checked: 2026-07-30

Summary

This is a published case summary from the Cayman Islands Ombudsman describing an informal resolution of a data breach complaint. An overseas fund administrator, acting as data processor for over one hundred Cayman Islands-based funds, was affected when a third-party vendor suffered a ransomware attack, resulting in personal data belonging to the funds being published by the attackers.

  • Finding: The data controllers had data processing agreements in place with the processor satisfying the seventh data protection principle, but those agreements lacked provisions on data breach reporting and personal data processing.
  • Recommendation 1: Data controllers should implement mechanisms to ensure all data breach notification obligations under the Data Protection Act (DPA) are observed going forward.
  • Recommendation 2: Data controllers should consider assurance mechanisms, such as auditing processors' data processing activities, to help ensure personal data is processed securely.
  • Risk assessment: The Ombudsman assessed the likelihood of adverse impact on affected data subjects' rights and freedoms as low.

This is a case outcome notice rather than a binding rule; it illustrates the Ombudsman's expectations for data processing agreements and breach notification practices under the DPA, relevant to any entity acting as a data controller or processor for Cayman Islands funds.

Applies to

data controllers, data processors, fund administrators, Cayman Islands-based funds

Topics

Version history

2026-07-30

source file (current)