Notice
RCIPS inadvertently release third party personal data in collision report (2022-10-04)
Issued 2022-10-04View on OMBUDSMAN's website Source document
Summary
This is a published case summary from the Cayman Islands Ombudsman describing an informal resolution of a data breach complaint against the Royal Cayman Islands Police Service (RCIPS). It illustrates how the Ombudsman handled a specific incident rather than setting new legal requirements.
- What happened: RCIPS inadvertently disclosed sensitive third-party personal data to the wrong recipient when releasing a collision report, due to an employee failing to correctly apply internal review policies.
- Containment: The unintended recipient verbally confirmed deletion of the email, but the Ombudsman required written confirmation from the individual given the severity of the breach.
- Remedial action: RCIPS agreed to provide further staff training and amended its policy to add an additional verification step before releasing collision reports to the public.
- Outcome: The Ombudsman considered the data controller's response appropriate and closed the case without further action.
While this notice does not create new binding rules, it signals the Ombudsman's expectations for breach containment (written confirmation of deletion) and remediation (policy updates and staff training) that other data controllers may look to as informal guidance.
Applies to
RCIPS, data controllers
Topics
Version history
2026-07-30