Notice

RCIPS sends misdirected data on firearms owner (2022-03-18)

Cayman Islands Office of the Ombudsman (OMBUDSMAN) · Cayman Islands

Issued 2022-03-18

Current version last checked: 2026-07-30

Summary

This is a case summary published by the Cayman Islands Ombudsman describing an informal resolution of a data protection complaint against the Royal Cayman Islands Police Service (RCIPS). It records the facts of a specific data breach and the Ombudsman's findings, rather than setting new general rules.

  • What happened: An email with personal information about a firearms licence holder was mistakenly sent to the wrong recipient; RCIPS became aware three days later and the recipient confirmed deletion of the email and attachment.
  • Outcome: The Ombudsman concluded RCIPS had taken appropriate action to close the breach.
  • Commitment made: RCIPS committed to implement encryption for this type of correspondence going forward.
  • Advice given: The Ombudsman advised RCIPS to ensure all elements of the legally required data breach notification were addressed, including notification to affected data subjects.

As a case outcome notice, it does not create binding obligations beyond the specific commitments RCIPS made in this instance, but it illustrates the Ombudsman's expectations for data breach handling and notification under Cayman Islands data protection law.

Key obligations

  • RCIPS committed to implement encryption for correspondence containing this type of personal data.
  • RCIPS was advised to ensure all elements of the data breach notification required by law were addressed, including notifying affected data subjects.

Applies to

Royal Cayman Islands Police Service (RCIPS), public authorities handling personal data

Topics

Version history

2026-07-30

source file (current)