Notice
Restructuring Administrator security incident results in a non-jurisdictional breach (2023-12-08)
Issued 2023-12-08View on OMBUDSMAN's website Source document
Summary
This is a published case summary from the Cayman Islands Ombudsman describing a personal data breach notification that the Ombudsman reviewed and ultimately declined jurisdiction over. It is informational only and does not create new rules or ongoing compliance requirements.
- What happened: An overseas law firm notified the Ombudsman of a personal data breach on behalf of its client, a global restructuring administrator, arising from a SIM swapping attack on a telecommunications company employee that affected almost 80,000 individuals, including non-sensitive personal data of 69 Cayman residents.
- Outcome: The Ombudsman reviewed the breach notification and determined it had no jurisdiction because the restructuring administrator was not registered in Cayman and the personal data was not being processed in Cayman.
The notice serves as a public record of how the Ombudsman applies its jurisdictional scope under Cayman data protection law to cross-border breach notifications; it does not impose any obligation on Cayman entities or set a precedent requiring action.
Topics
Version history
2026-07-30