Notice

Restructuring Administrator security incident results in a non-jurisdictional breach (2023-12-08)

Cayman Islands Office of the Ombudsman (OMBUDSMAN) · Cayman Islands

Issued 2023-12-08

Current version last checked: 2026-07-30

Summary

This is a published case summary from the Cayman Islands Ombudsman describing a personal data breach notification that the Ombudsman reviewed and ultimately declined jurisdiction over. It is informational only and does not create new rules or ongoing compliance requirements.

  • What happened: An overseas law firm notified the Ombudsman of a personal data breach on behalf of its client, a global restructuring administrator, arising from a SIM swapping attack on a telecommunications company employee that affected almost 80,000 individuals, including non-sensitive personal data of 69 Cayman residents.
  • Outcome: The Ombudsman reviewed the breach notification and determined it had no jurisdiction because the restructuring administrator was not registered in Cayman and the personal data was not being processed in Cayman.

The notice serves as a public record of how the Ombudsman applies its jurisdictional scope under Cayman data protection law to cross-border breach notifications; it does not impose any obligation on Cayman entities or set a precedent requiring action.

Topics

Version history

2026-07-30

source file (current)