Notice

Risk management entity sends misdirected shareholder data (2023-02-02)

Cayman Islands Office of the Ombudsman (OMBUDSMAN) · Cayman Islands

Issued 2023-02-02

Current version last checked: 2026-07-30

Summary

This is a published case summary from the Cayman Islands Ombudsman describing a resolved personal data breach complaint under the Data Protection Act. It illustrates how the Ombudsman's office handles inadvertent disclosure of shareholder data by a risk management entity, rather than establishing new binding rules.

  • Incident: An email containing board minutes for a group under a publicly owned company, including shareholders' personal data (bank names, account numbers, signatories, dividend information), was sent to the wrong recipient.
  • Response: The data controller notified the parent company's representative, alerted the unintended recipient, and had the email deleted, which was confirmed.
  • Ombudsman action: The Ombudsman was notified, supported the remedial steps taken, and recommended the entity revise its breach response procedures, pointing it to further guidance on the Ombudsman's website.

The summary is informational and case specific; it does not create new general obligations but signals the standard of breach response the Ombudsman expects from data controllers.

Applies to

data controllers, risk management entities

Topics

Version history

2026-07-30

source file (current)