Notice
Risk management entity sends misdirected shareholder data (2023-02-02)
Issued 2023-02-02View on OMBUDSMAN's website Source document
Summary
This is a published case summary from the Cayman Islands Ombudsman describing a resolved personal data breach complaint under the Data Protection Act. It illustrates how the Ombudsman's office handles inadvertent disclosure of shareholder data by a risk management entity, rather than establishing new binding rules.
- Incident: An email containing board minutes for a group under a publicly owned company, including shareholders' personal data (bank names, account numbers, signatories, dividend information), was sent to the wrong recipient.
- Response: The data controller notified the parent company's representative, alerted the unintended recipient, and had the email deleted, which was confirmed.
- Ombudsman action: The Ombudsman was notified, supported the remedial steps taken, and recommended the entity revise its breach response procedures, pointing it to further guidance on the Ombudsman's website.
The summary is informational and case specific; it does not create new general obligations but signals the standard of breach response the Ombudsman expects from data controllers.
Applies to
data controllers, risk management entities
Topics
Version history
2026-07-30