Notice
Unauthorized use of third-party website leads to data breach (2022-01-21)
Issued 2022-01-21View on OMBUDSMAN's website Source document
Summary
This is a published case summary from the Cayman Islands Ombudsman describing an informally resolved data breach investigation. It illustrates how the Ombudsman assessed a financial institution's handling of a breach caused by an employee uploading a corrupted PDF containing investor personal data to an unapproved third-party website.
- What happened: An employee of a financial institution (data controller) uploaded a file containing investors' names, dates of birth, ownership details, addresses and social security numbers to a third-party website not approved for that purpose, in an attempt to repair the corrupted file.
- Investigation findings: No evidence the data was accessed or used by the third-party website; the controller self-reported the breach and investigated.
- Remedial steps taken: Affected individuals were told to monitor accounts and offered 24 months of free identity theft monitoring; staff received additional training; steps were taken to ensure the third-party website did not retain the data.
- Notification timing: The breach notification to the Ombudsman was made outside the statutory 5-day notification period, but this was accepted as reasonable given the time needed to investigate and establish jurisdiction.
- Outcome: The case was closed without further action because the controller's mitigation steps were considered appropriate.
This document is informational only; it records the outcome of a specific case and does not itself create new rules, but it confirms that data controllers are expected to notify the Ombudsman of breaches within 5 days under the applicable statutory requirement.
Key obligations
- Data controllers must notify the Ombudsman of a data breach within the statutory notification period of 5 days.
- Data controllers should only use approved channels/systems (not unapproved third-party websites) for handling personal data.
- Where a breach occurs, controllers are expected to investigate, mitigate risk of harm to affected individuals (e.g. monitoring services), and take corrective staff training and technical steps.
Applies to
financial institutions, data controllers
Deadlines
- 5 days: Statutory data breach notification period referenced in the case (notification to the Ombudsman was made outside this period).
Topics
Version history
2026-07-30