Notice

Registry system statement (2024-03-07)

Jersey Financial Services Commission (JFSC) · Jersey

Issued 2024-03-07

Current version last checked: 2026-07-11

Summary

This is a public statement from the Jersey Financial Services Commission (JFSC) disclosing a data security incident affecting its Registry system. It is informational and does not create ongoing compliance obligations for regulated entities.

  • What happened: On 23 January 2024 a vulnerability was detected in the JFSC's Registry system, caused by a misconfiguration in a third party supplied system that had been in place since January 2021.
  • Data exposed: The vulnerability allowed access to non public names and addresses only; it did not link any individuals to registered entities or roles held.
  • Response taken: JFSC resolved the issue, conducted an initial forensic review with an independent cyber security partner, is undertaking further investigations, and has been working with the Jersey Office of the Information Commissioner throughout.
  • Individual notification: JFSC has separately written directly to individuals whose name and address were accessed and to whom it owes an obligation to communicate individually.
  • Public action: No action is required from the public unless they wish to raise queries, which can be directed to query@jerseyfsc.org.

The statement is a disclosure and reassurance notice rather than a rule change, and imposes no new filing, reporting, or compliance requirements on regulated entities.

Topics

Version history

2026-07-11

source file (current)