News
Print Article

Jersey’s data regulator [JOIC] cannot fine JFSC for a 2024 “3-year vulnerability” data breach

28/10/2025

In January 2024, JFSC’s Data Protection Officer contacted the Authority to advise that JFSC had suffered a personal data breach involving its Companies Registry portal due to a critical flaw in third-party-provided software implemented in 2021.

This has now been investigated, and the Jersey Office of the Information Commissioner [JOIC] has published its findings, and has said:-

  • The JFSC  has avoided a fine after the “restricted data” of nearly 67,000 individuals was put at risk by a system flaw dating back three years.

The issue first came to light in March 2024, with the Jersey Financial Services Commission confirming that the flaw allowed public access to a confidential register containing the names and addresses of 66,806 individuals associated with finance companies.

  • This included beneficial owners, controllers, directors, members, nominated persons, and company secretaries.
  • The vulnerability in the system dates back to 2021, when the registry was implemented, meaning the restricted personal information has been accessible to the public for three years.

In a statement published this afternoon, the Jersey Office of the Information Commissioner concluded

  • The nature of the breach would have warranted initiating the process to consider an administrative fine.
  • But “as public authorities are not subject to such fines under the current framework, no further consideration was given to this”.

The data protection watchdog also confirmed that.

  • There was no evidence that the personal information had been used to the detriment of the affected individuals, and
  • That no complaints had been received from them.
  • The JFSC co-operated fully with the inquiry and “made full and frank admissions as to the shortcomings in various areas that led to system vulnerability”,

The JOIC, therefore, concluded that it was

  • “Satisfied that there is little risk to individuals regarding a re-occurrence of these vulnerabilities in system security”.

In a statement posted online, the JFSC said it was

  • “Deeply sorry this data breach occurred” and fully accepted the JOIC’s findings.
  • “Together with a forensic review, we commissioned an independent third-party root cause analysis. All actions arising from this analysis have been completed, and we worked closely with JOIC throughout this process.
  • “We appreciate JOIC’s recognition of the steps we have taken to address the issues identified, and we remain committed to maintaining and enhancing the technical and organisational measures necessary to ensure the continued protection of data.
  • “We are grateful to JOIC for their engagement and guidance throughout this process, and to our wider stakeholder community.
  • “We will continue to embrace best practice to protect stakeholder data and Jersey’s reputation as a leading international finance centre.”

Source

JERSEY YOUTUBE-IMAGE DATA PROTECTION FINES

The Team

Meet the team of industry experts behind Comsure

Find out more

Latest News

Keep up to date with the very latest news from Comsure

Find out more

Gallery

View our latest imagery from our news and work

Find out more

Contact

Think we can help you and your business? Chat to us today

Get In Touch

News Disclaimer

As well as owning and publishing Comsure's copyrighted works, Comsure wishes to use the copyright-protected works of others. To do so, Comsure is applying for exemptions in the UK copyright law. There are certain very specific situations where Comsure is permitted to do so without seeking permission from the owner. These exemptions are in the copyright sections of the Copyright, Designs and Patents Act 1988 (as amended)[www.gov.UK/government/publications/copyright-acts-and-related-laws]. Many situations allow for Comsure to apply for exemptions. These include 1] Non-commercial research and private study, 2] Criticism, review and reporting of current events, 3] the copying of works in any medium as long as the use is to illustrate a point. 4] no posting is for commercial purposes [payment]. (for a full list of exemptions, please read here www.gov.uk/guidance/exceptions-to-copyright]. Concerning the exceptions, Comsure will acknowledge the work of the source author by providing a link to the source material. Comsure claims no ownership of non-Comsure content. The non-Comsure articles posted on the Comsure website are deemed important, relevant, and newsworthy to a Comsure audience (e.g. regulated financial services and professional firms [DNFSBs]). Comsure does not wish to take any credit for the publication, and the publication can be read in full in its original form if you click the articles link that always accompanies the news item. Also, Comsure does not seek any payment for highlighting these important articles. If you want any article removed, Comsure will automatically do so on a reasonable request if you email info@comsuregroup.com.