WILLEMSTAD – Curaçao’s trust sector is raising concerns about the handling and protection of confidential information submitted to the Curaçao Gaming Authority (CGA), following the data breach involving the regulator’s online licensing portal.
The United Trust Companies (UTC), which represents companies in Curaçao’s trust sector, says the incident goes beyond the technical security of the portal. According to the organization, it raises a more fundamental question about whether businesses and individuals can trust that sensitive information they are legally required to provide to a regulator remains adequately protected.
Trust companies and their clients are required to submit extensive information as part of gaming license applications and regulatory procedures. This can include corporate information, ownership structures, financial data, information about directors and details concerning Ultimate Beneficial Owners (UBOs).
UTC says companies must be able to rely on such information being used exclusively for the purpose for which it was provided and being protected against unauthorized access.
That confidence has now been damaged, according to the organization.
The concerns have become more serious following information provided by the CGA to the sector about the possible scale of the breach.
According to UTC, the Gaming Authority has informed the sector that it is working on the assumption that the entire database connected to the licensing portal was accessed and searched between December 2025 and September 2026.
That would potentially make the incident considerably broader than unauthorized access to a limited number of individual files.
The CGA has asked Corporate Service Providers to notify affected individuals. Where identity documents have been made public, the regulator has also warned of the possibility of identity fraud.
The development is particularly sensitive for Curaçao’s trust sector because companies do not necessarily have the option of withholding the information involved. Detailed documentation on clients, ownership and corporate structures is required as part of regulatory and licensing procedures.
UTC is not arguing that all information submitted to the CGA has been publicly disclosed. Its concern centers on whether the safeguards surrounding information that entered the licensing system were sufficient.
The organization maintains that when government regulation requires companies and individuals to provide highly sensitive information, there is a corresponding responsibility to ensure that the data is properly secured and handled only for legitimate regulatory purposes.
According to UTC, the breach demonstrates that the protection surrounding the information was insufficient.
The incident therefore creates a broader challenge for the CGA as it continues implementing Curaçao’s new regulatory system for the online gaming industry. Beyond determining how the unauthorized access occurred, the regulator faces the task of restoring confidence among the businesses and professionals required to provide it with confidential information.