Notice
Access to One's Own Personal Data (2020-10-30)
Issued 2020-10-30View on OMBUDSMAN's website Source document
Summary
This is a published case summary from the Cayman Islands Ombudsman describing an informal resolution of a data protection complaint concerning a subject access request. It illustrates how the Ombudsman applies the Data Protection Law (DPL) rather than creating new rules itself.
- Facts: Two individuals asked a financial institution (data controller) for copies of all internal instructions concerning them and their mortgage and loan facilities.
- Initial response: The data controller initially refused, arguing internal communications with supporting and processing partners were for internal use only and not to be shared with clients.
- Outcome: Following the Ombudsman's investigation, the data controller acknowledged its obligations under the DPL, complied with the subject access request within the appropriate timeframe, and provided appropriately redacted copies of the documentation.
The case serves as guidance that internal communications relating to a data subject's own personal data generally fall within scope of a subject access request under the DPL and cannot be withheld merely because they were intended for internal use.
Key obligations
- Data controllers must comply with valid subject access requests under the Data Protection Law within the appropriate timeframe, including internal communications concerning the data subject where they constitute personal data.
- Where documents contain third-party or otherwise exempt information, data controllers should provide appropriately redacted versions rather than withholding the entire document.
Applies to
data controllers, financial institutions
Topics
Version history
2026-07-30