Notice

Bank inadvertently sends existing clients’ data to new applicants (2022-02-21)

Cayman Islands Office of the Ombudsman (OMBUDSMAN) · Cayman Islands

Issued 2022-02-21

Current version last checked: 2026-07-30

Summary

This is a case summary published by the Cayman Islands Ombudsman describing an informal resolution of a data breach complaint against a bank under data protection rules. It illustrates how the Ombudsman assessed a bank's breach response rather than creating any new legal requirement.

  • What happened: A bank's Private Banking Team accidentally emailed a completed personal lending application containing another client's personal data to two external prospective clients, instead of a blank template.
  • Discovery: The breach was discovered and reported by one of the unintended recipients.
  • Bank's response: The bank contacted the recipients, confirmed deletion of the email and attachments, created a separate shared folder for blank templates, and published links to blank forms on its website for prospective and existing clients.
  • Outcome: The Ombudsman found the bank's containment and mitigation measures appropriate and confirmed all breach notification requirements were met, with no further action required.

As a case summary, this document is informational and does not itself impose new obligations, but it signals the Ombudsman's expectations for prompt breach containment, notification, and process improvements following a data breach.

Applies to

banks

Topics

Version history

2026-07-30

source file (current)