Notice
Bank inadvertently sends existing clients’ data to new applicants (2022-02-21)
Issued 2022-02-21View on OMBUDSMAN's website Source document
Summary
This is a case summary published by the Cayman Islands Ombudsman describing an informal resolution of a data breach complaint against a bank under data protection rules. It illustrates how the Ombudsman assessed a bank's breach response rather than creating any new legal requirement.
- What happened: A bank's Private Banking Team accidentally emailed a completed personal lending application containing another client's personal data to two external prospective clients, instead of a blank template.
- Discovery: The breach was discovered and reported by one of the unintended recipients.
- Bank's response: The bank contacted the recipients, confirmed deletion of the email and attachments, created a separate shared folder for blank templates, and published links to blank forms on its website for prospective and existing clients.
- Outcome: The Ombudsman found the bank's containment and mitigation measures appropriate and confirmed all breach notification requirements were met, with no further action required.
As a case summary, this document is informational and does not itself impose new obligations, but it signals the Ombudsman's expectations for prompt breach containment, notification, and process improvements following a data breach.
Applies to
banks
Topics
Version history
2026-07-30