Notice

Credit Union sends invitation without using BCC (2022-06-28)

Cayman Islands Office of the Ombudsman (OMBUDSMAN) · Cayman Islands

Issued 2022-06-28

Current version last checked: 2026-07-30

Summary

This is a published case summary from the Cayman Islands Ombudsman describing an informally resolved data protection complaint against a credit union. It illustrates how the Ombudsman applies personal data breach notification rules and controller accountability under the Data Protection Act, and is intended as guidance rather than a binding rule change.

  • What happened: A credit union sent a Microsoft Teams meeting invitation to 211 individuals without using BCC, exposing all recipients' email addresses; one recipient then replied all and inadvertently disclosed health related information.
  • Notification timing: Affected individuals were notified of the breach one day after the statutory 5 day notification period, though the notification was otherwise compliant.
  • Remedial steps accepted: The credit union proposed either sending meeting links via a separate BCC'd email with a warning that other participants' details would be visible, or using a third party webinar feature allowing participant anonymity.
  • Outcome: The Ombudsman found the credit union not responsible for the subsequent reply all disclosure of health data, provided guidance on sending Teams invitations via BCC, and closed the case with no further action after being satisfied with the corrective measures taken.

As an informal resolution case summary, this document does not itself create new legal obligations but signals the Ombudsman's expectations that data controllers use BCC or equivalent measures when sending mass meeting invitations and notify affected individuals of breaches within the statutory 5 day period.

Key obligations

  • Data controllers must notify affected data subjects of a personal data breach within the statutory 5 day notification period
  • Data controllers sending mass meeting invitations (e.g. via Microsoft Teams) should use BCC or an equivalent method to avoid disclosing recipients' personal data to one another

Applies to

credit unions, data controllers

Deadlines

  • 5-day notification period: Statutory period within which data subjects must be notified following a personal data breach

Topics

Version history

2026-07-30

source file (current)