Notice
Credit Union sends invitation without using BCC (2022-06-28)
Issued 2022-06-28View on OMBUDSMAN's website Source document
Summary
This is a published case summary from the Cayman Islands Ombudsman describing an informally resolved data protection complaint against a credit union. It illustrates how the Ombudsman applies personal data breach notification rules and controller accountability under the Data Protection Act, and is intended as guidance rather than a binding rule change.
- What happened: A credit union sent a Microsoft Teams meeting invitation to 211 individuals without using BCC, exposing all recipients' email addresses; one recipient then replied all and inadvertently disclosed health related information.
- Notification timing: Affected individuals were notified of the breach one day after the statutory 5 day notification period, though the notification was otherwise compliant.
- Remedial steps accepted: The credit union proposed either sending meeting links via a separate BCC'd email with a warning that other participants' details would be visible, or using a third party webinar feature allowing participant anonymity.
- Outcome: The Ombudsman found the credit union not responsible for the subsequent reply all disclosure of health data, provided guidance on sending Teams invitations via BCC, and closed the case with no further action after being satisfied with the corrective measures taken.
As an informal resolution case summary, this document does not itself create new legal obligations but signals the Ombudsman's expectations that data controllers use BCC or equivalent measures when sending mass meeting invitations and notify affected individuals of breaches within the statutory 5 day period.
Key obligations
- Data controllers must notify affected data subjects of a personal data breach within the statutory 5 day notification period
- Data controllers sending mass meeting invitations (e.g. via Microsoft Teams) should use BCC or an equivalent method to avoid disclosing recipients' personal data to one another
Applies to
credit unions, data controllers
Deadlines
- 5-day notification period: Statutory period within which data subjects must be notified following a personal data breach
Topics
Version history
2026-07-30