Notice
Enforcement Order 202100552-553 (2023-03-21)
Issued 2023-03-21View on OMBUDSMAN's website Source document
Summary
This is an Enforcement Order issued by the Cayman Islands Ombudsman against CIBC First Caribbean International Bank (Cayman) following complaints from two employees about a Covid-19 vaccination and PCR testing policy introduced in September 2021. Employees who did not provide proof of vaccination or negative test results were required to go on unpaid leave. The Ombudsman investigated the processing of this health related data under the Data Protection Act (2021 Revision) (DPA) and made specific findings of violation and non-violation of individual data protection principles.
- No violation: First principle fairness limb (employees were adequately told of the data controller's identity and purpose), second principle (purpose limitation), and fifth principle (retention, data kept only one month).
- Violation found: First principle legal basis limb and Schedules 2 and 3 (no valid legal basis for processing sensitive vaccination and test data; reliance on the Labour Act's general health and safety duty was insufficient).
- Violation found: Third principle (data minimisation) as the processing of vaccination status and PCR results was excessive and not necessary to meet the stated Labour Act obligation.
- Violation found: Seventh principle (security) because a reminder email to unvaccinated staff was sent without BCC, risking inferences about individuals' health or vaccination status.
- Outstanding issue: Eighth principle (international transfers) not adequately explained, given contradictory evidence that employee data may have been sent to the Bahamas.
Because the underlying processing has since stopped, no corrective action was ordered for the past conduct, but the Ombudsman imposed forward looking requirements on the Data Controller for any similar future processing and required further information on international data transfers within 45 days.
Key obligations
- In any similar future processing of sensitive personal data, the Data Controller must ensure it meets at least one legal basis condition in Schedule 2 and one in Schedule 3 of the DPA.
- In any similar future processing, the Data Controller must not process personal data excessively and must ensure processing is necessary to meet the applicable legal basis.
- The Data Controller must use BCC when sending emails from which inferences about individuals (e.g. health status) could be made, to avoid potential profiling.
- Within 45 days of the order, the Data Controller must provide the Ombudsman with documentation on the nature of its international transfers of personal data to non-adequacy countries, any derogations relied upon, safeguards in place (e.g. standard contractual clauses), any adequacy self-assessment, and any other relevant compliance information regarding the eighth data protection principle.
- A person receiving this enforcement order may, within 45 days of receipt and upon notice to the Ombudsman, seek judicial review of the order in the Grand Court.
Applies to
data controllers, banks
Deadlines
- 45 days: Data Controller must explain and provide documentation on its international personal data transfers and eighth principle compliance to the Ombudsman.
- 45 days of receipt: Deadline for a recipient of the enforcement order to seek judicial review of the order in the Grand Court, upon notice to the Ombudsman.