Notice

Enhanced due diligence by a financial services provider (2021-06-23)

Cayman Islands Office of the Ombudsman (OMBUDSMAN) · Cayman Islands

Issued 2021-06-23

Current version last checked: 2026-07-30

Summary

This is a published case summary from the Cayman Islands Ombudsman describing an informal resolution decision, not a rule or regulatory instrument. It concerns a complaint that a financial services provider's request for personal data as part of enhanced due diligence was excessive and breached the third data protection principle.

  • Complaint: A customer objected to a financial services provider's request for additional personal data during due diligence, alleging it was excessive under the Data Protection Act (DPA).
  • Finding: The Ombudsman found the data requested was consistent with Anti-Money Laundering Regulations (AMLR) requirements for enhanced due diligence based on a risk-based approach to assessing client financial activity.
  • Outcome: The provider had a valid legal basis for processing the data under the DPA, the request was not excessive, and no further action was taken.

The summary illustrates the Ombudsman's interpretation of how AMLR-driven enhanced due diligence requests interact with DPA data minimisation principles, but it does not itself create new obligations for financial services providers beyond existing AMLR and DPA requirements.

Applies to

financial services providers

Topics

Version history

2026-07-30

source file (current)