Notice

Erroneous group email sent by financial service provider (2019-11-26)

Cayman Islands Office of the Ombudsman (OMBUDSMAN) · Cayman Islands

Issued 2019-11-26

Current version last checked: 2026-07-30

Summary

This is a published case summary from the Cayman Islands Ombudsman describing an informal resolution of a data protection complaint. It is illustrative of how a specific incident was handled, not a rule or policy statement, and imposes no new legal requirements on regulated entities generally.

  • What happened: A financial services company self-reported that it sent a group email to 49 clients without using blind carbon copy, exposing all recipients' names and email addresses to each other.
  • Remedial steps taken: The company notified the affected clients, advised them to delete the email, and confirmed deletion; it also received further advice from the Ombudsman's office.
  • Outcome: The case was closed as an informal resolution because there was no evidence of prejudice to the rights of the affected clients.

The summary serves as a practical illustration of a personal data breach and an expected response (notification, mitigation, and cooperation with the Ombudsman) rather than a source of binding obligations.

Applies to

financial service providers

Topics

Version history

2026-07-30

source file (current)