Notice
Erroneous group email sent by financial service provider (2019-11-26)
Issued 2019-11-26View on OMBUDSMAN's website Source document
Summary
This is a published case summary from the Cayman Islands Ombudsman describing an informal resolution of a data protection complaint. It is illustrative of how a specific incident was handled, not a rule or policy statement, and imposes no new legal requirements on regulated entities generally.
- What happened: A financial services company self-reported that it sent a group email to 49 clients without using blind carbon copy, exposing all recipients' names and email addresses to each other.
- Remedial steps taken: The company notified the affected clients, advised them to delete the email, and confirmed deletion; it also received further advice from the Ombudsman's office.
- Outcome: The case was closed as an informal resolution because there was no evidence of prejudice to the rights of the affected clients.
The summary serves as a practical illustration of a personal data breach and an expected response (notification, mitigation, and cooperation with the Ombudsman) rather than a source of binding obligations.
Applies to
financial service providers
Topics
Version history
2026-07-30