Notice
Health Clinic Gathers Credit Card Data in Contravention of Data Security Standards (2020-11-02)
Issued 2020-11-02View on OMBUDSMAN's website Source document
Summary
This is a published case summary from the Cayman Islands Ombudsman describing an informal resolution of a data protection complaint against a health clinic. It illustrates how the Ombudsman applies the Data Protection Law (DPL) to a business that collected full credit card details, including sensitive cardholder data, via an unsecured registration form during the COVID-19 lockdown.
- What went wrong: The clinic's registration form collected full cardholder details and signatures and sent them as a PDF over unsecured email, contravening the Payment Card Industry Data Security Standard (PCI DSS) and the seventh data protection principle (data security).
- Privacy notice failure: The clinic's privacy notice, embedded in the registration form, did not meet the requirements of the first data protection principle (lawful, fair and transparent processing).
- Outcome: The Ombudsman advised the clinic on choosing an appropriate legal basis for processing, bringing its privacy notice into compliance, and securely destroying the cardholder data already collected. The clinic stopped using the form and the complaint was resolved informally.
As an informal resolution case summary, this document does not create new legal rules but signals the Ombudsman's expectations for how data controllers, including small businesses and health providers, must handle payment card and personal data under the DPL and relevant industry security standards such as PCI DSS.
Key obligations
- Data controllers must not store or transmit sensitive cardholder data (e.g. CVVs, PINs, magnetic stripe data) after payment authorization, per PCI DSS and the seventh data protection principle
- Card numbers must be masked wherever stored
- Privacy notices provided to data subjects must satisfy the first data protection principle (lawful, fair and transparent processing) under the DPL
- Data controllers should choose and document an appropriate legal basis for processing personal data
- Personal data no longer needed or unlawfully collected should be securely destroyed
Applies to
health clinics, data controllers, businesses handling payment card data