Notice
Misdirected Email with Account Information (2020-02-14)
Issued 2020-02-14View on OMBUDSMAN's website Source document
Summary
This is a published case summary from the Cayman Islands Ombudsman describing an informal resolution of a personal data breach complaint against a bank. It illustrates how the Ombudsman applies existing data protection breach notification and mitigation requirements, rather than creating any new rule.
- Incident: A bank employee sent a misdirected email to a client that inadvertently disclosed another individual's email address, partial account number, and account balance.
- Bank's response: The bank notified the Ombudsman and the affected data subject as required by law, secured deletion confirmation from the recipient, reinforced staff email-review practices, discouraged use of unapproved templates, and continued regular staff training.
- Outcome: The Ombudsman closed the case as an informal resolution, finding no harm to the data subject and that containment and mitigation measures were reasonable.
As a case outcome notice, it does not itself impose new obligations on regulated entities, but it reflects the Ombudsman's expectation that data controllers notify both the Ombudsman and affected individuals following a personal data breach and take reasonable containment and staff-training measures.
Applies to
banks, data controllers
Topics
Version history
2026-07-30