Notice

Misdirected Email with Account Information (2020-02-14)

Cayman Islands Office of the Ombudsman (OMBUDSMAN) · Cayman Islands

Issued 2020-02-14

Current version last checked: 2026-07-30

Summary

This is a published case summary from the Cayman Islands Ombudsman describing an informal resolution of a personal data breach complaint against a bank. It illustrates how the Ombudsman applies existing data protection breach notification and mitigation requirements, rather than creating any new rule.

  • Incident: A bank employee sent a misdirected email to a client that inadvertently disclosed another individual's email address, partial account number, and account balance.
  • Bank's response: The bank notified the Ombudsman and the affected data subject as required by law, secured deletion confirmation from the recipient, reinforced staff email-review practices, discouraged use of unapproved templates, and continued regular staff training.
  • Outcome: The Ombudsman closed the case as an informal resolution, finding no harm to the data subject and that containment and mitigation measures were reasonable.

As a case outcome notice, it does not itself impose new obligations on regulated entities, but it reflects the Ombudsman's expectation that data controllers notify both the Ombudsman and affected individuals following a personal data breach and take reasonable containment and staff-training measures.

Applies to

banks, data controllers

Topics

Version history

2026-07-30

source file (current)