Notice
Proof of vaccination had no legal basis and was excessive - CIBC FCIB (Cayman) (2023-03-21)
Issued 2023-03-21View on OMBUDSMAN's website Source document
Summary
This is a published case summary from the Cayman Islands Ombudsman describing the outcome of a data protection complaint against CIBC FCIB (Cayman). It illustrates how the Ombudsman applies the Data Protection Act (DPA) principles rather than creating new rules, but is instructive for how similar employer policies will be assessed.
- Background: In September 2021 the bank required employees to show proof of Covid-19 vaccination or weekly negative PCR results, with non-compliant staff placed on unpaid leave; two employees complained.
- No violation found: The Ombudsman found no breach of the first principle's right to be informed, the second principle (further processing), or the fifth principle (retention).
- Violations found: The bank lacked a valid legal basis (processing condition) for collecting vaccination and PCR data, and the processing was excessive because it was not necessary to meet Labour Act obligations, the legal basis it had invoked.
- Email practice breach: A reminder email sent to non-compliant employees without using BCC risked revealing health or medical status to other recipients, breaching the seventh principle (integrity and confidentiality).
- Outcome: No corrective action was required because the data controller had already stopped the practice; the bank also demonstrated compliance with the eighth principle on international transfers of personal data at the Ombudsman's request.
The case serves as guidance that employers acting as data controllers must have a clear legal basis and necessity justification before collecting health related data such as vaccination status, and must take care with email distribution methods to avoid exposing sensitive health inferences.
Applies to
data controllers, employers, banks
Topics
Version history
2026-07-30