Notice
Retail bank reveals overdrawn account (2021-11-29)
Issued 2021-11-29View on OMBUDSMAN's website Source document
Summary
This is a published case summary from the Cayman Islands Ombudsman describing an informal resolution of a data protection complaint against a retail bank. It illustrates how the Ombudsman applies the Data Protection Act (DPA) to breaches of client confidentiality by financial institutions, rather than setting new binding rules.
- What happened: A retail bank disclosed a client's overdrawn account balance to a close family member who had mistakenly transferred funds into that account.
- Bank's remedial steps: The bank apologized, reprimanded the staff involved, provided further training, and communicated with staff about client confidentiality obligations.
- Ombudsman's finding: The bank had not adequately notified the affected data subject of the breach as required under the DPA.
- Recommendation: The Ombudsman recommended that the bank's data breach procedures be reviewed to ensure compliance with the DPA.
As a case outcome notice, this document does not itself create new generally applicable rules, but signals the Ombudsman's expectation that data controllers, including retail banks, properly notify data subjects when their personal data is breached.
Key obligations
- Data controllers, including retail banks, must adequately notify affected data subjects when a data breach involving their personal information occurs, in accordance with the Data Protection Act.
- Following a breach, the entity involved should review and, if necessary, revise its data breach procedures to ensure DPA compliance.
Applies to
retail banks, data controllers
Topics
Version history
2026-07-30