Notice
Retail bank’s lack of response to a subject access request (2021-06-03)
Issued 2021-06-03View on OMBUDSMAN's website Source document
Summary
This is a published case summary from the Cayman Islands Ombudsman describing an informal resolution of a data protection complaint against a retail bank. It illustrates how the Ombudsman handles failures to respond to subject access requests (SARs) under the Data Protection Law, rather than creating new binding rules.
- What happened: A customer submitted a subject access request to her bank for her personal data; she received only an acknowledgement and no records or follow up, despite emailing again.
- Cause identified: The bank admitted the failure was due to a designated customer sales representative not monitoring the bank's customer care inbox, contrary to its own Privacy Handbook procedures.
- Outcome: The bank provided all requested information to the complainant, took internal steps to prevent recurrence, and the Ombudsman made recommendations on how the bank should handle subject access requests going forward; the case was then closed.
For compliance officers, the case is a reminder that entities holding personal data must have effective monitoring and escalation processes to ensure subject access requests are actioned within required timeframes, not just acknowledged.
Key obligations
- Data controllers, including banks, must substantively respond to subject access requests by providing the requested personal data, not merely acknowledging receipt.
- Entities must ensure internal processes (such as monitoring designated customer care inboxes) are followed so that subject access requests and follow-up communications are not overlooked.
Applies to
retail banks, data controllers
Topics
Version history
2026-07-30