Notice
Verification of employment letter by retail bank (2021-03-05)
Issued 2021-03-05View on OMBUDSMAN's website Source document
Summary
This is a case summary published by the Cayman Islands Ombudsman describing an informal resolution of a data protection complaint against a retail bank. It illustrates how the Ombudsman applies the Data Protection Law's seventh principle (appropriate organizational measures) in a real breach scenario, rather than creating new binding rules.
- What happened: A bank employee verifying a customer's employment letter emailed it to the employer's general inquiries address, which was accessible to multiple staff, resulting in five employees reading the letter.
- Finding: The bank's existing protocol created ambiguity and risk, and its own procedures were not followed, amounting to a violation of the seventh data protection principle requiring appropriate organizational measures against unauthorized or unlawful processing.
- Notification issue: The bank's breach notification to the affected data subject was found not to be fully compliant.
- Outcome: The bank offered the customer a fee waiver, the breach was assessed as contained, and the Ombudsman recommended the bank review and update its procedures and provide additional staff training.
As a case summary of an informal resolution, this document does not itself impose new legal requirements but signals the Ombudsman's expectations for how banks and other data controllers should handle verification requests, breach containment, and data subject notification under the Data Protection Law.
Key obligations
- Data controllers must establish and follow clear organizational measures, such as policies and procedures, to prevent unauthorized or unlawful processing of personal data
- Data controllers must ensure breach notifications to affected data subjects are fully compliant with applicable requirements
Applies to
retail banks, data controllers
Topics
Version history
2026-07-30