Notice
WORC sends bulk emails without using BCC (2022-06-22)
Issued 2022-06-22View on OMBUDSMAN's website Source document
Summary
This is a published case summary from the Cayman Islands Ombudsman describing an informal resolution of a data protection complaint against WORC (Workforce Opportunities and Residency Cayman). WORC sent a JobsCayman notice to about 4,000 registrants without using BCC, exposing many registrants' personal email addresses to each other.
- What happened: A bulk notice was sent via visible To/Cc fields rather than BCC, revealing personal email addresses; roughly 2,300 emails were successfully recalled and 300 were undeliverable, with follow up requests sent to remaining recipients to delete the email.
- Ombudsman's finding: The breach arose from a manual bulk-email process with high risk of error; WORC notified affected registrants in compliance with the Data Protection Act.
- Remedial measures agreed: WORC agreed to work with the JobsCayman portal developer to enable direct system-generated emails to recipients, eliminating manual bulk-email risk, and accepted additional Ombudsman recommendations on bulk email practices and staff training on email client use and etiquette.
- Outcome: The case was closed with no further action, as WORC's remedial steps were considered sufficient to prevent recurrence and support ongoing compliance with the seventh data protection principle (security of personal data).
This notice is a case study illustrating enforcement expectations under the seventh data protection principle regarding secure handling of personal data in bulk communications; it does not itself impose new binding rules but signals the Ombudsman's expectations for data controllers using bulk email.
Key obligations
- Data controllers should avoid manual bulk-email processes that expose recipients' personal email addresses and should use BCC or automated system-generated messaging to prevent unauthorized disclosure
- Data controllers must notify affected individuals of a personal data breach in compliance with the Data Protection Act
- Organizations should provide staff training on proper use of email clients and email etiquette to maintain compliance with the seventh data protection principle
Applies to
data controllers, government agencies handling personal data
Topics
Version history
2026-07-30