Data Protection and Bank Liability: Analysis of Address Update Refusal

Case Background: The Customer's Request

  • Parties Involved:
    • Plaintiff: A customer of a banking institution who initiated legal action regarding data correction procedures.
    • Defendant: Saudi Bank (the banking institution and data controller).
  • The Request: The plaintiff sought to update his personal correspondence address on file with the bank.
  • The Method: The request for the address change was submitted via email.
  • The Bank's Initial Response: Saudi Bank refused to process the plaintiff's request to update the address.

Rationale for the Bank's Refusal

  • Unsecured Communication Channel: The bank contended that the request was made via an unsecured channel, which posed a threat to the integrity of the process.
  • Identity Verification Concerns: The bank argued that it could not satisfactorily verify the identity of the sender through the email received.
  • Data Security Risks: Saudi Bank maintained that complying with an unverified request via an unsecured channel would expose the customer's personal data to specific risks, including:
    • Unauthorized Access: The possibility of a third party accessing or altering the information.
    • Fraudulent Issues: The risk that the request was a fraudulent attempt to redirect or manipulate customer data.

Legal Arguments and the Central Issue

  • Plaintiff's Argument: The plaintiff asserted that the bank's refusal to update the address was wrongful. He argued that under the Personal Data Protection Act (PDPA), the bank was under a strict obligation to correct or update personal data whenever a request is made by the data subject.
  • The Legal Issue: The core question before the court was whether the bank was legally entitled to refuse a correction request in order to fulfill its concurrent duty to safeguard the security of the customer's personal data.

High Court Ruling and Judicial Reasoning

  • The Decision: The High Court held that the bank had acted lawfully and was fully justified in refusing to process the plaintiff's request.
  • Statutory Obligation: The court emphasized that the bank, as a data controller, has a statutory obligation to protect its customers' data.
  • Requirement for Security Measures: Under the PDPA, organizations are required to adopt "reasonable and appropriate security measures" to ensure data protection.
  • Specific Objectives of Security Measures: The measures must be designed to prevent:
    • Unauthorized access.
    • Misuse of data.
    • Disclosure of data.
    • Avoidance of any compromise to the customer's personal data.

Section 9 of the Personal Data Protection Act (PDPA)

  • The Standard of Care: To fulfill the duty of care expected of a "prudent data controller" under Section 9 of the PDPA, the bank must demonstrate specific behaviors.
  • Mandatory Operational Controls:
    • Proper Monitoring: Continuous oversight of data access and update requests.
    • Impartial Enforcement of Access Controls: Security protocols must be enforced strictly across the board.
    • Positional Neutrality: Access controls and security protocols must be applied regardless of the user's position within the company.
    • Timely Intervention: The organization must act quickly to prevent or mitigate security breaches.
  • Conclusion on Compliance: The court concluded that by refusing the unsecured request and insisting on proper verification, Saudi Bank fulfilled its legal obligations and the expected standard of care as a data controller under Section 9.