Search

How can we help?

Icon

Recent data breaches and their impact on organisations

Organisations of all sizes are susceptible to data breaches and the damage caused by these breaches, both reputationally and financially, can be very significant. It is therefore vital that organisations have effective systems in place to protect the information that they hold and have procedures for preventing and dealing with any breaches.

A data breach occurs when the information held by an organisation is stolen or accessed without authorisation. Under the UK GDPR, organisations have a duty to report certain personal data breaches to the relevant authorities within 72 hours of becoming aware of the breach (if this meets the threshold to report). Organisations also have a duty to keep a record of all personal data breaches in any case, but relevant individuals must be informed if the breach has a high risk of adversely affecting them.

The following recent cases highlight the detrimental impact that data breaches can have on both organisations and individuals:

Police Service of Northern Ireland (PSNI)

In August 2023, PSNI received two freedom of information requests from an individual requesting information about the number of officers in each rank and their status, i.e. substantive, temporary or acting. PSNI provided this information in a excel spreadsheet which, unnoticed but quality assurance, had a mistakenly included a worksheet tab with the surnames, initials, ranks and roles of all 9,4831 PSNI officers and staff. PSNI was alerted of the breach internally at 4:10pm the same day and the file was deleted from the website at 5:27pm. PSNI made an announcement 6 days later. The ICO conducted an investigation and found that the internal procedures and sign off protocols had been inadequate. In October 2024, PSNI was fined £750,000 by the ICO for exposing personal information of its entire workforce. The fine would have been £5.6million, however the Commissioner used his discretion in this case as he was mindful of PSNI’s financial position and did not want to divert public money from where it was needed.

Jesse Akiwumi

Solicitor

View profile

+44 118 960 4662

The fine would have been £5.6million, however the Commissioner used his discretion in this case as he was mindful of PSNI’s financial position and did not want to divert public money from where it was needed.

The Central Young Men’s Christian Association (the Central YMCA)

The Central YMCA had incorrectly sent an email to 264 individuals participating in a HIV support programme using CC instead of BCC. As a result, the email addresses of the recipients were revealed and 166 individuals could be identified or potentially identified to be living with HIV. The ICO fined the Central YMCA £7,500 for the data breach of sensitive information which denied basic dignity and privacy for individuals living with HIV. Here, the Commissioner also used his discretion under the ICO’s public sector approach and reduced the fine which was initially recommended to be £300,000.

South Tees Hospitals NHS Foundation Trust (the Trust)

In November 2022, an employee of the Trust sent a standard letter to the father of a child patient informing him of an upcoming appointment. The appointment letter, however, was sent to the wrong address and was sent to the family of the child’s mother. This incident caused significant distress and upset to the patient and the family. The ICO launched an investigation and found no evidence of the Trust having a formal documented process or procedure in place. The ICO issued a reprimand to the Trust and advised that a formal written procedure be put in place to mitigate risks and ensure correct contact details were used.

The above cases demonstrate the need for organisations to have breach detection, investigation and reporting procedures in place and to notify relevant authorities or individuals with undue delay, where this is required. They also demonstrate that financial and reputational damage can be limited if an organisation has robust policies and procedures in place. If you have any questions about data breaches or would like assistance with implementing data protection policies and procedures within your organisation, please contact a member of our Data Protection Team. Our team is more than happy to assist and can provide a short assessment tailored to your organisation’s needs.

About this article

Disclaimer
This information is for guidance purposes only and should not be regarded as a substitute for taking legal advice. Please refer to the full General Notices on our website.

Jesse Akiwumi

Solicitor

View profile

+44 118 960 4662

About this article

Read, listen and watch our latest insights

art
  • 26 June 2025
  • Employment

A shift in EHRC guidance on single sex spaces in the workplace

In a recent significant shift, the Equality and Human Rights Commission (“the EHRC”) has quietly amended its guidance on single sex spaces in the workplace.

art
  • 18 June 2025
  • Employment

Pride Month: How Can You Celebrate as an Employer

The UK held its first Pride Parade in 1972, inspired by events held in major American cities following the Stonewall rebellion in New York in June 1969.

art
  • 13 June 2025
  • Employment

Human Resources – A Shift Towards artificial intelligence?

On 6 May 2025, the SRA authorised the first law firm providing legal services through artificial intelligence. Garfield.Law will provide an AI-powered tool which can assist businesses with the small claims court process, to aid in recovering unpaid debts.

art
  • 11 June 2025
  • Employment

Employment Contracts and Specific Performance

‘Specific performance’ is a type of equitable remedy available, in some circumstances, and at the court’s discretion, for breach of contract; it entails an order by the court which legally compels a party to a contract to fulfil its contractual obligations.

art
  • 09 June 2025
  • Employment

Can loss of temper arise from a disability?

Discrimination arising from disability occurs where an individual is treated unfavourably because of something arising in consequence of their disability. 

art
  • 09 June 2025
  • Employment

Clarkslegal representing UK employers at the International Labour Conference

I am writing this from Geneva, where I once again have the honour of attending the International Labour Organisation’s International Labour Conference.