Search

How can we help?

Icon

NHS Trust fined £180,000 over data protection breach

The Information Commissioner’s Office (ICO) have fined Chelsea and Westminster Hospital NHS Foundation Trust £180,000 after it revealed the email addresses of 781 users of an HIV service. Patients using the HIV service were sent a newsletter which mistakenly included all recipients email addresses in the ‘to’ field instead of the ‘bcc’ field.  730 of the email addresses displayed contained full names.  The ICO found that this amounted to a serious breach of the Data Protection Act 1998 and that it was likely to cause substantial distress as recipients of the e-mails could infer the HIV status of the other recipients.  In addition to the information being confidential sensitive personal data, the ICO was conscious that, due to the small geographical area the Trust serviced, the individuals may well have known each other.

The Trust had made a similar mistake in 2010 and, although some steps were taken then to prevent reoccurrence, the ICO found that no specific training had been implemented following that breach.

Chambers and Partners

The Clarkslegal team are commercial and good to work with. They get what our business needs and tell me what I need to hear.

Employers should ensure that they have adequate training in place on data protection obligations and staff should be reminded of the care that needs to be taken when sending group emails, particularly, when this may reveal sensitive information about those involved such as their health.

Disclaimer

This information is for guidance purposes only and should not be regarded as a substitute for taking legal advice. Please refer to the full General Notices on our website.

Author profile

Monica Atwal

Managing Partner

View profile

+44 118 960 4605

About this article

Read, listen and watch our latest insights

art
  • 24 October 2025
  • Commercial Real Estate

Navigating the building regulations regime in commercial property transactions

Building control is said to be one of the earliest forms of local government in England, with the modern building regulations progressing in the aftermath of the Great Fire of London.

art
  • 23 October 2025
  • Employment Rights Bill

Government launches Employment Rights Bill consultations – key changes employers need to know

The Employment Rights Bill is a draft law set to significantly expand workers’ rights. The Government has now launched the first round of consultations.

art
  • 23 October 2025
  • Privacy and Data Protection

AI and Data Protection – Is Fair and Transparent Privacy Possible?

We live in a digital world. Every facet of daily life is governed to some degree by phone, web or some form of connected technology.

art
  • 16 October 2025

Chambers and Partners 2026: Clarkslegal’s continued commitment to excellence

Clarkslegal is delighted to announce that we have once again been recognised by Chambers and Partners as a leading firm in their 2026 guide.

art
  • 15 October 2025
  • Immigration

Registering a child as a British Citizen: A guide to section 3(1) applications

This article explains the process of registering a child as a British citizen under section 3(1), including the eligibility criteria, the Home Office approach, and key factors that influence whether an application is approved.

art
  • 15 October 2025
  • Commercial Real Estate

A commercial lease in England: a few essential points to consider

Thinking about a commercial lease in England? Whether your lease is short or long, here are five essential clauses to keep in mind during negotiations.