Search

How can we help?

Icon

NHS Trust fined £180,000 over data protection breach

The Information Commissioner’s Office (ICO) have fined Chelsea and Westminster Hospital NHS Foundation Trust £180,000 after it revealed the email addresses of 781 users of an HIV service. Patients using the HIV service were sent a newsletter which mistakenly included all recipients email addresses in the ‘to’ field instead of the ‘bcc’ field.  730 of the email addresses displayed contained full names.  The ICO found that this amounted to a serious breach of the Data Protection Act 1998 and that it was likely to cause substantial distress as recipients of the e-mails could infer the HIV status of the other recipients.  In addition to the information being confidential sensitive personal data, the ICO was conscious that, due to the small geographical area the Trust serviced, the individuals may well have known each other.

The Trust had made a similar mistake in 2010 and, although some steps were taken then to prevent reoccurrence, the ICO found that no specific training had been implemented following that breach.

Chambers and Partners

The Clarkslegal team are commercial and good to work with. They get what our business needs and tell me what I need to hear.

Employers should ensure that they have adequate training in place on data protection obligations and staff should be reminded of the care that needs to be taken when sending group emails, particularly, when this may reveal sensitive information about those involved such as their health.

Disclaimer

This information is for guidance purposes only and should not be regarded as a substitute for taking legal advice. Please refer to the full General Notices on our website.

Author profile

Monica Atwal

Managing Partner

View profile

+44 118 960 4605

About this article

Read, listen and watch our latest insights

art
  • 20 May 2026
  • Immigration

AI vs Home Office approved Translations – why migrants are paying the price

AI is transforming almost every professional sector. Law firms now use AI-assisted drafting, businesses rely on automated translation software, and governments increasingly use digital systems for decision-making.

art
  • 20 May 2026
  • Employment

Trade Unions Right of Access from October – What you need to know

Under the Employment Rights Act 2025, independent Trade Unions (i.e. those with a certificate of independence) will have a right to access workplaces (physically and digitally) from October 2026.

art
  • 19 May 2026
  • Privacy and Data Protection

New Complaints Procedure for Data Protection Coming in June – Are You Ready?

The Data (Use and Access) Act 2025 (the “Act”) received Royal Assent last year and introduces slight reforms to the UK’s data protection regime.

art
  • 18 May 2026
  • Commercial Real Estate

Land Registry title to property mines and minerals

Depending on the location of the property, it is quite common in parts of England and Wales for a property title to contain a reference to mines and minerals, and for these to be excluded from the surface owner’s ownership in favour of another party.

art
  • 13 May 2026
  • Employment

10 top tips for negotiating a redundancy settlement agreement, for employers and employees

Redundancies are on the rise, resulting in increased use of settlement agreements. We’ve compiled our top 10 tips for drafting and negotiating these agreements to support both employers and employees through this challenging process.

art
  • 12 May 2026
  • Immigration

Supplementary Employment: When is it Allowed under UK Immigration Rules?

This article provides a guidance to understanding the rules on supplementary employment in the UK.