Search

How can we help?

Icon

NHS Trust fined £180,000 over data protection breach

The Information Commissioner’s Office (ICO) have fined Chelsea and Westminster Hospital NHS Foundation Trust £180,000 after it revealed the email addresses of 781 users of an HIV service. Patients using the HIV service were sent a newsletter which mistakenly included all recipients email addresses in the ‘to’ field instead of the ‘bcc’ field.  730 of the email addresses displayed contained full names.  The ICO found that this amounted to a serious breach of the Data Protection Act 1998 and that it was likely to cause substantial distress as recipients of the e-mails could infer the HIV status of the other recipients.  In addition to the information being confidential sensitive personal data, the ICO was conscious that, due to the small geographical area the Trust serviced, the individuals may well have known each other.

The Trust had made a similar mistake in 2010 and, although some steps were taken then to prevent reoccurrence, the ICO found that no specific training had been implemented following that breach.

Chambers and Partners

The Clarkslegal team are commercial and good to work with. They get what our business needs and tell me what I need to hear.

Employers should ensure that they have adequate training in place on data protection obligations and staff should be reminded of the care that needs to be taken when sending group emails, particularly, when this may reveal sensitive information about those involved such as their health.

Disclaimer

This information is for guidance purposes only and should not be regarded as a substitute for taking legal advice. Please refer to the full General Notices on our website.

Author profile

Monica Atwal

Managing Partner

View profile

+44 118 960 4605

About this article

Read, listen and watch our latest insights

art
  • 02 April 2026
  • Commercial Real Estate

Can I have access to a neighbour’s land to carry out works to my property?

As a landowner, maintaining and repairing your property is important. It may be the case that to do so, you will need to access the land of a neighbour.

art
  • 01 April 2026
  • Privacy and Data Protection

Recognising DSARs: top tips for organisations

The UK GDPR grants Data Subjects, who are the individuals to whom the personal data relates, rights over their personal data, including the rights of access, correction and erasure.

art
  • 30 March 2026
  • Employment

Legislative Changes – What Employers Need to Know for April 2026

With the phased implementation of the Employment Rights Act 2025 (ERA), alongside other legislative updates, April 2026 brings a wide range of important changes for employers.

Pub
  • 27 March 2026
  • Corporate and M&A

Shareholder Disputes: What to do when disputes arise – Episode 4

Join Stuart Mullins and Jack Hobbs for episode four of our Shareholder Disputes podcast series as they confront the realities of shareholder fallouts and share practical strategies for managing these complex situations.

art
  • 24 March 2026
  • Immigration

Spouse Visa – Is your relationship genuine and subsisting?

For years many couples have become frustrated by the requirements for a spouse visa as the rules and guidance are difficult to understand. A significant amount of applications are rejected on the basis of the applicant not providing the adequate documents to evidence the relationship requirement.

art
  • 20 March 2026
  • Corporate and M&A

Drag-Along & Tag-Along Rights: Why Every Company Needs Them

When starting a company, very few founders are aware of the potential issues around shares, share ownership and the implications of that when selling their company.