Search

How can we help?

Icon

NHS Trust fined £180,000 over data protection breach

The Information Commissioner’s Office (ICO) have fined Chelsea and Westminster Hospital NHS Foundation Trust £180,000 after it revealed the email addresses of 781 users of an HIV service. Patients using the HIV service were sent a newsletter which mistakenly included all recipients email addresses in the ‘to’ field instead of the ‘bcc’ field.  730 of the email addresses displayed contained full names.  The ICO found that this amounted to a serious breach of the Data Protection Act 1998 and that it was likely to cause substantial distress as recipients of the e-mails could infer the HIV status of the other recipients.  In addition to the information being confidential sensitive personal data, the ICO was conscious that, due to the small geographical area the Trust serviced, the individuals may well have known each other.

The Trust had made a similar mistake in 2010 and, although some steps were taken then to prevent reoccurrence, the ICO found that no specific training had been implemented following that breach.

Chambers and Partners

The Clarkslegal team are commercial and good to work with. They get what our business needs and tell me what I need to hear.

Employers should ensure that they have adequate training in place on data protection obligations and staff should be reminded of the care that needs to be taken when sending group emails, particularly, when this may reveal sensitive information about those involved such as their health.

Disclaimer

This information is for guidance purposes only and should not be regarded as a substitute for taking legal advice. Please refer to the full General Notices on our website.

Author profile

Monica Atwal

Managing Partner

View profile

+44 118 960 4605

About this article

Read, listen and watch our latest insights

art
  • 16 December 2025
  • Employment

Christmas Parties – Festive Fun or a New Year Hangover?

It’s Christmas party season! The office party is often a mixed blessing – an opportunity to boost morale and perhaps celebrate a successful year yet also a melting pot of workers letting their hair down, with potential for accidents, injuries, threats and claims.

art
  • 10 December 2025
  • Privacy and Data Protection

The 12 Data Protection Mistakes of Christmas

As the festive season approaches, it is not just last-minute shopping and office parties that can catch organisations off guard; data protection slip-ups are just as common.

Pub
  • 04 December 2025
  • Immigration

UK Immigration: What to expect in 2026 for employers

Join our UK immigration specialists, Ruth Karimatsenga and Monica Mastropasqua, as they explore the key updates and how they affect your business in 2026.

Pub
  • 04 December 2025
  • Corporate and M&A

Autumn Budget 2025 Breakdown: Key takeaways for business buyers and sellers

Join Stuart Mullins and Nicky Goringe Larkin as they delve into the key updates from the Chancellor’s announcement, with a focus on what matters most for businesses looking to buy and sell.

art
  • 03 December 2025
  • Corporate and M&A

Why is carrying out a legal Due Diligence investigation necessary during an proposed acquisition?

Merging with or acquiring another company is a high-stakes endeavour. The purpose, process and common areas of investigation during a M&A transaction.

art
  • 02 December 2025
  • Employment

All I Want for Christmas… Is No Tribunal Claims!

Before the festivities begin, it is worth unwrapping the key risks and understanding how employers can protect their staff, their reputation and their sanity, while still delivering a thoroughly enjoyable evening.