Search

How can we help?

Icon

NHS Trust fined £180,000 over data protection breach

The Information Commissioner’s Office (ICO) have fined Chelsea and Westminster Hospital NHS Foundation Trust £180,000 after it revealed the email addresses of 781 users of an HIV service. Patients using the HIV service were sent a newsletter which mistakenly included all recipients email addresses in the ‘to’ field instead of the ‘bcc’ field.  730 of the email addresses displayed contained full names.  The ICO found that this amounted to a serious breach of the Data Protection Act 1998 and that it was likely to cause substantial distress as recipients of the e-mails could infer the HIV status of the other recipients.  In addition to the information being confidential sensitive personal data, the ICO was conscious that, due to the small geographical area the Trust serviced, the individuals may well have known each other.

The Trust had made a similar mistake in 2010 and, although some steps were taken then to prevent reoccurrence, the ICO found that no specific training had been implemented following that breach.

Monica Atwal

Managing Partner

View profile

+44 118 960 4605

Chambers and Partners

The Clarkslegal team are commercial and good to work with. They get what our business needs and tell me what I need to hear.

Employers should ensure that they have adequate training in place on data protection obligations and staff should be reminded of the care that needs to be taken when sending group emails, particularly, when this may reveal sensitive information about those involved such as their health.

About this article

Disclaimer

This information is for guidance purposes only and should not be regarded as a substitute for taking legal advice. Please refer to the full General Notices on our website.

Monica Atwal

Managing Partner

View profile

+44 118 960 4605

About this article

Read, listen and watch our latest insights

art
  • 08 May 2025
  • Employment

Statutory Sick Pay Scheme changes: how can employers prepare for such changes?

The government has recently changed the Statutory Sick Pay provisions; it is anticipated that such changes will ‘help people to stay in work and grow the economy’.

Pub
  • 07 May 2025
  • Corporate and M&A

Thinking of exiting your business? Part 1

In the first part of this three-part series, we explore why planning your exit strategy early can shape the way you build, grow, and eventually sell your business for maximum value. From mindset to strategy, we unpack how thinking about the end from the beginning can lead to smarter decisions and better outcomes.

Pub
  • 07 May 2025
  • Immigration

UK Immigration: Essential update for employers

The UK’s immigration system will see major changes in 2025. Watch our UK immigration specialists, Ruth Karimatsenga and Monica Mastropasqua, as they explore the key updates and how they affect your business.

art
  • 06 May 2025
  • Corporate and M&A

Can a disclosure letter give rise to a misrepresentation claim?

Provided by a seller to a buyer, a disclosure letter is an important element in any business sale or purchase transaction.

art
  • 02 May 2025
  • Employment

Sex, Gender and the Law: What the Supreme Court’s Recent Ruling Means for Employers

The recent UK Supreme Court decision in For Women Scotland Ltd v The Scottish Ministers  UKSC 16 has generated significant attention, but for most employers, we would argue that its practical impact is relatively limited—at least for now.

art
  • 29 April 2025
  • Privacy and Data Protection

Use of Personal Devices at Work: Why a Bring Your Own Device Policy is Essential

We will highlight in this article what changes have been made to the DUAB since the early stages of the Bill.