Search

How can we help?

Icon

NHS Trust fined £180,000 over data protection breach

The Information Commissioner’s Office (ICO) have fined Chelsea and Westminster Hospital NHS Foundation Trust £180,000 after it revealed the email addresses of 781 users of an HIV service. Patients using the HIV service were sent a newsletter which mistakenly included all recipients email addresses in the ‘to’ field instead of the ‘bcc’ field.  730 of the email addresses displayed contained full names.  The ICO found that this amounted to a serious breach of the Data Protection Act 1998 and that it was likely to cause substantial distress as recipients of the e-mails could infer the HIV status of the other recipients.  In addition to the information being confidential sensitive personal data, the ICO was conscious that, due to the small geographical area the Trust serviced, the individuals may well have known each other.

The Trust had made a similar mistake in 2010 and, although some steps were taken then to prevent reoccurrence, the ICO found that no specific training had been implemented following that breach.

Monica Atwal

Managing Partner

View profile

+44 118 960 4605

Chambers and Partners

The Clarkslegal team are commercial and good to work with. They get what our business needs and tell me what I need to hear.

Employers should ensure that they have adequate training in place on data protection obligations and staff should be reminded of the care that needs to be taken when sending group emails, particularly, when this may reveal sensitive information about those involved such as their health.

About this article

Disclaimer

This information is for guidance purposes only and should not be regarded as a substitute for taking legal advice. Please refer to the full General Notices on our website.

Monica Atwal

Managing Partner

View profile

+44 118 960 4605

About this article

Read, listen and watch our latest insights

art
  • 31 October 2024
  • Employment

Potential impact of the Employment Rights Bill – Amanda Glover and Jesse Akiwumi write for Employee Benefits

Amanda Glover and Jesse Akiwumi write for Employee Benefits about the Employment Rights Bill, which addresses exploitative zero-hour contracts and allows workers to opt for guaranteed hours.

art
  • 29 October 2024
  • Privacy and Data Protection

The ICO’s 2024-2025 priorities for protecting children’s personal information online

The Information Commissioner Officer (the “ICO”) has set out its 2024-2025 priorities for protecting children’s personal information online.

Pub
  • 25 October 2024
  • Employment

TUPE Podcast Series: Changing Terms and Conditions

In this seventh episode of our TUPE Podcast Series, Louise Keenan will discuss the restrictions on changing terms and conditions for employees who are transferring. 

art
  • 25 October 2024
  • Employment

Changing Attitudes to Menopause

We have set out some answers to the frequently asked questions that employers ask when considering how to support a menopausal employee.

art
  • 25 October 2024
  • Employment

Court rules that ignoring employee’s greeting contributed to a breach of trust and confidence

In a recent ruling, an Employment Tribunal held that an employer had contributed to the breakdown of the trust and confidence with their employee by failing to respond to the employee’s greeting.

art
  • 21 October 2024
  • Commercial Real Estate

Commercial Property Standard Enquiries (CPSE): why is it important to get them right?

Commercial Property Standard Enquiries (CPSE) have been a part of a commercial property transaction for over two decades now. Nonetheless, it would be safe to say they can be tricky to deal with.