Search

How can we help?

Icon

NHS Trust fined £180,000 over data protection breach

The Information Commissioner’s Office (ICO) have fined Chelsea and Westminster Hospital NHS Foundation Trust £180,000 after it revealed the email addresses of 781 users of an HIV service. Patients using the HIV service were sent a newsletter which mistakenly included all recipients email addresses in the ‘to’ field instead of the ‘bcc’ field.  730 of the email addresses displayed contained full names.  The ICO found that this amounted to a serious breach of the Data Protection Act 1998 and that it was likely to cause substantial distress as recipients of the e-mails could infer the HIV status of the other recipients.  In addition to the information being confidential sensitive personal data, the ICO was conscious that, due to the small geographical area the Trust serviced, the individuals may well have known each other.

The Trust had made a similar mistake in 2010 and, although some steps were taken then to prevent reoccurrence, the ICO found that no specific training had been implemented following that breach.

Chambers and Partners

The Clarkslegal team are commercial and good to work with. They get what our business needs and tell me what I need to hear.

Employers should ensure that they have adequate training in place on data protection obligations and staff should be reminded of the care that needs to be taken when sending group emails, particularly, when this may reveal sensitive information about those involved such as their health.

Disclaimer

This information is for guidance purposes only and should not be regarded as a substitute for taking legal advice. Please refer to the full General Notices on our website.

Author profile

Monica Atwal

Managing Partner

View profile

+44 118 960 4605

About this article

Read, listen and watch our latest insights

art
  • 29 April 2026
  • Privacy and Data Protection

UK Data Protection – what’s new?

Having come into force on 19 June 2025, it comes as no surprise that we are now seeing the effects of the Data (Use and Access) Act 2025 (‘DUAA’). This article highlights a few of DUAA’s fundamental reforms, delves into one in particular, and examines how this will impact the recruitment sphere.

art
  • 29 April 2026
  • Employment

Employment Rights Act: Changing key contract terms will be harder from January 2027

The Employment Rights Act 2025 (“ERA 2025”) introduces a new regime that restricts how employers can change certain core contractual terms, with the key provisions now expected to commence on 1 January 2027.

art
  • 28 April 2026
  • Immigration

Proposed expansion of right to work checks from 1 October 2026: what employers need to know

The Home Office has published a consultation on a draft Code of Practice addressing how employers can avoid unlawful discrimination while preventing illegal working. The draft indicates a planned expansion of right to work (RTW) check obligations to take effect from 1 October 2026.

Pub
  • 27 April 2026
  • Corporate and M&A

Quarterly Insights: Key Corporate & Commercial Topics – Q2 2026

Join Stuart Mullins and Emma Docking as they explore key corporate and commercial topics, including SME growth and exit strategies for 2026, EMI schemes for employee incentives, and the importance of drag along and tag along rights.

art
  • 22 April 2026
  • Commercial Real Estate

Historic rent reviews: A warning for tenants

We have been asked whether a landlord is able to operate historic rent reviews. 

art
  • 14 April 2026
  • Employment

Updates to Vento Bands 2026: Injury to feelings awards

For discrimination and detriment cases, compensation can also cover non-financial losses, which, in most cases, will include an injury to feelings award.