Human resources at a click

NHS Trust fined £180,000 over data protection breach

data-html-coding-on-computer-screen

The Information Commissioner’s Office (ICO) have fined Chelsea and Westminster Hospital NHS Foundation Trust £180,000 after it revealed the email addresses of 781 users of an HIV service. Patients using the HIV service were sent a newsletter which mistakenly included all recipients email addresses in the ‘to’ field instead of the ‘bcc’ field.  730 of the email addresses displayed contained full names.  The ICO found that this amounted to a serious breach of the Data Protection Act 1998 and that it was likely to cause substantial distress as recipients of the e-mails could infer the HIV status of the other recipients.  In addition to the information being confidential sensitive personal data, the ICO was conscious that, due to the small geographical area the Trust serviced, the individuals may well have known each other.

The Trust had made a similar mistake in 2010 and, although some steps were taken then to prevent reoccurrence, the ICO found that no specific training had been implemented following that breach.

Chambers and Partners

The Clarkslegal team are commercial and good to work with. They get what our business needs and tell me what I need to hear.

Employers should ensure that they have adequate training in place on data protection obligations and staff should be reminded of the care that needs to be taken when sending group emails, particularly, when this may reveal sensitive information about those involved such as their health.

Clarkslegal’s data protection lawyers are here to help. For further information or if you have any questions, please do not hesitate to get in touch with our data protection lawyers.

Disclaimer This information is for guidance purposes only and should not be regarded as a substitute for taking professional and legal advice. Please refer to the full General Notices on our website.
Monica Atwal
Monica Atwal
Managing Partner

Related Articles

The Data (Use and Access) Act 2025 (DUAA) marks the most significant refinement of the UK’s data protection framework since...

Businesses and self-employed professionals are in a constant pursuit of efficiency and productivity. There are, as a result, no end...

Since the UK GDPR came into force in 2018, which was an overhaul in data protection, many employers and organisations...

Related Resources

Data breaches factsheet

Facts and examples of personal data breaches and information required to report a data breach. Personal Data Breach What is...

Confidentiality statement

Confidentiality statement in regards to the monitoring policy. Confidentiality Statement – Monitoring Policy  I agree, save if required by law...

Monitoring policy

This monitoring policy provides a brief overview of how a company should approach monitoring in the workplace. Employees and other...

Human resources at a click