HIV Scotland – €11,700 Fine (United Kingdom, 2021)

€11,700Information Commissioner's Office18 October 2021United Kingdom
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

HIV Scotland mistakenly exposed the email addresses of 65 individuals by using the wrong email settings. This error could reveal sensitive information about their HIV status. The case shows that organizations must handle personal data carefully to avoid breaches.

What happened

HIV Scotland sent an email that revealed the addresses of 65 recipients instead of keeping them private.

Who was affected

Members of the Community Advisory Network (CAN) who were included in the email.

What the authority found

The Information Commissioner's Office found that HIV Scotland did not have sufficient security measures in place, violating Articles 5(1)(f) and 32(1) of GDPR.

Why this matters

This incident highlights the critical need for proper training and policies regarding personal data handling. Organizations must ensure staff are equipped to protect sensitive information.

GDPR Articles Cited

AI-verified

Art. 5(1)(f) GDPR
Art. 32(1) GDPR
Art. 32(2) GDPR
View original scraped data
Art. 5(1)(f) GDPR
Art. 32(1) GDPR
Art. 32(2) GDPR

Original data from scraper before AI verification against source document.

National Law Articles

AI-identified

Section 155 DPA 2018
Source verified 31 March 2026
national law identified
Full Legal Summary
Detailed

HIV Scotland is a charity that helps people living with HIV, those at risk of HIV and individuals that support people with HIV. HIV Scotland got a MailChimp account for the purpose of online mailing and migrated contact details to the bulk mailing platform. A list of contact details of the Community Advisory Network (CAN) was not migrated. On 3 Feburary 2020, an email was sent using Microsoft Outlook to 105 members of CAN in CC rather than BCC. This meant that email addresses of 65 recipients were apparent, identifying the individual by name. HIV Scotland noticed the error instantly and submitted a breach report, highlighting that individuals' HIV statuses could be deduced from this breach. HIV Scotland contacted the individuals to apologise and offered support if distress was caused. HIV Scotland has since implemented MailChimp for all its mailing operations to reduce the risk of a repeat incident. The Information Commissioner's Office (ICO) conclude that HIV Scotland failed to set up appropriate organisational and technical measures. The following steps taken by HIV Scotland prior to the breach were insufficient according to the ICO: * Employees asked to read and refer to HIV Scotland's privacy policy * Training on GDPR awareness in the first three months of employment * Awareness of the BCC requirement for group emails * Attempt to migrate contact details to MailChimp for better security. The ICO found following deficiencies in the technical and organisational measures at HIV Scotland. * HIV Scotland did not have a specific internal Policy for handling personal data securely. Reliance on the external Privacy Policy was not an appropriate data protection policy for staff handling personal data. * The staff did not have guidance on how to handle personal data securely. According to the ICO, employees should have had GDPR training prior to handling personal data and within one month of their start data. This is especially required when staff handle special cat

Related Enforcement Actions (0)

No other enforcement actions found for HIV Scotland in UK

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

18 October 2021

Authority

Information Commissioner's Office

Fine Amount

€11,700

10,000 GBP

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. HIV Scotland - United Kingdom (2021). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: