Tavistock & Portman NHS Foundation Trust – €91,000 Fine (United Kingdom, 2022)

€91,000Information Commissioner's Office9 June 2022United Kingdom
reduced
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

The Tavistock and Portman NHS Foundation Trust accidentally sent emails revealing patients' association with a gender identity clinic to hundreds of recipients. The UK data protection authority fined the trust EUR 91,000 for not having measures to prevent such errors. This case underscores the need for strong data protection practices, especially with sensitive information.

What happened

The Tavistock and Portman NHS Foundation Trust sent emails with an open distribution list, revealing patients' association with a gender identity clinic.

Who was affected

Patients of the adult gender identity clinic whose association with the clinic was disclosed in emails.

What the authority found

The UK authority ruled that the trust lacked adequate measures to prevent data breaches, violating GDPR's data protection and security requirements.

Why this matters

This case emphasizes the critical need for healthcare providers to implement robust data protection measures. It serves as a reminder that handling sensitive health information requires extra caution to prevent accidental disclosures.

GDPR Articles Cited

Art. 32 GDPR
Art. 5(1)(f) GDPR
Full Legal Summary
Detailed

The UK DPA (ICO) has fined the Tavistock and Portman NHS Foundation Trust EUR 91,000. The Tavistock and Portman NHS Foundation Trust is a mental health specialist trust located in London. In early September 2019, the trust wanted to run a contest asking patients at the adult gender identity clinic to provide artwork to decorate a renovated clinic building. For this, two emails were inadvertently sent with an open distribution list (one to 912 recipients and the second to 869 recipients). It was clear from the content of the email that all recipients were patients of the clinic. The trust immediately recognized the error and unsuccessfully attempted to recall the emails. As part of its investigation, the IOC determined that the trust had no technical or organizational measures in place to prevent or mitigate this highly predictable human error. The ICO rated the harm to affected individuals as high given that information about the affected individuals' relationship with a gender identity clinic is very sensitive personal information. Due to immediate implementation of security measures and extensive cooperation with the ICO, the fine was reduced from EUR 910,000 to EUR 91,00.

Related Enforcement Actions (0)

No other enforcement actions found for Tavistock & Portman NHS Foundation Trust in UK

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

9 June 2022

Authority

Information Commissioner's Office

Fine Amount

€91,000

Enforcement Tracker ID

ETid-1250

About this data

Data: CMS GDPR Enforcement Tracker
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Tavistock & Portman NHS Foundation Trust - United Kingdom (2022). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: