Tavistock & Portman NHS Foundation Trust – €91,000 Fine (United Kingdom, 2022)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
The Tavistock and Portman NHS Foundation Trust accidentally sent emails revealing patients' association with a gender identity clinic to hundreds of recipients. The UK data protection authority fined the trust EUR 91,000 for not having measures to prevent such errors. This case underscores the need for strong data protection practices, especially with sensitive information.
What happened
The Tavistock and Portman NHS Foundation Trust sent emails with an open distribution list, revealing patients' association with a gender identity clinic.
Who was affected
Patients of the adult gender identity clinic whose association with the clinic was disclosed in emails.
What the authority found
The UK authority ruled that the trust lacked adequate measures to prevent data breaches, violating GDPR's data protection and security requirements.
Why this matters
This case emphasizes the critical need for healthcare providers to implement robust data protection measures. It serves as a reminder that handling sensitive health information requires extra caution to prevent accidental disclosures.
GDPR Articles Cited
The UK DPA (ICO) has fined the Tavistock and Portman NHS Foundation Trust EUR 91,000. The Tavistock and Portman NHS Foundation Trust is a mental health specialist trust located in London. In early September 2019, the trust wanted to run a contest asking patients at the adult gender identity clinic to provide artwork to decorate a renovated clinic building. For this, two emails were inadvertently sent with an open distribution list (one to 912 recipients and the second to 869 recipients). It was clear from the content of the email that all recipients were patients of the clinic. The trust immediately recognized the error and unsuccessfully attempted to recall the emails. As part of its investigation, the IOC determined that the trust had no technical or organizational measures in place to prevent or mitigate this highly predictable human error. The ICO rated the harm to affected individuals as high given that information about the affected individuals' relationship with a gender identity clinic is very sensitive personal information. Due to immediate implementation of security measures and extensive cooperation with the ICO, the fine was reduced from EUR 910,000 to EUR 91,00.
Related Enforcement Actions (0)
No other enforcement actions found for Tavistock & Portman NHS Foundation Trust in UK
This is the only recorded action for this entity in this jurisdiction.
Details
Fine Date
9 June 2022
Authority
Information Commissioner's Office
Fine Amount
€91,000
Enforcement Tracker ID
ETid-1250
About this data
Cite as: Cookie Fines. Tavistock & Portman NHS Foundation Trust - United Kingdom (2022). Retrieved from cookiefines.eu
Last updated: