Staines Health Group – Complaint Upheld (United Kingdom, 2025)

Complaint Upheld
Information Commissioner's Office16 December 2025United Kingdom
final
Complaint Upheld

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Staines Health Group mistakenly sent 23 years of a patient's medical records to their insurer instead of the requested 5 years. The UK's data protection authority found this was a serious error and reprimanded the clinic for not properly securing personal data. This incident emphasizes the importance of handling patient information carefully.

What happened

A clinic disclosed 23 years of medical records to an insurer instead of the requested 5 years.

Who was affected

A patient who requested their medical history for the last 5 years.

What the authority found

The authority found that the clinic violated data protection rules by sharing excessive information and failing to ensure proper security measures.

Why this matters

This case serves as a reminder for healthcare providers to strictly adhere to data requests and maintain robust security protocols to protect patient information.

National Law Articles

AI-identified

Article 32 UK GDPR
Article 33 UK GDPR
Article 5(1)(c) UK GDPR
Article 5(1)(f) UK GDPR
Source verified 18 March 2026
verified correct
Full Legal Summary
Detailed

Staines Health Group (the controller) is a General Practitioner clinic. A patient (the data subject) requested their medical history from the last 5 years to be sent to their insurer by the controller. The controller allegedly disclosed 23 years of the data subject medical records to their insurer. The DPA found that the controller infringed Article 5(1)(c) UK GDPR, Article 5(1)(f) UK GDPR, Article 32 UK GDPR and Article 33 UK GDPR and issued a reprimand. Firstly, the DPA noted that the controller shared personal data that were not adequate, relevant and limited to what was necessary in breach of Article 5(1)(c) UK GDPR. Specifically, the DPA found that the controller transmitted the medical records of the past 23 years to the data subject’s insurer even though the request of the data subject referred only to the medical records of the last 5 years. Moreover, the DPA found that the controller did not ensure the appropriate security of the personal data processing by failing to ensure, among other things, the existence of written guidance for handling insurance requests, thus breaching Article 5(1)(f) UK GDPR and Article 32 UK GDPR. Finally, the controller did not contact the DPA within 72 hours of being aware of a data breach, in violation of Article 33 UK GDPR.

Outcome

Complaint Upheld

A data subject complaint that was upheld by the DPA.

Related Enforcement Actions (0)

No other enforcement actions found for Staines Health Group in UK

This is the only recorded action for this entity in this jurisdiction.

Details

Decision Date

16 December 2025

Authority

Information Commissioner's Office

GDPRhub ID

gdprhub-9789

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Staines Health Group - United Kingdom (2025). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: