Staines Health Group – Complaint Upheld (United Kingdom, 2025)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
Staines Health Group mistakenly sent 23 years of a patient's medical records to their insurer instead of the requested 5 years. The UK's data protection authority found this was a serious error and reprimanded the clinic for not properly securing personal data. This incident emphasizes the importance of handling patient information carefully.
What happened
A clinic disclosed 23 years of medical records to an insurer instead of the requested 5 years.
Who was affected
A patient who requested their medical history for the last 5 years.
What the authority found
The authority found that the clinic violated data protection rules by sharing excessive information and failing to ensure proper security measures.
Why this matters
This case serves as a reminder for healthcare providers to strictly adhere to data requests and maintain robust security protocols to protect patient information.
National Law Articles
Staines Health Group (the controller) is a General Practitioner clinic. A patient (the data subject) requested their medical history from the last 5 years to be sent to their insurer by the controller. The controller allegedly disclosed 23 years of the data subject medical records to their insurer. The DPA found that the controller infringed Article 5(1)(c) UK GDPR, Article 5(1)(f) UK GDPR, Article 32 UK GDPR and Article 33 UK GDPR and issued a reprimand. Firstly, the DPA noted that the controller shared personal data that were not adequate, relevant and limited to what was necessary in breach of Article 5(1)(c) UK GDPR. Specifically, the DPA found that the controller transmitted the medical records of the past 23 years to the data subject’s insurer even though the request of the data subject referred only to the medical records of the last 5 years. Moreover, the DPA found that the controller did not ensure the appropriate security of the personal data processing by failing to ensure, among other things, the existence of written guidance for handling insurance requests, thus breaching Article 5(1)(f) UK GDPR and Article 32 UK GDPR. Finally, the controller did not contact the DPA within 72 hours of being aware of a data breach, in violation of Article 33 UK GDPR.
Outcome
Complaint Upheld
A data subject complaint that was upheld by the DPA.
Related Enforcement Actions (0)
No other enforcement actions found for Staines Health Group in UK
This is the only recorded action for this entity in this jurisdiction.
Details
About this data
Cite as: Cookie Fines. Staines Health Group - United Kingdom (2025). Retrieved from cookiefines.eu
Last updated: