Data Protection Update: ICO Issues Record Monetary Penalty
This was posted on Friday, June 15th, 2012 at 11:06 am.
The Information Commissioner’s Office (ICO) has issued Brighton and Sussex University Hospitals NHS Trust with a monetary penalty of £325,000 following a serious breach of the Data Protection Act 1998.
This is the largest monetary penalty issued by the ICO since it was first granted the power to hand out penalties of up to £500,000 in April 2010. It is also some £185,000 more than the previous highest penalty of £140,000, issued against Midlothian Council in January 2012.
The breach involved the disclosure of highly sensitive personal data belonging to tens of thousands of patients and staff (including the results of medical tests) contained on hard drives which the Trust failed to ensure were adequately destroyed. The destruction of approximately 1,000 hard drives was subcontracted to an individual engaged by the Trust’s IT service provider. However, rather than destroying the hard drives, the subcontractor removed at least 252 of them from the Trust’s premises and sold them on an internet auction site.
The Trust is to appeal the decision on the basis that all of the hard drives were subsequently recovered and that they can ill afford the fine.
Comment
The ICO is certainly adhering to the promise it made in January 2012 to give “particular regulatory attention” to health organisations as part of its enforcement strategy – indeed, the Trust is the third health organisation to receive a monetary penalty in just over a month.
This case stands as a cautionary reminder to all organisations – and particularly those that process sensitive medical data – to review their data security practices now (including their processes for vetting, and their contracts with, potential IT contractors) as the information watchdog’s bite is rapidly becoming as severe as its bark.
For more information or advice on the contents of this update, please contact Jessica Brickley or Anna Jones.
Sort news by practice area
News Archives
Links
Latest News & Events
- Forget Corporate Manslaughter – It Is Individual Liability That Matters
6th March 2013 - By Hill Hofstetter
Darren Smith Speaking At The Recent IOSH 2013 seminar It could be you in the dock, consultants and Read more...
- High Court ruling casts new uncertainty over Competition Appeal Tribunal jurisdiction
21st February 2013 - By Hill Hofstetter
In December 2012 the High Court handed down a decision that appears to widen the scope of the jurisdiction of Read more...
- Jonathan Hofstetter short-listed for honours at the 2013 Birmingham Law Society Legal Awards
15th February 2013 - By Hill Hofstetter
Congratulations to Jonathan Hofstetter who is one of five nominees for 'International Lawyer of the Year' at the 2013 Birmingham Read more...
- Employment News: “Off The Record”?
15th February 2013 - By Hill Hofstetter
Technological advances are having a myriad of unexpected consequences in Employer/ Employee relations. What was once seen as a “private” Read more...
- Employment News: Developments in 2013 and Beyond
16th January 2013 - By Hill Hofstetter
The Government has announced its intended timetable to introduce new employment legislation in 2013. In addition, there are many other Read more...


