The defendant worked for a charity which supports young people and their families. It was reported that the defendant had sent 11 emails from his work email account to his personal email account in February 2017. These emails contained spreadsheets outlining the full names, dates of birth, telephone numbers and medical information of 183 individuals, 3 of whom were children. The ICO also discovered that the defendant had sent himself similar sensitive information via email in 2016.

Sharing personal and sensitive information in this way is a clear breach of section 55 of the Data Protection Act 1998 which prohibits a person knowingly or recklessly obtaining or disclosing personal data without the consent of the data controller (the person who is responsible for the data e.g. the charity trustees if the charity is unincorporated).

The defendant was convicted on 8th November and received a conditional discharge, was ordered to pay £1,845.25 in prosecution costs and to pay a victim surcharge of £15.

Although it is thought the defendant sent the personal data only to himself and it is not believed that he subsequently shared the information with third parties, this is not considered relevant and the act of copying and sending the information in this way constituted a breach of data protection law. This prosecution emphasises the obligation for charity trustees and directors of companies to ensure that proper processes are in place to protect individual’s data and that staff are adequately trained in data protection.

Breaches of section 55 are not limited to the charity sector. In November, the ICO prosecuted an NHS Auxilliary Nurse in Wales for accessing a patient’s medical records without a legal reason. She was fined £232 and ordered to pay £150 in costs and a £30 victim surcharge.

Prosecutions for breaches of section 55 offences are increasing and the head of the ICO’s Criminal Investigations Team has stated the ICO would be in favour of custodial sentences for the most serious cases of data protection breaches. Since January 2017 there have been 15 prosecutions for section 55 offences, many a result of individuals collecting information of employees and clients to use in a new job.

Even though the penalties for breaches of section 55 of the Data Protection Act are imposed on the employee who acts without authorisation, this does not mean that there will not be any consequences for the employer. On 1 December 2017, the Queen’s Bench Division of the High Court handed down a judgment in the case of Various Claimants v. Wm Morrisons Supermarket PLC in which it held that Morrisons is liable to compensate individuals whose data was disclosed by an employee in breach of section 55 of the Data Protection Act, even though Morrisons was not at fault.

The increase in prosecutions, combined with the implementation of the GDPR in May 2018, emphasise the importance of ensuring that data handled by your organisation is protected and only processed with a valid legal reason.

Charity trustees should also be mindful of the Charity Commission’s reporting requirements which include breaches of data protection law.

Further information

For more information or to answer any questions you may have, please get in touch with Lauro Fava.

Is £400m enough?
Is £400m enough?

The government announced on 16 May that it will provide a fund of £400m to cover the costs of removal and replacement of cladding to high rise residential blocks which have failed tests.

The problems with co-owned properties and attorneys
The problems with co-owned properties and attorneys

Whilst some people are under the impression that preparing a Lasting Power of Attorney (LPA) is simply a case of completing a form and ticking a few boxes, it is about far more than this.

What's mine is (not) yours!
What's mine is (not) yours!

A big fear for some people facing divorce and the inevitable carving up of the matrimonial assets. They seek assurances that such assets will be “ring-fenced” and retained for them.

How to avoid the PET trap
How to avoid the PET trap

When an individual is thinking about making a gift to another individual, consideration needs to be given to the Potentially Exempt Transfer (PET) trap.

Fictitious divorces
Fictitious divorces

Arising from the recent Family Division announcement, people who think they are legally divorced may in fact still be married.