The defendant worked for a charity which supports young people and their families. It was reported that the defendant had sent 11 emails from his work email account to his personal email account in February 2017. These emails contained spreadsheets outlining the full names, dates of birth, telephone numbers and medical information of 183 individuals, 3 of whom were children. The ICO also discovered that the defendant had sent himself similar sensitive information via email in 2016.
Sharing personal and sensitive information in this way is a clear breach of section 55 of the Data Protection Act 1998 which prohibits a person knowingly or recklessly obtaining or disclosing personal data without the consent of the data controller (the person who is responsible for the data e.g. the charity trustees if the charity is unincorporated).
The defendant was convicted on 8th November and received a conditional discharge, was ordered to pay £1,845.25 in prosecution costs and to pay a victim surcharge of £15.
Although it is thought the defendant sent the personal data only to himself and it is not believed that he subsequently shared the information with third parties, this is not considered relevant and the act of copying and sending the information in this way constituted a breach of data protection law. This prosecution emphasises the obligation for charity trustees and directors of companies to ensure that proper processes are in place to protect individual’s data and that staff are adequately trained in data protection.
Breaches of section 55 are not limited to the charity sector. In November, the ICO prosecuted an NHS Auxilliary Nurse in Wales for accessing a patient’s medical records without a legal reason. She was fined £232 and ordered to pay £150 in costs and a £30 victim surcharge.
Prosecutions for breaches of section 55 offences are increasing and the head of the ICO’s Criminal Investigations Team has stated the ICO would be in favour of custodial sentences for the most serious cases of data protection breaches. Since January 2017 there have been 15 prosecutions for section 55 offences, many a result of individuals collecting information of employees and clients to use in a new job.
Even though the penalties for breaches of section 55 of the Data Protection Act are imposed on the employee who acts without authorisation, this does not mean that there will not be any consequences for the employer. On 1 December 2017, the Queen’s Bench Division of the High Court handed down a judgment in the case of Various Claimants v. Wm Morrisons Supermarket PLC in which it held that Morrisons is liable to compensate individuals whose data was disclosed by an employee in breach of section 55 of the Data Protection Act, even though Morrisons was not at fault.
The increase in prosecutions, combined with the implementation of the GDPR in May 2018, emphasise the importance of ensuring that data handled by your organisation is protected and only processed with a valid legal reason.
Charity trustees should also be mindful of the Charity Commission’s reporting requirements which include breaches of data protection law.
For more information or to answer any questions you may have, please get in touch with Lauro Fava.