A new National Framework for Continuing Health Care (CHC) and other NHS funding for health and social care services came into effect on 1 October 2018.
The defendant worked for a charity which supports young people and their families. It was reported that the defendant had sent 11 emails from his work email account to his personal email account in February 2017. These emails contained spreadsheets outlining the full names, dates of birth, telephone numbers and medical information of 183 individuals, 3 of whom were children. The ICO also discovered that the defendant had sent himself similar sensitive information via email in 2016.
Sharing personal and sensitive information in this way is a clear breach of section 55 of the Data Protection Act 1998 which prohibits a person knowingly or recklessly obtaining or disclosing personal data without the consent of the data controller (the person who is responsible for the data e.g. the charity trustees if the charity is unincorporated).
The defendant was convicted on 8th November and received a conditional discharge, was ordered to pay £1,845.25 in prosecution costs and to pay a victim surcharge of £15.
Although it is thought the defendant sent the personal data only to himself and it is not believed that he subsequently shared the information with third parties, this is not considered relevant and the act of copying and sending the information in this way constituted a breach of data protection law. This prosecution emphasises the obligation for charity trustees and directors of companies to ensure that proper processes are in place to protect individual’s data and that staff are adequately trained in data protection.
Breaches of section 55 are not limited to the charity sector. In November, the ICO prosecuted an NHS Auxilliary Nurse in Wales for accessing a patient’s medical records without a legal reason. She was fined £232 and ordered to pay £150 in costs and a £30 victim surcharge.
Prosecutions for breaches of section 55 offences are increasing and the head of the ICO’s Criminal Investigations Team has stated the ICO would be in favour of custodial sentences for the most serious cases of data protection breaches. Since January 2017 there have been 15 prosecutions for section 55 offences, many a result of individuals collecting information of employees and clients to use in a new job.
Even though the penalties for breaches of section 55 of the Data Protection Act are imposed on the employee who acts without authorisation, this does not mean that there will not be any consequences for the employer. On 1 December 2017, the Queen’s Bench Division of the High Court handed down a judgment in the case of Various Claimants v. Wm Morrisons Supermarket PLC in which it held that Morrisons is liable to compensate individuals whose data was disclosed by an employee in breach of section 55 of the Data Protection Act, even though Morrisons was not at fault.
The increase in prosecutions, combined with the implementation of the GDPR in May 2018, emphasise the importance of ensuring that data handled by your organisation is protected and only processed with a valid legal reason.
Charity trustees should also be mindful of the Charity Commission’s reporting requirements which include breaches of data protection law.
For more information or to answer any questions you may have, please get in touch with Lauro Fava.
A recent review has brought into question the position regarding donations made by for-profit subsidiary companies to their parent charities.
Government has confirmed it will take forward the ban on use of combustible materials on external walls of high-rise residential buildings, hospitals, care homes and student accommodation above 18m.
The Pensions Ombudsman has introduced fixed awards for distress and inconvenience (or “non-financial injustice”) caused by maladministration in the management of pension schemes.
Dominic Curran becomes head of charities at Anthony Collins Solicitors.
Partner and Head of the Personal Injury and Clinical Negligence Department, Rankeshwar Batta, has been listed in the Legal 500 “Hall of Fame” for both his personal injury and clinical negligence work.
The Employment Appeal Tribunal (EAT) has found that where a TUPE transfer has taken place, subsequent changes to employees’ terms and conditions may not be invalid...
Sadly, neonatal deaths and injuries in the UK remain at a high level. The inquiry underway at Shrewsbury and Telford NHS Trust only serves to highlight that sometimes errors are made.
The Health and Social Care team are delighted to have been nominated as finalists for the LaingBuisson Independent Legal Advisor award.
The Government has now published its “no deal notice” for public procurement.
To receive invitations to our events, as well as information and articles on legal issues and sector developments that are of interest to you, please sign up to Newsroom.