All the latest UK technology news, reviews and analysis

NHS Trust loses £90,000 ICO tribunal ruling

17 Jan 2013

An NHS Trust has lost an appeal to have a £90,000 fine issued by the Information Commissioner Office (ICO) overturned.

The Central London Community Healthcare NHS Trust was hit with the fine in May 2012 after its Pembridge Palliative Care Unit faxed data on a number of its patients to the wrong recipient.

However, at the time the Trust announced it would challenge the penalty, citing numerous concerns, including the fact it self-reported the breach.

"We consider that the commissioner has acted incorrectly as a matter of law and so we have no alternative but to bring an appeal," it said in a statement at the time.

However, the Tribunal ruling this week upheld the ICO's initial fine and dismissed the action by the Trust, reinstating the £90,000 fine.

This also means the Trust loses the right to reduce the fine by 20 percent by paying it early.

A Freedom of Information request from V3 to the Trust showed it £24,000 for legal advice on the case.

The ICO welcomed the decision by the Tribunal judge John Angel, with deputy commissioner David Smith claiming it was an important reminder of the ICO's authority.

"The ruling removes any doubt that we cannot take action when an organisation self-reports a serious data breach", he said.

"While we do look favourably on organisations that contact us after a serious breach, and take this into account when setting the amount of any penalty, self-reporting a breach to the ICO cannot be seen ‘as a get out of jail free' card."

The Tribunal also said the ICO is within its right to refuse to accept early payment, and allow a challenge to a fine, arguing the purpose of the early payment system is to end the matter quickly.

"The failure of the ICO to accept the without prejudice offer outside the basis of the MPN [monetary penalty notice] guidance does not seem to us to amount to an error of law and/or wrong exercise of discretion," the judge wrote.

The Trust is the second organisation to lose an appeal against the ICO after Brighton NHS Trust was also forced to pay £325,000 for an incident in 2012.

  • Comment  
  • Tweet  
  • Google plus  
  • Facebook  
  • LinkedIn  
  • Stumble Upon  
Dan Worth

Dan Worth is the news editor for V3 having first joined the site as a reporter in November 2009. He specialises in a raft of areas including fixed and mobile telecoms, data protection, social media and government IT. Before joining V3 Dan covered communications technology, data handling and resilience in the emergency services sector on the BAPCO Journal

View Dan's Google+ profile

More on Law
What do you think?
blog comments powered by Disqus

BYOD vs CYOD vs BYOC poll

Which approach is your firm taking to managing employees' mobile devices?

Popular Threads

Powered by Disqus
Sony Xperia Z2 Tablet powered by Android KitKat 4.4

Sony Xperia Z2 Tablet video

We take a look at the lightweight, waterproof tablet

Updating your subscription status Loading

Get the latest news (daily or weekly) direct to your inbox with V3 newsletters.

newsletter sign-up button

Data protection: the key challenges

Deduplication is a foundational technology for efficient backup and recovery


iPad makes its mark in the enterprise

The iPad can become a supercharged unified communications endpoint, allowing users to enhance their productivity

Senior IS Compliance Analyst (Risk Assessments) - Growing area

Senior IS Compliance Analyst / Risk Analyst (Risk Assessments...

Web Designer / UI Front End Developer - Opp in new department!

Web Designer / UI Front End Developer (HTML(5), CSS...

Senior Product Manager x2 (Online & Web Platform) - Global Org

Senior Product Manager x2 (Online, Software & Web...

Senior Web Developer / OO Software Engineer (Learn Ruby!)

Senior Web Developer / Software Engineer (Opportunity...
To send to more than one email address, simply separate each address with a comma.