Authority
ICO
Country
United Kingdom
Date Issued
November 9, 2022
Industry
Healthcare
Summary
The NHS trust improperly stored sensitive hysteroscopy scan data on unmanaged USB sticks for nine years without adequate controls, resulting in inaccessibility and loss of encrypted backups. The ICO issued a reprimand for inadequate data retention procedures and security practices.
Violation Types
Data DisposalSecurityData Retention
Articles Violated
Related Enforcement Actions
Avoid enforcement risk with automated compliance
IQWorks helps organizations automate UK GDPR compliance before regulators come knocking.
Talk to an Expert