Back to Explorer
UK GDPRHealthcare

Royal Free London NHS Foundation Trust

Data Disposal

Authority

ICO

Country

United Kingdom

Date Issued

November 9, 2022

Industry

Healthcare

Summary

The NHS trust improperly stored sensitive hysteroscopy scan data on unmanaged USB sticks for nine years without adequate controls, resulting in inaccessibility and loss of encrypted backups. The ICO issued a reprimand for inadequate data retention procedures and security practices.

Violation Types

Data DisposalSecurityData Retention

Articles Violated

Avoid enforcement risk with automated compliance

IQWorks helps organizations automate UK GDPR compliance before regulators come knocking.

Talk to an Expert