Authority
ICO
Country
United Kingdom
Date Issued
July 18, 2023
Industry
Healthcare
Summary
The Patient and Client Council received a reprimand from the ICO for failing to implement adequate security measures under UK GDPR Articles 5(1)(f) and 32(1). The organization disclosed special category data to 15 individuals by sending an email using carbon copy instead of blind carbon copy, exposing recipients' email addresses.
Violation Types
SecurityData BreachData Processing
Articles Violated
Related Enforcement Actions
Avoid enforcement risk with automated compliance
IQWorks helps organizations automate UK GDPR compliance before regulators come knocking.
Talk to an Expert