Back to Explorer
UK GDPRHealthcare

University Hospitals Bristol and Weston NHS Foundation Trust

Data Retention

Authority

ICO

Country

United Kingdom

Date Issued

March 6, 2023

Industry

Healthcare

Summary

The NHS Trust failed to properly manage the decommissioning of an Electronic Document Viewing System, resulting in incomplete data migration that left numerous patient records inaccessible and some permanently lost after the system licence expired. The Trust did not investigate the failed download before allowing the system to expire, violating data retention and disposal obligations under UK GDPR.

Violation Types

Data RetentionData DisposalSecurity

Articles Violated

Avoid enforcement risk with automated compliance

IQWorks helps organizations automate UK GDPR compliance before regulators come knocking.

Talk to an Expert