Notice
Committee for Health & Social Care Reprimanded (2025-05-08)
Issued 2025-05-08View on ODPA's website Source document
Summary
This is a public statement from the Guernsey Office of the Data Protection Authority (ODPA) announcing that it has issued a reprimand against the Committee for Health & Social Care (HSC) for breaches of the Data Protection (Bailiwick of Guernsey) Law, 2017. The breaches arose from HSC mistakenly emailing an individual's personal data (including special category medical information) to the wrong recipient, failing to use available technical tools to revoke access, and failing to notify the Authority of the breach.
- Security failure: HSC breached section 6 (integrity and confidentiality) and section 41 (duty to take reasonable steps to ensure security) by failing to train staff on how to revoke email access using its Egress secure-email tool after a misdirected email containing personal data.
- Notification failure: HSC breached section 42 (notification and records required in case of a personal data breach) by wrongly concluding that the breach did not meet the threshold for notifying the Authority, despite the data being special category (medical) information.
- Sanction: The Authority imposed a reprimand on HSC; no fine is mentioned.
- Learning points: The Authority reiterated that controllers must train employees on technical security tools, must assess each breach on its own facts, and cannot rely solely on a recipient's assurance of deletion as sufficient mitigation to avoid notifying the Authority.
The statement functions as an enforcement notice and guidance for other controllers in the Bailiwick of Guernsey on breach containment and notification obligations under the Data Protection Law.
Key obligations
- Controllers must take reasonable steps to ensure the security of personal data, including training employees on technical security tools they use (e.g. secure email platforms) and implementing clear policies and protocols.
- Controllers must notify the Authority of personal data breaches unless the breach is unlikely to result in any risk to the significant interests of affected individuals, assessed on a case-by-case basis.
- Controllers should not treat an incorrect recipient's assurance that data will be deleted as, by itself, sufficient to conclude a breach poses no risk and thereby avoid notification to the Authority.
- Where technical means exist to revoke access to wrongly sent data (e.g. audit and revocation tools), controllers must use them promptly to contain a breach rather than relying solely on recipient assurances.
Applies to
data controllers, public authorities (Committee for Health & Social Care)