George Green Solicitors Banner Image


Data protection: appeal against monetary penalty notice dismissed

In the first case involving the appeal of a monetary penalty notice (MPN) to be heard at the Upper Tribunal (Administrative Appeals Chamber), the Central London Community Healthcare NHS Trust lost its appeal against an MPN issued for £90,000 by the Information Commissioner (IC) following a data breach. The Trust had mistakenly faxed patients' sensitive medical details to a member of the public on numerous occasions and self-reported the breach to the IC. The Tribunal held that the IC was not prevented from serving an MPN where a breach was self-reported, regardless of whether a data controller subsequently co-operated.

Although the decision illustrates that self-reporting does not provide immunity from MPNs, organisations should not be deterred from self-reporting, as the IC has previously taken it to be a mitigating factor when considering the level of MPNs.