HOW BREACHING GDPR IS ALL TOO EASY

HOW BREACHING GDPR IS ALL TOO EASY

Touted as the most significant change in data privacy in twenty years, GDPR is a statute in EU law on privacy and data protection for citizens of the EU and the European Economic Area. It also discusses the transfer of personal data outside the EU and EEA areas.

Information stored by the NHS and then used by a second or third party for medical research must go through a stringent system and set of procedures, in line with GDPR, to become ‘anonymised’ data. However, it has become increasingly apparent that breaching these laws is all too easy.

An example of just how easy it is to breach GDPR was that of a Fordingbridge man in 2016, who discovered by chance that his medical records were accessed and shared by the NHS and local council without his knowledge or consent.

In an investigation into the man’s mental health condition, by the Council, a member of NHS staff handed over medical records. The man had contacted the board of Councillors following a case of intimidation and threatening behaviour by a neighbour. He had requested a more secure door for his home to add security and peace of mind following the threats.

According to the man, the Council were not forthcoming, and after making a ‘Right of Access’ information request, he discovered the breach, which included personal notes and unsubstantiated opinions on him, which were both inappropriate and unlawful.

Not only should this information have not been kept on file as the individual was not aware nor was it a legal requirement, but the content could influence other readers opinions of the individual, which is not acceptable.

It is important to note that you ARE able to make negative notes on someone, but they must be factual. The following examples show how to correctly record notes, providing they are GDPR compliant…

‘Mr Jones was on the phone for 1 hour and swore constantly’, is OK.

‘Mr Jones needs to attend anger management classes’, is not!

‘Debbie is lazy’, is not acceptable.

‘Debbie consistently takes twice as long as colleagues to perform tasks’, is lawful.

A Southern Health NHS Foundation Trust spokesperson stated that the NHS takes the confidentiality of patients very seriously and works hard to ensure people’s data is processed according to their wishes. They went on to apologise for falling short of these standards. Information on sharing policies and staff guidance to define information sharing requests from third parties has been since updated and reiterated.

If you have any worries about potential gaps in your GDPR compliance, get in touch with our specialists on 01673 885533 and we’ll be happy to help. 

Paul Adams LLB (Hons)

Information Governance, Data Protection & GDPR Consultant, Trainer. External DPO and NED.

4 年

Thanks for sharing Mike

要查看或添加评论,请登录

Mike Martin LLM Information Rights Law的更多文章

  • SMS/MMS Direct Marketing

    SMS/MMS Direct Marketing

    The Court of Rome overthrow Garante’s previous decision on SMS/MMS direct marketing The Tribunal of Rome has recently…

  • The rise of cybercriminals

    The rise of cybercriminals

    Recently, Amazon’s Alexa turned a new corner in AI technology, and rolled out a brand-new email-reading feature to its…

  • COOKIES & PIXEL BEACONS - are you using them lawfully?

    COOKIES & PIXEL BEACONS - are you using them lawfully?

    Cookie walls have been showing up a lot recently. They’re the pop-ups demanding you agree to relinquish your privacy…

    1 条评论
  • COOKIES & PIXEL BEACONS

    COOKIES & PIXEL BEACONS

    Cookies and Pixel Beacons – are you using them lawfully? Cookie walls have been showing up a lot recently. They’re the…

  • Cookies and Pixel Beacons – are you using them lawfully?

    Cookies and Pixel Beacons – are you using them lawfully?

    Cookie walls have been showing up a lot recently. They’re the pop-ups demanding you agree to relinquish your privacy…

    1 条评论
  • First GDPR fine issued for illegal facial recognition activity

    First GDPR fine issued for illegal facial recognition activity

    With the uprise of smart technology, such as facial recognition software, more companies need to be aware of any…

  • POLITICAL CAMPAIGNS & MICRO-TARGETING

    POLITICAL CAMPAIGNS & MICRO-TARGETING

    Whenever it gets closer to election time, you may notice that the amount of political mail and advertising you receive…

  • RANSOMWARE ATTACKS COULD HOLD YOUR DATA HOSTAGE ANY TIME

    RANSOMWARE ATTACKS COULD HOLD YOUR DATA HOSTAGE ANY TIME

    Imagine reading this message: “Your files have been encrypted with the strongest military algorithms… without our…

    2 条评论
  • IS IT AN ISSUE IF ALEXA GIVES MY DATA TO BIG BUSINESSES?

    IS IT AN ISSUE IF ALEXA GIVES MY DATA TO BIG BUSINESSES?

    Amazon’s Alexa is passing back gigabytes of users’ data to big businesses and, for the first time in a long time, users…

    3 条评论
  • BREXIT - Practical steps

    BREXIT - Practical steps

    I am sorry to start by swearing, but I have to use the ‘B’ word – yes, the BIG issue at hand is Brexit, and this can…

    1 条评论

社区洞察

其他会员也浏览了