Data Breach at the YMCA
The Central YMCA sent an email to individuals participating in a programme for people living with HIV. They used “CC” rather than “BCC”, revealing the email addresses to all recipients. 166 individuals could be identified or potentially identified from their email address. As a result, it could be inferred that these individuals were likely to be living with HIV. The Central YMCA was issued with a fine of £7,500 and issued with a reprimand.

Sadly, we hear about this every day. Fortis DPC has always advocated using specialist mailing tools rather than email for large scale messaging. Failing to use “BCC” is all too common and we hear of it constantly. This could have easily been avoided with simple guidance and staff training.
The Central YMCA is an education and wellbeing charity that provides a number of community programmes. This includes the Positive Health Programme. The Positive Health Programme (“Programme”) is an exercise scheme for people living with HIV. It is run by the Positive Health Team as part of YMCA Club.
In October 2023, a team member sent an email to a mailing list of 270 recipients. The email was to invite them to talk about nutrition. Sadly, the email addresses were placed on the carbon copy “CC” box. The email was then sent. The following day a recall email was attempted. This led to yet another email to the same 270 recipients!
How many email addresses were involved?
So how did they end up revealing only 166 individual email addresses? Initially 270 email addresses were added but taking into account of duplicates, the figure became 264 email addresses. 9 emails weren’t delivered, bringing the number down to 257. 115 of those email addresses had clear names in them, and a further 51 contained at least part of a name, making individuals potentially identifiable. Therefore, 166 data subjects were affected by the breach, all of whom are in the Programme.
Recipients of the email can infer from its contents that the 166 individuals, whose email addresses were disclosed in the breach, could be living with HIV. This means that the disclosed personal data included health data, which is special category data under Article 9(1) of the UK GDPR.
Technical Security Measures
The ICO decided that the Central YMCA simply failed to implement appropriate security of personal data and security measures. They also failed to evidence policies and procedures for managing the use of data with only a verbal policy in place to use blind carbon copy (“BCC”) in emails. Both were insufficient to protect Article 9 special category data. The team member had not received GDPR training. Ironically, a mailing tool was available which would have prevented the breach. There was simply a lack of awareness within the business.
Remediation
However, the ICO welcomed the remedial actions taken by the Central YMCA including the report to the ICO and to the recipients. The incident was reported to the Data Protection Officer and learnings were shared across the organisation.
Sadly, this is a story we hear often where businesses believe that having a privacy notice makes them compliant. Most businesses haven’t carried out training or if they have, it has been online which normally means staff have the opportunity to catch up on emails whilst the training plays in the background.
The Central YMCA failed to understand the data protection legislation, failed to train its staff and there was simply no GDPR culture within the business. If you think this is you, then call us for a chat and let’s find out. Please book a call here. Don’t make the same mistakes because, as a commercial enterprise, the fines for you won’t be so lenient.
Leave a Reply