HIV Scotland fined £10,000
HIV Scotland has been fined £10,000 after the charity sent out an email containing the personal details of dozens of people.

The data protection breach involved an email to 105 people. Recipients included patient advocates representing people living in Scotland with HIV.
All the email addresses were visible to recipients, and 65 of the addresses identified people by name.
The Information Commissioner’s Office (ICO) issued the penalty after a probe.
The watchdog said an assumption could be made about individuals’ HIV status or risk from the personal data disclosed.
HIV Scotland runs projects aimed at preventing the disease and raising awareness about it. It also offers support in getting treatment.
New interim chief executive Alastair Hudson said the charity took full responsibility. He apologised unreservedly to anyone who had been affected by the data breach.
A similar incident occurred in June of 2019. You can read that article from the BBC here.
ICO Investigation
The ICO said its investigation of the incident in February this year found shortcomings in the Glasgow-based charity’s email procedures.
These included inadequate staff training and incorrect methods of sending bulk emails. This was further aggravated by an inadequate data protection policy.
It also found that despite the charity’s own recognition of the risks and the procurement of a more secure system for bulk messages, it was continuing to use a less secure method seven months later.
Ken Macdonald, head of ICO regions, said, “All personal data is important but the very nature of HIV Scotland’s work should have compelled it to take particular care. This avoidable error caused distress to the very people the charity seeks to help.”
Mr Hudson, of HIV Scotland, said a new team and board of trustees had taken “robust steps” to improve information security.
He added, “For a small charity, financially, I cannot deny that this is a heavy blow. However, we will find a way to pay the £10,000 fine to the ICO. As an organisation, HIV Scotland would like to re-iterate its commitment to providing a safe and supportive space. Our stakeholders and networks can contribute to better health and wellbeing for those impacted by HIV and improving sexual health for all.”
How and Why?
This is the same old story. A charity or any business believes it is compliant but never checks! A simple audit could have resolved this and revealed problems before revealing data! Yet another CEO apology though it does sound like there is new management in place. All too late for those affected however.
Donors give to charity to help those in need, not to pay fines. The charity will pay I have no doubt but, it is the responsible directors who should pay. The money should not come from the charity’s funds. The ICO needs to get tougher with those who choose to ignore or disrespect the law.
Emails are one of the easiest ways to commit a data breach. The BCC field should be as standard on all clients and staff should be trained and also warned of the consequences of getting his wrong. West Ham United made this mistake in 2018 as reported by City AM. The Premier League Club has had further problems this week with its website leaking fan information.
How to avoid this
Your business, be it a charity or a commercial entity, should take data protection seriously. Simply saying we have a Privacy Policy isn’t enough and downloading templates will also not suffice. “HIV Scotland fined £10,000” is not a good headline. However, place your business name instead of HIV Scotland and see how it looks.
GDPR and DPA2018 is not as expensive as you might think. It certainly doesn’t cost £10,000!
Why not call us today and ask for a quote. You might well be surprised that unlike others, we don’t charge ridiculous consulting fees. We charge a fixed fee so there is no budget creep and no nasty surprises at a price that will please you. We don’t cut corners or use templates. You can call us on 03333 22 1011 where your call will be answered by a human being with no menus. Or, contact us here.