Be careful when responding to a subject access request

The ICO recently reprimanded a GP surgery for releasing too much information and to the wrong person, when asked by a patient to share certain data with an insurer after checking it with them. You can read their blog at https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/02/gp-surgery-reprimanded-after-excessive-medical-history-of-terminally-ill-patient-sent-to-insurer/ but how do you score on the lessons learnt of:

  • The need for written processes to be in place to support staff when handling personal data.
  • Consider the need for a quality assurance process when sharing personal data externally.
  • Provide up-to-date and regular data protection training for staff.