None
Financial penalty
Reprimand, no fine
11 July 2022
Date on the register
UK GDPR
Law relied on
provision not named
Central government
Sector
14 actions on the register
In one line
The ICO issued Department of Health and Social Care with a reprimand on 11 July 2022 under the UK General Data Protection Regulation. No financial penalty attaches to it.
01The record
- Organisation named
- Department of Health and Social Care
- Action
- Reprimand
- Date published
- 11 July 2022
- Register year
- 2022
- Law relied on
- UK GDPR
- Provisions cited
- Not named in the published notice
- Penalty
- None (not a financial penalty)
- Sector on the register
- Central government
- ICO register reference
- 17238
- Register status
- Published on the ICO enforcement register, 4 September 2026
- Notice documents
- 2 PDFs published by the ICO
- Sector share of register
- 14 of 216 actions (6%)
- Actions published that year
- 32
- Actions under this law
- 95
- Position on the register
- 9th of 216, oldest first
- Published the same day
- This entry alone
02What happened, and where it sits
Department of Health and Social Care received an ICO reprimand on 11 July 2022. The Commissioner acted under the UK General Data Protection Regulation. A formal criticism on the public record. A reprimand carries no fine and no order, but it is published and the ICO expects the shortcomings named in it to be fixed.
No sum is attached to this action. Reprimands are corrective, not financial, which is why Department of Health and Social Care appears on the register without a figure beside it.
Department of Health and Social Care is filed under Central government, which accounts for 14 of the 216 actions on the register (6%). In 2022 the ICO published 32 enforcement actions in total, 31 of them reprimands. 95 actions on the register name UK GDPR.
Counted from the oldest entry forward, this is the 9th of 216 actions on the register and the 1st of 14 in Central government. The ICO publishes 2 documents for this action, 285 KB in total: "DHSC-reprimand" and "ICO-Update-Note-24-August-2023-redactions". They are the authority for everything on this page.
03The ICO's own account
The ICO has issued the DHSC with a reprimand in relation to data protection compliance matters under the General Data Protection Regulation (GDPR), the UK General Data Protection Regulation (UKGDPR) and the UK Data Protection Act 2018 (DPA).
The ICO does not take the view that the DHSC, and public bodies in general, should never send information containing personal data to private communication channels. However, where such channels are in use and the processing of personal data is taking place, they should be operated in compliance with the requirements of UK data protection law.
The use of private correspondence channels was taking place, without appropriate controls in place to sufficiently manage the risks such processing presented.
The law behind this action
UK GDPR
The UK GDPR is the data protection regime the ICO enforces against controllers and processors. Its upper tier is capped at £17.5 million or 4% of total worldwide annual turnover, whichever is higher.
What a reprimand does
A formal criticism on the public record. A reprimand carries no fine and no order, but it is published and the ICO expects the shortcomings named in it to be fixed.
Published notice
- PDFDHSC-reprimand(158 KB)
- PDFICO-Update-Note-24-August-2023-redactions(128 KB)
04Nearest entries on the register
| Organisation | Date | Action | Law | Penalty |
|---|---|---|---|---|
| Secretary of State for the Home Department (Home Office) | 16 Aug 2022 | Reprimand | UK GDPR | - |
| Department for Work and Pensions | 31 Oct 2022 | Reprimand | UK GDPR | - |
| Department for Education | 2 Nov 2022 | Reprimand | UK GDPR | - |
| Executive Office | 21 Jul 2023 | Reprimand | UK GDPR | - |
| ACRO Criminal Records Office | 7 Aug 2026 | Reprimand | UK GDPR | - |
All Central government actions/All 2022 actions/The full register
05Work out an exposure of your own
Article 83 fine calculator
Estimate upper and lower tier exposure from turnover and infringement type, on the same scale the ICO works to.
How a fine is calculated
The Article 83(2) factors, the turnover caps, and how a regulator gets from a contravention to a number.
The ICO profile
How the UK regulator works post-Brexit, the £17.5M and £8.7M UK GDPR caps, and its divergence from the EU regime.
Provenance and independence
Source: ICO enforcement register (ico.org.uk/action-weve-taken/enforcement/), as published on 4 September 2026. Contains public sector information licensed under the Open Government Licence v3.0.
GDPRFine.com is an independent tracker of ICO enforcement. It is not affiliated with, endorsed by or connected to the Information Commissioner's Office, and it uses no ICO branding. Where the ICO's own wording is reproduced it is quoted and attributed; everything else on these pages is our own summary of the published record.
The ICO's register held 222 entries on that date. 6 of them are prosecutions of named individuals, with ages and home towns in the ICO's own summary. This tracker indexes organisations, so those 6 are excluded and every count on these pages is out of 216. They remain on the ICO's own register.
An entry says what the Commissioner did on the date shown. It is not a statement about the organisation today, and the ICO can amend or remove a register entry at any time. Amounts and provisions are as published by the ICO; where the published notice does not state a figure or name a provision, these pages say so rather than filling the gap. This entry was read from the register page at https://ico.org.uk/action-weve-taken/enforcement/2022/07/department-of-health-and-social-care/.
Register: ico.org.uk/action-weve-taken/enforcement/. Corrections: [email protected].