None
Financial penalty
Reprimand, no fine
16 December 2025
Date on the register
UK GDPR
Law relied on
UK GDPR Article 5(1)(c), UK GDPR Article 5(1)(f)
Health
Sector
15 actions on the register
In one line
The ICO issued Staines Health Group with a reprimand on 16 December 2025 under the UK General Data Protection Regulation. No financial penalty attaches to it.
01The record
- Organisation named
- Staines Health Group
- Action
- Reprimand
- Date published
- 16 December 2025
- Register year
- 2025
- Law relied on
- UK GDPR
- Provisions cited
- UK GDPR Article 5(1)(c), UK GDPR Article 5(1)(f), UK GDPR Article 32, UK GDPR Article 33
- Penalty
- None (not a financial penalty)
- Sector on the register
- Health
- ICO register reference
- 84537
- Register status
- Published on the ICO enforcement register, 4 September 2026
- Notice documents
- 1 PDF published by the ICO
- Sector share of register
- 15 of 216 actions (7%)
- Actions published that year
- 31
- Actions under this law
- 95
- Position on the register
- 195th of 216, oldest first
- Published the same day
- This entry alone
02What happened, and where it sits
Staines Health Group received an ICO reprimand on 16 December 2025. The Commissioner acted under the UK General Data Protection Regulation, citing UK GDPR Article 5(1)(c), UK GDPR Article 5(1)(f), UK GDPR Article 32 and UK GDPR Article 33. A formal criticism on the public record. A reprimand carries no fine and no order, but it is published and the ICO expects the shortcomings named in it to be fixed.
No sum is attached to this action. Reprimands are corrective, not financial, which is why Staines Health Group appears on the register without a figure beside it.
Staines Health Group is filed under Health, which accounts for 15 of the 216 actions on the register (7%). In 2025 the ICO published 31 enforcement actions in total, 8 of them reprimands. 95 actions on the register name UK GDPR.
Counted from the oldest entry forward, this is the 195th of 216 actions on the register and the 15th of 15 in Health. The ICO publishes one document for this action, 219 KB in total: "Staines Health Group reprimand". It is the authority for everything on this page.
03The ICO's own account
Reprimand Issued - Staines Health Group sent excessive medical details about a terminally ill patient to their insurance company. The patient requested that five years of medical records be sent to them to review, before being sent to the insurer in order to progress the claim. But, instead of five years medical history being sent to the patient, Staines Health Group sent 23 years of medical records direct to the insurer. The patient believed the excessive disclosure of unnecessary medical records led to a reduction in the payout of their claim. Failures of Staines Health Group included a lack of written process for staff to follow when handling insurance requests and a lack of regular refresher data protection training for staff.
The law behind this action
UK GDPR
The UK GDPR is the data protection regime the ICO enforces against controllers and processors. Its upper tier is capped at £17.5 million or 4% of total worldwide annual turnover, whichever is higher.
What a reprimand does
A formal criticism on the public record. A reprimand carries no fine and no order, but it is published and the ICO expects the shortcomings named in it to be fixed.
Published notice
- PDFStaines Health Group reprimand(219 KB)
04Nearest entries on the register
| Organisation | Date | Action | Law | Penalty |
|---|---|---|---|---|
| United Lincolnshire Teaching Hospitals NHS Trust | 13 Dec 2024 | Reprimand | UK GDPR | - |
| University Hospital of Southampton NHS Foundation Trust | 25 Mar 2024 | Reprimand | UK GDPR | - |
| South Tees Hospitals NHS Trust | 20 Dec 2023 | Reprimand | UK GDPR | - |
| University Hospital of Derby and Burton NHS Trust (UHDB) | 30 Oct 2023 | Reprimand | UK GDPR | - |
| NHS Lanarkshire | 31 Jul 2023 | Reprimand | UK GDPR | - |
05Work out an exposure of your own
Article 83 fine calculator
Estimate upper and lower tier exposure from turnover and infringement type, on the same scale the ICO works to.
How a fine is calculated
The Article 83(2) factors, the turnover caps, and how a regulator gets from a contravention to a number.
The ICO profile
How the UK regulator works post-Brexit, the £17.5M and £8.7M UK GDPR caps, and its divergence from the EU regime.
Provenance and independence
Source: ICO enforcement register (ico.org.uk/action-weve-taken/enforcement/), as published on 4 September 2026. Contains public sector information licensed under the Open Government Licence v3.0.
GDPRFine.com is an independent tracker of ICO enforcement. It is not affiliated with, endorsed by or connected to the Information Commissioner's Office, and it uses no ICO branding. Where the ICO's own wording is reproduced it is quoted and attributed; everything else on these pages is our own summary of the published record.
The ICO's register held 222 entries on that date. 6 of them are prosecutions of named individuals, with ages and home towns in the ICO's own summary. This tracker indexes organisations, so those 6 are excluded and every count on these pages is out of 216. They remain on the ICO's own register.
An entry says what the Commissioner did on the date shown. It is not a statement about the organisation today, and the ICO can amend or remove a register entry at any time. Amounts and provisions are as published by the ICO; where the published notice does not state a figure or name a provision, these pages say so rather than filling the gap. This entry was read from the register page at https://ico.org.uk/action-weve-taken/enforcement/2025/12/staines-health-group/.
Register: ico.org.uk/action-weve-taken/enforcement/. Corrections: [email protected].