UK information commissioner John Edwards has condemned data protection standards at health services for people living with HIV, calling for urgent improvements.
The criticism follows a string of data breaches where a number of people living with the health condition have been made identifiable.
“People living with HIV are being failed across the board when it comes to their privacy and urgent improvements are needed across the UK,” he said.
“We have seen repeated basic failures to keep their personal information safe – mistakes that are clear and easy to avoid.”
“We know from speaking to those living with HIV and experts in the sector that these data breaches shatter the trust in these services,” he added.
“They also expose people to stigma and prejudice from wider society and deny them the basic dignity and privacy that we all expect when it comes to our health.”
Advancements in treatment over the last few decades has meant that HIV in 2024 isn’t only a manageable condition, but people on effective treatment also can’t pass it on.
However, the outdated stigma and prejudice surrounding it — which stems from the 80s — lives on.
This means that data breaches that cause people living with HIV to be identifiable poses a risk of further discrimination and harassment, in addition to distrust in the services meant to support them.
Edwards’ statement comes after the Information Commissioner’s Office (ICO) fined the Central Young Men’s Christian Association (the Central YMCA) of London £7,500 for a data breach from 2022.
Emails that were intended for those on a HIV support programme were sent to 264 email addresses using the CC function rather than BCC, resulting in 166 people being identifiable or potentially identifiable.
The fine, which has now been paid in full, was initially recommended to be £300,000. This was then reduced in line with the ICO’s public sector approach.
The approach is designed to reduce how much public money is used to pay fines for organisations’ errors, lessening the impact on those directly in need of the public services.
A formal reprimand has also been issued.
The ICO has previously issued fines or reprimands for data breaches affecting people living with HIV to health board NHS Highland and charity HIV Scotland.
Both of these data breaches were due to mistakes in using BCC emails for sensitive communications, which the ICO called on organisations to stop last year.
The ICO is now further calling for better staff training, appropriate technical procedures, and prompt reporting from HIV services.
Recommended reading
- ICO Reprimands NHS Highland for “Serious” Data Breach
- Scotland to Home World-first Online HIV Prevention Service
- Grindr Sharing Sensitive Data with Third Parties
Adam Freedman, the policy, research, and influencing manager at the National AIDS Trust responded to Edwards’ full statement, saying: “We are very supportive of today’s statement by the ICO.
“Strong regulatory action is needed when organisations breach protection of HIV status data, which unfortunately continues to carry with it more harmful stigma than other types of personal data.
“People living with HIV need the confidence to know that they have recourse when their data rights are breached, and to prevent risk of further discrimination and harassment.
“Someone’s HIV status is personal data and it should be a person’s choice to decide whether or not they share that information.
“We are pleased to see the ICO recognising the detrimental impact such data breaches can have on people living with HIV, and welcome this much needed intervention.”





