Hi
Can anyone give me advice regarding taking action for a data breach and possibly point me in the direction of form letters.
My ex employer sent a wrongly addressed letter containing personal and medical information. They knew it had been delivered and signed for by someone and failed to tell me at the time or disclose it in a SAR request. I only found out via a SAR to a different organisation.
The same ex-employer long after I was no longer employed had asked for copies of a large number of medical documents to pass on to their OH doctor. They did this but also retained these documents, made copies and passed the copies on to their lawyers. Again this was not disclosed in the SAR.
I took my employer to an Employment Tribunal. The lawyers asked for my medical records, I objected and the tribunal refused to order that my medical records be disclosed. Despite this, the lawyers, knowing that these documents had been retained but not disclosed in the SAR, then made copies and included them in an evidence bundle for the tribunal.
The judge at the tribunal stated that it was not a matter for tribunal but a data breach.
Has anyone any advice. I am in Scotland if it makes a difference.
Thanks.
Can anyone give me advice regarding taking action for a data breach and possibly point me in the direction of form letters.
My ex employer sent a wrongly addressed letter containing personal and medical information. They knew it had been delivered and signed for by someone and failed to tell me at the time or disclose it in a SAR request. I only found out via a SAR to a different organisation.
The same ex-employer long after I was no longer employed had asked for copies of a large number of medical documents to pass on to their OH doctor. They did this but also retained these documents, made copies and passed the copies on to their lawyers. Again this was not disclosed in the SAR.
I took my employer to an Employment Tribunal. The lawyers asked for my medical records, I objected and the tribunal refused to order that my medical records be disclosed. Despite this, the lawyers, knowing that these documents had been retained but not disclosed in the SAR, then made copies and included them in an evidence bundle for the tribunal.
The judge at the tribunal stated that it was not a matter for tribunal but a data breach.
Has anyone any advice. I am in Scotland if it makes a difference.
Thanks.
Comment