Hazard

Reprimands · Transport and leisure

Processing of special category biometric data

No fineReprimands
Root cause Unlawful disclosure Personal data published or shared with people who had no right to see it, including failures to redact.

What happened

In November 2022, the Information Commissioner committed to publish all reprimands from 2022 onwards unless there is a good reason not to.

We assess every reprimand on its own merit when deciding whether or not to publish it, in line with our policy on communicating our regulatory activities. That includes considering representations from organisations and redaction of confidential, personally sensitive, and commercially sensitive information.

On this occasion, we considered it was not in the public interest to name the organisation in the reprimand due to delays in the case, as well as the regulatory pause for Covid-19.

We have chosen to still publish this reprimand, as organisations can learn where other organisations failed to comply with data protection law and identify what they need to do if they find themselves in a similar scenario.

Summarised from the notice published by the ICO on 4 October 2022. Read the original notice — it is the authoritative version.