Blog

Two data breaches, two very different outcomes

When personal data is destroyed, it can have serious consequences, not just for the organisations responsible, but for the people affected. Destruction of personal data is a vital part of the data lifecycle and under data protection law, organisations shouldn’t hold on to personal information longer than necessary.

In practice, that means clear retention schedules and secure and well-documented destruction when the time comes. However, when destruction happens without proper oversight, or the wrong data is destroyed, that’s another story.

Recently, two ICO enforcement actions have highlighted just how wide the gap can be between similar incidents and how very different the outcomes are.

The two breaches we’re looking at are:

  1. A police force deleting over 96,000 body-worn video files, including footage linked to criminal cases.
  2. A small Scottish charity destroying around 4,800 personal records, including irreplaceable letters, photographs and birth certificates.

Both breaches were the result of poor oversight and both involved data that should have been protected. One received a reprimand and the other a £18,000 fine.

Case One: South Yorkshire Police

South Yorkshire Police (SYP) permanently deleted over 96,000 body-worn video files, including footage linked to 126 criminal cases.

The breach was traced back to a storage system upgrade, followed by a flawed workaround that led to mass deletion. While most footage had been copied across, SYP couldn’t confirm what was lost due to poor recordkeeping.

The ICO found:

  • No clear backup and recovery procedures in place.
  • A lack of escalation to senior leadership.
  • No risk assessment was carried out before granting third-party access.
  • Undefined responsibilities for IT contractors.

The ICO noted this case as a warning for any organisation using bodycams or similar tech. Data compliance doesn’t just apply to collecting the footage but also protecting and managing it responsibly.

Although only a small number of cases were impacted (allegedly), this incident highlights why retention policies, backup systems and clear oversight are vital, especially in law enforcement where data can be central to justice.

Enforcement outcome: reprimand, no fine.

Read the full details on the ICO’s website: https://ico.org.uk/action-weve-taken/enforcement/2025/08/south-yorkshire-police/

Case Two: Birthlink

The Scottish charity Birthlink destroyed around 4,800 personal records, including potentially irreplaceable items like handwritten letters, photographs and birth certificates.

In January 2021, Birthlink reviewed whether they could destroy certain records as they were running out of space in the charity’s filing. This was agreed the following month at a Board Meeting and approximately 4,800 records were destroyed in April and May 2021.

It wasn’t until an inspection by the Care Inspectorate in 2023 that the Board became aware irreplaceable records had been destroyed.

How did it happen?

  • Poor records management and a lack of clear retention rules.
  • Inadequate training and no meaningful understanding of data protection law.
  • Destruction continued despite concerns being raised at the time.
  • Inability to identify exactly who has been affected.

The ICO highlighted this as a breach with real-world emotional consequences, Sally Anne Poole, Head of Investigations, said:

“The destroyed records had the potential to be an unknown memory, an identity, a sense of belonging, answers – all deeply personal pieces in the jigsaw of a person’s history –  some now lost for eternity.”

The fine was reduced from an initial £45,000 due to mitigating actions now taken by Birthlink, including:

  • Digitising and securely storing all remaining physical records.
  • Appointing a Data Protection Officer.
  • Staff training and awareness work.

Enforcement outcome: fine of £18,000

Read the full details on the ICO’s website: https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2025/07/charity-fined-following-destruction-of-irreplaceable-personal-records/

Reprimand vs. Fine. Why is there a difference?

Neither of these incidents were malicious and both involved poor data governance and a lack of safeguards, but it raises a few important questions:

  • Why does a charity receive a financial penalty, but a police force doesn’t?
  • What’s the actual difference in harm, especially if one of those videos could have changed the outcome of a trial?
  • Should we expect more understanding for under-resourced third sector organisations?

The ICO says fines for government departments are simply money moving from one public purse to another. That’s understandable, but if that logic applies to public bodies, shouldn’t charities, often delivering vital services on tight budgets from public donations, receive similar consideration?

What do you think?

Is it time for more consistency in enforcement or do the differences between public bodies and third-sector organisations justify different treatment?

Let us know your thoughts, email info@dunwelldataprotection.co.uk