Data breaches

Year

Number of incidents

Main types of breach

Key learning / Action taken

2025

17

Incorrect attachments and letters, vulnerability information shared in error, unencrypted data transfer, personal data sent to wrong recipients, bulk email errors.

Enhanced GDPR training, disciplinary action in repeat cases, encryption reminders, process reviews and stronger checks before sending communications.

2026*

10

Incorrect email recipients, subject access request disclosure errors, personal information shared with third parties, misuse of distribution lists.

Additional review procedures, staff retraining, disciplinary action where appropriate and strengthened quality assurance checks.

*2026 figures are year-to-date based on the incidents recorded in the log.