The UK Information Commissioner’s Office (ICO) has finally issued its first fine under the General Data Protection Regulation (GDPR).
D
oorstep Dispensaree, a pharmaceutical supplier, has been fined £275,000 (NZ$539,000) for dumping 500,000 sensitive medical documents about aged care residents in unlocked containers outside its London premises. The ICO described the company as demonstrating a “cavalier attitude to data protection”.
While the company acknowledged to some extent its failure to securely store or process the data, according to the ICO the company had “sought to downplay the seriousness” of breaches relating to its lack of appropriate privacy policies and procedures, including a suitable privacy notice. The ICO said it had found “considerable evidence of extremely poor data protection practice, amounting to significantly negligent conduct”.