An MHRA search warrant unrelated to data protection stumbled on an estimated ~500,000 (later found to be far fewer) care-home patients' hard-copy prescription and NHS records left rotting in unlocked crates, bin bags and a cardboard box in the open rear yard of a London pharmacy supplier, triggering the ICO's first-ever GDPR fine.
Reviewed by the Social Engineering Examples team.
Doorstep Dispensaree Ltd, a London-based pharmacy wholesaler that MHRA/ICO's original estimate said supplied medicines to about 78 care homes (a figure later found by the First-tier Tribunal to be an overstatement: DDL's actual dispensing contracts covered no more than 27 care homes as of July 2018, falling to 15 by September 2019), was found to have stored hundreds of thousands of hard-copy patient documents (an MHRA estimate later substantially revised down on appeal), consisting of names, addresses, dates of birth, NHS numbers, medical information and prescriptions dated June 2016 to June 2018, in unlocked crates, disposal bags and a cardboard box in the open rear yard of its premises at 75-79 Masons Avenue, Harrow (the company traded from the Edgware/Burnt Oak Broadway area of North-West London). The exposure was discovered on 24 July 2018 when the Medicines and Healthcare products Regulatory Agency (MHRA) executed a search warrant at the site for an unrelated medicines-regulation investigation and found 47 stacked unlocked crates plus disposal bags/boxes of paperwork, some of it visibly water-damaged or mouldy, none marked as confidential waste. MHRA alerted the Information Commissioner's Office (ICO) on 31 July 2018. Following an information notice, a notice of intent, and written submissions, the ICO issued Doorstep Dispensaree a Monetary Penalty Notice of £275,000 and an Enforcement Notice on 17 December 2019, the first fine ever issued by the UK ICO under the GDPR/Data Protection Act 2018, for breaches of Articles 5(1)(f) and 5(1)(e) (integrity/confidentiality and storage-limitation principles), 24(1) (controller responsibility) and 32(1)-(2) (security of processing), plus defective privacy notices under Articles 13-14. The company challenged the penalty; the First-tier Tribunal in 2021 found the true document count was far smaller than MHRA's initial ~500,000 estimate and cut the fine to £92,000 while upholding the Enforcement Notice, a result subsequently affirmed on further appeal by the Upper Tribunal (2023) and the Court of Appeal (9 December 2024).
This was not an attacker-executed social engineering operation but a records-security failure that created a live social-engineering/identity-theft exposure risk of the kind the "discarded/insecurely stored physical records" variant is meant to illustrate. Doorstep Dispensaree Ltd, a London pharmacy wholesaler that MHRA/ICO's original estimate said supplied medicines to roughly 78 care homes (a figure the First-tier Tribunal later found was overstated: DDL's actual dispensing contracts covered no more than 27 care homes as of July 2018, falling to 15 by September 2019), accumulated years of hard-copy paperwork (dated between June 2016 and June 2018) covering dispensing and prescription records for elderly, vulnerable care-home residents. Instead of destroying this paperwork as confidential waste or storing it under lock and access control, the company (and/or its waste-disposal contractor, Joogee Pharma Limited, a licensed waste-disposal firm the Court of Appeal confirmed was wholly owned by the same sole director/shareholder as Doorstep Dispensaree, Sanjay Budhdeo, rather than an independent outside vendor) left the documents piled in the open rear yard/courtyard of its premises: 47 stacked unlocked crates, two disposal bags, and a cardboard box, none marked "confidential waste," some visibly soaking wet or mouldy from prolonged exposure to the weather. The documents contained patients' full names, home addresses, dates of birth, NHS numbers, medical information, and prescription details, exactly the kind of special-category personal data that enables identity theft, medical-identity fraud, and highly convincing pretexting/impersonation attacks against vulnerable elderly individuals or their families. The exposure was discovered not by the company or a whistleblower but by sheer coincidence: the UK Medicines and Healthcare products Regulatory Agency (MHRA) executed an unrelated search warrant at the premises (75-79 Masons Avenue, Harrow, Middlesex) on 24 July 2018 as part of a separate criminal investigation into the company's medicines-handling practices, and in doing so physically found the unsecured records in the yard.
There was no deceptive lure in the conventional social-engineering sense: no attacker crafted a pretext to obtain the records. The "tell" that exposed the failure was entirely incidental: MHRA investigators executing a search warrant for an unrelated medicines-regulation matter physically walked into the rear yard and found stacks of unlocked crates and bags of patient paperwork sitting in the open, some already water-damaged, none marked as confidential waste. MHRA notified the ICO of what it had found on 31 July 2018, which opened the data-protection investigation. In effect, the "tell" was simply that unsecured, undisposed sensitive records left in a publicly accessible outdoor space are trivially discoverable by regulators in this case, but just as easily by anyone with casual physical access, which is the core lesson of this variant.
The ICO issued a Monetary Penalty Notice of £275,000 and an accompanying Enforcement Notice against Doorstep Dispensaree Ltd on 17 December 2019, the first fine issued by the UK ICO under the GDPR/Data Protection Act 2018 (the notice was formally announced/published around 19-20 December 2019). The Enforcement Notice required the company to appoint an information governance lead/DPO, roll out mandatory staff training, and bring its privacy notices and retention/destruction policies into compliance within three months. Separately, the MHRA's own criminal medicines investigation into the company concluded on 26 November 2019 with no further action for insufficient evidence of a reasonable prospect of conviction. Doorstep Dispensaree appealed the MPN; the First-tier Tribunal (18 August 2021) found the true audited scale of exposed documents was materially smaller than MHRA's original ~500,000 estimate (accepting figures in the tens of thousands, with roughly 53,871 documents containing special-category data) and reduced the fine to £92,000 while upholding the Enforcement Notice in full. Doorstep Dispensaree continued appealing; the Upper Tribunal ([2023] UKUT 132 (AAC)) and then the Court of Appeal (9 December 2024, [2024] EWCA Civ 1515) both rejected the company's further challenges, finally settling the case at a £92,000 fine plus the Enforcement Notice, over five years after the original discovery. Companies House records show Doorstep Dispensaree Limited is now in liquidation.
This case is the canonical UK/EU example that GDPR "appropriate technical and organisational security measures" obligations apply just as much to paper records as to digital systems, and that basic physical security failures (unlocked, unmarked, weather-exposed storage of sensitive health data) can trigger the same scale of regulatory penalty as a cyberattack. It also established that a data controller cannot discharge its security obligations merely by pointing to a waste-disposal contractor, here a commonly-owned firm rather than an arm's-length vendor: the ICO and tribunals held Doorstep Dispensaree, not the contractor, primarily liable as the controller. For social-engineering and physical-security education specifically, the case demonstrates the upstream failure mode this repository's "discarded/insecurely stored physical records" variant targets: troves of names, NHS numbers, addresses and medical/prescription detail sitting in publicly accessible outdoor space are exactly the raw material used downstream for identity theft, targeted phishing/vishing, and impersonation scams against elderly and vulnerable people (and their families), even though in this instance the exposure was caught by a regulator before any known criminal exploitation occurred. The five-year appeal saga (2019 ICO fine to 2024 Court of Appeal) also became a leading precedent on burden of proof and evidentiary standards in UK data-protection appeals more broadly.
Basic controls that would have prevented this: locked/access-controlled storage for hard-copy patient records; use of certified confidential-waste destruction rather than ad hoc disposal via a third-party processor; a documented, GDPR-compliant records retention and destruction policy (Article 5(1)(e)); a Data Protection Officer/Information Governance lead; up-to-date, non-template privacy notices (Articles 13-14); and periodic internal audits of physical document handling akin to those applied to digital systems. The ICO's Enforcement Notice specifically ordered Doorstep Dispensaree to appoint an information governance lead, introduce mandatory staff training, and update policies within three months. The case is widely cited as the regulatory baseline showing that GDPR "security of processing" duties (Art. 5(1)(f), 24(1), 32) apply equally to paper records as to IT systems, and that outsourcing disposal to a waste contractor does not shift controller liability.
A Rapid7 penetration tester tailgated into a client's building using door-holding reciprocity and a cloned-looking badge, rode an elevator up…
A Chinese national talked her way past three layers of Mar-a-Lago's Secret Service and club-staff checkpoints using a false pool…
An Atlantic City woman posed as a life-insurance/retirement-benefit representative on burner-phone calls to recently widowed elderly victims, telling them their…