A Metropolitan Police officer spotted customers' passports and tax-credit paperwork clearly visible through transparent bin bags left on the street outside an unidentified Robertson, Smith & Kempson estate agent branch, and after the agency ignored an initial ICO warning and repeated the practice, the ICO secured a formal undertaking rather than a fine.
Reviewed by the Social Engineering Examples team.
Between December 2013 and March 2014, a branch of Robertson, Smith & Kempson estate agents (RSK, a trading brand of Thamesview Estate Agents Ltd) - the specific branch is not identified in ICO records - repeatedly left confidential customer paperwork, including copies of passports and documents showing tax credit awards and prior tax payments, in transparent refuse sacks on a public street outside its premises. The data was clearly visible to anyone walking past. A Metropolitan Police Community Support Officer first reported the exposure to the UK Information Commissioner's Office (ICO) on 11 December 2013, after previously raising it directly with the company; the ICO contacted the company on 24 December 2013 and warned it to dispose of personal data securely. The same complainant observed the practice recurring on 12 March 2014 and reported it to the ICO on 13 March 2014. The ICO's investigation found the breach centered on the Seventh Data Protection Principle (security under the Data Protection Act 1998): staff were insufficiently aware of the company's confidential-waste policy, and the company had no written contract with any vendor engaged to securely destroy confidential waste. On 11 August 2014, the ICO closed the case (ENF0525612) by having Thamesview Estate Agents Ltd sign an undertaking - rather than issuing a formal Enforcement Notice or monetary penalty - committing the company to refresher staff training, improved confidential-waste storage, and formal processor contracts by 31 December 2014.
This was not an active "attack" but a passive data-exposure enabled by inadequate physical disposal practice, of the type dumpster-diving/discarded-media threats are built to exploit. Staff at a branch of Robertson, Smith & Kempson (RSK, a trading brand of data controller Thamesview Estate Agents Ltd) placed confidential paper waste - including copies of customers' passports and documents showing tax credit awards and prior tax payments - into ordinary transparent (clear) refuse sacks and left them unattended on the public street outside the branch's premises. Neither the ICO undertaking nor the ICO press release identifies which specific RSK branch or street this was; RSK's own published branch list and history show only four West London offices (Acton, Ealing, Hanwell, Northfields, the company having been established in Hanwell in 1991), with no Teddington branch. The address given for the data controller on the undertaking, 3 Park Road, Teddington, is a registered/correspondence address (also the current registered office of a same-named successor company per Companies House), not a confirmed shopfront or incident site. Because the sacks were see-through, personal and financial data was visible to any passer-by without needing to open or search the rubbish - the "diving" barrier that normally deters casual snooping was removed entirely. A Metropolitan Police Community Support Officer spotted the exposed documents; per the undertaking, he had raised the issue directly with the company about a week earlier and then reported it to the ICO on 11 December 2013 after observing the practice continue over several more days. The ICO contacted the company on 24 December 2013 and warned it to dispose of personal data securely. Despite that warning, the same complainant observed the practice recurring on 12 March 2014 (per the undertaking) and reported this second occurrence to the ICO on 13 March 2014 (per the ICO press release), triggering the ICO's investigation and enforcement action. The ICO's findings centered on the Seventh Data Protection Principle (security): staff were not adequately aware of the company's own confidential-waste disposal policy, confidential waste was stored in a way accessible to staff/contractors without a legitimate need to see it, and the company had no written contract with the vendors it used to destroy confidential waste, as required under Schedule 1 Part II paragraph 12 of the Data Protection Act 1998.
There was no lure or social-engineering "tell" aimed at a victim in the conventional sense - this is a passive/opportunistic exposure case rather than an active con. The only "tell" available to an alert observer was the visual giveaway itself: confidential paperwork readable through a clear plastic bin bag sitting in public view on a residential street, an obvious red flag that any passer-by (in this case a police officer) could recognize and report. For organizations, the analogous "tell" to watch for internally is the mismatch between a written confidential-waste policy and what staff actually do at the curb - if refresher training doesn't cover disposal specifically, and no one audits what leaves the building in bin bags, exposures like this go undetected until an outsider notices.
The ICO resolved the case with a Data Protection Act 1998 undertaking (case ENF0525612), signed by Thamesview Estate Agents Ltd on 11 August 2014, in lieu of the Commissioner exercising his power to serve an Enforcement Notice under section 40 of the Act. No monetary penalty was issued. The company committed to company-wide confidential-waste and training reforms with a 31 December 2014 deadline (refresher training and improved secure-storage arrangements), and to putting written contracts in place with any processor engaged to destroy customer personal data. The ICO publicized the case via press release naming the company and quoting its Head of Enforcement, Stephen Eckersley, highlighting the identity-fraud risk from exposed passport copies and tax payment details.
This case is a clean, well-documented illustration that "dumpster diving" risk does not require a determined attacker digging through trash - it can be as trivial as an organization using see-through bin bags for paperwork containing passport copies and tax/financial data, turning routine confidential waste disposal into a walk-by data breach. It also demonstrates a common escalation pattern in regulatory enforcement: a first warning that goes unheeded converts a minor compliance lapse into a public enforcement action and press release naming the company, even without any confirmed fraud or financial loss. For any business handling customer identity or financial documents (estate agents, letting agents, financial services, recruiters), it underscores that physical waste-handling policy is only as good as staff habit and disposal-vendor contracts - the same "insider negligence" failure mode recurs across sectors regardless of company size. It's also a caution for record-keeping itself: absent a named branch/street in the primary sources, it is easy to mistake a company's registered/correspondence address for the actual incident location - a reminder to distinguish confirmed facts from plausible-sounding inferences when documenting incidents.
The ICO undertaking (11 Aug 2014) required Thamesview Estate Agents Ltd / Robertson, Smith & Kempson to: (1) introduce mandatory refresher data-protection training for all staff handling personal data, by 31 December 2014 and on a regular basis thereafter; (2) review and improve confidential-waste storage arrangements across all branches by 31 December 2014 so waste is not accessible to staff/contractors without a legitimate need; (3) maintain a written record of all data processors and put formal written contracts in place with any company engaged to destroy or otherwise process customer personal data, per the Seventh Principle/Schedule 1 Part II para 12 requirement; (4) continue reviewing internal policies and procedures until full compliance is achieved; and (5) implement appropriate technical/organisational security measures against unauthorised or unlawful processing and against accidental loss, destruction or damage of personal data. Broader lesson for any organisation: transparent/clear refuse sacks should never be used for confidential paper waste; use opaque sacks or locked shred-bins, contract disposal only under a written data-processing agreement, and treat a first regulator warning as a hard stop, not a formality - Thamesview's failure to act after the December 2013 warning is what converted a minor lapse into an enforcement action.
A Pennsylvania shredding-business owner's 2010 qui tam suit alleged that Shred-It, Iron Mountain, and Cintas billed federal agencies for GSA-spec…
Two unencrypted TD Bank backup tapes carrying data on 260,000 customers vanished in transit between Massachusetts offices in 2012; a…
A widely circulated security-awareness case study (NINJIO) claims a tailgating "badge surfer" photographed passwords exposed by a clean-desk-policy failure to…