Care home pharmacy receives first GDPR fine

The Information Commissioner’s Office (ICO) has fined a London-based pharmacy £275,000 for failing to ensure the security of special category data. This is the first fine issued by the Information Commissioner’s Office under the General Data Protection Regulation, which came into effect on 25 May 2018.

Doorstep Dispensaree Ltd supplies medicines to customers and care homes, left approximately 500,000 documents in unlocked containers at the back of its premises in Edgware. The documents included names, addresses, dates of birth, NHS numbers, medical information and prescriptions belonging to an unknown number of people.

Documents, some of which had not been appropriately protected against the elements and were therefore water damaged, were dated between June 2016 and June 2018. Failing to process data in a manner that ensures appropriate security against unauthorised or unlawful processing and accidental loss, destruction or damage is an infringement of the General Data Protection Regulation (GDPR).

The ICO launched its investigation into Doorstep Dispensaree after it was alerted to the insecurely stored documents by the Medicines and Healthcare Products Regulatory Agency, which was carrying out its own separate enquiry into the pharmacy.

Doorstep Dispensaree has also been issued an enforcement notice due to the significance of the contraventions and ordered to improve its data protection practices within three months. Failure to do so could result in further enforcement action. In setting the fine, the ICO only considered the contravention from 25 May 2018, when the GDPR came into effect.

  • Guidance has been published to support data protection by design and by default. This obliges data controllers to have data protection designed into and as a default setting in the processing of personal data. This means that controllers must be able to demonstrate that they have in place the appropriate measures and safeguards in the processing to ensure that the data protection principles and the rights and freedoms of data subjects are effective.
Facebooktwitterredditpinterestlinkedinmail
[pro_ad_display_adzone id=489]

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

By continuing to browse or by clicking "Accept All Cookies" you agree to the storing of first and third-party cookies on your device to enhance site navigation, analyze site usage, and assist in our marketing efforts.
Cookie Policy
Cookie Settings
Decline All
Accept All Cookies
By continuing to browse or by clicking "Accept All Cookies" you agree to the storing of first and third-party cookies on your device to enhance site navigation, analyze site usage, and assist in our marketing efforts.
Cookie Policy
Cookie Settings
Decline All
Accept All Cookies
Cookie Settings
STAY UPDATED!
Thank you for visiting CHMonline.co.uk, the website for the leading magazine for care home managers, operators and directors. If you would like to receive the digital edition and/or the editor's regular newsletters via email please subscribe here.
Are you a care home staff member or operator?
Terms: Care Home Management (S&A Publishing) may use the information you provide on this form to get in touch with you with relevant industry news and promotions. You can change your mind at any time by clicking the unsubscribe link in the footer of any email you receive from us, or by contacting us. We will treat your information with respect. For more information please view our privacy policy.
By submitting this form you agree to the terms.
SUBSCRIBE