Our website uses cookies to give you the best experience and for us to analyse our site usage. If you continue to use our site, we will take it you are OK about this. Click on More for information about the cookies on our site and what you can do to opt out.

We respect your Do Not Track preference.

Breach Case 7: Rubbishing privacy Neil Sanson
5 April 2018


A recent data breach incident provided an example of how your responsibility to protect personal information does not end when you put the rubbish out for collection.

A member of the public noticed some rubbish strewn along a street. The litter included prescription labels with a person’s name and address. The nature of the prescription clearly indicated the condition of the patient who was being treated with the medication.

The person who discovered the prescription labels informed our office and we contacted the agency most likely responsible and discussed the situation with them.

The health agency’s rubbish was supposed to have been double-bagged, which would usually prevent spillages. However, the agency also had access to a secure shredding service and is now looking at using the service to dispose of prescription labels which are on cardboard packaging.

Each agency is responsible for working out a practical solution that works for their circumstances. Because of the range of possible circumstances, our published guidance on handling health information does not specify particular methods of disposal. That’s up to an individual agency to work out for itself. A useful check, when deciding on a solution, can be to ask what steps you would expect to be taken if the personal information belonged to you.

At home, you might want to rip labels off cardboard packaging and recycle the cardboard while disposing of the prescription label in some other way.

We regularly get data breach notifications and we will continue to share the lessons learned from these more regularly. If you want to know more about data breaches, please check out our Data Safety Toolkit.

For more information on handling health information:

Image credit: Rubbish - free image via Pixabay


, ,



No one has commented on this page yet.

Post your comment

The aim of the Office of Privacy Commissioner’s blog is to provide a space for people to interact with the content posted. We reserve the right to moderate all comments. We will not publish any content that is abusive, defamatory or is obviously commercial. We ask for your email address so that we can contact you if necessary to clarify your comment. Please be respectful of authors and others leaving comments.