TechNewsReel
Live

ICO Reprimands Metropolitan Police Over Serious Data Protection Failures

The UK data watchdog issued an enforcement notice after a stalking victim's details were leaked to a defendant and parliamentary contacts were exposed.

TechNewsReel Newsroom · August 5, 2026

The Information Commissioner's Office (ICO) has issued a formal reprimand and enforcement notice to the Metropolitan Police Service (MPS) following two serious data breaches. The watchdog cited systemic failures in training and governance that compromised the safety of a vulnerable witness and the privacy of government-linked individuals.

In the first instance, the MPS sent unredacted documents in a Stalking Protection Order case to a defendant, revealing the victim's new address and phone number. This breach forced the victim to move house and change her contact details to ensure her safety. In a separate incident involving a 'honeytrap' case, the police sent a group email to 18 people associated with the UK Parliament. By placing all recipients in the 'To' field rather than using BCC, the MPS exposed the names and email addresses of all 18 individuals to one another.

Systemic Training Failures

An investigation by the ICO revealed that these errors were not merely isolated mistakes but the result of "serious shortcomings" in policy and oversight. Most notably, the ICO found that the officer responsible for sending the honeytrap email, as well as their direct line manager, had not completed mandatory data protection training for more than four years prior to the breach. The watchdog characterized the force's existing policies as "weak" and insufficient to prevent such lapses.

Implications for Public Safety

These failures represent a critical breakdown in the safeguarding of high-risk individuals. When law enforcement agencies fail to protect the identity of stalking victims, the consequences can be life-threatening, shifting the burden of security onto the victim. Furthermore, the exposure of parliamentary contacts highlights a lack of basic digital hygiene within an organization handling some of the state's most sensitive information.

Jo Stones of the ICO emphasized that public sector organizations must maintain rigorous monitoring and assurance. "Policies and reminders are not enough if they are not followed, checked and enforced," Stones stated, noting that effective training is mandatory for those handling law enforcement data.

Required Remediation

Under the terms of the enforcement notice, the Metropolitan Police has been ordered to urgently overhaul its data protection framework. The ICO has mandated that the MPS improve its training compliance, monitoring, and governance arrangements, with specific deadlines for implementation set at three and 12 months. The force must now demonstrate that it can reliably protect the sensitive data of witnesses and public officials to avoid further regulatory action.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.