ICO Penalises Metropolitan Police Over Serious Data Protection Failures

Share this Article:

The Information Commissioner’s Office (ICO) has issued an enforcement notice and a formal reprimand to the Metropolitan Police Service (MPS) following significant failures in handling sensitive personal information.

The regulator concluded that these incidents were not isolated mistakes, but reflected broader structural weaknesses across data protection governance, staff training and internal monitoring.

What Triggered the Action?

The ICO investigated two separate operational data breaches involving the unlawful disclosure of personal details:

  1. Stalking Protection Order Disclosure: Unredacted documents were handed directly to an alleged stalker, exposing the victim’s new home address, phone number and witness contact details. The victim had changed her contact details specifically to escape the individual. The ICO found that redaction procedures had failed, quality assurance checks were missing and the officers involved had received no specialist training.

  2. “Honeytrap” Email Breach: An email sent to 18 individuals linked to a high-profile parliamentary investigation placed all recipient addresses in the “To” field rather than using “BCC” or separate emails. Although the email body contained no sensitive details, exposing the list allowed recipients to infer sensitive facts about each other.

Why the Regulator Stepped In

Under the Data Protection Act 2018, organisations are legally required to maintain appropriate technical and organisational safeguards. The ICO’s investigation highlighted low completion rates for mandatory data protection training, weak management oversight and poor governance across the force. In one case, key officers had not completed refresher training in more than four years.

The MPS has now been ordered to improve training compliance, governance, and assurance procedures within strict timeframes.

Essential Lessons for Businesses

This enforcement action highlights a clear operational reality: severe data breaches frequently stem from everyday human error rather than sophisticated cyber attacks.

To minimise risk and maintain compliance, organisations should make sure that:

  • Mandatory data protection training is completed by all staff and is regularly refreshed.

  • Clear redaction protocols and secondary checks are embedded into high-risk document workflows.

  • Group email communications are carefully controlled using dedicated mailing platforms or strict procedures.

  • Compliance rates, training logs and internal policies are routinely audited by management.

Privacy Helper Comment

The ICO’s action against the Metropolitan Police demonstrates that regulatory scrutiny extends beyond cyber security incidents and includes day-to-day operational failures. Organisations should recognise that even simple mistakes, such as sending an email incorrectly or failing to remove sensitive information from documents, can have serious consequences for individuals and lead to regulatory enforcement. Effective training, oversight and accountability remain essential components of a strong data protection framework.

How Privacy Helper Can Support Your Business

If your internal teams lack the capacity for continuous oversight, engaging an outsourced Data Protection Officer (DPO) gives your organisation expert accountability, regular compliance audits and proactive risk management. Speak to us to make sure you are compliant.

About the Author:

Explore More Articles