Brian Sims
Editor

Metropolitan Police Service issued with Enforcement Notice by ICO

THE INFORMATION Commissioner’s Office (ICO) has issued an Enforcement Notice and a reprimand to the Metropolitan Police Service after personal information relating to two highly sensitive police cases was erroneously disclosed.

The ICO found that the Metropolitan Police Service failed to put in place appropriate technical and organisational measures to protect people’s personal information, which is an infringement of Section 40 of the Data Protection Act 2018. The ICO’s investigation revealed a common issue of poor data protection training compliance rates at the Metropolitan Police Service with inadequate monitoring and governance.  

Incident one

A Metropolitan Police Service officer served unredacted documents to a defendant in a Stalking Protection Order (SPO) case. The documents included the victim’s new address and telephone number, as well as the names and contact details of three witnesses.

The victim had changed her address and phone number due to the risks she faced. The defendant later contacted the victim on her new number and said he had received documents containing her new contact details from the Metropolitan Police Service.

The ICO found that the Metropolitan Police Service failed to ensure confidential third party information was redacted before documents were served. The ICO also found that relevant officers had not received the required specialist SPO training at the time, and also that the process for preparing and quality assuring documents was inadequate.

Incident two

This related to the so-called ‘Honeytrap matter’, where people linked to the UK’s Parliament had been targeted by someone via WhatsApp messages in 2024 and 2025 in an attempt to gather compromising information.

A Metropolitan Police Service officer e-mailed all of the individuals affected to advise them of a change to the suspect’s bail date. The recipients’ e-mail addresses were placed in the ‘To’ field, meaning that all recipients could see each other’s e-mail addresses and names.

The context of the e-mail meant that highly sensitive information could potentially be inferred about the recipients, even though the body of the e-mail didn’t explicitly contain that information.

The Metropolitan Police Service confirmed that 18 individuals linked to the UK Parliament were affected. The ICO concluded that the Metropolitan Police Service should have used more appropriate methods to communicate with the affected individuals and not relied on sending one bulk e-mail in such sensitive circumstances. 

Investigation findings 

The ICO’s investigations revealed that the breaches were not isolated mistakes. Rather, they reflected wider weaknesses in Metropolitan Police Service policies, procedures and assurance arrangements for handling sensitive personal information.

The ICO also found serious and ongoing shortcomings in Metropolitan Police Service data protection training. The officer who sent the e-mail in the second incident had not completed data protection training for over four years before the incident, while the officer’s line manager had also not completed relevant training for almost four years prior to the incident occurring.

Wider completion rates for mandatory Managing Information-focused training were discovered to be low, with the Metropolitan Police Service itself acknowledging that further improvement is required.

As a result, the ICO issued the Metropolitan Police Service with a reprimand for the infringements identified in both incidents. The ICO also issued an Enforcement Notice requiring the Metropolitan Police Service to take steps within three and 12 months to improve its data protection training compliance, monitoring and governance arrangements.

Secure handling

Jo Stones, the ICO’s Group manager in charge of civil and cyber investigations, said: “People entrust the police service with some of their most sensitive personal information, often at moments when they’re vulnerable or at risk. They have the right to expect that this information will be handled securely.”

Stones continued: “In these cases, the Metropolitan Police Service failed to put in place the safeguards needed to protect people’s personal information. One breach exposed a stalking victim’s new contact details to the person from whom she needed to be protected. Another revealed the identities of individuals connected to a highly sensitive investigation.”

In conclusion, Stones noted: “These incidents were foreseeable and preventable. Our action makes clear that organisations, particularly so those in the public sector handling sensitive law enforcement information, must have effective training, monitoring and assurance in place. Policies and reminders are not enough if they’re not followed, checked and enforced.”

Steps towards mitigation 

The ICO considered remedial steps that the Metropolitan Police Service has taken when reaching its decision. These included notifying affected people, offering additional support in the SPO case, delivering further specialist training and embedding a strengthened multi-stage quality assurance process for SPO-centred applications.

Following the e-mail incident, the Metropolitan Police Service contacted the affected individuals, issued a force-wide reminder about mandatory information security training and introduced a new behavioural alert tool designed to prompt staff when e-mails are being sent to multiple external recipients.

The ICO considered these steps, but found that further action was still needed. Training completion rates remain low and some planned improvements, including wider technical solutions and stronger monitoring arrangements, had not yet been fully implemented or otherwise demonstrated to be effective.

*Further information is available online at www.ico.org.uk

Company Info

Western Business Media Limited

Dorset House
64 High Street
East Grinstead
RH19 3DE
UNITED KINGDOM

Login / Sign up