ICO orders MPS to improve data protection after serious disclosure breaches

The Information Commissioner’s Office (ICO) has ordered the Metropolitan Police Service (MPS) to improve its data protection practices after identifying serious failings that led to the unlawful disclosure of sensitive personal information in two separate cases.

Aug 5, 2026

The regulator has issued the force with an enforcement notice and a reprimand after concluding the breaches reflected wider weaknesses in data protection training, governance and compliance.

One incident saw an officer serving unredacted documents in a Stalking Protection Order case, revealing a victim’s new address and telephone number to the alleged stalker, along with the personal details of three witnesses. The victim had changed her contact details because of concerns for her safety, and the defendant later used the disclosed information to contact her.

A second breach involved the investigation into the so-called “honeytrap” affair, in which people linked to the UK Parliament were targeted via WhatsApp messages. An officer emailed 18 people affected by the investigation using the “To” field rather than blind copy, disclosing recipients’ names and email addresses to everyone on the distribution list.

The ICO found the incidents were not isolated mistakes but highlighted broader shortcomings in the force’s data protection arrangements. It found low compliance with mandatory data protection training, with one officer and their line manager having gone almost four years without completing the required training.

The enforcement notice requires the MPS to improve its data protection training, monitoring and governance within three and 12 months.

Jo Stones, ICO group manager for Civil and Cyber Investigations, said: “People entrust the police with some of their most sensitive personal information, often at moments when they are vulnerable or at risk. They have the right to expect that information will be handled securely.

“In these cases, the Metropolitan Police Service failed to put in place the safeguards needed to protect people’s personal information. One breach exposed a stalking victim’s new contact details to the person she needed protection from. Another revealed the identities of people connected to a highly sensitive investigation.”

The MPS has since introduced additional safeguards, including further specialist training for officers dealing with Stalking Protection Orders, a strengthened quality assurance process and a behavioural alert tool that warns staff when emails are being sent to multiple external recipients.

However, the ICO said further improvements were needed, noting that mandatory training completion rates remained too low and that planned monitoring and technical measures had yet to be fully implemented.

Related News

Select Vacancies

Assistant Chief Constables

South Wales Police

Deputy Chief Constable

Essex Police

Copyright © 2026 Police Professional