Metropolitan Police Ordered to Overhaul Data Protection After Two Preventable Disclosure Failures

Metropolitan Police Ordered to Overhaul Data Protection After Two Preventable Disclosure Failures

By
Key Takeaways
  • ICO Orders Metropolitan Police Reforms: The UK's Information Commissioner's Office issued the Metropolitan Police Service with both a reprimand and an enforcement notice after finding failures to implement appropriate technical and organizational measures to protect personal information under the Data Protection Act 2018.
  • Sensitive Personal Information Was Exposed: One breach revealed a stalking victim's new address and telephone number to the defendant in a Stalking Protection Order case, while another exposed the identities of 18 people connected to the "Honeytrap" criminal investigation through an improperly addressed email.
  • Regulator Found Systemic Weaknesses: The ICO concluded the incidents reflected broader deficiencies in the Metropolitan Police's data protection policies, governance, quality assurance processes, and oversight rather than isolated human errors.
  • Training Compliance Was Inadequate: Investigators found significant shortcomings in mandatory data protection training, including officers and managers who had not completed required training for nearly four years and low force-wide compliance rates.
Deep Dive

The Information Commissioner's Office did not describe the Metropolitan Police Service's latest data protection failures as isolated mistakes. After investigating two unrelated disclosures of highly sensitive personal information, the regulator concluded that both pointed to the same underlying problem: basic safeguards had been allowed to weaken inside one of Britain's largest police forces.

On Tuesday, the ICO issued the Metropolitan Police with a reprimand and an enforcement notice after finding that the force had failed to implement appropriate technical and organizational measures to protect personal information, in breach of Section 40 of the Data Protection Act 2018. The enforcement notice requires improvements to data protection training, monitoring, and governance over the next three and twelve months.

The first breach unfolded during proceedings for a Stalking Protection Order. According to the ICO, an MPS officer served court documents on the defendant without properly redacting them. Buried inside were the victim's new address and telephone number, along with the names and contact details of three witnesses.

The significance of that omission was immediate rather than theoretical. The victim had changed both her address and telephone number because of the danger she faced. After receiving the documents, the defendant contacted her on the new number and told her he had obtained it from paperwork supplied by the Metropolitan Police.

The ICO concluded that confidential third-party information should never have left police hands in that form. Officers involved had not completed the specialist training required for Stalking Protection Order cases, the regulator found, and the force's process for preparing and checking documents before they were served failed to catch what should have been an obvious error.

The second incident looked different on the surface but revealed the same weakness beneath it. It concerned the so-called "Honeytrap matter," the investigation into attempts during 2024 and 2025 to obtain compromising information from people connected to the UK Parliament through WhatsApp messages. When an MPS officer needed to notify those affected that a suspect's bail date had changed, the message went to everyone at once. Their names and email addresses were entered into the "To" field rather than concealed from one another.

The email itself disclosed little beyond the administrative update. The context disclosed far more. Because every recipient could see everyone else, the identities of 18 people connected to the investigation became visible to one another. In a case built around sensitive allegations and prominent public figures, that alone was enough for the ICO to conclude that the Metropolitan Police had chosen the wrong method of communication entirely.

Beyond Human Error

The regulator's findings become more troubling precisely because they refuse the easy explanation. Neither breach, the ICO concluded, was simply the result of an officer making a bad decision on a difficult day. Investigators found broader weaknesses running through the force's policies, oversight arrangements, and assurance processes for handling sensitive personal information. The failures shared a common origin.

Training was one of the clearest symptoms. The officer responsible for the bulk email had not completed mandatory data protection training for more than four years before the incident. The officer's line manager had also gone almost four years without completing the relevant training. Across the wider organization, mandatory Managing Information training completion rates remained low enough that the Metropolitan Police itself acknowledged further improvement was necessary.

That matters because data protection rarely fails in spectacular ways at first. It begins quietly, with routines that stop feeling mandatory, checks that become assumptions, governance that exists on paper but not in practice. By the time personal information reaches the wrong person, the real failure has usually happened months or years earlier.

For the ICO, those conditions amounted to a breach of Section 40 of the Data Protection Act 2018, which requires organizations to implement appropriate technical and organizational measures to protect personal information. The regulator responded with both a reprimand and an enforcement notice requiring the Metropolitan Police to improve its training compliance, monitoring, and governance within three and twelve months.

Jo Stones, the ICO's Group Manager for Civil and Cyber Investigations, said people often provide police with their most sensitive personal information when they are at their most vulnerable and have every right to expect it will be protected.

She said one incident exposed a stalking victim's contact details to the very person she sought protection from, while the other disclosed the identities of people connected to a highly sensitive investigation. Both incidents, she said, were foreseeable and preventable, adding that organizations handling sensitive law enforcement information cannot rely on written policies alone if they are not reinforced through effective training, monitoring, and oversight.

The Metropolitan Police has already taken steps to reduce the likelihood of similar failures. Following the stalking case, it notified those affected, offered additional support to the victim, expanded specialist training, and introduced a strengthened quality assurance process for Stalking Protection Order applications. After the email disclosure, it contacted the recipients, reminded staff of mandatory information security training, and introduced a behavioral alert tool designed to warn officers before emails are sent to multiple external recipients.

The ICO acknowledged those efforts without accepting them as enough. Training completion rates, it said, remain too low. Planned technical safeguards have yet to be fully implemented or demonstrated to work consistently. The force has begun repairing the machinery, but the regulator's message is that repair cannot be measured by intention. It has to be measured by whether the next vulnerable person can trust the system to keep a secret that was never theirs to protect alone.

The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.

Oops! Something went wrong