The UK Information Commissioner’s Office has reprimanded the Metropolitan Police Service after two separate incidents exposed highly sensitive personal information.
The regulator said the Metropolitan Police data leaks were foreseeable and preventable. It has issued both a reprimand and an enforcement notice requiring the force to improve its data protection practices.
The cases involved information belonging to vulnerable victims and witnesses. The ICO said they revealed broader failures in police training, procedures, oversight, and assurance arrangements.
Unredacted documents exposed stalking victim’s new address
In the first incident, a Metropolitan Police officer failed to properly redact documents in a stalking protection order case.
The documents were provided to the defendant and included the victim’s new address and telephone number. They also revealed the names and contact details of three witnesses.
The defendant later contacted the victim on her new phone number and said he had obtained the information from the Metropolitan Police.
For people at risk of stalking or harassment, exposing a new address or contact number can create serious safety concerns. It can also undermine confidence in the police at a time when victims may already feel vulnerable.
Email mistake exposed 18 recipients
The second incident involved an unrelated police email sent to people who had been targeted on WhatsApp by someone seeking compromising information.
An officer put all recipients in the “To” field rather than using a method that concealed their details. As a result, every recipient could see the names and email addresses of the other people contacted.
A total of 18 people were affected.
Although the leak was smaller, it still exposed the identities of people linked to a sensitive investigation. The ICO said police organisations must take particular care when handling information that could reveal a person’s circumstances, risks, or involvement in a case.
ICO finds wider data protection failures
The watchdog concluded that the Metropolitan Police data leaks did not represent isolated mistakes.
Instead, the ICO found wider weaknesses in the force’s policies, procedures, and assurance arrangements for handling sensitive personal information. It also identified continuing gaps in data protection training.
Jo Stones, Group Manager for Civil and Cyber Investigations at the ICO, said policies and reminders are not enough if organisations fail to follow, monitor, and enforce them.
The regulator stressed that people should be able to trust police forces with their most sensitive information, especially when they are at risk or seeking help.
Enforcement notice requires action
Because of the severity of the incidents, the ICO issued an enforcement notice alongside its reprimand.
An enforcement notice is one of the regulator’s strongest powers. It requires an organisation to take specific corrective measures, and failure to comply can result in further action.
The Metropolitan Police must now strengthen the way it protects personal information. That is likely to require improved training, tighter checks on document redaction, clearer email-handling practices, and stronger management oversight.
The case is a reminder that data security does not depend only on cyber defences. Everyday errors, such as sending an email to the wrong field or failing to remove sensitive details from a document, can put people at real risk.


0 responses to “Metropolitan Police Ordered to Strengthen Data Security After Victim Information Leaks”