August 7, 2026
metropolitan-police-issued-with-enforcement-notice-and-reprimand-by-information-commissioners-office-to-radically-overhaul-data-protection-protocols

The Metropolitan Police Service (MPS) has been served with a formal enforcement notice and a severe reprimand by the Information Commissioner’s Office (ICO), mandating substantial improvements to its data protection training, monitoring, and overall governance arrangements. This decisive action by the UK’s data watchdog comes after investigations uncovered "multiple weaknesses" within the force’s handling of personal information, leading to orders for immediate and comprehensive changes to mitigate the significant risk of unlawful disclosure of highly sensitive data. The ICO concluded that the MPS had failed to implement appropriate technical and organisational measures to safeguard individuals’ personal information, constituting a clear infringement of Section 40 of the Data Protection Act 2018.

Background to the Regulatory Action

The Information Commissioner’s Office serves as the independent authority established to uphold information rights in the public interest, promoting openness by public bodies and data privacy for individuals. Under the Data Protection Act 2018 (DPA 2018), which supplements the UK General Data Protection Regulation (UK GDPR), the ICO has broad powers to investigate data breaches, issue warnings, reprimands, enforcement notices, and impose substantial fines. Part 3 of the DPA 2018 specifically governs the processing of personal data by competent authorities for law enforcement purposes, underscoring the critical need for robust data security within police forces. Section 40 of this Act mandates that controllers must implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, especially concerning the processing of sensitive personal data inherent in law enforcement activities.

The Met Police, as the largest police force in the United Kingdom, holds an unparalleled volume of highly sensitive personal data, ranging from criminal records and victim details to intelligence reports and health information. The public entrusts the police with this information, often during moments of extreme vulnerability, with a fundamental expectation that it will be handled with the utmost security, integrity, and discretion. Breaches of this trust can have severe real-world consequences, from compromising investigations to endangering individuals, and can significantly erode public confidence in law enforcement. This latest action by the ICO highlights a critical failing in the Met’s adherence to these foundational principles of data protection.

Uncovering Systemic Failures: Two Incidents Illuminate Broader Weaknesses

The ICO’s decision stems from thorough investigations into two distinct, yet equally concerning, data protection incidents within the Metropolitan Police Service. These incidents, far from being isolated errors, were found to "reflect wider weaknesses in MPS policies, procedures and assurance arrangements for handling sensitive personal information." The regulator emphasised that these were not mere oversights but symptoms of systemic deficiencies that required immediate and significant remediation.

Incident One: Endangering a Stalking Victim

The first incident, which directly led to the reprimand, involved the egregious disclosure of a stalking victim’s unredacted personal details to the very individual from whom she sought protection. A police officer, tasked with serving documents to a defendant in a stalking case, inadvertently provided papers that contained the victim’s new address and phone number. This was particularly alarming given that the victim had previously changed her contact details specifically due to the risks she faced from the stalker. Compounding the severity, the documents also included the contact details of three witnesses involved in the case. The catastrophic nature of this breach was confirmed when the defendant subsequently contacted the victim on her newly compromised phone number, explicitly stating that he had obtained her updated contact information directly from the police-served documents.

The ICO’s investigation into this incident revealed multiple layers of failure. Firstly, the Met had failed to ensure that confidential third-party information was properly redacted before documents were served, a basic and fundamental step in data protection protocols. Secondly, it was found that the relevant police officers involved had not received the required specialist training on Stalking Protection Orders (SPOs) at the time of the incident. This lack of specific training meant officers were ill-equipped to understand the critical importance of data security in such sensitive cases and the potentially life-threatening implications of disclosure. Thirdly, the process for preparing and quality assuring legal documents was deemed inadequate, indicating a severe lapse in internal checks and balances designed to prevent such disclosures. The psychological and physical safety implications for the victim and witnesses in this case were profound, underscoring the tangible harm that can arise from data protection failures.

Incident Two: Mass Email Disclosure of Sensitive Identities

The second incident, which contributed to the enforcement notice, involved the improper disclosure of personal email addresses of individuals linked to Parliament. This incident occurred in the context of an investigation into a series of WhatsApp messages sent in 2024 and 2025, targeting various people connected to Parliament in an attempt to gather compromising information. A Met police officer, intending to advise the affected individuals of a change to the suspect’s bail date, sent a bulk email where all recipients’ email addresses were placed in the "To" field. This meant that every recipient could view the email addresses and names of all other recipients.

While the body of the email itself did not explicitly contain highly sensitive information about the recipients, the context of the communication was crucial. The email implicitly linked all recipients to a highly sensitive investigation concerning attempts to gather compromising information related to Parliament. The mere fact of being included in such an email could allow for highly sensitive inferences to be drawn about individuals’ connections and potential vulnerabilities. The Met Police confirmed that 18 people linked to Parliament were affected by this breach. The ICO concluded that, given the extremely sensitive nature of the investigation and the individuals involved, the Met should have employed more appropriate and secure communication methods, rather than relying on a single bulk email, which inherently carries a high risk of disclosure in such circumstances.

ICO’s Stern Admonition: "Foreseeable and Preventable" Failures

ICO finds ‘serious’ flaws in Met Police’s data protection training

Jo Stones, ICO Group Manager for Civil and Cyber Investigations, unequivocally condemned the Met’s failings, stating, "People entrust the police with some of their most sensitive personal information, often at moments when they are vulnerable or at risk. They have the right to expect that information will be handled securely." Stones highlighted the direct and severe consequences of the breaches: "One breach exposed a stalking victim’s new contact details to the person she needed protection from. Another revealed the identities of people connected to a highly sensitive investigation."

Crucially, Stones emphasised the preventable nature of these incidents: "These incidents were foreseeable and preventable." Her statement underscored the systemic nature of the problem, asserting, "Our action makes clear that organisations, particularly those in the public sector handling sensitive law enforcement information, must have effective training, monitoring and assurance in place. Policies and reminders are not enough if they are not followed, checked and enforced."

The ICO’s investigation into the second incident specifically revealed a glaring deficiency in mandatory training compliance. The police officer who sent the bulk email, along with their line manager, had not completed mandatory data protection training for over four years prior to the incident. More broadly, the investigation uncovered low completion rates across the force for essential managing information training. The Met Police itself acknowledged that further significant improvement was required in this area, indicating a recognised but unaddressed problem.

Broader Context: Data Protection Challenges in the Public Sector

The Met Police’s predicament is not entirely unique within the broader landscape of public sector data handling, though the scale and sensitivity of its operations make its failures particularly impactful. Public sector organisations, including police forces, healthcare providers, and local councils, routinely manage vast quantities of personal data, often operating under immense pressure and with constrained resources. The ICO frequently issues warnings, reprimands, and enforcement notices to various public bodies, highlighting a persistent challenge in embedding robust data protection practices. In 2023, for instance, the ICO issued numerous reprimands and enforcement notices across sectors, with a significant proportion directed at government and policing bodies, reflecting ongoing struggles with data governance, training, and security.

Statistics on data breaches consistently show that human error, often linked to inadequate training or procedural lapses, remains a leading cause of incidents. A significant percentage of reported breaches involve misconfigured systems, insecure disposal of data, or, as seen in these Met cases, incorrect emailing practices and failure to redact sensitive information. The cost of data breaches, both reputational and operational, can be substantial. While the ICO did not impose a monetary penalty in this instance, the reputational damage and the diversion of resources to implement remedial actions represent a significant indirect cost. Moreover, a failure to comply with an enforcement notice can lead to far more severe penalties, including substantial fines, in the future.

Met Police Response and Remedial Actions

In response to the ICO’s findings, a Metropolitan Police spokesperson issued an apology, acknowledging the potential "real consequences for victims" and extending apologies to those affected by the two cases. The spokesperson affirmed the Met’s commitment to addressing the issues: "The Met has taken significant steps to strengthen information disclosure processes, as acknowledged by the ICO, and remains committed to ensuring the right training and safeguards are in place to prevent similar breaches from happening again in the future."

The ICO’s decision did take into account various remedial steps already undertaken by the Met Police following the incidents. These included:

  • Notification and Support: Promptly notifying the affected individuals and offering additional support, particularly in the highly sensitive stalking protection order case.
  • Specialist Training: Delivering further specialist training specific to the handling of Stalking Protection Orders.
  • Quality Assurance: Embedding a strengthened multi-stage quality assurance process for SPO applications, aiming to prevent future redaction failures.
  • Email Incident Response: Following the bulk email incident, the Met Police contacted the affected individuals, issued a force-wide reminder about mandatory information security training, and introduced a new behavioural alert tool. This tool is designed to prompt staff when emails are being sent to multiple external recipients, encouraging a pause and review of the recipient list and communication method.

However, despite these efforts, the data protection regulator found that "further action was still needed." The ICO’s assessment indicated that training completion rates across the force remained low, suggesting that reminders and new tools were not yet fully translating into a culture of consistent compliance. Furthermore, some planned improvements, including broader technical solutions and stronger monitoring arrangements, had not yet been fully implemented or demonstrably proven effective. This highlights an ongoing gap between policy, intention, and actual operational practice within the force.

Implications for Public Trust and Future Policing

The ICO’s enforcement action against the Metropolitan Police carries significant implications, particularly concerning public trust and the operational integrity of the force. The Met has faced considerable scrutiny in recent years regarding its standards, conduct, and accountability. Incidents of data mismanagement only exacerbate existing concerns about the force’s ability to protect the very citizens it is sworn to serve. For victims of crime, particularly those in vulnerable situations like stalking victims, the assurance that their sensitive information will be handled securely is paramount to their willingness to engage with law enforcement and seek justice. Breaches like the one detailed here can shatter that trust, potentially deterring future reporting and cooperation.

Operationally, this reprimand and enforcement notice necessitate a fundamental shift in the Met’s approach to data protection. It can no longer be viewed as a peripheral compliance exercise but must be ingrained as a core operational principle at every level of the organisation. This will require not only sustained investment in training and technology but also a cultural transformation that prioritises data privacy and security. The "foreseeable and preventable" nature of these incidents implies a systemic failure to learn from past mistakes or to proactively identify and mitigate risks.

The ICO’s action serves as a stark reminder to all public sector organisations, especially those in law enforcement, of their profound responsibilities under data protection legislation. It underscores that robust policies are meaningless without effective implementation, consistent monitoring, and a culture of accountability. The Met Police now faces a critical period where it must demonstrate not just a willingness to improve, but tangible, measurable progress in overhauling its data protection framework to regain public confidence and ensure the safety and privacy of those it serves. Failure to comply fully with the ICO’s demands could lead to more severe sanctions, further eroding its standing and impacting its ability to effectively police the capital.