ICO issues formal reprimand to ACRO over website security failings
Published: 12/08/2026
| ICO
The Information Commissioner's Office (ICO) has formally reprimanded the ACRO Criminal Records Office (ACRO) for infringements of Articles 32(1), 32(1)(b) and 32(1)(d) of the UK General Data Protection Regulation (GDPR) following cybersecurity failures that could have exposed the personal data of up to 10,920 people.
An ICO investigation revealed that between August 2022 and March 2023, a hacker gained unauthorised access to ACRO's website and content management system (CMS). The hacker collected data from various locations and staged it in a hidden location for later exfiltration. The data included names, dates of birth, addresses, National Insurance numbers, passport and driving licence details, bank accounts, biometric data, and highly sensitive criminal offence information. While ACRO could not conclusively state whether the data was removed from its systems, potentially affected individuals included applicants for Police Certificates and International Child Protection Certificates, as well as subjects of subject access requests.
The ICO found ACRO failed to ensure clear responsibility for monitoring critical security updates, lacked an effective patch management process despite hiring third-party security providers, and failed to investigate security alerts adequately.
In issuing a reprimand rather than a harsher penalty, the ICO noted that network segmentation prevented the hacker from accessing core systems. The ICO also welcomed ACRO's remedial actions, which included decommissioning the compromised infrastructure, migrating services, strengthening network segmentation, and enhancing threat monitoring.
Following the announcement, a debate has emerged after a comment by Owen S on a LinkedIn post by Jon Baines (see also this follow up post) concerning why the reprimand had been "issued under the UK GDPR, given that ACRO were processing as a Law Enforcement Authority under paragraph 17 of Schedule 7 of the Data Protection Act 2018, and, therefore, Part 3 of the DPA, and not the UK GDPR, applies."
Training announcement: Freevacy provides comprehensive training for new and existing practitioners on the changes introduced by the DUA Act to the UK General Data Protection Regulation (GDPR), the Data Protection Act 2018 (DPA18), and the Privacy and Electronic Communications Regulations 2003 (PEC-Regulations). Our courses are always up to date and provide a forum for learning and discussing how to ensure your data protection processes remain compliant. Find out more.
What is this page?
You are reading a summary article on the Privacy Newsfeed, a free resource for DPOs and other professionals with privacy or data protection responsibilities helping them stay informed of industry news all in one place. The information here is a brief snippet relating to a single piece of original content or several articles about a common topic or thread. The main contributor is listed in the top left-hand corner, just beneath the article title.
The Privacy Newsfeed monitors over 300 global publications, of which more than 3,250 summary articles have been posted to the online archive dating back to the beginning of 2020. A weekly roundup is available by email every Friday.