ICO reprimands Met Police over poor data protection governance and training
Published: 05/08/2026
| ICO
The Information Commissioner's Office (ICO) has issued an enforcement notice and reprimand to the Metropolitan Police Service (MPS) following the disclosure of personal information in two highly sensitive police cases. An ICO investigation found the MPS breached section 40 of the Data Protection Act 2018 (DPA) by failing to implement appropriate technical and organisational measures to safeguard data.
In the first incident, an MPS officer served unredacted documents to a defendant in a Stalking Protection Order (SPO) case, revealing the victim’s new address and phone number, as well as contact details for three witnesses. The victim had moved specifically to avoid risk but was called by the defendant as a result of the disclosure. The ICO noted that relevant officers lacked specialist SPO training and that document preparation and quality assurance processes were inadequate.
In the second incident, connected to the Honeytrap incident involving parliamentarians targeted via WhatsApp in 2024 and 2025 that led to a Conservative MP resigning from two Parliamentary Committees. The ICO found that an officer sent a bulk email about a suspect's bail date, exposing 18 parliamentary-linked email addresses in the "To" field, allowing sensitive inferences to be drawn.
The ICO concluded the breaches reflected systemic weaknesses in MPS policies, governance, and training. The officer in the second incident and their line manager had not completed data protection training for over four years. The ICO issued an enforcement notice requiring the MPS to improve training compliance, monitoring, and governance within three and 12 months.
Training announcement: Freevacy provides comprehensive training for new and existing practitioners on the changes introduced by the DUA Act to the UK General Data Protection Regulation (GDPR), the Data Protection Act 2018 (DPA18), and the Privacy and Electronic Communications Regulations 2003 (PEC-Regulations). Our courses are always up to date and provide a forum for learning and discussing how to ensure your data protection processes remain compliant. Find out more.
What is this page?
You are reading a summary article on the Privacy Newsfeed, a free resource for DPOs and other professionals with privacy or data protection responsibilities helping them stay informed of industry news all in one place. The information here is a brief snippet relating to a single piece of original content or several articles about a common topic or thread. The main contributor is listed in the top left-hand corner, just beneath the article title.
The Privacy Newsfeed monitors over 300 global publications, of which more than 3,250 summary articles have been posted to the online archive dating back to the beginning of 2020. A weekly roundup is available by email every Friday.