VYPR
breachPublished Aug 5, 2026· 1 source

London Police Cited for Mishandling Sensitive Data, Including Victim's Location

The UK's data protection watchdog has reprimanded London's Metropolitan Police Service for two significant data handling failures in 2024, including one where a stalking victim's new contact details were given to her abuser.

London's Metropolitan Police Service (MPS) has been issued an enforcement notice and a reprimand by the UK's Information Commissioner's Office (ICO) following two serious data protection failures that occurred in 2024. These incidents highlight broader weaknesses in the MPS's policies and procedures for managing sensitive personal information.

The first incident involved a man subject to an interim Stalking Protection Order (SPO) who had been arrested for harassment and malicious communications. Despite the victim having to change her phone number and home address for her safety, officers mistakenly provided the perpetrator with unredacted documents, including witness statements that contained the victim's new contact details and those of her family. This breach occurred despite explicit warnings that all personal information must be redacted. Tragically, the victim reported being contacted by the man on her new number within days, shortly before he fled the UK. He was later arrested upon re-entering the country and imprisoned after pleading guilty to stalking offenses.

The second incident involved a significant email blunder where the MPS inadvertently exposed the email addresses of 18 individuals involved in a sensitive honeytrap operation. While attempting to update those affected about a suspect's bail date, an officer failed to use the BCC function, sending the email to all recipients in the 'To' field and revealing their identities to one another. The MPS reported this breach immediately, acknowledging the potential for recipients to identify each other, though some email accounts had been deactivated.

The ICO's investigation revealed that the officer responsible for the email blunder had not completed data protection training for over four years, and their line manager had a similar lapse. The regulator noted that completion rates for data protection training were generally low across the force, indicating systemic issues.

Jo Stones, group manager of civil and cyber investigations at the ICO, emphasized the critical importance of secure data handling, stating, "People entrust the police with some of their most sensitive personal information, often at moments when they are vulnerable or at risk. They have the right to expect that information will be handled securely." She added that the MPS had failed to implement necessary safeguards in these instances, leading to foreseeable and preventable breaches.

In response to the ICO's findings, the MPS has committed to improving its data protection practices. Over the next 12 months, the force must work towards achieving 100 percent completion of data protection training for its staff, with follow-ups for those who miss deadlines. Additionally, the MPS will conduct quarterly reviews of its email communication procedures for multiple recipients, explore more secure alternatives, and report its training progress to the ICO.

These enforcement actions underscore the significant responsibility public sector organizations, particularly law enforcement agencies, have in safeguarding sensitive personal data. The ICO's intervention serves as a stark reminder that policies and reminders are insufficient if not rigorously followed, checked, and enforced.

Synthesized by Vypr AI