Metropolitan Police ordered to tighten data security after sensitive information leaks
“These incidents were foreseeable and preventable.”

Image by Loredana Sangiuliano | Shuttterstock
- The ICO reprimanded the Metropolitan Police after two separate data breaches exposed victims’ personal information.
- One officer failed to redact documents, revealing a victim’s new address, phone number, and witness contact details.
- In another case, an officer exposed 18 recipients’ names and email addresses by misusing the email field.
- The ICO said the incidents showed wider weaknesses in Met Police data protection training, procedures, and oversight.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
The Information Commissioner’s Office (ICO) has reprimanded the Metropolitan Police Service and ordered it to improve its handling of personal information after data was leaked in 2 highly sensitive police cases.
According to the UK’s data protection regulator, the personal information of victims was exposed in 2 separate cases because it failed to implement appropriate technical and organizational measures.
In the first case, a Metropolitan police officer neglected to redact documents for a defendant in a stalking protection order (SPO) case.
Consequently, the victim’s new address and telephone number, as well as the names and contact details of three witnesses, ended up in the suspect's hands. The defendant contacted the victim on her new number, saying that he got her contact information from the Metropolitan Police.
In an unrelated matter, a police officer sent an email to people who had been targeted on WhatsApp by someone attempting to gather compromising information.
The officer placed the recipients’ email addresses in the “To” field, meaning that all recipients could see each other’s names and email addresses. A total of 18 people were affected by the officer’s mistake.
The ICO’s investigation revealed that the breaches weren’t isolated incidents. Instead, they reflected a “wider weakness in the Metropolitan Police Service’s policies, procedures, and assurance arrangements” for handling sensitive personal information. Researchers also found ongoing shortcomings in data protection training.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
“These incidents were foreseeable and preventable. Our action makes clear that organizations, particularly those in the public sector handling sensitive law enforcement information, must have effective training, monitoring, and assurance in place. Policies and reminders are not enough if they are not followed, checked, and enforced,” Jo Stones, ICO Group Manager Civil and Cyber Investigations, said in a response.
Stones emphasizes that people should be able to entrust the police with some of their most sensitive personal information, especially at moments when they are vulnerable or at risk.
“They have the right to expect that information will be handled securely,” he concludes.
Because of the severity and implications of the incidents, the ICO issued an enforcement notice and reprimand to the Metropolitan Police.
An enforcement notice is one of the ICO’s strongest regulatory powers and requires an organization to take corrective measures. Failing to comply can lead to further action.