Info Gov

The Information Commissioner’s Office (ICO) has issued a formal reprimand to the City of London Police (CoLP) after finding that the force repeatedly failed to meet statutory deadlines for responding to subject access requests (SARs) over a twoyear period.

The reprimand, dated 20 February 2026, concludes that CoLP infringed Article 12(3) UK GDPR and section 45(3) of the Data Protection Act 2018, with the ICO determining that the force did not provide information to data subjects “without undue delay and in any event within one month” as required.

This story in a nutshell

  • The ICO has issued a formal reprimand to the City of London Police for failing to meet statutory deadlines for subject access requests under Article 12(3) UK GDPR and s45(3) DPA 2018.
  • Between April 2023 and July 2025, more than one‑third of SARs were not answered on time; compliance was as low as 30% in 2023–24.
  • The force held a backlog of 45 overdue SARs at its peak and provided the ICO with inaccurate compliance statistics during the investigation.
  • The ICO received 24 complaints, with some data subjects reporting emotional distress caused by prolonged delays.
  • City of London Police blamed resourcing pressures within its Information Access Team; action plans have since been implemented and the backlog cleared.
  • The ICO warns that repeat failings may lead to stronger enforcement action in future.

The ICO’s investigation found that between April 2023 and July 2025, CoLP failed to respond to more than onethird of SARs within the statutory timeframe. Compliance was particularly poor in 2023–24, when only 30% of requests were answered on time.

Although performance improved to 64% in 2024–25 and 93% in the first quarter of 2025–26, the Commissioner noted that the force had maintained a backlog of overdue SARs for much of the period, peaking at 45 outstanding requests in July 2024.

CoLP acknowledged in its representations that it “did not consistently meet its statutory obligations” during the relevant period.

The ICO received 24 complaints from data subjects between April 2023 and July 2025. Several complainants reported emotional distress caused by prolonged delays, with one individual telling the regulator they had been “worrying about not receiving any response” from the force.

CoLP attributed its failings to significant resourcing pressures within its central Information Access Team, which handles SARs alongside FOI and EIR requests. The force reported increased FOI volumes, staff absences, and reliance on temporary personnel.

The ICO also criticised CoLP for providing inaccurate SAR statistics during the investigation, citing miscategorisation of thirdparty enquiries and errors in extracting data from internal systems. Revised figures had to be requested on multiple occasions.

CoLP submitted a SAR Action Plan in August 2024, including recruitment of a temporary data protection specialist, process improvements, and new KPIs. The force later pointed to its Freedom of Information Act (FOIA) Action Plan - implemented following a separate enforcement notice- as also covering SARrelated improvements, though the ICO noted that the FOIA plan initially lacked SARspecific detail.

By November 2025, CoLP reported that it had cleared its SAR backlog.

While the reprimand itself carries no financial penalty, the ICO recommended that CoLP continues to strengthen its internal systems for identifying, logging and responding to SARs. The Commissioner warned that any future repeat of the failings could be treated as an aggravating factor when considering further enforcement action.

Also in this section

May 26, 2026

Key Data Protection Issues for Automated Recruitment in the Public Sector

The need to recruit faster in a competitive market, the need to minimise costs in the recruitment process, and the need to secure the best candidate quickly, makes the use of AI an appealing option for any employer including public bodies. But there are pitfalls for the unwary write David Leach and Charlotte Smith.
May 08, 2026

Schools warned over AI blackmail threat as guidance urges rethink on pupil images

Schools across the UK are being urged to review or remove identifiable photographs of pupils from their websites and social media accounts, following warnings that criminals are using artificial intelligence tools to manipulate those images into child sexual abuse material (CSAM) and then threaten to release it unless a ransom is paid.
Apr 28, 2026

AI in Education: Why Data Protection Must Come First

Artificial Intelligence promises a lot. It can undoubtedly do amazing things. But secretly (or maybe not so secretly), it also makes us slightly nervous. Adam Halsey looks at what this means for schools, and why data protection needs to sit at the centre of any decision to use AI.
Apr 22, 2026

Preparing for the new complaints regime

From 19 June 2026, all organisations acting as data controllers are required to have in place an effective process to enable individuals to raise complaints about how their personal data is handled. Ashleigh Dibb looks at what this will mean in practice.
Apr 17, 2026

When data protection doesn’t protect you

Recently, the Information Commissioner’s Office published the outcome of a criminal prosecution. The title? Just two names: Christopher Munro and William Chipoma. No explanation. No softening. No anonymity. And that, in itself, is a powerful lesson in how data protection law really works.

InfoGov Masthead Newsletter 800