Info Gov

The Information Commissioner’s Office (ICO) has issued an enforcement notice and reprimand to the Metropolitan Police Service (Met Police) after personal information in two highly sensitive police cases was erroneously disclosed.

The ICO’s investigation into the police service revealed a common issue of poor data protection training compliance rates at the MPS with inadequate monitoring and governance.

The first incident involved a Met Police officer serving unredacted documents disclosing the victim’s new address and telephone number, as well as the names and contact details of three witnesses, to a defendant in a Stalking Protection Order (SPO) case.

The defendant later contacted the victim on her new number and said he had received documents containing her new contact details from the Met Police.

The ICO found Met Police failed to ensure confidential third-party information was redacted before documents were served, and relevant officers had not received the required specialist SPO training at the time.

The second incident involves the well-publicised ‘Honeytrap Matter’, where people linked to the UK parliament had been targeted by someone via WhatsApp messages in 2024 and 2025 in an attempt to gather compromising information.

A Met Police officer emailed all the people affected to advise them of a change to the suspect’s bail date, adding each of the recipients’ email addresses in the “To” field, meaning all recipients could see each other’s email addresses and names.

The context of the email meant that highly sensitive information could potentially be inferred about the recipients, even though the body of the email did not explicitly contain that information.

The Met Police confirmed that 18 people linked to the UK Parliament were affected, with the ICO finding that it should have used more appropriate methods to communicate with the affected people and not relied on sending one bulk email in such sensitive circumstances.

The ICO’s investigations revealed that the breaches were not isolated mistakes, but reflected wider weaknesses in Met Police policies, procedures and assurance arrangements for handling sensitive personal information.

The ICO also found serious and ongoing shortcomings in Met Police data protection training.

The officer who sent the email to those affected in the ‘Honeytrap Matter’ had not completed data protection training for over four years before the incident, and the officer’s line manager had also not completed relevant training for almost four years prior to the incident.

Wider completion rates for mandatory Managing Information training were discovered to be low, with Met Police itself acknowledging that further improvement was required.

However, the ICO noted that the Met Police took mitigation measures in response to the identified errors, with the service notifying affected people, offering additional support in the SPO case, delivering further specialist training, and embedding a strengthened multi-stage quality assurance process for SPO applications.

Following the email incident, the Met Police contacted the affected people, issued a force-wide reminder about mandatory information security training, and introduced a new behavioural alert tool designed to prompt staff when emails are being sent to multiple external recipients.

The Met Police will be forced to take steps within three and 12 months to improve its data protection training compliance, monitoring and governance arrangements after it failed to put in place appropriate technical and organisational measures to protect people’s personal information, which is a breach of section 40 of the Data Protection Act 2018.

 Jo Stones, ICO Group manager – Civil and Cyber Investigations, said: “People entrust the police with some of their most sensitive personal information, often at moments when they are vulnerable or at risk. They have the right to expect that information will be handled securely.

“In these cases, the Metropolitan Police Service failed to put in place the safeguards needed to protect people’s personal information. One breach exposed a stalking victim’s new contact details to the person she needed protection from. Another revealed the identities of people connected to a highly sensitive investigation.

“These incidents were foreseeable and preventable. Our action makes clear that organisations, particularly those in the public sector handling sensitive law enforcement information, must have effective training, monitoring and assurance in place. Policies and reminders are not enough if they are not followed, checked and enforced.”

A Met Police spokesperson said: “We take all information breaches extremely seriously and ensure they are reported to the Information Commissioner’s Office (ICO) as soon as they become apparent.

“We are aware that these incidents can have real consequences for victims and have apologised to those affected by these two cases.

“While we are disappointed to have received this enforcement action, particularly given the improvements already made, we recognise that these breaches were not acceptable and fell short of the standards we expect.

“The Met has taken significant steps to strengthen information disclosure processes, as acknowledged by the ICO, and remains committed to ensuring the right training and safeguards are in place to prevent similar breaches from happening again in the future.”

Also in this section

Jul 30, 2026

Section 166 application succeeds as tribunal finds ICO left complaints unresolved

The First-tier Tribunal (General Regulatory Chamber) has ordered the Information Commissioner to take further steps and issue a written outcome on a data protection complaint after finding that the regulator invited the complainant to return if dissatisfied with the department's response, received her further material but then did not demonstrate that it had concluded the complaints.
Jul 29, 2026

Regulators clarify medical device status and governance expectations for NHS AI scribes

The Medicines and Healthcare products Regulatory Agency (MHRA) has published new guidance to clarify how existing medical device law applies to ambient voice technology (AVT) products used in health and care settings in Great Britain, setting a regulatory line between tools that merely transcribe and summarise clinical conversations and those that go further into diagnosis or automated action.
Jul 22, 2026

Publication of judgments in care proceedings

A High Court judge in the Family Division recently considered the question of the extent to which judgments he had handed down should be anonymised and whether the transparency order in force in respect of care proceedings should be varied accordingly. Molly Giles considers the key points from the ruling.

InfoGov Masthead Newsletter 800