Info Gov

The Ministry of Justice (MoJ) has launched an “urgent investigation” after court files detailing victims, their families and survivors of the Southport attack in July 2024 were accessed without authorisation.

According to the MoJ, the issue was identified through a review of its digital systems.

It said: “The Ministry of Justice's independent Data Protection Officer has assessed the matter and determined that, for a limited number of individuals, the information accessed included sensitive and personal data, likely to result in a high risk to their rights and freedoms.

“HMPPS and HMCTS are now investigating this, and any victims impacted are being notified directly and the Information Commissioner's Office has been informed.”

The MoJ found no evidence that personal data had been shared with third parties.

This comes after North-West Ambulance Service issued a formal investigation in July into whether staff “inappropriately” accessed the medical records of Southport attack victims.

The service confirmed it had identified concerns about potential inappropriate access to patient records.

Lawyers representing one of the girls said a recent string of patient data breaches had highlighted “a deep-rooted culture of snooping within the NHS”.

On 29 July 2024, Bebe King, Elsie Dot Stancombe, and Alice da Silva Aguiar were killed by Axel Rudakubana (AR), at a Taylor Swift-themed dance class.

A Ministry of Justice spokesperson said: “We are appalled that this happened and recognise the distress it will have caused victims, survivors, and their families.

“We apologise to those affected - unauthorised access to court files is completely unacceptable.

“This is now being investigated urgently, and the Prime Minister has asked the Lord Chancellor to oversee this. All wrongdoing will be met with extremely firm action.”

Also in this section

Sep 23, 2026

Hospital trust reports personal data breach to ICO after reused database script wipes maternity access logs

Nottingham University Hospitals NHS Trust has reported a personal data breach to the Information Commissioner's Office after a script intended to copy a radiotherapy database was run against its legacy maternity system instead, overwriting records for women and babies treated between September 2011 and November 2022 and permanently destroying most of the audit trail showing who accessed them.
Sep 22, 2026

Section 166 offers no route to challenge ICO decisions not to investigate under new complaints framework, tribunal rules

The First-tier Tribunal has struck out an application seeking to force the Information Commissioner to investigate a subject access complaint, in a decision that confirms the ICO's harm-based complaints prioritisation framework can dispose of a complaint without any engagement with the data controller and still count as an outcome beyond the reach of section 166 of the Data Protection Act 2018.
Sep 11, 2026

ICO opens investigation into Police Scotland's handling of subject access requests

The Information Commissioner's Office has opened an investigation into Police Scotland's handling of subject access requests, seeking to establish whether the force has failed, or is failing, to comply with its obligations under Articles 12 and 15 of the UK GDPR and section 45 of the Data Protection Act 2018, including responding to requests within the statutory timescale.

InfoGov Masthead Newsletter 800