Summary
- The ICO issued the Metropolitan Police with an enforcement notice and reprimand under the Data Protection Act 2018.
- Separate incidents exposed a stalking victim's contact details and identities connected to a sensitive parliamentary investigation.
- The regulator found wider weaknesses in training compliance, monitoring, quality assurance, and governance.
The Metropolitan Police has been ordered to improve its data protection training, monitoring, and governance after the UK privacy regulator concluded that two serious disclosures reflected wider control failures rather than isolated employee mistakes.
The Information Commissioner’s Office issued an enforcement notice and reprimand to the Metropolitan Police Service, finding that it had failed to put appropriate technical and organisational measures in place to protect personal information. The regulator said this breached section 40 of the Data Protection Act 2018.
One investigation concerned documents served to a defendant in a Stalking Protection Order case. An officer failed to redact the victim’s new address and telephone number, as well as names and contact details for three witnesses. The victim had changed her address and phone number because of the risk she faced, and the defendant subsequently contacted her using the newly disclosed number.
The ICO found that relevant officers had not received required specialist training and that the process for preparing and quality-assuring the documents was inadequate.
A separate incident involved a bulk email to people connected to the Metropolitan Police’s so-called Honeytrap investigation. Recipients were placed in the main address field, exposing their names and email addresses to one another. The Met confirmed that 18 people linked to the UK Parliament were affected.
The message itself did not explicitly reveal the sensitive information under investigation, but the context could allow recipients to infer that others on the distribution list were connected to the case.
The ICO’s findings extended beyond the actions of the individual officers. It identified wider weaknesses in policies, procedures, assurance arrangements, training compliance, and management oversight.
The officer who sent the bulk email had not completed data protection training for more than four years before the incident. Their line manager had also gone almost four years without completing the relevant training, while the regulator found wider completion rates for mandatory Managing Information training remained low.
The enforcement notice requires the force to take specified steps over three- and 12-month periods to improve training compliance, monitoring, and governance. That creates measurable obligations rather than a general recommendation to improve awareness.
The Met had already introduced some remedial measures before the enforcement action. These included additional specialist training, a strengthened quality-assurance process for Stalking Protection Order applications, and a behavioural alert intended to warn staff when email is being sent to multiple external recipients.
The ICO concluded that further work was still required, saying some technical and monitoring measures had not yet been fully implemented or demonstrated to be effective.
The incidents illustrate the connection between information governance and security controls without requiring an external cyberattack. Sensitive information crossed organisational boundaries because document handling, email practice, training, assurance, and technical safeguards did not collectively prevent foreseeable mistakes.
In policing, the consequence of those failures can go well beyond ordinary privacy exposure. Records can identify victims, witnesses, suspects, officers, and people associated with sensitive investigations. Disclosure can create personal-safety risks alongside regulatory and institutional consequences.
Technical controls can reduce the opportunities for human error to become a breach, but they depend on governance defining where safeguards are needed. An email warning has limited value if risk thresholds are poorly configured; document-redaction controls need quality assurance; and mandatory training requires monitoring if non-completion is to have any operational significance.
The ICO described the two incidents as foreseeable and preventable. Its enforcement action now puts the Met’s response on a timetable, with progress expected in training completion, monitoring, and governance rather than another round of policy reminders alone.



