The Information Commissioner’s Office (ICO) has issued an enforcement notice and reprimand to the Metropolitan Police Service (MPS) after personal information in two highly sensitive police cases was erroneously disclosed.
The ICO found that MPS failed to put in place appropriate technical and organisational measures to protect people’s personal information, an infringement of section 40 of the Data Protection Act 2018. The ICO’s investigation revealed a common issue of poor data protection training compliance rates at the MPS with inadequate monitoring and governance.
Incident one
An MPS officer served unredacted documents to a defendant in a Stalking Protection Order (SPO) case. The documents included the victim’s new address and telephone number, as well as the names and contact details of three witnesses. The victim had changed her address and phone number because of the risks she faced. The defendant later contacted the victim on her new number and said he had received documents containing her new contact details from the MPS.
The ICO found MPS failed to ensure confidential third-party information was redacted before documents were served. The ICO also found relevant officers had not received the required specialist SPO training at the time, and that the process for preparing and quality assuring documents was inadequate.
Incident two
This related to the so-called “Honeytrap matter”, where people linked to the UK parliament had been targeted by someone via WhatsApp messages in 2024 and 2025 in an attempt to gather compromising information.
An MPS officer emailed all the people affected to advise them of a change to the suspect’s bail date. The recipients’ email addresses were placed in the “To” field, meaning all recipients could see each other’s email addresses and names. The context of the email meant that highly sensitive information could potentially be inferred about the recipients, even though the body of the email did not explicitly contain that information.
MPS confirmed that 18 people linked to the UK Parliament were affected. The ICO concluded MPS should have used more appropriate methods to communicate with the affected people and not relied on sending one bulk email in such sensitive circumstances.
Investigations findings
The ICO’s investigations revealed that the breaches were not isolated mistakes. They reflected wider weaknesses in MPS policies, procedures and assurance arrangements for handling sensitive personal information.
The ICO also found serious and ongoing shortcomings in MPS data protection training. The officer who sent the email in Incident two had not completed data protection training for over four years before the incident, and the officer’s line manager had also not completed relevant training for almost four years prior to the incident. Wider completion rates for mandatory Managing Information training were discovered to be low, with MPS itself acknowledging that further improvement was required.
As a result, the ICO issued MPS with a reprimand for the infringements identified in both incidents. The ICO also issued an enforcement notice requiring MPS to take steps within three and 12 months to improve its data protection training compliance, monitoring and governance arrangements.
Jo Stones, ICO Group manager – Civil and Cyber Investigations, said: “People entrust the police with some of their most sensitive personal information, often at moments when they are vulnerable or at risk. They have the right to expect that information will be handled securely.
“In these cases, the Metropolitan Police Service failed to put in place the safeguards needed to protect people’s personal information. One breach exposed a stalking victim’s new contact details to the person she needed protection from. Another revealed the identities of people connected to a highly sensitive investigation.
“These incidents were foreseeable and preventable. Our action makes clear that organisations, particularly those in the public sector handling sensitive law enforcement information, must have effective training, monitoring and assurance in place. Policies and reminders are not enough if they are not followed, checked and enforced.”
Mitigation steps subsequently taken by MPS
The ICO considered remedial steps MPS has taken when reaching its decision. These include notifying affected people, offering additional support in the SPO case, delivering further specialist training, and embedding a strengthened multi-stage quality assurance process for SPO applications.
Following the email incident, MPS contacted the affected people, issued a force-wide reminder about mandatory information security training, and introduced a new behavioural alert tool designed to prompt staff when emails are being sent to multiple external recipients.
The ICO considered these steps but found that further action was still needed. Training completion rates remain low and some planned improvements, including wider technical solutions and stronger monitoring arrangements, had not yet been fully implemented or demonstrated to be effective.







