← Back to Regulatory Updates

Regulatory Update • August 2026

Metropolitan Police Issued Enforcement Notice After Data Protection Failures

Published: 5 August 2026 Topic: Data Protection / Disclosure Failures Source: ICO Enforcement

The ICO has issued an enforcement notice and reprimand to the Metropolitan Police Service after serious data protection failures involving sensitive personal information.

The case highlights the importance of disclosure checks, redaction, staff training, governance and careful handling of sensitive information before it is shared.

Reading time 2 minutes

What changed

The ICO has issued an enforcement notice and reprimand to the Metropolitan Police Service after personal information was wrongly disclosed in two highly sensitive police cases.

One incident involved unredacted documents in a Stalking Protection Order case. The documents included the victim’s new address and telephone number, as well as names and contact details of witnesses. A second incident involved a bulk email where recipients’ email addresses and names were visible to each other in the “To” field.

What is an enforcement notice?

An enforcement notice is a formal regulatory notice requiring an organisation to take specific action. In this case, the ICO required improvements to reduce the risk of unlawful disclosure and to improve data protection training, monitoring and governance.

Why this matters

The case shows how data protection failures can happen through everyday operational processes, not only through cyber attacks or lost devices. Sending the wrong information, failing to redact documents properly, or using the wrong email method can create serious harm where sensitive information is involved.

The ICO also found wider weaknesses in training compliance, monitoring and governance. This is an important reminder that policies are not enough on their own. Organisations need practical checks, clear ownership, completed training and assurance that procedures are actually being followed. For wider updates across privacy, data protection and compliance, see our Regulatory Updates page.

What organisations should do

Organisations should use this case as a prompt to review how sensitive information is checked before it is shared.

  • Check whether staff know when documents need to be redacted before disclosure.
  • Use a second-person review or quality assurance step for high-risk disclosures.
  • Avoid using ordinary bulk email methods where recipients’ identities may be sensitive.
  • Make sure staff complete mandatory data protection and information security training.
  • Monitor training completion rates rather than relying on policies or reminders alone.
  • Review governance arrangements for teams handling sensitive, confidential or high-risk information.
  • Introduce prompts, checklists or technical controls to reduce accidental disclosure risks.

Practical takeaway

Sensitive information should not be sent, disclosed or shared without proper checks. Staff need training, but organisations also need monitoring, quality assurance and practical controls that help prevent avoidable mistakes.

Grounded in

ICO enforcement action against the Metropolitan Police Service following two serious disclosure incidents and wider findings about training compliance, monitoring and governance.

Sources

Future Implementation Support Waitlist