"People entrust the police with some of their most sensitive personal information, often at moments when they are vulnerable or at risk," Jo Stones, group manager of civil and cyber investigations at the Information Commissioner’s Office, said in a blunt rebuke of the Metropolitan Police Service's handling of two 2024 data breaches.
How officers exposed a stalking victim’s new address and number
The ICO identified two major incidents in 2024 that it said "reflected wider weaknesses" in how the Metropolitan Police Service (MPS) handles sensitive law‑enforcement information. The first centred on a man subject to an interim Stalking Protection Order (SPO) authorised in January 2024. The man had been arrested the previous year on suspicion of harassment and malicious communications and was subject at that time to bail conditions prohibiting contact with the victim and her friends and family.
Because of the stalker’s actions the unnamed victim changed both her phone number and home address. Despite clear warnings that personal information should be redacted from the documents provided to the defendant, officers included unredacted witness statements and other materials. Those documents exposed the victim’s new address and phone number and the contact details of her friends and family.
Within days—after the man fled the UK and thereby breached his bail conditions—the victim reported to the MPS that the defendant had contacted her on her new phone number. A full SPO was issued in May 2024; the suspect was arrested in July upon re‑entering the UK, later charged with stalking offences and imprisoned following a guilty plea.
The honeytrap email: CC instead of BCC exposed 18 parliamentary contacts
The second incident was a classic "CC‑not‑BCC" error. An MPS email updating people about the date by which a suspect in a honeytrap operation would have to answer bail exposed the email addresses of 18 people connected to the UK Parliament because the sender failed to use the BCC field.
The MPS told the ICO it reported the breach on the same day and acknowledged that recipients "might be able to deduce one another's identities" from the revealed addresses; three of the accounts had recently been deactivated. The force said there was "no reported detriment" and no official complaints, though it was aware that "some" targets were "displeased" that their names had been shared. One Member of Parliament raised the issue in the House of Commons.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildTraining shortfalls and systemic weaknesses the ICO found
The ICO flagged training failures as a central cause. The officer who sent the honeytrap email had not completed data protection training for over four years, and their line manager had not done so for nearly four years. Inspectors found data protection training completion rates were low across the force; the MPS has committed to improving those rates.
Jo Stones laid the responsibility squarely at the MPS’s door: "These incidents were foreseeable and preventable," she said, adding that policies and reminders are insufficient "if they are not followed, checked and enforced." The ICO concluded that the MPS "failed to put in place the safeguards needed to protect people's personal information."
ICO enforcement: requirements, timetable and prior actions
The ICO issued the MPS an enforcement notice and a reprimand over the two incidents. The ICO explained that enforcement notices set out specific steps organisations must take to comply with UK data‑protection law, while reprimands are official warnings about breaches of that law.
Under the enforcement notice the MPS has 12 months to improve compliance with its data protection training requirements, with the aim of achieving 100 percent completion and implementing follow‑up with staff who miss the deadline. The force must also review, every three months, how officers send emails to multiple recipients, consider more secure alternatives, and report progress on training completion to the ICO.
The ICO noted this action follows earlier regulation of the Met: the commissioner was served with a separate enforcement notice earlier this year over failures to meet duties under the Freedom of Information Act, and that followed a previous notice two years earlier with which the MPS complied.
How victims, MPs, and the Metropolitan Police will be affected
- Victims: The first breach directly endangered a stalking victim by revealing her newly established contact details to the person she sought protection from, and the ICO’s findings underline the risk when redaction and handling procedures are not enforced.
- Members of Parliament and parliamentary staff: The CC‑not‑BCC error disclosed identities connected to a sensitive honeytrap investigation; at least one MP raised the matter in Parliament and some targets were "displeased" at the disclosure.
- The Metropolitan Police Service: The force now faces a 12‑month compliance clock, quarterly email‑handling reviews, mandatory training completion targets, and ongoing reporting to the ICO—requirements the ICO framed as necessary because "policies and reminders are not enough if they are not followed, checked and enforced."
The ICO’s action makes clear that the MPS must convert commitments into verifiable change: complete training to 100 percent, alter how sensitive emails are handled, and report progress. The next concrete milestone is the quarterly review schedule and the 12‑month deadline for full training compliance; whether that will be sufficient to restore public confidence in handling the most sensitive police records remains the immediate question the force must answer.



