grc-scan
← Back to home
ICO watch · UK19 August 2026

ICO fines & breach roundup

Recent UK ICO enforcement in plain English — who was fined, why, and what a small business should learn from each. The mistakes repeat, and the fixes are cheap.

The takeaway

Every case this fortnight was a control that existed on paper but nobody actually owned day to day — a second check, a patch, a permissions setting.

  • Require a second person to check any document or export before it leaves your organisation.
  • Write down, in the contract, exactly who patches what when you split hosting and development across suppliers.
  • Ask whoever built your website or portal to confirm anonymous visitors can't read customer or staff data through it.

ICO fines & breach roundup — 19 August 2026

A plain-English look at recent UK Information Commissioner's Office (ICO) enforcement and notable data-protection news — who was penalised, why, and what a small business should learn from it. The pattern is consistent and the lessons are cheap to act on.


1. Metropolitan Police Service issued an enforcement notice and reprimand after handing a stalking victim's new address to her alleged stalker

The ICO reprimanded the Metropolitan Police Service and issued a formal enforcement notice after two serious disclosure failures. In the first, an officer served unredacted court documents relating to a Stalking Protection Order to the defendant — documents that included the victim's new home address and phone number (she had moved and changed her number specifically because of the risk he posed), plus the names and contact details of three witnesses. The defendant later contacted the victim on her new number and told her he'd received the documents from the police. The ICO's investigation found the MPS lacked appropriate technical and organisational measures to protect personal information, an infringement of the Data Protection Act 2018, and pointed to a wider pattern of poor data-protection training compliance and weak monitoring and governance. The enforcement notice requires the MPS to fix training, monitoring and governance within three and twelve months.

What your business should learn: Any document leaving your organisation containing a person's address, phone number or other sensitive detail needs a checked step before it goes out — a second person confirming redaction, not a single person's judgement under time pressure. If you handle information about people who may be at risk (an ex-employee, a complainant, a vulnerable customer), a wrong disclosure isn't a paperwork error; it's a safety failure. A five-minute peer-review step before sending sensitive documents costs nothing and would have stopped this.


2. ACRO Criminal Records Office reprimanded after a hacker had access to its systems for seven months, with nobody applying the patches

The ICO reprimanded ACRO Criminal Records Office — which processes criminal-record checks including Police Certificates and International Child Protection Certificates — following a cyber security failing between August 2022 and March 2023, when an attacker gained unauthorised access to ACRO's website and content management system (Kentico CMS) and remained inside for around seven months. The ICO's investigation found the breach came down to a gap nobody owned: ACRO's managed service provider patched the operating system but not the CMS, while ACRO's separate web-development supplier was responsible for applying CMS patches but not for flagging when patches were due. Data belonging to up to 10,920 people was assessed as having been staged for possible theft, including names, dates of birth, addresses, National Insurance numbers, passport and driving licence details, bank details and, for some, biometric and criminal-offence data; ACRO could not conclusively rule out that it was actually taken. ACRO notified over 84,000 people as a precaution. Several of the 35 formal complaints received came from domestic-violence victims worried about their safety.

What your business should learn: If patching a system is split across two suppliers — a hosting provider and a developer, say — write down explicitly, in the contract, who patches what and who is responsible for noticing when a patch is overdue. "Someone else handles updates" is the single most common excuse behind a long-running breach, and it's almost always because nobody actually owns it. A simple patch-tracking spreadsheet, checked monthly, would have caught this within weeks rather than months.


3. PNLD police-legal database breach exposes contact details for over 100,000 officers and staff after being published on the dark web

The Police National Legal Database (PNLD) — a legal reference system used by all 43 police forces in England and Wales, alongside its public "Ask the Police" Q&A service — identified a data security incident on 26 July 2026 and began notifying those affected in early August. A group calling itself ExfilSquad claimed to have obtained roughly 1.9GB of data covering around 114,000 PNLD subscribers and 21,000 Ask the Police users — names, organisations and work email addresses of police officers, criminal-justice professionals and government partners — and published it. Security researchers have floated a possible link to a misconfigured Microsoft Power Pages portal, where an "Anonymous Users" web role could read backend database tables directly through a standard API call with no login required, though PNLD has not confirmed the exact cause. The incident is under joint investigation by PNLD, the National Crime Agency and the ICO.

What your business should learn: If your website or customer portal is built on a low-code platform (Power Pages, and similar tools from other vendors), check what your "anonymous"/public-facing user role can actually read from the backend database — these platforms default to broad table access unless someone deliberately restricts it. Ask whoever built or manages the site to confirm, in writing, that anonymous visitors cannot query customer or staff records through the public forms or API. It's a five-minute permissions review that closes a whole class of silent, no-login-required data exposure.


Sources

Would your business pass the same test?

Almost every fine above traces back to a handful of basics — MFA, patching, access control, lawful marketing. You can check where your business stands against the UK's baseline, free and in plain English, in a few minutes.

📣 Share this roundup

A short ready-made post built around this roundup's takeaway. Copy it, or open a platform and paste.

Share on X

Tip: X pre-fills the post. LinkedIn can't pre-fill text, so Copy + open LinkedIn copies the post for you — just paste (Ctrl/Cmd+V) into the box that opens (the link still shows the preview card). Pasting the link in the first comment instead of the body often gets more reach.

Compiled from public ICO enforcement notices and UK data-protection news. For awareness only — not legal advice, and not affiliated with the ICO. Always check the ICO's own published notices for the authoritative detail.