ICO fines & breach roundup — 19 August 2026
A plain-English look at recent UK Information Commissioner's Office (ICO) enforcement and notable data-protection news — who was penalised, why, and what a small business should learn from it. The pattern is consistent and the lessons are cheap to act on.
1. Metropolitan Police Service issued an enforcement notice and reprimand after handing a stalking victim's new address to her alleged stalker
The ICO reprimanded the Metropolitan Police Service and issued a formal enforcement notice after two serious disclosure failures. In the first, an officer served unredacted court documents relating to a Stalking Protection Order to the defendant — documents that included the victim's new home address and phone number (she had moved and changed her number specifically because of the risk he posed), plus the names and contact details of three witnesses. The defendant later contacted the victim on her new number and told her he'd received the documents from the police. The ICO's investigation found the MPS lacked appropriate technical and organisational measures to protect personal information, an infringement of the Data Protection Act 2018, and pointed to a wider pattern of poor data-protection training compliance and weak monitoring and governance. The enforcement notice requires the MPS to fix training, monitoring and governance within three and twelve months.
What your business should learn: Any document leaving your organisation containing a person's address, phone number or other sensitive detail needs a checked step before it goes out — a second person confirming redaction, not a single person's judgement under time pressure. If you handle information about people who may be at risk (an ex-employee, a complainant, a vulnerable customer), a wrong disclosure isn't a paperwork error; it's a safety failure. A five-minute peer-review step before sending sensitive documents costs nothing and would have stopped this.
2. ACRO Criminal Records Office reprimanded after a hacker had access to its systems for seven months, with nobody applying the patches
The ICO reprimanded ACRO Criminal Records Office — which processes criminal-record checks including Police Certificates and International Child Protection Certificates — following a cyber security failing between August 2022 and March 2023, when an attacker gained unauthorised access to ACRO's website and content management system (Kentico CMS) and remained inside for around seven months. The ICO's investigation found the breach came down to a gap nobody owned: ACRO's managed service provider patched the operating system but not the CMS, while ACRO's separate web-development supplier was responsible for applying CMS patches but not for flagging when patches were due. Data belonging to up to 10,920 people was assessed as having been staged for possible theft, including names, dates of birth, addresses, National Insurance numbers, passport and driving licence details, bank details and, for some, biometric and criminal-offence data; ACRO could not conclusively rule out that it was actually taken. ACRO notified over 84,000 people as a precaution. Several of the 35 formal complaints received came from domestic-violence victims worried about their safety.
What your business should learn: If patching a system is split across two suppliers — a hosting provider and a developer, say — write down explicitly, in the contract, who patches what and who is responsible for noticing when a patch is overdue. "Someone else handles updates" is the single most common excuse behind a long-running breach, and it's almost always because nobody actually owns it. A simple patch-tracking spreadsheet, checked monthly, would have caught this within weeks rather than months.
3. PNLD police-legal database breach exposes contact details for over 100,000 officers and staff after being published on the dark web
The Police National Legal Database (PNLD) — a legal reference system used by all 43 police forces in England and Wales, alongside its public "Ask the Police" Q&A service — identified a data security incident on 26 July 2026 and began notifying those affected in early August. A group calling itself ExfilSquad claimed to have obtained roughly 1.9GB of data covering around 114,000 PNLD subscribers and 21,000 Ask the Police users — names, organisations and work email addresses of police officers, criminal-justice professionals and government partners — and published it. Security researchers have floated a possible link to a misconfigured Microsoft Power Pages portal, where an "Anonymous Users" web role could read backend database tables directly through a standard API call with no login required, though PNLD has not confirmed the exact cause. The incident is under joint investigation by PNLD, the National Crime Agency and the ICO.
What your business should learn: If your website or customer portal is built on a low-code platform (Power Pages, and similar tools from other vendors), check what your "anonymous"/public-facing user role can actually read from the backend database — these platforms default to broad table access unless someone deliberately restricts it. Ask whoever built or manages the site to confirm, in writing, that anonymous visitors cannot query customer or staff records through the public forms or API. It's a five-minute permissions review that closes a whole class of silent, no-login-required data exposure.
Sources
- ICO — Metropolitan Police Service issued with enforcement notice and reprimand following data protection failures
- The Register — London cops handed victim's new address and number to her stalker, watchdog says
- Police Professional — ICO orders MPS to improve data protection after serious disclosure breaches
- ICO — ACRO reprimanded following cyber security failings
- The Register — Exposed: Woeful security at UK criminal records office that led to sensitive data leak
- Infosecurity Magazine — ICO Reprimands Criminal Records Office After 2023 Breach
- DataBreaches.net — UK: ICO reprimands ACRO Criminal Records Office after data breach
- The Hacker News — PNLD Breach Exposes U.K. Police and Government Contact Details on Dark Web
- SC Media — UK police legal database breach exposes officer details, increasing phishing risks
- Rescana — PNLD Data Breach Exposes UK Police and Government Contact Information via Microsoft Power Platform Misconfiguration