A stalker received his victim’s new address. The ICO says the real failure started long before

Human error is often blamed when personal data is exposed. Someone forgets to redact a document. Someone clicks “Reply All.” Someone puts recipients in the wrong email field.

But in its latest enforcement action against the Metropolitan Police Service (MPS), the Information Commissioner’s Office (ICO) emphasises that these incidents weren’t simply the result of individual mistakes. They were the inevitable outcome of weak governance, poor oversight and, crucially, inadequate data protection training.

The case serves as a powerful reminder that organisations cannot rely on policies alone. If employees are not properly trained and if organisations fail to monitor whether that training is completed, serious data protection failures become far more likely.

The case: What happened?

The ICO issued the Metropolitan Police with both an enforcement notice and a reprimand after investigating two separate data breaches involving highly sensitive personal information.

Although the incidents were unrelated, investigators found they shared the same underlying organisational weaknesses.

Rather than isolated mistakes, the ICO concluded they reflected broader failures in data protection governance, training compliance and assurance processes.

Incident one: A stalking victim’s personal details disclosed to her alleged stalker

The first breach involved one of the most serious types of personal data disclosure imaginable.

During proceedings relating to a Stalking Protection Order, officers served documents on the defendant that had not been properly redacted.

Those documents contained the victim’s new home address and telephone number, information she had deliberately changed to protect herself, as well as the names and contact details of three witnesses.

The defendant subsequently contacted the victim using the newly disclosed phone number.

The ICO found that the officers involved had not received the specialist Stalking Protection Order training required for handling these cases. It also identified weaknesses in the quality assurance process that should have detected the unredacted information before the documents were served.

The result was not merely a procedural failure but one that directly undermined the protections the justice system was intended to provide.

Incident two: A single email that revealed more than intended

The second incident arose during the high-profile Westminster “honeytrap” investigation.

An officer emailed individuals connected to the investigation to notify them of a change to the suspect’s bail date.

Instead of using BCC or another secure communication method, every recipient’s name and email address was visible to everyone else.

Although the email itself did not reveal details about the recipients, the context meant highly sensitive information could easily be inferred about those involved.

Eighteen people connected to the UK Parliament were affected.

Perhaps most strikingly, the ICO found that the officer responsible had not completed mandatory data protection training for more than four years. Their line manager had also gone almost four years without completing the relevant training.

The investigation uncovered a bigger problem

The ICO’s findings extend well beyond the two individual breaches.

Investigators discovered low completion rates for mandatory information management training across the Metropolitan Police, alongside inadequate monitoring and governance.

This distinction is significant. Had the ICO viewed these incidents as simple human error, the response might have focused on reminding staff to be more careful.

Instead, regulators concluded the failures were systemic.

The organisation had not ensured staff received the necessary training, had insufficient oversight of compliance, and lacked assurance processes capable of identifying and addressing these weaknesses before they resulted in real-world harm.

As the ICO noted, these incidents were “foreseeable and preventable.”

Training becomes the central issue

Many organisations still treat mandatory data protection training as a compliance exercise. Employees complete an annual module, tick a box and move on. This case demonstrates why regulators increasingly expect much more.

Training is only effective if organisations ensure it is completed, remains current and is appropriate for the risks employees face in their specific roles.

The officer handling Stalking Protection Orders required specialist training because of the heightened risks involved in those cases.

The officer sending sensitive communications needed up-to-date knowledge of secure handling procedures.

Neither safeguard was in place.

Equally important, managers were not ensuring compliance, and organisational oversight failed to identify these gaps before the incidents occurred.

The ICO’s enforcement notice reflects this broader expectation by requiring the Metropolitan Police not simply to deliver more training, but to improve compliance rates, monitoring and governance arrangements.

What should organisations do?

Although this enforcement action concerns a police force, the lessons apply to any organisation handling sensitive personal information.

Many organisations focus heavily on drafting policies while paying far less attention to whether employees actually understand and consistently follow them.

The ICO’s message couldn’t be clearer. A policy sitting on a shelf won’t prevent a data breach. Organisations need trained staff, managers who enforce compliance, and systems that make sure the right processes are followed. 

If regulators find that employees have gone years without mandatory training or that organisations cannot demonstrate effective monitoring, it becomes much harder to argue that appropriate organisational measures were in place.

The implications for compliance

This case also illustrates how regulators increasingly assess the effectiveness of an organisation’s entire compliance framework rather than examining isolated incidents.

A single breach may trigger a much broader review into governance, oversight, quality assurance processes and organisational culture.

The Metropolitan Police had already introduced several improvements after the incidents, including additional specialist training, stronger quality assurance processes for Stalking Protection Orders and behavioural alerts to warn staff before sending emails to multiple external recipients.

Yet the ICO still concluded further enforcement action was necessary because training completion remained low and wider monitoring arrangements had not yet demonstrated they were effective.

Implementing improvements after an incident is important, but regulators also expect evidence that those improvements are embedded, monitored and working in practice.

The takeaway

The Metropolitan Police case demonstrates that data protection failures rarely begin with a single click or a forgotten redaction. They often begin much earlier, with missed training, inadequate oversight and weak governance.

For organisations handling personal information, especially sensitive or high-risk data, compliance cannot end with publishing policies or delivering occasional reminders.

Training must be current. Completion must be monitored. Managers must be accountable. Governance must actively verify that safeguards are working before, not after, a breach occurs.

As this enforcement action makes clear, when training becomes optional in practice, data protection can quickly become optional too.

Try our Our UK GDPR and Data(Use and Access) Act 2025 (DUAA) training courses

Get more info here →