London Cops Handed Victim's New Address and Number to Her Stalker, Watchdog Says
London Cops Handed Victim’s New Address and Number to Her Stalker, Watchdog Says 🚨
The UK’s data protection regulator has criticized London’s Metropolitan Police Service (MPS) after its officers handed a victim’s stalker details about her new phone number and home address, among other failures. The Information Commissioner’s Office (ICO) today issued the MPS with an enforcement notice and a reprimand over the two incidents, which occurred in 2024.
The ICO outlined two major incidents that were caused by failures at the MPS, but added that they were not isolated and “reflected wider weaknesses in MPS policies, procedures, and assurance arrangements for handling sensitive personal information.”
Incident Overview
Stalking Protection Order Breach: The first incident involved a man subject to an interim Stalking Protection Order (SPO), which restricted him from contacting his victim. As a result of the man’s actions, the unnamed victim had to change her phone number and home address. Despite warnings that all personal information had to be redacted from the copy handed to the defendant, officers included unredacted witness statements and other documents. These exposed the new address and phone number of the victim, and those of her friends and family members. Within days, the victim reported to the MPS that the defendant had contacted her on her new phone number. A full SPO was issued in May 2024, and the stalker was arrested in July upon re-entering the UK.
Email Blunder: The second incident was a classic CC-not-BCC email blunder, exposing the addresses of 18 people connected to the UK Parliament who had been targeted in a honeytrap operation by “a malicious actor.” The MPS emailed those affected by the honeytrap scheme but forgot to use the BCC function, exposing the target’s email addresses to one another. The ICO noted that the officer who sent the email had not completed data protection training for over four years at the time, and their line manager had not completed it for nearly four years also. The ICO found that data protection training completion rates were low across the force, and the MPS has committed to improving them.
Statement from ICO
Jo Stones, group manager of civil and cyber investigations at the ICO, stated: “People entrust the police with some of their most sensitive personal information, often at moments when they are vulnerable or at risk. They have the right to expect that information will be handled securely. In these cases, the Metropolitan Police Service failed to put in place the safeguards needed to protect people’s personal information. One breach exposed a stalking victim’s new contact details to the person she needed protection from. Another revealed the identities of people connected to a highly sensitive investigation. These incidents were foreseeable and preventable. Our action makes clear that organisations, particularly those in the public sector handling sensitive law enforcement information, must have effective training, monitoring and assurance in place. Policies and reminders are not enough if they are not followed, checked and enforced.”
Next Steps
The Met now has 12 months to improve compliance with its data protection training requirements, aiming for 100 percent completion. It must also review every three months how officers send emails to multiple recipients, consider more secure alternatives, and report its progress on training completion to the ICO.