London cops handed victim's new address and number to her stalker, watchdog says
Met ordered to improve safeguards after two preventable data breaches
The UK's data protection regulator, the Information Commissioner's Office (ICO), has criticized London's Metropolitan Police Service (MPS) for improperly sharing a victim's new phone number and home address with a stalker. This incident, among others, has led to two enforcement notices and a reprimand from the ICO. The first incident involved an interim Stalking Protection Order (SPO) issued in January 2024, restricting a man from contacting his victim.
Despite warnings, an unredacted copy containing the victim's new contact details was handed to the defendant, who then used this information to bypass bail conditions and contact the victim. The second incident resulted from a poorly structured email sent by the MPS during a honeytrap operation, exposing the email addresses of 18 individuals connected to the UK Parliament.
The IPO found that these breaches stemmed from wider weaknesses in the MPS's policies, procedures, and assurance arrangements for handling sensitive personal information. The regulator emphasized that organizations, especially in the public sector, must have effective data protection training, monitoring, and assurance in place.
The MPS has been given 12 months to improve compliance with data protection training requirements and review email practices.
Written by urgent.news from The Register's reporting — not their text. Machine-written — it may contain errors, so check the original before relying on it.