On 7 August 2026 the Information Commissioner’s Office announced that it had issued the Metropolitan Police Service with both a reprimand and an enforcement notice following two unrelated disclosure failures. The ICO’s legal finding was that the MPS failed to put in place appropriate technical and organisational measures to protect personal data, infringing section 40 of the Data Protection Act 2018.
Two features of that sentence deserve more attention than the incidents themselves.
First, the provision. Section 40 is not UK GDPR Article 32. It sits in Part 3 of the DPA 2018, the law-enforcement processing regime, and it is a data protection principle rather than a downstream security obligation. Getting that distinction right changes what the finding means and which organisations should read the case as binding on them.
Second, the instrument. An enforcement notice under section 149 DPA 2018 is not a smaller fine. It is a binding, time-bound order to do specified things by specified dates, backed by the power to convert non-compliance into a monetary penalty. The ICO gave the MPS three months and twelve months to improve data protection training compliance, monitoring and governance arrangements. That structure — not the underlying disclosures — is the compliance story, because it tells every controller what the regulator now expects “we trained our staff” to look like as evidence.
What the ICO Found
The two incidents were unconnected in subject matter and, on the ICO’s analysis, identical in cause.
Incident one — unredacted service in a Stalking Protection Order case. An MPS officer served documents on a defendant without redacting them. The documents contained the victim’s new address and telephone number, together with the names and contact details of three witnesses. The victim had changed her address and phone number precisely because of the risk she faced. The defendant subsequently contacted her on the new number, telling her he had received documents from the MPS containing her new details.
That is the clearest possible illustration of why the security principle exists. The protective measure the victim had taken — changing her contact details — was defeated by the organisation that existed to protect her, through a document-handling step in a workflow whose entire purpose was disclosure to the person she feared.
Incident two — a bulk email that exposed its own recipients. An officer sent a notification about a change to a suspect’s bail date to 18 people connected to a sensitive parliamentary investigation (reported as the “Honeytrap” matter), placing the addresses in a field visible to all recipients rather than concealing them. Every recipient’s name and email address was disclosed to every other recipient, revealing the identities of individuals linked to the investigation to one another.
The ICO’s central conclusion was that these were not isolated mistakes. Reporting on the action records that the officer involved in the bulk email had not completed mandatory data protection training for more than four years, and that the investigation found a common issue of poor data protection training compliance rates across the MPS, with inadequate monitoring and governance. ICO group manager Jo Stones described the breaches as “foreseeable and preventable” — the regulator’s shorthand for a failure that a working control system would have caught, as distinct from an attack that defeated one.
That framing is the hinge of the case. Two errors by two individuals in two unrelated matters were treated as evidence about the organisation’s control environment, because the same absent control — assured, completed, monitored training supported by procedural and technical checks on outbound disclosure — sat behind both.
Why Section 40, and Why It Is Not Article 32
Most UK data protection commentary runs on UK GDPR. Policing does not.
Part 3 of the DPA 2018 implements the Law Enforcement Directive regime domestically. It applies where a competent authority processes personal data for any of the law enforcement purposes — the prevention, investigation, detection or prosecution of criminal offences, or the execution of criminal penalties. Competent authorities include police forces, the CPS, and other bodies listed in Schedule 7 or exercising statutory functions for those purposes. Where Part 3 applies, UK GDPR does not: the two regimes are mutually exclusive for a given processing operation, which is why the ICO cited section 40 rather than Article 32 or Article 5(1)(f).
This matters operationally for any competent authority, because a single organisation routinely straddles both. A police force’s HR records, procurement data and public-facing website analytics sit under UK GDPR. Its case files, disclosure bundles, witness details and investigation correspondence sit under Part 3. The same officer can move between regimes in the course of a morning, and the policies, retention rules, subject rights processes and lawful bases differ on each side of that line.
Section 40 states the sixth data protection principle: personal data processed for any of the law enforcement purposes must be processed in a manner that ensures appropriate security, using appropriate technical or organisational measures, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage. Part 3 also carries a more granular security duty at section 66, which is the closer analogue of Article 32.
The choice to find an infringement of the principle rather than only the operational duty is deliberate and worth noting. Principles apply to the processing as a whole and are the yardstick against which the controller’s entire arrangement is measured. A finding under section 40 says the organisation’s security posture for law-enforcement data was inadequate as a matter of first principle — not that a particular measure was misconfigured.
The substantive test, though, will be familiar to anyone who works with Article 32: appropriateness, judged against the risk. And appropriateness is where the training point bites. Under both regimes, “technical and organisational measures” is a conjunction that controllers habitually read as though the second half were decorative. Policies, procedures, training, supervision, quality assurance and governance oversight are the organisational measures. When they do not function, the security duty is breached even where no system was misconfigured and no attacker was involved.
One further difference is worth holding on to: Part 3 has its own breach-notification architecture at sections 67 and 68, with carve-outs reflecting the investigative context, and where the ICO does fine under Part 3 the penalty runs under section 155 with the maxima set by section 157. The exposure is real even though the framework text differs from UK GDPR.
An Enforcement Notice Is Not a Discounted Fine
Because the headline number is absent, enforcement notices get read as a soft outcome. That reading is wrong in both directions.
Section 149 DPA 2018 empowers the Commissioner, where satisfied that a person has failed to comply with a data protection requirement, to issue an enforcement notice requiring that person to take specified steps, or to refrain from taking specified steps, by a specified time. Two structural consequences follow.
It is prospective and specific. A fine looks backwards and prices a past failure; a notice looks forwards and dictates the remediation. The recipient loses discretion over the shape and pace of its own improvement programme, and it acquires a set of dated deliverables the regulator has already committed to checking.
Non-compliance escalates. Under section 155, the Commissioner may issue a penalty notice where a person has failed to comply with an enforcement notice — the failure to remediate becomes an independently fineable act, distinct from the original infringement. It is worth correcting a common misconception here: under the DPA 2018 there is no general criminal offence of failing to comply with an enforcement notice, as there was under section 47 of the DPA 1998. The criminal exposure in this area is narrower — section 148 makes it an offence to destroy, falsify or conceal information or documents required in connection with an information notice, an assessment notice or an enforcement notice. The realistic consequence of missing the deadlines is a monetary penalty and a second, worse public finding, not a prosecution.
An appeal lies to the First-tier Tribunal under section 162, which is itself a signal: the ICO must be able to defend each specified step as necessary and proportionate. That constrains regulators to order things that are objectively verifiable — which is exactly why the Met’s notice is expressed in terms of compliance rates, monitoring and governance arrangements rather than sentiments about culture.
The Public Sector Approach in the Background
The absence of a fine is not an accident of this case. Since 2022 the ICO has operated a public sector approach, using warnings, reprimands and enforcement notices in preference to monetary penalties against public authorities, reserving fines for the most egregious cases. The rationale is that fining a police force, a hospital trust or a council moves money between public budgets and degrades the service the affected individuals depend on, without reaching the decision-makers. Following a review and a consultation that closed in January 2025, the ICO confirmed it would continue the approach, citing feedback that published reprimands are effective at reaching senior leadership through reputational pressure.
The approach has vocal critics, who point out that public bodies receive reprimands for failures that would attract seven-figure penalties in the private sector. Whatever the merits of that argument, the operational consequence for public authorities is the opposite of a discount: you are more likely to receive an order you must execute against a clock, and less likely to be able to close the matter by writing a cheque. For our analysis of the same regulator taking the fining route against a private-sector controller, see the South Staffordshire Water £963,900 penalty and the £1.2m LastPass fine.
The Real Signal: Training Completion as an Auditable Control
Strip out the policing context and the Met case states a proposition that applies to every controller in the UK.
The ICO did not find that the MPS had failed to provide data protection training. A force of that size unquestionably has a mandatory training module, a policy requiring it, and an e-learning platform delivering it. What the ICO found is that compliance rates were poor and that monitoring and governance around them were inadequate — and that an officer handling an exceptionally sensitive distribution list had been out of compliance for over four years without the organisation registering the fact or restricting what he could do.
That is a distinction most organisations have never operationalised:
- Training delivery is a fact about the organisation: a module exists, it is assigned, it covers the right material.
- Training compliance is a fact about each individual: this named person completed this version of this module on this date, and their record is current.
- Training assurance is a fact about the control: someone independent of the training function periodically tests whether the completion data is accurate, whether non-completion triggers a consequence, and whether the trained behaviour actually appears in the work product.
Only the first is captured by most “we trained them” defences. The ICO’s notice is directed squarely at the second and third — and the three-month/twelve-month split tells you how the regulator sequences them. Three months is not enough time to change an organisation’s culture, but it is ample time to produce an accurate completion report, an escalation route for non-completers, and a named governance owner. Twelve months is the horizon for embedding: sustained compliance rates, a functioning monitoring regime, and governance arrangements that surface exceptions to people with the authority to act on them.
Read that as a template. When a regulator asks how you evidence appropriate organisational measures, the acceptable answer is a report, not a policy — and the report must show completion, exceptions, ageing of exceptions, and what happened to the exceptions.
The same pattern of “the control existed on paper and failed in practice” runs through the Lloyds Bank app defect that exposed 450,000 customers’ transaction data and the ICO’s Reddit age-assurance decision, where a declared control that no one tested was held not to be a control at all.
Redaction Is a Control Point, Not a Task
The stalking case failure is worth isolating because disclosure workflows are the one process where an organisation deliberately sends sensitive data to an adverse party. In every other data flow, the recipient is trusted to some degree. In service of proceedings, the recipient is by definition the person the data subject is being protected from.
Yet in most organisations — police forces, local authorities, regulators, HR and legal functions handling subject access, litigation disclosure or safeguarding — redaction is treated as a task performed by whoever owns the file, not as a control with a defined owner, a defined standard, and a verification step. Nothing structural stands between an officer’s judgement at 4pm and the served bundle.
What a controlled redaction process looks like:
- A separated preparation step. The redacted version is produced as a distinct artefact from the master file, and the master is never the thing that leaves the building.
- Second-person verification for defined risk categories. Not every bundle, but every bundle in a category — protective orders, safeguarding, domestic abuse, witness material, anything where the recipient is adverse to the data subject.
- Field-level standards, not judgement. A written list of what must be removed in each case category — victim address, victim telephone, witness contact details, third-party identifiers — so that redaction is a checklist rather than an act of discretion under time pressure.
- True redaction, technically enforced. Flattening to remove the underlying text layer, and blocking the well-known failure modes: black boxes drawn over live text, metadata and revision history, hidden spreadsheet rows and columns, comments and tracked changes.
- A record that the check happened. The name of the verifier and the date, held with the case file. Without this, you cannot evidence the control to a regulator, and you cannot audit it yourself.
The bulk email has an equally concrete answer. Address-field errors are the single most common cause of reported UK personal data breaches, and they are substantially preventable by technical measure: enforced Bcc for outbound distribution lists, a warning prompt above a threshold recipient count, an external-recipient interstitial, and — the option most organisations overlook — removing the ability to send group notifications by ad hoc email altogether in favour of a case management system that issues individual notifications. The MPS has reportedly since introduced behavioural alert tooling for email. That is the right category of fix: where human error is predictable, the appropriate measure is technical, not exhortatory.
Compliance Checklist
For public authorities, and for any organisation doing Part 3 processing:
Scope and regime mapping
- Identify which of your processing operations are for law enforcement purposes by a competent authority, and confirm they are governed by Part 3, not UK GDPR. Document the boundary — including the operations (HR, estates, corporate) that sit under UK GDPR.
- Ensure your policies, retention schedules, rights-request procedures and breach playbooks are regime-specific. A single “GDPR policy” applied across a competent authority is a finding waiting to happen.
Redaction and disclosure controls
- Name an accountable owner for the disclosure workflow, distinct from the case owner.
- Define the case categories requiring mandatory second-person redaction verification, and make the verification record part of the file.
- Publish field-level redaction standards per category; do not rely on individual judgement about what is sensitive.
- Enforce technically true redaction and test for the standard failure modes (text layers, metadata, hidden rows, comments).
- Treat “documents served on an adverse party” as a distinct high-risk processing category in your DPIA and risk register.
Training compliance, not training delivery
- Produce a completion report by individual, role and business unit, with the version and date of the module completed — and be able to generate it on demand.
- Set a defined completion threshold and an expiry period, and report against both to a governance body with minutes.
- Define the consequence of non-completion and make it real: escalation to line management, then restriction of access to sensitive systems or high-risk workflows. An officer four years out of compliance should not have been able to send that email.
- Target training by risk, not headcount: staff performing disclosure, service of documents, or bulk communications need role-specific content, not the annual all-staff module.
Assurance and second-line testing
- Have a function independent of the process owner test whether the control works — sampling served bundles for residual personal data, testing whether completion records are accurate, checking whether escalations actually occurred.
- Test the technical measures too: does the Bcc enforcement fire, does the recipient-count warning appear, does the redaction tool actually flatten.
- Record findings, owners, and closure dates, and report exceptions upward.
Evidencing “appropriate technical and organisational measures”
- For each measure you would cite to a regulator, be able to produce: the policy, the implementation record, the monitoring output, and the assurance test result. Three out of four is a finding.
- Maintain a dated governance trail — which body reviewed the training compliance data, on what date, and what it decided about the exceptions.
- Keep a risk-based justification for the measures you chose, referenced to the sensitivity of the data and the consequences of disclosure. Appropriateness is relative; you must be able to show what you weighed.
Conclusion
The Metropolitan Police case will be reported as a story about a stalking victim and a leaked email chain, and those facts matter — a woman who took the one protective step available to her had it undone by the police. But the reason the case belongs in every compliance function’s reading is narrower and more durable.
The ICO took two individual human errors and, instead of treating them as individual human errors, asked what organisational measures should have stood between the individual and the consequence. It found that the answer was training that people had not completed, monitoring that did not detect non-completion, and governance that did not act on it. It then wrote an order requiring those three things to be fixed on a three-month and twelve-month clock, with a section 155 penalty available if they are not.
The transferable rule is simple to state and uncomfortable to implement: under section 40 DPA 2018 and equally under Article 32 UK GDPR, an organisational measure that is not monitored is not a measure. Delivering training is an activity. Completion data, escalation on non-completion, and independent testing of whether the trained behaviour appears in the work product are the control. Only the second set is evidence, and evidence is what an enforcement notice — unlike a fine — obliges you to produce on a date the regulator has already chosen.
Sources: ICO — Metropolitan Police Service issued with enforcement notice and reprimand following data protection failures (August 2026), PublicTechnology — ICO finds ‘serious and ongoing shortcomings’ after Met Police gave victim’s details to alleged stalker (7 August 2026), Police Professional — ICO orders MPS to improve data protection after serious disclosure breaches, UKAuthority — Met Police data failures put stalking victim and MPs’ contacts at risk, Bitdefender HotForSecurity — Met Police exposed a woman’s address to her alleged stalker, Data Protection Act 2018, section 40, Data Protection Act 2018, Part 6 (enforcement), ICO — Public sector approach
This article is provided for informational purposes only and does not constitute legal advice.



