TEARDOWN Published 4 October 2026 at 03:43. Evidence-based. Source-cited. No sponsored content.

Two police forces exposed years of sexual-offence and grooming case data hidden inside routine Excel files. The regulator calculated an identical fine for both despite nearly double the victims, then named the wrong force in its own verdict.

3 out of 5 stars3/54 documented mistakes in this teardownHow ratings work

Estimated reading time: 7 minutes

Norfolk Constabulary's police station on Holt Road in Cromer, a single-storey building with a Union flag, a small wind turbine and a Norfolk Constabulary sign at the entrance.
Norfolk Constabulary's police station on Holt Road, Cromer, photographed 23 November 2019. Photo: Kolforn / Wikimedia Commons, CC BY-SA 4.0.

In short. The Information Commissioner reprimanded Suffolk and Norfolk Constabularies on 20 May 2026 for infringing Article 5(1)(f) UK GDPR: hidden worksheets and pivot-table links inside Excel spreadsheets sent in response to Freedom of Information requests exposed data on sexual offences, grooming, revenge porn and other crimes, affecting "not less than 436" people tied to Suffolk and "not less than 846" tied to Norfolk [1] [2]. The Commissioner's own Fining Guidance scored the infringement "medium" rather than "high" severity, citing an "absence of evidence of actual harm" (page 42-43) [1], despite Suffolk's own admission, quoted two pages earlier, that the exposure "would cause the data subjects psychological distress" (page 40) [1]. Both forces receive an identical indicative penalty of £70,875, despite Norfolk's breach affecting nearly double Suffolk's total, and Norfolk's own published reprimand names the wrong force when explaining that figure (page 41) [2]. Four documented mistakes: three stars.

A Freedom of Information officer at Suffolk Constabulary opened a request in September 2018 asking for statistics on sexual offences involving under-18s. The raw crime data went into an Excel file, a second worksheet was built on top of it for the public-facing answer, and the file was passed along with that worksheet still attached. Nobody noticed. The spreadsheet, raw data included, sat on the force's website from some point between October 2018 and February 2019 until a member of the public found it on Google and contacted two of the people named inside it, on 7 November 2022 [1]. Three years later, a near-identical failure, this time via pivot tables that silently retained a live link to the underlying database, exposed data from 18 more FOI responses shared jointly by Suffolk and Norfolk's combined information management command [1].

On 20 May 2026 the Information Commissioner published reprimands against both forces for infringing Article 5(1)(f) UK GDPR, the requirement to keep personal data secure [3] [4]. Both documents run to dozens of pages of genuinely forensic detail: dates, internal investigation findings, named failures in training and policy. The reprimands are also where the Commissioner's own account of the harm, and the two forces' own figures, start to pull against each other.

What was exposed, and for how long

Suffolk's reprimand states plainly that "not less than 436 individuals" had personal data unlawfully published, combining 74 people from the 2018 request (36 suspects, 34 victims, three witnesses, one other party, with seven flagged "at high risk to safeguarding") and 362 people specific to Suffolk from the 2021-2022 batch, of whom 45 needed a personal visit because of that same high-risk flag (page 4, page 9, page 14) [1]. Norfolk's companion reprimand states "not less than 846" people specific to Norfolk, 85 of them high-risk (page 4, page 10) [2]. The exposed fields covered names, dates of birth, offence types and incident summaries tied to "revenge porn, weapons in school, online grooming, street crime death, theft, drug offences and hate crimes" [1]. The 2018 breach ran from no later than February 2019 to November 2022, and the 2021-2022 breach from March 2021 to July 2024, when the last two exposed spreadsheets were confirmed removed from a web archive [1].

The claim and the evidence

The Commissioner's reprimands both describe a formal "public sector approach" adopted in June 2022: a commitment to "increasing the use of Reprimands and Enforcement Notices, only issuing monetary penalties in the most egregious cases" (page 42) [1]. Under that approach, Suffolk's reprimand states that the Commissioner weighed whether this case cleared the "egregious" bar, and at "Step 1" of the Fining Guidance, "assessed the degree of seriousness as 'medium' rather than 'high', noting that whilst there was a clear lack of appropriate measures in place, a no-more-than basic general approach to data protection, and a significant duration of infringement, there was insufficient evidence of significant harm being suffered... due to the number of data subjects affected and the absence of evidence of actual harm" (pages 42-43) [1].

Two pages earlier, the same document records Suffolk's own submission to the Commissioner about the 2018 breach: "there is a chance the individual could be identified and the data in question is around sexual offences and therefore we can reasonably assume that it would cause the data subjects psychological distress having known it was in the public domain" (page 40) [1]. The same page notes Suffolk received direct contact from affected people raising concerns about the 2021-2022 breach. A "medium" severity finding citing an "absence of evidence of actual harm" sits awkwardly against a force's own written acknowledgement, quoted in the same notice, that harm was reasonably foreseeable, and against 52 people flagged for a personal safeguarding visit across the two forces.

The indicative fine

Because both forces are public authorities, neither pays anything. But the Commissioner's public sector approach also commits to calculating and publishing what the fine would have been, "so there is wider learning" (page 42) [1]. Both notices arrive at the same number: "The penalty of £70,875 would not be more than is appropriate or necessary in the circumstances" (Suffolk, page 52; Norfolk, page 41) [1] [2]. Norfolk's own stated total of affected people is nearly double Suffolk's, 846 against 436, yet the indicative figure that is supposed to reflect the seriousness of each case does not move at all between the two notices.

Norfolk's version of that sentence also reads: "This figure does not reflect any additional discount that may have been applied specifically due to Suffolk Constabulary's status as a public authority" (page 41) [2]. That is Norfolk's own reprimand, about Norfolk's own penalty, naming Suffolk. Both notices close with the same line, changed only by force name: "The Commissioner does not require [Norfolk/Suffolk] Constabulary to take any steps as a result of this Notice" (Suffolk, page 52; Norfolk, page 42) [1] [2].

The claims, tested

The Commissioner's own words What the record shows Verdict
The infringement's severity was "medium" rather than "high", citing "the absence of evidence of actual harm" (Suffolk, pages 42-43) [1] The same notice quotes Suffolk's own submission that the exposure "would cause the data subjects psychological distress" (page 40), and records 52 people across both forces flagged "at high risk to safeguarding" [1] [2] A harm finding resting on an evidentiary gap the document's own quoted material partly closes
The indicative penalty reflects the seriousness of each case, calculated individually per force Suffolk (436 people) and Norfolk (846 people) both receive £70,875, with no stated adjustment for the near-double difference in scale [1] [2] A case-specific figure that does not move when the stated number of affected people nearly doubles
Each reprimand is a distinct, case-specific legal finding against the named force Norfolk's own published reprimand names "Suffolk Constabulary" when explaining Norfolk's own indicative penalty (page 41) [2] A drafting error in a published legal document, consistent with one notice being copied into the other
The public sector approach "prevent[s] harms before they occur, and learn[s] lessons when things have gone wrong" Both notices end: "The Commissioner does not require [the force] to take any steps as a result of this Notice" (Suffolk, page 52; Norfolk, page 42) [1] [2], despite the forces' own internal report calling hidden FOI data "a recurring source of data breach across the country within the last decade" A finding of years-long, foreseeable failure that imposes no corrective step or review date

Credit where due

Both reprimands are genuinely detailed documents: dated correspondence, named internal reports, a careful walk through two separate technical failure modes (a stray worksheet in 2018, a pivot-table link in 2021-2022), and an explicit, public commitment to disclosing what a fine would have been even when none is charged. That transparency is more than most enforcement regimes offer. An earlier version of each reprimand, issued 13 May 2026, was withdrawn on 18 May after the Constabularies made further submissions, and the Commissioner reissued both rather than letting a contested version stand [1] [2]. Suffolk and Norfolk also removed the exposed material promptly once each breach was reported, and their joint internal inquiry, the Operation report quoted throughout both notices, is unsparing about its own force's failures.

Verdict

Three stars, from four documented mistakes. The underlying police failure here is itself well-documented and not in dispute; what this piece tests is the regulator's own account of it. A "medium" harm rating sitting next to a quoted admission of likely psychological distress, an indicative fine that does not respond to a near-doubling in the number of people affected, and a published legal notice that names the wrong force when explaining its own penalty: none of these is a single slip. Together they describe a process producing twin findings that read, in places, like one document edited into two.

The star score counts four documented mistakes: the "medium" severity finding citing an absence of evidence of harm, set against Suffolk's own quoted submission that the breach "would cause... psychological distress"; an indicative £70,875 penalty identical for both forces despite Norfolk's affected population being nearly double Suffolk's; Norfolk's own published reprimand naming "Suffolk Constabulary" in the paragraph explaining Norfolk's own penalty; and a "no steps required" conclusion in both notices despite the forces' own internal report describing this exact failure as a recurring, foreseeable national pattern. Four falls in the 4 to 9 band: three stars; the bands are on the ratings page. This piece makes no finding against the accuracy of the underlying facts the Commissioner establishes about either force's conduct, which are detailed and, on their own terms, convincing; the finding is narrower, that the regulator's own published reasoning about severity, penalty and which force is which does not fully hold up against its own evidence. Checked directly against both reprimand PDFs (52 pages and 42 pages, full text) and both ICO enforcement pages, all fetched 4 October 2026.

Sources

  1. Reprimand: The Chief Officer of Police for Suffolk Constabulary (PDF), Information Commissioner's Office, dated 20 May 2026
  2. Reprimand: The Chief Officer of Police for Norfolk Constabulary (PDF), Information Commissioner's Office, dated 20 May 2026
  3. Suffolk Constabulary, Information Commissioner's Office enforcement action page, 20 May 2026
  4. Norfolk Constabulary, Information Commissioner's Office enforcement action page, 20 May 2026
SHARE THIS ARTICLEXBlueskyMastodonLinkedInRedditEmail