TEARDOWN Published 5 October 2026 at 03:41. Evidence-based. Source-cited. No sponsored content.

The Metropolitan Police exposed a stalking victim's new address to the man she was hiding from, and the regulator's own notice says that exact risk then came true. No fine was ever discussed.

3 out of 5 stars3/55 documented mistakes in this teardownHow ratings work

Estimated reading time: 7 minutes

The rotating triangular New Scotland Yard sign outside the Metropolitan Police's headquarters in London.
The New Scotland Yard sign, London, photographed 24 April 2024. Photo: Colin McLaughlin / Wikimedia Commons, CC0.

In short. The Information Commissioner reprimanded the Metropolitan Police Service (MPS) on 27 July 2026 over two 2024 data breaches (page 1) [1]. In the first, an unredacted file served to a defendant in a Stalking Protection Order case disclosed the victim's new address and phone number, information she had withheld specifically for her own safety (page 37) [1]. The Commissioner's own words: "this was a risk that subsequently materialised" when the defendant contacted her on the new number (page 37) [1]. Nowhere in the 65-page notice is a monetary penalty discussed or ruled out. Five documented mistakes: three stars.

A Stalking Protection Order exists so a court can restrict what a person poses a risk to another is allowed to do, before anything worse happens. The process depends on the people being protected trusting the police with details, particularly a new address, that only the police are supposed to hold. In February 2024, an MPS officer preparing the paperwork for an Interim Stalking Protection Order sent the defendant a file that had not been redacted. It included the victim's new address and telephone number, and the names, addresses and phone numbers of three witnesses (page 33) [1]. The officer in charge of the case was away on a training course; the file was prepared by colleagues who, the force's own breach report said, were not clear on what needed to be withheld, against an "overwhelming workload" (page 12) [1].

A risk the regulator says actually happened

The Commissioner does not treat this as a hypothetical. Having set out what stalking means in law, the notice states plainly that the victim "had purposefully not disclosed" her new address and number to the defendant, "with a view to self-protection following a history of domestic abuse" (page 37) [1]. Then: "this was a risk that subsequently materialised when, following Incident 1, the Defendant contacted the Victim on her new telephone number" (page 37) [1]. The same disclosure named the three witnesses who had given evidence to support the order, with the notice recording a further risk that the defendant could contact them too (page 37) [1]. This is a document about a process failure that is also, on its own account, a document about a specific person being found by the man a court order was meant to keep away from her.

A second breach, in the same force, the same year

The second incident sits in a different investigation entirely. During the "Honeytrap Matter", in which people connected to Parliament were targeted through WhatsApp messages gathering compromising material, an MPS officer emailed 18 of those affected on 29 November 2024 about a change to a bail date, and put every recipient's address in the "To" field instead of blind-copying them (page 33) [1]. All 18 could see each other's names and addresses; the force caught its own mistake within a minute and tried to recall the email at 15:36, three minutes after sending (page 17) [1]. The notice records that an unspecified number of the 18 were "displeased" their names had been shared, and that an MP raised the matter in the House of Commons (page 52) [1], a fact independently reflected in trade coverage of the notice once it was published [3] [4].

A finding of negligence, and no mention of a fine

The Commissioner's conclusion on both incidents is that they happened "as a result of the Metropolitan Police Service's negligence", and that the force "has not intentionally sought to infringe its data protection obligations" (page 53) [1]. The same paragraph adds that the infringements were "both foreseeable and preventable" (page 53) [1]. From there the notice moves straight to a reprimand as "appropriate and proportionate" (page 55) [1]. What the document does not contain, across all 65 pages, is any paragraph weighing a monetary penalty against a reprimand and explaining why the lesser sanction was chosen for a case in which the Commissioner's own words describe a stalking victim's protected address reaching her alleged stalker. The UK GDPR gives the Commissioner power to fine; this notice never says it was considered.

The one target in the whole notice, and who set it

Annex 1 requires the Metropolitan Police Service to review its email procedures within three months, and within 12 months to "significantly improve" training compliance rates, improve how it follows up staff who miss training, and implement "an appropriate monitoring programme" so compliance is "appropriately logged and audited" (page 63) [1]. None of those four terms carries a number. The only verification mechanism attached to any of them is that the force reports its own progress to the Commissioner every three months (page 63) [1]; no audit, inspection or independent check is specified. A fifth proposed term, requiring the force to improve its specialist Stalking Protection Order training compliance specifically, was dropped entirely. The reason given: the force's own representations stated SPO training compliance had reached 88%, and that from 26 April 2026 it would track towards "a mandatory compliance rate of 100%" (page 59) [1]. That 100% is the only numeric compliance figure anywhere in this enforcement notice, and the Metropolitan Police Service set it itself.

Numbers that kept changing

The 88% figure, and the force's general training record, rest on self-reported statistics that shifted repeatedly through the investigation. In February 2025 the force gave the Commissioner one set of completion rates; a letter dated 31 July 2025 gave another; on 19 August 2025 it wrote again "claiming that the statistics provided on 21 February 2025 were inaccurate" and supplying revised figures the Commissioner's own footnote calls "somewhat unclear", because they no longer distinguished the measure the earlier figures had used (page 29) [1]. The Commissioner's assessment of the 19 August figures, before a further revision arrived in May 2026, was that they "remained objectively low" (page 30) [1]. Four different sets of compliance statistics inside fifteen months is the evidence base the notice relies on to accept the force's account of its own improvement, with no independent audit of any of them built into the remedy that follows.

The same gap, one level up

The email that caused the second breach was sent by an officer who had not completed mandatory data protection training since 2020. The notice does not stop there: "the manager conducting the appraisals also had not completed their own data protection training since 2020 which, in the Commissioner's view, goes towards demonstrating a systemic issue with regards to the monitoring of staff training" (page 48) [1]. That finding, that the person meant to catch the lapse shared it, sits awkwardly against the Commissioner's later framing of the same facts as the force's "negligence" (page 53) [1], a word that describes a single failure to take care rather than two unsupervised people missing the same training for four years running.

The claims, tested

The notice's own words What the record shows Verdict
The Incident 1 disclosure "was a risk that subsequently materialised" when the defendant contacted the victim (page 37) [1] The Commissioner moves from this finding to "negligence" and a reprimand (page 53) [1], with no paragraph anywhere weighing or rejecting a monetary penalty A materialised safety risk to a stalking victim gets no recorded penalty discussion at all
Annex 1 requires the force to "significantly improve" training compliance and implement "appropriate" monitoring (page 63) [1] The only numeric target in the notice, 100% SPO compliance, is the force's own voluntary commitment (page 59) [1], not an ICO-set figure, and verification is quarterly self-report only (page 63) [1] The regulator sets no number and checks nothing independently
The 88% SPO figure and wider training record justified dropping a binding term (page 59) [1] The force supplied at least four different sets of training statistics across 15 months, one revision explicitly correcting the last as inaccurate, another called "somewhat unclear" by the Commissioner's own footnote (page 29) [1] The evidence trusted to close out a term was itself unstable throughout the investigation
Both infringements are attributed to the force's "negligence" (page 53) [1] The supervising manager had missed the identical mandatory training since 2020, which the Commissioner calls "a systemic issue" (page 48) [1] The document's own evidence points to a supervisory gap the penalty reasoning does not separately address

Credit where due

The force did some things right. Incident 2 was self-reported to the Commissioner the same day it happened, within the 72-hour statutory window, and the sending officer tried a recall within minutes, followed by a request that recipients delete the email (page 17) [1]. The force had also, before this notice, rolled out stalking-awareness training and built a multi-stage quality-assurance gateway for Stalking Protection Order paperwork (page 13) [1]. None of that undoes what happened to the people affected, but it is the difference between a force that hid a breach and one that reported its own mistake on the day it made it.

Verdict

Three stars, from five documented mistakes. The Commissioner's own notice establishes that a stalking victim's protection failed in exactly the way the underlying order was meant to prevent, then closes the case with a reprimand, a self-set target the regulator did not set, and a training record that changed shape four times before anyone trusted it. A document that can write "this was a risk that subsequently materialised" about a named victim and never once discuss a fine has left the hardest question in its own case unanswered.

The star score counts five documented mistakes: the notice records a stalking-related risk that materialised into actual contact with the defendant, yet contains no discussion anywhere of a monetary penalty as an alternative to reprimand; Annex 1 sets no ICO-imposed numeric compliance target, relying instead on the force's own voluntary 100% commitment and quarterly self-reported updates with no independent audit specified; the 88% SPO training figure used to drop a binding term rests on self-reported statistics that changed across at least four different submissions in 15 months, one explicitly correcting the last as inaccurate; the force's "negligence" finding does not separately address the Commissioner's own evidence that the supervising manager had missed the same mandatory training as the officer involved, which the notice itself calls a systemic issue; and the Notice of Intent followed the force's last substantive investigative response by more than eight months, with no explanation given, stretching the gap between the Incident 1 breach and the final notice to nearly two and a half years. Five falls in the 4 to 9 band: three stars; the bands are on the ratings page. This piece makes no finding on whether a reprimand was the legally correct outcome, a judgement for the Commissioner alone, or on the adequacy of the force's stalking-awareness training itself, which the notice describes in some detail as already improved. The finding is narrower: that the notice's own words document a materialised safety risk and a self-reported, repeatedly revised evidence base, and never explains why neither changed the choice of sanction. Checked directly against the 65-page reprimand and enforcement notice PDF (full text) and independent reporting, all fetched 5 October 2026.

Sources

  1. Chief Constable Commissioner for the Metropolis / Metropolitan Police Service (MPS): Reprimand and Enforcement Notice (PDF), Information Commissioner's Office, dated 27 July 2026
  2. Chief Constable Commissioner for the Metropolis/ Metropolitan Police Service (MPS), Information Commissioner's Office, enforcement action page
  3. ICO finds 'serious and ongoing shortcomings' after Met Police gave victim's details to alleged stalker, PublicTechnology, 7 August 2026
  4. Met Police data failures put stalking victim and MPs' contacts at risk, UKAuthority, 7 August 2026
SHARE THIS ARTICLEXBlueskyMastodonLinkedInRedditEmail