TEARDOWN Published 5 October 2026 at 09:06. Evidence-based. Source-cited. No sponsored content.

An Information Commissioner audit found West Midlands Police lacks a policy document the law requires, and rated its records management only "Limited" assurance. None of the audit's 50 recommendations, eleven urgent, carries a date to fix it by.

3 out of 5 stars3/55 documented mistakes in this teardownHow ratings work

Estimated reading time: 6 minutes

The illuminated glass canopy and signage reading West Midlands Police Headquarters, Lloyd House, over the entrance of the force's Birmingham headquarters at night.
Lloyd House, West Midlands Police headquarters, Birmingham, photographed 2 April 2013. Photo: West Midlands Police / Wikimedia Commons, CC BY-SA 2.0.

In short. West Midlands Police agreed to a voluntary data protection audit under section 129 of the Data Protection Act 2018, not the compulsory assessment-notice power at section 146 (page 2) [1]. The Information Commissioner's Office rated Governance and Accountability "Reasonable" and Records Management "Limited", the weaker of its two grades (page 4) [1]. In the Governance section it also records that the force has no Appropriate Policy Document in place, a document section 42(3)(a) of the same Act says a controller "must" retain for the sensitive processing it relies on (page 8) [1] [3]. Fifty recommendations follow, eleven of them marked urgent, and not one carries a date by which it must be done. Five documented mistakes: three stars.

An audit report is only as useful as the deadline attached to it. West Midlands Police's data protection audit, published by the Information Commissioner's Office on 18 September 2026, runs to eleven pages and fifty numbered recommendations, eleven of them flagged the highest priority the ICO uses. It does not contain a single date. Not for the recommendations, not for a return visit, not for the Appropriate Policy Document the report itself says the force is missing. The audit happened because West Midlands Police asked for it, under a section of the Data Protection Act that exists precisely so no deadline needs to attach.

A voluntary check, and the force chose it

The report is explicit about which power produced it. "West Midlands Police (WMP) agreed to a consensual audit of its data protection practices," under section 129 of the Data Protection Act 2018, which lets the Commissioner assess good practice only "with the consent of a controller or processor" (page 2) [1] [2]. The Act gives the Commissioner a different, compulsory power at section 146, an assessment notice that can require entry to premises and production of documents whether or not the controller agrees [4]. That power was not used here. Nothing in the report explains why a force whose Records Management scope area was found to need "considerable scope for improvement" (page 4) [1] was checked on a voluntary basis rather than a compulsory one, or when, if ever, either kind of check will happen again.

Two grades, and the better one sits next to a missing legal document

The audit covered two scope areas. Governance and Accountability was rated "Reasonable": "a reasonable level of assurance that processes and procedures are in place and are delivering data protection compliance," with "some scope for improvement" (page 4) [1]. Records Management scored worse: "a limited level of assurance," with "considerable scope for improvement" (page 4) [1].

The better of the two grades sits beside findings that read like more than "some scope for improvement." Under Governance and Accountability, the same report records that "WMP must ensure that it has an Appropriate Policy Document (APD) in place" (page 8) [1], and that the force "must ensure that the lawful basis and condition(s) for processing personal information is sufficiently recorded on the Record of Processing Activities (ROPA)," including for children's personal data (page 8) [1]. An Appropriate Policy Document is not an optional best-practice extra. Section 42(3)(a) of the Data Protection Act 2018 states that where personal data is processed in reliance on a condition requiring one, "the controller must during the relevant period retain the appropriate policy document" [3]. The audit does not name that statutory duty, does not say how long the document has been missing, and sets no date by which it has to exist.

A backlog with no size attached to it

The audit also records that "WMP should continue its work in handling the backlog of Subject Access Requests (SARs) and introduce formal training for staff who handle such requests" (page 8) [1]. That is the entire finding. No figure for how many requests are outstanding, how old the oldest is, or what "continuing the work" has achieved so far appears anywhere in the eleven pages. A reader checking this report in a year's time has no number to check it against.

The weaker grade, and the paperwork that still does not exist

Records Management's "Limited" assurance rating sits on findings that are concrete rather than abstract. "WMP should create or finalise records management policies and Standard Operating Procedures (SOPs) which are currently in draft or yet to be written," covering "naming conventions, retention and weeding, and tracking of physical files" (page 8) [1]. The force is separately told it "must complete data mapping exercises to create a ROPA to ensure it has accurate and up to date information about the records it holds" (page 8) [1], and that it "should ensure that weeding of records is documented and routinely completed" (page 9) [1]. Weeding, the scheduled destruction of records no longer needed, is one of the oldest disciplines in records management. An August 2026 audit finding it undocumented, in a force holding criminal-justice records on millions of people, is not a footnote finding; it is the kind of gap the "considerable scope for improvement" language was presumably written to describe.

Nobody is committed to checking any of this again

The recommendations carry priority labels: 21 for Governance and Accountability (five urgent, six high, eight medium, two low) and 29 for Records Management (six urgent, 16 high, seven medium) (page 5) [1]. Eleven recommendations across the two areas are rated urgent, the highest category the report uses. None of the fifty, urgent or not, has a date attached in the document, and the ICO's own landing page for the audit adds nothing beyond the fact that the audit happened: "The ICO has carried out a data protection audit of West Midlands Police with its consent" [5]. The force itself, per the same report, has no programme of external audits of its own either: "WMP should establish a programme of external audits rather than relying on internal audits. The internal audits which are carried out should also be established as a formalised programme" (page 8) [1]. Taken together, that leaves this voluntary, undated ICO audit as close to the only outside check on these findings, and the document that recorded them commits nobody to looking again.

Credit where due

The audit also records real strengths, and the report is specific rather than vague about them. It found "a strong culture of privacy awareness with an organisation wide approach to data protection," an information governance training programme "endorsed and monitored by senior management," and a newly established Data Assurance Board providing general oversight (page 10) [1]. On the higher-risk end of processing, it found that a documented Data Protection Impact Assessment "is completed where the processing is likely to result in a high risk to the rights and freedoms of individuals," with outputs "acted on to effectively mitigate or manage any risks identified" and "kept under review" (page 10) [1]. On records specifically, it found user access permissions for electronic records "logged" and "periodically reviewed," alongside ongoing staff awareness campaigns and feedback following data quality checks (page 10) [1]. West Midlands Police also did not have to be made to accept this audit; it consented to it, and nothing in the report suggests it disputed the findings.

The claims, tested

The document's own words What the record shows Verdict
Governance and Accountability has "a reasonable level of assurance" (page 4) [1] The same scope area records no Appropriate Policy Document in place, a document section 42(3)(a) of the Data Protection Act 2018 says a controller "must" retain (page 8) [1] [3] The better of the two grades is awarded without naming the statutory duty the missing document represents, or a date to fix it
"WMP should continue its work in handling the backlog of Subject Access Requests (SARs)" (page 8) [1] No figure anywhere in the report for the backlog's size, age or trend A reader has no number against which to check whether this recommendation has since been met
Eleven recommendations are marked the ICO's highest "urgent" priority (page 5) [1] The audit was entirely voluntary under section 129, not the compulsory section 146 power [1] [2], and no re-audit date appears in the report or its ICO landing page [5] "Urgent" carries no enforceable deadline and no committed follow-up check
Records management SOPs for retention, weeding and physical files "are currently in draft or yet to be written" (page 8) [1] This sits in the scope area rated "Limited" assurance, the weaker of the two grades (page 4) [1] Basic recordkeeping infrastructure is confirmed absent, with no date set for when it will exist

Verdict

Three stars, from five documented mistakes. This is not a force that stonewalled its regulator: West Midlands Police asked for this audit, and the report records a genuine information-governance culture underneath the gaps, a training programme senior management actually monitors, DPIAs done properly where it counts most. What the document does not do is attach a single date to anything it found, including a document the law itself says the force must hold. Fifty recommendations and eleven urgent flags read as a serious document. Without a deadline anywhere in it, there is no way for anyone outside West Midlands Police, including this site, to check a year from now whether a single one of them was acted on.

The star score counts five documented mistakes: a "Reasonable" Governance and Accountability rating awarded in the same section that records no Appropriate Policy Document in place, a document section 42(3)(a) of the Data Protection Act 2018 says a controller must retain, with no reference to that duty and no date to fix it; the same "Reasonable" rating sitting beside a Record of Processing Activities that does not sufficiently record the lawful basis for processing, including children's personal data; a Subject Access Request backlog recommendation with no figure given for its size, age or trend, making it unmeasurable from the document alone; core records management policies and procedures, covering retention, weeding and physical file tracking, still in draft or unwritten in the scope area rated the weaker "Limited" assurance; and an entirely voluntary audit, under the Data Protection Act's consensual-audit power rather than its compulsory one, that sets no re-audit date and records that the force has no established external audit programme of its own either, leaving none of the 50 recommendations, including 11 marked urgent, attached to any deadline or committed follow-up check. Five falls in the 4 to 9 band: three stars; the bands are on the ratings page. This piece makes no finding that West Midlands Police's data protection practices are generally poor, or that the strengths the audit records, a genuine privacy culture, a monitored training programme, properly completed DPIAs, are not real; the finding is narrower, that the document recording these specific gaps attaches no date or enforcement mechanism to any of them. Checked directly against the eleven-page audit executive summary PDF (full text) and the ICO's audit landing page, both fetched 5 October 2026, and the relevant sections of the Data Protection Act 2018 on legislation.gov.uk.

Sources

  1. West Midlands Police: Data protection audit report (PDF), Information Commissioner's Office, August 2026, published 18 September 2026
  2. Data Protection Act 2018, section 129: Consensual audits, legislation.gov.uk
  3. Data Protection Act 2018, section 42: Safeguards: sensitive processing, legislation.gov.uk
  4. Data Protection Act 2018, section 146: Assessment notices, legislation.gov.uk
  5. West Midlands Police, Information Commissioner's Office, audits and overview reports
SHARE THIS ARTICLEXBlueskyMastodonLinkedInRedditEmail