
A woman who changes her address and phone number to escape an alleged stalker should be able to trust that the police will keep those details confidential. However, in one case examined by the UK’s data protection regulator, an unredacted police document put that information directly into the hands of the person she feared.
The Information Commissioner’s Office (ICO) has reprimanded the Metropolitan Police Service (MPS) over that breach and a separate email error connected to the high-profile “Honeytrap” investigation.
The regulator said the incidents exposed weaknesses in training, monitoring, governance and safeguards for sensitive information—not merely two isolated mistakes.
The reprimand and enforcement action, announced on Aug. 5, requires the MPS to improve its data protection practices on deadlines of three and 12 months.
• The MPS disclosed a woman’s new address and phone number to her alleged stalker in unredacted documents
• A separate bulk email exposed the names and email addresses of 18 people linked to the UK Parliament and the “Honeytrap” investigation
• The ICO found that the MPS lacked appropriate technical and organisational safeguards, breaching Section 40 of the Data Protection Act 2018
• Investigators identified wider failures in training compliance, oversight, document checks and secure communication practices
• The MPS must make improvements to training, monitoring and governance within three and 12 months
The first incident involved documents supporting an application for a Stalking Protection Order, a legal measure intended to protect people from stalking-related risks.
According to the ICO, an MPS officer served the defendant with documents that had not been properly redacted. They contained the victim’s new home address and phone number, along with the names and contact details of three witnesses.
The victim had changed her address and phone number to reduce the risk. The defendant subsequently contacted her on the new number and told her that the MPS had supplied documents containing her updated details.
The regulator found that the MPS had failed to ensure confidential third-party information was removed before the documents were served. Relevant officers had also not received the required specialist training on Stalking Protection Orders, while the process for preparing and checking documents was inadequate.
This is what makes the disclosure especially serious. Contact details are often treated as routine personal data, but their sensitivity depends on context. For someone trying to hide from a stalker, a phone number or address can become safety-critical information.
The second breach arose from the so-called “Honeytrap matter,” in which people connected to the UK Parliament were targeted through WhatsApp messages in 2024 and 2025 in an apparent attempt to obtain compromising information.
An officer sent a bulk email notifying affected people that the suspect’s bail date had changed. Instead of concealing the distribution list, the officer placed every recipient in the “To” field. All recipients could therefore see one another’s names and email addresses.
The MPS confirmed that 18 people linked to Parliament were affected. Although the body of the message did not explicitly include sensitive details about them, the context could allow recipients to infer their connection to the investigation.
The ICO concluded that the MPS should have used a more appropriate communication method rather than a single bulk email in such sensitive circumstances.
Neither incident involved a hacker exploiting a software vulnerability or breaking into a police network. Both resulted from preventable failures in how people, processes and technology handled sensitive data.
The ICO found that the MPS had not put appropriate technical and organisational measures in place to protect personal information, infringing Section 40 of the Data Protection Act 2018.
Its investigation also uncovered poor compliance with mandatory data protection training and inadequate management oversight.
The officer responsible for the Honeytrap email had not undergone data protection training for more than four years before the incident. The officer’s line manager had also gone almost four years without the training.
More broadly, completion rates for the MPS’s mandatory Managing Information course were found to be low, with the force itself acknowledging that further improvement was needed.
Jo Stones, ICO group manager for Civil and Cyber Investigations, described the incidents as “foreseeable and preventable,” adding:
Policies and reminders are not enough if they are not followed, checked and enforced.
That distinction matters well beyond policing. Written policies cannot protect sensitive data unless staff understand them, managers verify compliance, high-risk processes include meaningful checks, and technical safeguards help prevent predictable human errors.
The MPS notified the people affected and offered additional support in the stalking case. It also delivered more specialist training and introduced a stronger, multi-stage quality-assurance process for Stalking Protection Order applications.
Following the bulk-email incident, the force contacted the affected people, issued a force-wide reminder about mandatory information-security training and introduced a behavioral alert designed to warn staff when they are about to email multiple external recipients.
The ICO took those measures into account but concluded they were not enough. Training completion remained low, while some wider technical controls and monitoring arrangements had not been fully implemented or shown to work effectively.
The enforcement notice therefore gives the MPS three- and 12-month deadlines to improve training compliance, monitoring and governance. The reprimand formally records the infringements associated with both incidents.
The decision adds to the force’s recent information-governance scrutiny. In March 2026, the ICO served the MPS with a separate enforcement notice over its performance under the Freedom of Information Act.
A proper response depends on what was disclosed and who received it. A leaked password creates different risks than an exposed home address, case history or list of contacts.
If an organisation tells you that your information has been exposed:
• Ask exactly what information was disclosed, when it happened, who received it and what the organisation has done to contain the incident
• Treat physical safety information as urgent—contact the police or the organisation’s safeguarding team if an address, phone number or location data could put you at risk
• Be alert for targeted calls, messages and emails that use the exposed information to appear credible
• Change passwords and enable multi-factor authentication if login credentials or account details were involved; there is no need to reset unrelated accounts
• Keep the breach notice and records of your communications in case you need to make a complaint or document resulting harm
• Raise unresolved data protection concerns with the organisation first and, where appropriate, report the matter to the ICO
Data-exposure monitoring can also help people discover whether personal information appears in known breaches. Services such as Bitdefender Digital Identity Protection provide alerts and guidance, but monitoring cannot reverse a disclosure—especially when the exposed information affects someone’s physical safety. Rapid containment and direct support are essential.
The MPS incidents show that a data breach does not need malware, stolen credentials or an advanced attacker to cause real harm. An unredacted document or a poorly addressed email can be enough—particularly when an organisation holds information about victims, witnesses and sensitive investigations.
Training matters, but the ICO’s message goes further: when personal information can affect someone’s safety, privacy can’t depend on a simple reminder. Organisations must verify that training is completed, build checks into high-risk workflows, use technical guardrails and hold managers accountable.
Related:
What to do if your data gets caught in a breach
Have you fallen victim to a data breach? Follow these six steps
tags
Filip has 17 years of experience in technology journalism. In recent years, he has focused on cybersecurity in his role as a Security Analyst at Bitdefender.
View all posts