Met Police ICO Reprimand: Sensitive Data Mistakes Show Why Email Hygiene Matters
The ICO says two Metropolitan Police incidents exposed highly sensitive personal information, including a stalking victim's new contact details and names linked to a high-profile investigation.
Quick takeaways
- The ICO issued the Metropolitan Police Service with an enforcement notice and reprimand after two sensitive disclosure incidents.
- One incident involved unredacted documents revealing a stalking victim's new address and phone number to the alleged stalker; another put 18 people's names and email addresses in the To field in a sensitive investigation update.
- A VPN can protect traffic on a network, but it cannot undo an email sent to the wrong audience, missing redactions, weak training or poor data-handling governance.
What happened?
The UK Information Commissioner's Office issued the Metropolitan Police Service with an enforcement notice and reprimand after finding data protection failures in two highly sensitive cases. The ICO says MPS failed to put appropriate technical and organisational measures in place to protect personal information, infringing section 40 of the Data Protection Act 2018.
In one incident, an MPS officer served unredacted documents in a Stalking Protection Order case. The ICO says the papers included the victim's new address and telephone number, plus names and contact details for three witnesses; the defendant later contacted the victim on the new number. In another incident linked to the so-called Honeytrap matter, 18 people connected to the UK Parliament were emailed with recipients placed in the To field, exposing names and email addresses in a sensitive context.
Why it matters for anyone handling sensitive data
The ICO's point is that these were not only one-off slips. Its investigation found wider weaknesses in MPS policies, procedures and assurance arrangements, along with low data-protection training completion rates. The regulator ordered improvements to training compliance, monitoring and governance over three- and 12-month deadlines.
For ordinary users, the incident is a reminder that privacy failures often happen through everyday workflows: redaction, email addressing, attachments, shared folders and staff training. The data may be protected while stored or transmitted, but it can still be exposed if the wrong person receives it.
What you can do now
If you send sensitive information at work, slow down around three moments: redaction, recipients and attachments. Use a second-person review for high-risk disclosures, send sensitive updates through controlled portals where possible, and avoid bulk emails for groups where membership itself reveals sensitive context.
Individuals affected by a disclosure should save evidence, change exposed contact routes where necessary, watch for phishing that references the incident, and use official complaint or support routes. Organisations should treat training completion as a measurable control, not a policy document nobody checks.
Where a VPN helps — and where it does not
A VPN can protect traffic on public Wi-Fi and reduce what a local network or ISP can see. For remote workers, enterprise VPNs and zero-trust access controls can also help restrict access to internal systems.
But a VPN cannot redact a document, hide email recipients from each other, recall a disclosure after it has been read, or make weak governance disappear. This story is about human process, training, assurance and safer communication channels more than network encryption.
VPN Rocks view
Good privacy is boring by design: fewer recipients, fewer copies, clearer checks and safer defaults. The Met Police case shows why sensitive organisations need controls that catch mistakes before vulnerable people pay the price.
For readers, the takeaway is not to abandon digital services but to understand the limits of each protection layer. A VPN is useful on the network; it does not fix data that an organisation has already put in the wrong hands.
Sources and further reading
VPN Rocks adds plain-English analysis and practical advice. Source links are included so readers can check the underlying guidance directly.