The Metropolitan Police has been formally reprimanded by the Information Commissioner’s Office (ICO) for significant failures in handling sensitive personal data. The watchdog’s findings follow two separate incidents in which the police improperly disclosed personal information, including addresses, phone numbers, and witness details, to individuals involved in ongoing cases.

In one case, a woman who was the subject of a stalking protection order was forced to relocate and change her phone number after a Metropolitan Police officer mistakenly sent her contact information to the defendant. The offender subsequently contacted the victim on her new number, claiming to have obtained her updated details through police documents. Additionally, the Met improperly disclosed the names and contact information of three witnesses to the same defendant.

The second incident involved communications related to the bail conditions of a suspect in the so-called "honeytrap" case involving former Conservative MP William Wragg. When notifying those affected of a change in the suspect’s bail date via email, the Met failed to use blind carbon copy (BCC). This oversight exposed the full list of recipients’ names and email addresses to one another, raising significant privacy concerns.

The ICO described the Metropolitan Police’s data protection policies as “weak” and marked by “serious shortcomings.” It noted that at least one officer implicated in the breaches had not undertaken mandatory data protection training for more than four years prior to the incidents. While the force took some remedial steps—including informing those affected and issuing internal reminders to staff—the ICO concluded that these actions were insufficient to address the systemic issues.

As a result, the ICO issued a formal enforcement notice to the Metropolitan Police requiring them to urgently improve their data protection practices and staff training protocols. The regulator emphasized that the breaches reflect broader weaknesses in the force’s handling of personal information, underscoring the need for comprehensive reforms to prevent similar incidents in the future.

The Metropolitan Police has been approached for comment on the ICO’s findings but has yet to provide a response.