The UK's data protection regulator has reprimanded London's Metropolitan Police Service after officers disclosed a stalking victim's new home address and phone number directly to the man prohibited from contacting her. The Information Commissioner's Office issued an enforcement notice and formal reprimand on August 5, 2026, following two separate data breaches that occurred in 2024. The watchdog determined that both incidents were avoidable and pointed to systemic shortcomings in how the force manages sensitive personal data.

The first breach involved a man placed under an interim Stalking Protection Order in January 2024, which barred him from reaching out to his victim. Officers provided the defendant with unredacted witness statements and documents that revealed the victim's new address and phone number, along with contact details for her friends and family, despite explicit warnings to remove all identifying information. Within days of receiving these materials, the man—who had already fled the country in violation of his bail terms—contacted the victim using her new number. He was arrested in July 2024 when he returned to the UK, later pleaded guilty to stalking charges, and was sent to prison. The second incident exposed the email addresses of 18 individuals connected to Parliament who had been targeted in a honeytrap scheme, after an officer forgot to use the blind carbon copy function and instead sent a group message that allowed recipients to see one another's addresses.

According to the Information Commissioner's Office, the officer who sent the honeytrap email hadn't finished data protection training in more than four years, and his supervisor had gone nearly as long without completing the required coursework. The regulator found that training completion rates across the Metropolitan Police were consistently low and that the breaches "reflected wider weaknesses in MPS policies, procedures, and assurance arrangements for handling sensitive personal information." Jo Stones, group manager of civil and cyber investigations at the ICO, said people "have the right to expect that information will be handled securely," adding that "these incidents were foreseeable and preventable."

The enforcement notice requires the Metropolitan Police to reach 100 percent compliance with data protection training within 12 months and to pursue officers who miss deadlines. Every three months, the force must also examine how personnel send emails to multiple people, weigh more secure options, and update the regulator on training progress. The ICO emphasized that policies and reminders aren't sufficient if they're not consistently followed, monitored, and enforced—particularly for public sector agencies handling law enforcement data. A Metropolitan Police spokesperson acknowledged that the breaches "fell short of the standards we expect" and said the force has already taken steps to strengthen disclosure processes, though it remains "disappointed" by the enforcement action. For organizations managing sensitive information during crises, the cost of procedural lapses extends well beyond regulatory penalties—victims can lose faith in the institutions designed to protect them, and staff accountability becomes harder to enforce when training is treated as optional rather than mission-critical.