Ariana Grande Song Leak: A Cyber...
The alleged theft and leak of Ariana Grande’s unreleased material highlights how cyber criminals can reach valuable information through trusted...
Read MoreWhen a data breach is traced back to an individual employee, describing the cause as “human error” can be tempting. Someone sent an email to the wrong recipients, failed to redact a document correctly, or did not follow an established procedure.
However, the Information Commissioner’s Office’s recent enforcement action against the Metropolitan Police Service demonstrates why organisations need to look beyond the individual mistake. When employees have not been properly trained, procedures are inadequate, compliance is not monitored, or known weaknesses are allowed to persist, human error can become a governance failure.
On 5th August 2026, the ICO announced that it had issued the Metropolitan Police Service (MPS) with an enforcement notice and reprimand following two serious disclosures of personal information. The regulator did not treat the cases as isolated employee mistakes. Instead, its investigation identified wider weaknesses in data protection training, policies, procedures, monitoring, assurance and governance.
For leaders in organisations handling personal information, the case provides an important reminder: responsibility for data protection does not end when a policy has been written or an annual training course has been assigned. Organisations must be able to demonstrate that controls are working in practice.
The ICO investigated two separate incidents involving highly sensitive personal information.
The first concerned a Stalking Protection Order case. An MPS officer served unredacted documents on a defendant which contained the victim’s new address and telephone number, alongside the names and contact details of three witnesses. The victim had changed her contact details because of the risks she faced. The defendant subsequently contacted her using the new telephone number that had been disclosed in the documents.
The ICO found that the MPS had failed to ensure confidential third-party information was properly redacted before the documents were served. Relevant officers had also not received the required specialist Stalking Protection Order training at the time, while the process for preparing and quality-assuring documents was considered inadequate.
The second incident involved people connected with the so-called parliamentary “Honeytrap” investigation. An officer sent a bulk email updating affected individuals about a change to the suspect’s bail date. Rather than concealing the recipients, their email addresses were placed in the “To” field, allowing everyone receiving the message to see the names and email addresses of the other recipients. The context of the communication meant that sensitive information about their connection to the investigation could potentially be inferred. Eighteen people linked to the UK Parliament were affected.
On their own, both events could easily have been characterised as staff mistakes. However, the ICO reached a much broader conclusion.
The ICO found that the two breaches reflected wider weaknesses in the MPS’s policies, procedures and assurance arrangements for handling sensitive information. It also identified serious shortcomings in data protection training.
Particularly significantly, the officer responsible for sending the bulk email had not completed data protection training for more than four years before the incident. The officer’s line manager had also not completed the relevant training for almost four years. The investigation subsequently found that completion rates for mandatory Managing Information training were low across the organisation.
The ICO concluded that the MPS had failed to put appropriate technical and organisational measures in place to protect personal information, infringing section 40 of the Data Protection Act 2018. Section 40 applies to law enforcement processing and requires personal information to be processed in a manner that ensures appropriate security, including protection against unauthorised or unlawful processing, using appropriate technical or organisational measures.
The distinction is important. The immediate action that causes a breach may be performed by one person, but the conditions that make the breach possible can be organisational. A member of staff may fail to redact a document, but management determines whether a reliable quality assurance process exists. An employee may send sensitive information incorrectly, but the organisation determines whether they have received recent and relevant training, whether completion is monitored, whether managers follow up on non-compliance and whether technical controls are available to reduce the likelihood of mistakes. Those are governance decisions.
One of the clearest lessons from the enforcement action is that having a policy does not, by itself, demonstrate compliance. The ICO’s position was particularly clear: policies and reminders are insufficient when they are not followed, checked and enforced. It described both incidents as foreseeable and preventable and emphasised the need for effective training, monitoring and assurance.
The principle extends well beyond policing. An organisation may have an information security policy, data protection policy, data handling procedure, mandatory training programme and documented breach management process. The documents are valuable, but they do not prove that the organisation’s controls are operating effectively.
The ICO’s wider accountability guidance makes the same point. Accountability is not intended to be a box-ticking exercise. Organisations are expected to take responsibility for their processing and be capable of demonstrating the measures they have implemented to protect people’s information and rights. For leadership teams, this changes the question from “Do we have a policy?” to “Can we demonstrate that the policy is working?”
Annual data protection training is common across organisations, but its existence is only one part of the control. Leadership also needs visibility of whether employees have actually completed it.
The ICO’s Data Protection Audit Framework recommends induction and refresher training for staff, appropriate monitoring of completion rates, defined timescales for completing refresher training and managerial responsibility for following up with employees who have not completed it. It even identifies removal of access to personal information as a possible measure where required refresher training remains incomplete.
The framework also recommends treating training completion as a measurable governance issue. Relevant key performance indicators can include the percentage of staff completing data protection and information governance training, alongside metrics covering security incidents, breaches and near misses. That makes training completion more than an administrative responsibility for HR, compliance or an e-learning platform. For organisations processing significant quantities of personal or sensitive information, persistent non-completion should be visible to senior management.
A dashboard showing that mandatory training has been assigned to 100% of employees tells leadership very little. A dashboard showing completion rates, overdue training, repeat non-compliance, department-level trends and remediation actions provides meaningful assurance.
The ICO’s accountability framework specifically expects data protection and information governance to have strong leadership and oversight, with clear reporting lines, responsibilities and information flows. It recommends assigning overall responsibility for data protection and information governance at board or senior management level and ensuring that significant issues and risks are reported upwards.
This does not mean directors need to become data protection lawyers or personally review every outgoing email. It means they should receive enough information to challenge whether the organisation’s controls remain effective.
If mandatory training completion has remained low for months, has the issue been escalated? If repeated near misses involve emails being addressed incorrectly, has the organisation considered technical measures to reduce the risk? If employees routinely handle particularly sensitive records, do processes include additional checks or approvals before information is disclosed? If an audit identifies control weaknesses, who owns the corrective actions, and how does leadership know when they have genuinely been resolved? Governance becomes ineffective when senior leaders receive confirmation that policies exist but no evidence about whether employees are following them.
The Met’s response also illustrates the role technology can play in reducing human error. Following the bulk email incident, the MPS introduced a behavioural alert tool designed to prompt staff when emails were being sent to multiple external recipients. It also strengthened quality assurance arrangements in relation to Stalking Protection Order applications and delivered additional specialist training.
These are useful examples of controls being redesigned around real-world behaviour. Training staff to use BCC appropriately may reduce risk. Configuring technology to recognise potentially risky bulk emails and prompt the sender before information is disclosed provides another layer of protection. Likewise, telling employees to check documents before sending them is helpful. Creating a formal review or approval process for particularly sensitive disclosures provides greater assurance.
This reflects the broader requirement within data protection law to consider both technical and organisational measures. The ICO’s security guidance states that appropriate security involves risk analysis, organisational policies, and physical and technical controls, with organisations expected to test their effectiveness and make improvements when weaknesses are identified.
Good governance therefore does not assume that employees will never make mistakes. It designs processes so that a single mistake is less likely to result in a serious breach.
The first MPS incident also highlights something that can sometimes be forgotten during compliance exercises: data protection is ultimately concerned with risk to people.
This was not simply an incorrect document being sent. A stalking victim had deliberately changed her address and telephone number because of concerns about her safety. Those new details were then disclosed to the person from whom she required protection. The severity of that potential harm should influence the safeguards surrounding the information.
A process handling a generic business contact email address does not necessarily require the same controls as a process handling health information, financial details, criminal records, information relating to vulnerable individuals, or confidential investigations.
The ICO’s security guidance emphasises this risk-based approach. Appropriate measures depend on the nature, scope, context and purpose of the processing, alongside the potential risks to individuals. Its examples of potential consequences of poor information security include fraud, intimidation and the exposure of addresses belonging to people who may be at risk.
Leadership teams should therefore understand not only what information their organisation processes, but where the consequences of a mistake could be particularly serious. Those processes warrant greater security.
Human error is already the leading cause of personal data breaches reported to the ICO. The regulator advises organisations to consider measures such as mandatory induction and refresher training, supervision, improved procedures, technical controls and investigation of the root causes behind breaches and near misses.
That final point is crucial. Closing an incident with “employee error” as the root cause risks missing the real problem. Those in leadership roles should be asking further questions: why did the employee make the mistake? Was the procedure unclear? Had they received adequate training? Was the training relevant to their role? Was workload or time pressure a factor? Was a second-person review appropriate given the sensitivity of the information? Could technology have detected the mistake? Had similar near misses previously occurred? Was management aware that training completion or policy compliance was poor?
These questions shift incident investigation away from assigning individual blame and towards identifying weaknesses in the control environment.
The Metropolitan Police enforcement action provides an opportunity for organisations to review their own arrangements before a similar incident exposes weaknesses. Senior leadership should be able to answer several fundamental questions:
The ICO’s audit framework specifically recommends ongoing monitoring, internal auditing, testing staff adherence to policies, documenting findings, maintaining action plans and reporting relevant outcomes to oversight and governance bodies.
Being unable to answer these questions does not necessarily mean a serious breach is imminent. It does, however, indicate that leadership may have limited visibility over whether the organisation’s data protection controls work outside the policy document.
The ICO’s action against the Metropolitan Police should not be interpreted simply as a warning to employees to be more careful when sending emails or redacting documents. Its more significant message concerns organisational accountability.
People will make mistakes. Effective governance should reduce how often those mistakes happen, detect them where possible and limit their consequences when they do. That requires training, but also monitoring of that training. It requires policies, but also assurance that those policies are followed. It requires technical controls, but also processes to test whether those controls remain effective. Most importantly, it requires leadership to have sufficient visibility of data protection risks to challenge weaknesses before an incident forces the issue.
The Met case demonstrates what can happen when individual errors expose broader weaknesses within the control environment. For boards and senior leadership teams, the lesson is straightforward: data protection cannot be delegated entirely to the DPO, compliance team or individual employees handling the information.
Accountability ultimately sits with the organisation, and when an organisation cannot demonstrate that its safeguards are working, human error can quickly become a governance failure.
AJC helps organisations strengthen their approach to data protection by reviewing how policies, processes and controls work in practice. Our data protection services can help identify gaps, assess compliance and provide practical recommendations to improve governance, reduce risk and demonstrate that appropriate safeguards are in place.
Contact us on 020 7101 4861 or email us at info@ajollyconsulting.co.uk if you think we can help.
Sources:
https://ico.org.uk/action-weve-taken/enforcement/2026/07/metropolitan-police-service-en/
https://www.infosecurity-magazine.com/news/ico-reprimands-metropolitan-police/
https://www.freevacy.com/news/ico/mps-issued-second-enforcement-notice-for-foi-failings/7290
https://www.bbc.co.uk/news/articles/czek8dd35ywo
Image accreditation: James Mitchell (2011) from Wikimedia Commons. Last accessed on 19 August 2026. Available at:
https://commons.wikimedia.org/wiki/File:Metropolitan_Police_officers_at_Occupy_London_Finsbury_Square.jpg
The alleged theft and leak of Ariana Grande’s unreleased material highlights how cyber criminals can reach valuable information through trusted...
Read MoreRecent incidents involving OpenAI, Anthropic and Meta have shown how advanced AI models can cross intended boundaries during cyber security...
Read MoreThe AssuranceAmerica data breach has exposed sensitive personal and insurance-related information belonging to almost seven million people. This article looks...
Read More