ICO action against the Metropolitan Police: why training and assurance must be demonstrable

Scott Dooley
5 min read · Aug 9, 2026

An ICO enforcement notice and reprimand issued to the Metropolitan Police Service (MPS) offer a practical reminder for any organisation that handles sensitive personal information: training, monitoring and assurance must work together—and be capable of being demonstrated. A policy or annual reminder is not evidence that people have the knowledge, supervision and checks required for the work they actually do.

On 5 August 2026, the Information Commissioner’s Office announced action following two disclosures in highly sensitive police cases. The ICO found that MPS had not put appropriate technical and organisational measures in place, an infringement of section 40 of the Data Protection Act 2018. This was an enforcement notice and reprimand, not a monetary fine. The regulator’s announcement should not be recast as a UK GDPR Article 32 finding.

What the ICO found

The ICO enforcement notice describes two incidents. In one, unredacted documents in a Stalking Protection Order case revealed a victim’s new contact details to the defendant. In the other, a bulk email exposed the names and email addresses of people connected with a highly sensitive investigation. The facts differ, but the underlying lesson is the same: a task that may seem routine can create severe consequences when confidential information is handled without the right safeguards.

The regulator said the incidents were not isolated mistakes. Its investigation found wider weaknesses in policies, procedures and assurance arrangements for sensitive personal information, alongside inadequate monitoring and governance of training compliance. The ICO also recorded that the officer who sent the second email had not completed data-protection training for more than four years before the incident; the line manager had also not completed relevant training for almost four years.

That matters beyond policing. Employers should not treat completion data as a compliance metric with no operational meaning. As recent lessons from medical-record access and council-record access show, the risk sits where people can see, send, export or discuss personal information as part of their day-to-day work.

The operational lesson: completion is only the start

Mandatory training needs a defensible operating model. First, identify roles that handle sensitive data or make decisions that affect it. Then give those roles training that is relevant to their actual activities—for example, checking redactions, choosing secure recipients, using email fields correctly, escalating uncertainty and applying local procedures.

Second, measure completion in a way managers can act on. A central dashboard should show the required population, overdue learners, due dates, exceptions and the named manager responsible for follow-up. Escalation needs an owner and a timetable. Otherwise a low completion rate can persist as background noise, rather than triggering intervention before an incident.

Third, test whether learning changes practice. Short scenario checks can test decision-making, but they should be supported by proportionate assurance: sampling high-risk processes, reviewing errors and near misses, checking that supervisors intervene, and recording corrective action. When a process changes after an incident, repeat the assurance after implementation rather than assuming a revised procedure has solved the problem.

A manager checklist for sensitive-data work

  • Define the population. Map employees, contractors and managers who use or supervise sensitive data.
  • Set a practical standard. Specify the course, deadline, refresher cycle and role-specific modules each group must complete.
  • Act on overdue training. Give line managers clear ownership, regular reports and an escalation route for persistent non-completion.
  • Assure critical tasks. Sample areas such as redaction, email distribution, record access and case preparation; look for evidence that the intended control operates.
  • Close the loop. Record findings, actions, owners and retest dates. Use incident themes to update learning and local processes.

Risk assessment can help focus this effort. Where a processing activity is likely to create a high risk to people, a DPIA may identify the relevant safeguards, owners and review points. The output is most useful when it drives real controls—rather than becoming a document disconnected from the teams handling the data.

What the enforcement notice requires

The ICO announcement says the enforcement notice requires MPS to improve data-protection training compliance, monitoring and governance within three and 12 months. It also acknowledges steps already taken, including further specialist training, a strengthened quality-assurance process for Stalking Protection Order applications and a behavioural alert intended to prompt staff when sending emails to multiple external recipients. The regulator nevertheless concluded that further action was needed because completion rates remained low and some proposed improvements had not been fully implemented or shown to be effective.

This distinction is important for senior leaders. Introducing a control is not the same as assuring its effectiveness. Boards and accountable executives should be able to ask: who must complete training, what is the current rate, where are the exceptions, what checks test the high-risk process, and what evidence shows the response is working? Similar discipline is relevant when preventing insider access misuse or protecting employee data.

Frequently asked questions

Was MPS fined by the ICO?

No. The ICO announcement describes an enforcement notice and a reprimand. It does not describe a monetary penalty.

What should a training dashboard show?

At minimum: the people required to complete training, their due dates and status, overdue exceptions, the responsible manager, and the action and escalation for unresolved gaps. For high-risk work, pair this with evidence from assurance checks.

Is a completed course enough to demonstrate compliance?

No. Completion is useful evidence, but it does not by itself show that a process is being followed or that controls work in practice. Use appropriate monitoring, sampling and corrective action alongside training.

Sources