The Met handed a stalker his victim's new address
The UK Information Commissioner's Office has issued an enforcement notice and a reprimand to the Metropolitan Police over two data protection failures in 2024. In the first, officers handed unredacted documents to a man subject to a Stalking Protection Order, exposing his victim's new address and phone number along with contact details for her friends and family. She had fled and changed her number; he contacted her on the new one within days. He was later arrested, charged and imprisoned after pleading guilty. In the second, an officer sent an email to 18 people connected to Parliament regarding a honeytrap investigation using the To field rather than BCC, exposing every recipient's address to the others.
The ICO's root-cause findings are the part worth reading. Officers failed to redact as instructed, data protection training completion rates were low, and relevant staff had not completed training in three to four years. The regulator identified wider weaknesses in the force's policies, procedures and assurance arrangements rather than treating these as isolated errors. The Met has twelve months to reach 100% training completion, review multi-recipient email practice quarterly, and report progress every three months.
Digital security and privacy is a named sub-need under SECURITY, and this is a reminder that the threat model for most people is not a sophisticated attacker. It is an institution holding their data without the operational discipline to handle it. No technology in this file would have prevented either incident.
Source: The Register
MANY MINDED