Met criticised by data watchdog over two breaches
EPAThe Metropolitan Police has been criticised by the data watchdog after it sent the address and phone number of a female stalking victim to the defendant.
The Information Commissioner's Office (ICO) ordered the force to urgently step up its data protection policies and training after failings in two cases, including the Westminster 'honeytrap' case.
The ICO said the Met's policies were "weak" and had "serious shortcomings". One officer involved had not completed data protection training for more than four years before they broke data rules.
The force said it was "disappointed" by the enforcement notice issued by the ICO but it recognised the information breaches were not acceptable.
Jo Stones, from the ICO, said both incidents were "foreseeable and preventable".
"Organisations, particularly those in the public sector handling sensitive law enforcement information, must have effective training, monitoring and assurance in place," she said.
"Policies and reminders are not enough if they are not followed, checked and enforced."
In one case, a woman had to move house and change her phone number after a Met Police officer sent her details to a defendant in a stalking protection order (SPO) case. It also wrongly sent out the names and contact details of three witnesses to the defendant.
The defendant later contacted the victim on her new number and said he had received documents containing her new contact details from police.
In the other incident, involving the alleged "honeytrap" of former Conservative MP William Wragg, the Met emailed all of the people affected to tell them of a change to the suspect's bail date.
In doing so all recipients were informed of each other's names and email addresses.
The ICO said it meant "highly sensitive information could potentially be inferred about the recipients, even though the body of the email did not explicitly contain that information".
It added that 18 people linked to Parliament were affected.
'Wider weaknesses'
The Metropolitan Police said it had reported the breaches to the ICO "as soon as they became apparent", and said it had apologised to victims.
A statement from the ICO said the issues showed "wider weaknesses" in the Metropolitan Police's policies.
The officer who sent the email to those involved in the honeytrap case had not done data protection training for more than four years, and their manager had not done their relevant training for a similar period before.
The Met took action and told those affected and sent reminders to staff. However the ICO believed more action was needed, and issued a reprimand and enforcement notice.
A spokesperson for the Metropolitan Police said they took all information breaches extremely seriously.
"We are aware that these incidents can have real consequences for victims and have apologised to those affected by these two cases," they said.
"The Met has taken significant steps to strengthen information disclosure processes, as acknowledged by the ICO, and remains committed to ensuring the right training and safeguards are in place to prevent similar breaches from happening again in the future."
Listen to the best of BBC Radio London on Sounds and follow BBC London on Facebook, X and Instagram. Send your story ideas to hello.bbclondon@bbc.co.uk
