CYBERSECURITYTRACKER
TRACKING
Permanent story citation

UK: ICO reprimands ACRO Criminal Records Office after data breach

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4477

As cited

Copy frozen at (site build).

breaches incidents

UK: ICO reprimands ACRO Criminal Records Office after data breach

The UK Information Commissioner's Office (ICO) issued a reprimand to ACRO Criminal Records Office, a national police unit, for violations of data security requirements under the UK General Data Protection Regulation (GDPR). The reprimand cited breaches of Articles 32(1), 32(1)(b), and 32(1)(d), which address technical and organizational security measures. The incident involved a data breach affecting the organization's handling of Police Certificates and International Child Protection Certificates.

Why it matters: Organizations processing sensitive personal data such as criminal records or child protection information must ensure adequate security controls; this case demonstrates that law enforcement agencies face the same GDPR obligations and enforcement action as private sector entities.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary