When Data Protection Training Fails: Lessons from the Metropolitan Police
IT Club — Powered by Altitude IT (opens in a new tab)

Keep up with IT Club
Add IT Club as a preferred source in Google Search.
Two Metropolitan Police data disclosures led to an ICO enforcement notice and reprimand. The cases show why organisations need role-specific training, usable procedures and evidence that staff understand their responsibilities.
In August 2026, the Information Commissioner’s Office (ICO) announced an enforcement notice and reprimand for the Metropolitan Police Service after two serious personal-data disclosures. The cases are a reminder that a written policy is only a starting point: people need to understand what to do when they handle information under pressure.
The findings concern the organisation and the specific incidents investigated. They are not a claim that every police employee—or every organisation with a training gap—has mishandled data.
What happened in the two cases?
In one case, information in documents connected with a stalking protection order disclosed the contact details of a victim and witnesses to a defendant. In another, an email about a “honeytrap” case exposed the names and email addresses of 18 people to the other recipients. The ICO said weaknesses in training, policy and oversight contributed to the risk of personal information being sent to the wrong people.
The regulator reported that officers and managers involved in the incidents had not completed relevant data-protection training for more than four years. The ICO issued a reprimand and ordered improvements. It is important to describe this as the regulator’s documented finding about the people and processes involved—not as a statistic about every member of staff.
Why a policy is not enough
A policy may correctly say “check recipients before sending” or “share only what is necessary”. But an employee still needs to recognise a risky situation, know which tool to use and feel able to pause or ask for help. A generic annual presentation will not prepare every role equally: a payroll team, receptionist, engineer and case worker handle different information and make different decisions.
Training also needs to connect to the systems people use. If a mailbox automatically suggests an external recipient, a case-management tool makes it hard to restrict access, or staff use broad shared accounts, reminders alone cannot fix the underlying control. Managers are responsible for making the safe way to work practical and for checking that it is followed.
A practical checklist for smaller organisations
- 1Include data handling in onboarding. Explain what counts as personal or sensitive information, where it belongs and who can approve sharing.
- 2Train by role. Use realistic examples from the work people do, such as sending payroll files, handling customer complaints or sharing documents with suppliers.
- 3Refresh and check understanding. Schedule short refreshers after process changes and use a few scenario questions rather than relying only on attendance.
- 4Keep useful evidence. Record who completed training, when, which version they took and how gaps or failed checks were addressed.
- 5Make reporting easy. Tell staff how to report a misdirected email or lost device quickly, without first deciding whether it is a formal breach.
- 6Limit access. Give each role the information and permissions it needs, remove access when duties change and review shared mailboxes and accounts.
For example, a person who sends case files should practise checking recipients and attachments, while someone who manages a mailing list should learn when to use a blind-copy field or a secure distribution tool. Short exercises using realistic, fictional examples help reveal whether a process is understood before a real customer, patient or employee is affected.
If an incident occurs, act quickly: contain the disclosure where possible, preserve the facts, assess who may be affected and follow the organisation’s breach-response process. Do not wait for the next training session to decide what to do. The right response will depend on the information and the circumstances, so get privacy or legal advice when the risk is serious.
For leaders, the test is not simply whether a policy exists or a course was assigned. Can staff explain the safe process? Are access controls proportionate? Are mistakes reported early? Can the organisation show that it learned from them? Those answers turn training from a box-ticking exercise into a working safeguard.
Sources and further reading
ICO: enforcement notice and reprimand →
Plain-English Takeaway
A data protection policy in a folder does not protect anyone if staff cannot apply it. Train people for the tasks they actually do, make reporting easy and give managers responsibility for checking the controls work.
Related Articles
What Confidential Documents Can Google Find About Your Business?
Search engines can index publicly accessible PDFs, Word documents, spreadsheets and presentations — even files that are no longer linked from your main website. This article explains how to use authorised searches to identify documents associated with your own domains, what the results may reveal, why search results are incomplete, and what to do when sensitive business information appears online.
Read articleWhen Your IT Provider Finds a Compliance Problem, Who Benefits From the Fix?
Your IT provider finds six compliance gaps and can sell you six fixes. That is not automatically a problem — but it is a reason to ask what is required, what is recommended and who benefits from the decision.
Read articleMI5 Warning: Do You Really Know Who Is Funding Your Research?
MI5’s alert concerns an alleged funding route into research. It is not evidence that every researcher involved knew the source or acted improperly.
Read articleNeed help putting this into practice?
IT Club helps you understand the technology. If you need implementation, support or consultancy, the teams behind IT Club can help.
Altitude IT (opens in a new tab) — IT support, cyber security, Microsoft 365 and technology operations.
Altitude AI (opens in a new tab) — AI discovery, automation, governance and implementation.