A woman changed her phone number. Moved house. Did everything right to disappear from the man stalking her. Then the Metropolitan Police handed him her new address and phone number in unredacted court documents. The UK’s Information Commissioner’s Office has now issued the Met an enforcement notice and formal reprimand, concluding that both this incident and a second breach involving Westminster politicians were, in the ICO’s words, “foreseeable and preventable.” Not a glitch. Not bad luck. Institutional failure.
When the System Becomes the Threat
Officers were explicitly warned to redact all personal information from documents shared with the defendant — and handed them over unredacted anyway.
In January 2024, Met officers applied for an interim Stalking Protection Order against a man already on bail for harassment. The victim had relocated and changed her number specifically to escape him. Despite explicit instructions to redact every personal detail before sharing paperwork with the defendant, officers handed over unredacted witness statements. Those documents contained her new address, new phone number, and contact details for three witnesses. Within days, the defendant contacted her on that supposedly confidential number, then fled the country. He was arrested upon returning to the UK in July 2024, charged with stalking, and imprisoned after a guilty plea. For those shaken by how little institutional protection can mean, home security may be worth revisiting when the systems meant to safeguard you fall short.
The second breach looks almost mundane by comparison — the Reply All of law enforcement — until you consider the stakes. The Met used CC instead of BCC when emailing 18 Parliament-linked individuals about the Westminster honeytrap investigation, exposing MPs, parliamentary staff, and political journalists to each other as alleged victims of a covert sexting operation. The Met referred itself to the ICO the same day, reporting “no reported detriment.” One MP raised it in the House of Commons regardless. The officer who sent that email hadn’t completed data protection training in over four years. Neither had their line manager.
“One breach exposed a stalking victim’s new contact details to the person she needed protection from. Another revealed the identities of people connected to a highly sensitive investigation. These incidents were foreseeable and preventable.” — ICO group manager Jo Stones
A Pattern, Not a Blip
The ICO says these failures reflect systemic weaknesses in Met data handling, not isolated mistakes.
This isn’t aberrant behaviour. The Met previously leaked a gangs database that ended up photographed and shared on social media — a pattern not unlike the covert surveillance app built to harvest personal data on unsuspecting targets. It received a separate enforcement notice over Freedom of Information failures earlier in 2024. The ICO explicitly states these breaches “reflected wider weaknesses” in Met policies and procedures — not one-off human error.
The enforcement notice gives the Met 12 months to reach the following:
- 100% data protection training completion
- Quarterly reviews of multi-recipient email practices
- Regular progress reports to the ICO
The Met called itself “disappointed” given “improvements already made.” That framing may satisfy the Met’s communications team, but it offers nothing to the woman whose safety was handed to the man threatening it. When the institution meant to protect victims can accidentally arm their attackers, “foreseeable and preventable” stops being an explanation. It becomes an indictment.






























