Trending
Case filePolicingLondon

Metropolitan Police ordered to improve data protection after stalking and honeytrap breaches

Information Commissioner’s Office issues reprimand and enforcement notice following two serious incidents

Reporting desk London Crime News Desk||5 min read|London Crime News
Metropolitan Police ordered to improve data protection after stalking and honeytrap breachesIncident → evidence → outcome
Metropolitan Police ordered to improve data protection after stalking and honeytrap breachesThis Is Local London — Crime (embedded from source)

The Metropolitan Police must urgently overhaul its data protection policies after the Information Commissioner’s Office found serious failings in two cases. One involved a stalking victim whose new address and phone number were sent to the defendant by an officer. The other exposed the identities of 18 people linked to Parliament in the Westminster honeytrap investigation.

The ICO issued a reprimand and enforcement notice on 12 September 2024, demanding immediate improvements. Jo Stones, the ICO’s group manager for civil and cyber investigations, said the breaches were foreseeable and preventable. The Met has been given a deadline to implement changes, including updated training and stricter monitoring of compliance.

Stalking victim’s details sent to defendant

In one case, a woman who had already moved home to escape a stalker was forced to relocate again after a Metropolitan Police officer sent her new address and phone number to the defendant. The officer also disclosed the names and contact details of three witnesses in the same document. The defendant later contacted the victim using her new number, confirming he had received the information from police.

The ICO found the officer involved had not completed data protection training for more than four years before the breach. Their manager had also missed required training for a similar period. The Met later issued reminders to staff but the ICO said this was insufficient, calling the force’s policies weak and lacking safeguards.

Honeytrap case email exposed 18 identities

In a separate incident, the Met sent an email to individuals affected by the Westminster honeytrap case, notifying them of a change to the suspect’s bail date. The email failed to use blind carbon copy, meaning all recipients could see each other’s names and email addresses. The ICO said this could allow inferences about highly sensitive connections, even though the email’s content did not explicitly state them.

Eighteen people linked to Parliament were affected. The case centres on allegations that former Conservative MP William Wragg shared politicians’ contact details with someone he met on a dating app. Oliver Steadman, 29, from Islington, faces charges of blackmail and improper use of a public communications network. His trial is scheduled to begin in October 2027.

People entrust the police with some of their most sensitive personal information, often at moments when they are vulnerable or at risk. They have the right to expect that information will be handled securely.
Jo Stones, ICO group manager for civil and cyber investigations

What happens next

The Metropolitan Police must now comply with the ICO’s enforcement notice, which requires specific improvements to data protection policies, training and monitoring. The force has not yet publicly responded to the reprimand. The ICO will review progress within six months. Residents affected by the breaches were informed by the Met at the time, but the ICO’s action means further safeguards must be put in place.

Reader briefing

Questions this report answers

Q/A
01What did the Metropolitan Police do wrong?

The Met sent a stalking victim’s new address and phone number to the defendant, and failed to hide recipients’ identities in an email about the Westminster honeytrap case. The ICO said these breaches were preventable and showed weak data protection policies.

02How many people were affected by the honeytrap email breach?

Eighteen people linked to Parliament had their names and email addresses exposed. The email was sent without using blind copy, allowing all recipients to see each other’s details, which the ICO called a serious risk.

03What happens now the ICO has issued a reprimand?

The Metropolitan Police must improve its data protection policies, training and monitoring within a set deadline. The ICO will review progress in six months. The force has not yet publicly responded to the enforcement notice.

04Who is Oliver Steadman and what is he accused of?

Oliver Steadman, 29, from Islington, is accused of blackmailing former MP William Wragg and improperly using a public communications network. He is alleged to be behind messages sent to MPs and Westminster figures. His trial begins in October 2027.

LC
Source-led case desk

London Crime News Desk

Source-led, editor-supervised

See the reporting protocol →
Help after crime

Support is available without a police report

Find London services, specialist support and the rights set out in the Victims’ Code. If someone is in immediate danger, call 999.

Find victim support
Secure the detail

Send a correction or case update

If a hearing, charge or outcome has changed, send the court, case number and source document so we can update the record.

Contact the desk

Continue the investigation

Who else reported this

Our article above is written from the facts in these reports. Read the originals — every one is linked.

The morning case file

London Crime Briefing

Significant incidents, hearings, outcomes and public-data changes across the capital.

Met Police ordered to improve data protection after breaches | London Crime News