Edition

This is a permanent edition. It carries the briefing exactly as published on this date and does not change.

ICO reprimands ACRO Criminal Records Office for UK GDPR security failings after cyber incident affecting 10,000 data subjects

The Information Commissioner has reprimanded ACRO Criminal Records Office on 7 August 2026 for UK GDPR infringements. This action follows a cyber incident affecting approximately 10,000 UK data subjects. The reprimand cites breaches of Articles 32(1), 32(1)(b) and 32(1)(d) of the UK GDPR.

The Information Commissioner issued a reprimand to ACRO Criminal Records Office on 7 August 2026, citing infringements of UK GDPR Articles 32(1), 32(1)(b), and 32(1)(d). This enforcement action directly addresses a cyber incident that potentially compromised the personal data of around 10,000 UK data subjects. The reprimand underscores the critical importance of robust technical and organisational measures for ensuring information security, particularly for central government entities handling sensitive personal data.

Organisations must ensure their security measures are appropriate to the risks presented by processing activities. Article 32(1) mandates that controllers and processors implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. Specifically, Article 32(1)(b) requires the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services, while Article 32(1)(d) requires a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of processing. This reprimand serves as a clear signal to all public sector bodies regarding their obligations under the UK GDPR to prevent unauthorised access and data breaches.

Regulators consistently enforce security obligations under data protection laws, particularly when sensitive personal data is involved and basic cybersecurity hygiene is neglected.

Articles 32(1), 32(1)(b) and 32(1)(d) of the UK GDPR

Who this binds
This binds central government organisations and any entity acting as a data controller or processor under the UK GDPR.
What changed
The Information Commissioner has clarified that ACRO Criminal Records Office infringed Articles 32(1), 32(1)(b) and 32(1)(d) of the UK GDPR.
What to check
Organisations should review their technical and organisational measures for data security, particularly their ability to ensure ongoing confidentiality, integrity, availability and resilience of processing systems and services, and their processes for regularly testing and evaluating these measures.
What this does not mean
This reprimand does not mean that all data breaches automatically result in formal enforcement action, as the ICO considers various factors including the nature, gravity and duration of the infringement.

Send this to your team

The Information Commissioner has reprimanded ACRO Criminal Records Office for infringements of UK GDPR Articles 32(1), 32(1)(b) and 32(1)(d) following a cyber incident affecting approximately 10,000 UK data subjects, underscoring security obligations for central government entities.

Today's question

A UK public sector organisation experiences a cyber incident due to unpatched software, leading to unauthorised access to its content management system and potential exposure of sensitive personal data for approximately 10,000 individuals. Under the UK GDPR, what is the primary obligation infringed by the organisation's failure to maintain adequate security?

  1. Article 5(1)(a) - Lawfulness, fairness and transparency
  2. Article 32(1) - Security of processing
  3. Article 33(1) - Notification of a personal data breach to the supervisory authority
  4. Article 25(1) - Data protection by design and by default

Answer this question on the site

Worth knowing

  1. FTC stops credit repair scheme that defrauded consumers of nearly $200 million

    The Federal Trade Commission (FTC) has halted a credit repair scheme that scammed consumers out of nearly $200 million. This enforcement action demonstrates the FTC's continued focus on protecting consumers from deceptive business practices, particularly those involving financial services and personal data.

  2. Texas Attorney General Paxton finalizes settlement with Texas Children’s Hospital, creating first-ever detransition clinic and securing nearly $10 million for Texas

    Attorney General Paxton has finalized a historic settlement with Texas Children’s Hospital, which includes the creation of the first-ever detransition clinic and secures nearly $10 million for the state of Texas. This settlement addresses complex issues at the intersection of healthcare, personal autonomy, and state regulatory oversight.

  3. California AG Bonta celebrates court order denying Meta’s attempt to evade trial

    Attorney General Bonta has celebrated another court order denying Meta’s attempt to avoid trial, indicating continued legal scrutiny over the company's practices. This development suggests ongoing litigation and regulatory pressure on major technology platforms regarding their operations and potential liabilities.

Compiled that morning from regulator, court and authority sources. Primary sources are linked on every story.