ICO reprimands ACRO Criminal Records Office for UK GDPR security failings after cyber incident affecting 10,000 data subjects
The Information Commissioner has reprimanded ACRO Criminal Records Office on 7 August 2026 for UK GDPR infringements. This action follows a cyber incident affecting approximately 10,000 UK data subjects. The reprimand cites breaches of Articles 32(1), 32(1)(b) and 32(1)(d) of the UK GDPR.
The Information Commissioner issued a reprimand to ACRO Criminal Records Office on 7 August 2026, citing infringements of UK GDPR Articles 32(1), 32(1)(b), and 32(1)(d). This enforcement action directly addresses a cyber incident that potentially compromised the personal data of around 10,000 UK data subjects. The reprimand underscores the critical importance of robust technical and organisational measures for ensuring information security, particularly for central government entities handling sensitive personal data.
Organisations must ensure their security measures are appropriate to the risks presented by processing activities. Article 32(1) mandates that controllers and processors implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. Specifically, Article 32(1)(b) requires the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services, while Article 32(1)(d) requires a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of processing. This reprimand serves as a clear signal to all public sector bodies regarding their obligations under the UK GDPR to prevent unauthorised access and data breaches.
Regulators consistently enforce security obligations under data protection laws, particularly when sensitive personal data is involved and basic cybersecurity hygiene is neglected.
Articles 32(1), 32(1)(b) and 32(1)(d) of the UK GDPR
- Who this binds
- This binds central government organisations and any entity acting as a data controller or processor under the UK GDPR.
- What changed
- The Information Commissioner has clarified that ACRO Criminal Records Office infringed Articles 32(1), 32(1)(b) and 32(1)(d) of the UK GDPR.
- What to check
- Organisations should review their technical and organisational measures for data security, particularly their ability to ensure ongoing confidentiality, integrity, availability and resilience of processing systems and services, and their processes for regularly testing and evaluating these measures.
- What this does not mean
- This reprimand does not mean that all data breaches automatically result in formal enforcement action, as the ICO considers various factors including the nature, gravity and duration of the infringement.
Send this to your team
The Information Commissioner has reprimanded ACRO Criminal Records Office for infringements of UK GDPR Articles 32(1), 32(1)(b) and 32(1)(d) following a cyber incident affecting approximately 10,000 UK data subjects, underscoring security obligations for central government entities.