14-08-2026
The Information Commissioner’s Office (ICO) has reprimanded ACRO Criminal Records Office following cyber security failings which potentially exposed the personal information of up to 10,920 people.
The case is a useful reminder for organisations that cyber security is not simply an IT issue. It is a fundamental part of data protection compliance, accountability and good information governance.
What happened?
The ICO’s investigation found that between August 2022 and March 2023, an attacker gained unauthorised access to ACRO’s website and content management system (CMS).
The attacker was able to stage personal information to be stolen, although ACRO could not conclusively establish whether the information was actually removed from its systems.
The potential scale and sensitivity of the information involved was significant. According to the ICO, it included:
- names, dates of birth and addresses;
- National Insurance numbers;
- passport and driving licence details;
- bank account information;
- biometric data; and
- criminal offence and special category information.
Those potentially affected included applicants for Police Certificates and International Child Protection Certificates, subject access request applicants and third parties connected with those applications.
Outsourcing a service does not outsource accountability
One of the most important aspects of the ICO’s findings relates to the use of third-party suppliers.
ACRO had engaged external providers to deliver certain security services, including patch management. However, the ICO found that ACRO had not ensured there was clear responsibility for identifying and monitoring critical CMS security updates.
It also identified weaknesses in patch management and found that security alerts which could potentially have identified the attack sooner had not been adequately investigated.
This provides an important lesson for controllers: you can outsource a service, but you cannot outsource accountability.
A contract allocating security responsibilities to a supplier is only part of the picture. Organisations need to understand how those responsibilities operate in practice and have appropriate oversight and assurance arrangements in place.
Article 32 is about organisational measures too
Article 32 UK GDPR requires controllers and processors to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk.
The ACRO case demonstrates why both elements matter.
Cyber security cannot simply be placed in an “IT box”. Information Governance, Data Protection, Procurement, ICT and service owners all have a role in ensuring that systems processing personal data are appropriately governed throughout their lifecycle.
Organisations should be able to identify who is responsible for security updates and vulnerability management, how supplier performance is monitored, who receives and investigates security alerts, and how significant risks are escalated.
The importance of getting the basics right
The ICO also recognised the remedial measures taken by ACRO following the incident. These included decommissioning the compromised infrastructure, migrating services, implementing additional security monitoring, improving visibility of cyber threats and strengthening network segmentation.
Importantly, existing network segmentation prevented the attacker from moving from the compromised website environment into ACRO’s core systems, limiting the potential scale of the incident.
The ICO’s message to other organisations is straightforward: make accountability clear, act on warning signs and get the basics right.
As Jonathan Balmforth, the ICO’s Group Manager – Civil and Cyber Investigations, said:
“Having the right policies, responsibilities and oversight arrangements in place is just as important as having the right technology.”
For organisations processing significant volumes of personal data – particularly special category, biometric or criminal offence data – this case provides a timely opportunity to review not only technical security controls, but the governance and accountability arrangements sitting behind them.
Good information governance protects people, builds trust and reduces risk.

Leave a comment