14-08-2026

The Information Commissioner’s Office (ICO) has reprimanded ACRO Criminal Records Office following cyber security failings which potentially exposed the personal information of up to 10,920 people.

The case is a useful reminder for organisations that cyber security is not simply an IT issue. It is a fundamental part of data protection compliance, accountability and good information governance.

What happened?

The ICO’s investigation found that between August 2022 and March 2023, an attacker gained unauthorised access to ACRO’s website and content management system (CMS).

The attacker was able to stage personal information to be stolen, although ACRO could not conclusively establish whether the information was actually removed from its systems.

The potential scale and sensitivity of the information involved was significant. According to the ICO, it included:

  • names, dates of birth and addresses;
  • National Insurance numbers;
  • passport and driving licence details;
  • bank account information;
  • biometric data; and
  • criminal offence and special category information.

Those potentially affected included applicants for Police Certificates and International Child Protection Certificates, subject access request applicants and third parties connected with those applications.

Outsourcing a service does not outsource accountability

One of the most important aspects of the ICO’s findings relates to the use of third-party suppliers.

ACRO had engaged external providers to deliver certain security services, including patch management. However, the ICO found that ACRO had not ensured there was clear responsibility for identifying and monitoring critical CMS security updates.

It also identified weaknesses in patch management and found that security alerts which could potentially have identified the attack sooner had not been adequately investigated.

This provides an important lesson for controllers: you can outsource a service, but you cannot outsource accountability.

A contract allocating security responsibilities to a supplier is only part of the picture. Organisations need to understand how those responsibilities operate in practice and have appropriate oversight and assurance arrangements in place.

Article 32 is about organisational measures too

Article 32 UK GDPR requires controllers and processors to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk.

The ACRO case demonstrates why both elements matter.

Cyber security cannot simply be placed in an “IT box”. Information Governance, Data Protection, Procurement, ICT and service owners all have a role in ensuring that systems processing personal data are appropriately governed throughout their lifecycle.

Organisations should be able to identify who is responsible for security updates and vulnerability management, how supplier performance is monitored, who receives and investigates security alerts, and how significant risks are escalated.

The importance of getting the basics right

The ICO also recognised the remedial measures taken by ACRO following the incident. These included decommissioning the compromised infrastructure, migrating services, implementing additional security monitoring, improving visibility of cyber threats and strengthening network segmentation.

Importantly, existing network segmentation prevented the attacker from moving from the compromised website environment into ACRO’s core systems, limiting the potential scale of the incident.

The ICO’s message to other organisations is straightforward: make accountability clear, act on warning signs and get the basics right.

As Jonathan Balmforth, the ICO’s Group Manager – Civil and Cyber Investigations, said:

“Having the right policies, responsibilities and oversight arrangements in place is just as important as having the right technology.”

For organisations processing significant volumes of personal data – particularly special category, biometric or criminal offence data – this case provides a timely opportunity to review not only technical security controls, but the governance and accountability arrangements sitting behind them.

Good information governance protects people, builds trust and reduces risk.

Leave a comment

  • Cyber security is a data protection issue: lessons from the ICO’s ACRO reprimand

    14-08-2026 The Information Commissioner’s Office (ICO) has reprimanded ACRO Criminal Records Office following cyber security failings which potentially exposed the personal information of up to 10,920 people. The case is a useful reminder for organisations that cyber security is not simply an IT issue. It is a fundamental part of data protection compliance, accountability and…

  • Council officer convicted for unlawfully accessing personal data

    24/07/2026 The Information Commissioner’s Office (ICO) has recently highlighted an important reminder for all organisations that handle personal information: having access to a system does not mean you are entitled to access every record within it. A former Herefordshire Council employee has received a suspended prison sentence after unlawfully accessing approximately 490 personal records and…

  • Why Smart Companies Keep Getting Data Protection Wrong

    12/07/2026 The biggest data protection risk? It’s certainty. The organisations most likely to get into difficulty with data protection are rarely the ones asking difficult questions. They’re the ones convinced they’re already compliant. Whether it’s a multinational or a start-up, the mistakes are remarkably similar: Collecting data because they can, not because they need to.…

  • The Rise of the Cake Shed

    When Home Business CCTV Stops Being “Purely Personal or Household” 05/07/2026 Have you noticed the increase of “cake sheds” in your area? It seems every week another one pops up on local social media groups. Home businesses are booming. Whether it’s a side hustle or the start of something much bigger, garden bakeries, honesty shops,…