Skip to main content

folkfox

Skip to main content
Skip to content
Compliance & Certification

The ICO Picked Reprimands Over Fines, and Two Landed in One Month

Two reprimands, one regulator, one month. Neither carried a fine, and that is precisely why every compliance team should be paying closer attention, not less.

Quick answerData protection compliance now runs on reprimands, not just fines. The ICO issued 65 reprimands against 58 penalties since 2023, and two landed in August alone: ACRO Criminal Records Office and the Metropolitan Police.
Section 01

What the ICO actually did, and to whom#

A fox does not need to catch every rabbit in the hedgerow to prove the hedgerow is dangerous. It only needs to catch one, cleanly, in view of every other rabbit watching. That is roughly what the UK's Information Commissioner's Office did twice this August, and the pattern matters more than either single case.

On 14 August 2026, PublicTechnology reported that the ICO had reprimanded ACRO Criminal Records Office, the body that processes criminal-record checks for employers, visa applicants and international travel. The ICO's own reprimand, dated 7 August 2026, is more specific than the headline: a hacker held unauthorised access to ACRO's content management system for seven months, between August 2022 and March 2023, before anyone noticed. Up to 10,920 people had data exposed, including National Insurance numbers and, for some, biometric and criminal-offence information. The regulator found ACRO in breach of Articles 32(1), 32(1)(b) and 32(1)(d) of the UK GDPR, the security-of-processing provisions that ask a controller to actually operate the protections it says it has.

The second case is quieter but sits in the same file. The Metropolitan Police Service was issued an enforcement notice and a reprimand earlier in August, this time for two separate incidents: unredacted court documents that exposed a stalking victim's new address and phone number, and a bulk email sent with recipients visible to one another in the "To" field, exposing eighteen people connected to a parliamentary matter. Both breach section 40 of the Data Protection Act 2018, the law-enforcement processing regime that sits alongside UK GDPR. The enforcement notice gives the Met three months to fix the immediate gap and twelve to close the rest.

Two cases, one instrument#

Neither ACRO nor the Met Police was fined. That is not the ICO going soft, it is the ICO choosing its tool deliberately, and the choice is the actual story here for anyone selling into data protection compliance.

@juliobmelo
The UK Criminal Records Office (ACRO) had three separate intrusions go undetected for seven months. The cause was not sophisticated evasion. Staff never read the antivirus alerts, and an unpatched content management system remained vulnerable throughout. For CISOs, this is the governance gap between having security tools and operating them. Alerts without triage are noise. Patches without deployment are documentation.
16 August 2026View on X

That reaction, from a working CISO commentator rather than a journalist, names the real failure mode precisely: ACRO had alerting tools running and simply was not reading them. It is the kind of governance gap a fox would spot from the tree line before it ever became a breach, the mismatch between equipment purchased and behaviour practised.

Section 02

Why reprimands, not fines, are doing the work#

If you sell, market or advise on data protection compliance, the instinct is to track fines. Fines make headlines and headlines make case studies. But an analysis of the ICO's full public enforcement register, run by Bridewell and reported by Compare the Cloud, shows the regulator's actual instrument of choice between 2023 and May 2026: 65 reprimands, 58 monetary penalties and 49 enforcement notices.

The ICO's enforcement toolkit, 2023 to May 2026
Bar chart showing ICO enforcement instrument counts: 65 reprimands, 58 monetary penalties, 49 enforcement noticesReprimands: 65Monetary penalties: 58Enforcement notices: 4980604020065Reprimands58Monetary penalties49Enforcement notices
Reprimands outnumber monetary penalties and enforcement notices combined against neither: they are the single most-used instrument in the register.

A reprimand costs an organisation nothing in direct fees. It costs something else: a permanent, public, dated entry naming exactly which article of UK GDPR was breached and why, sitting on the regulator's own website for as long as the ICO chooses to keep it there. For a security vendor or GRC platform selling data protection compliance services, that public record is more useful marketing evidence than a fine, because it names the specific control gap rather than a headline number.

Reprimands as a share of ICO enforcement
Reprimands as a share of ICO enforcementWaffle chart showing reprimands make up 38 percent of ICO enforcement actions38% of every ICO enforcement action againstACRO, the Met Police and every other case in this three-
Thirty-eight per cent of the ICO's enforcement register is reprimands, the largest single category, ahead of both fines and enforcement notices on their own.

This is the shift a genuine data protection compliance framework has to account for now. A programme built only to survive an audit that ends in a monetary penalty is built for the wrong regulator behaviour. The one that actually lands, more often than not, is a named, published reprimand that a client, a journalist or a competitor can read in full within a day of release.

Section 03

What actually broke, in both cases#

Read past the headline in each case and the failures are almost boringly ordinary, which is exactly why they are worth studying. ACRO's content management system stayed unpatched through the entire seven-month intrusion window. The alerts existed. Nobody triaged them. The Met Police's failures were procedural rather than technical: a document sent unredacted, an email sent with the wrong field carrying recipient addresses.

Sounds finished, proves nothing

We take data protection seriously and maintain robust security controls across our estate.

Names the control, states the check

Every CMS deployment is patched within 14 days of a critical advisory, and unread alerts over 48 hours trigger an escalation to a named owner.

The second version is the one a genuine data protection compliance framework produces, and it is the one an auditor, a regulator or a prospective client can actually verify. ACRO's reprimand names precisely this gap: security tooling present, security tooling unoperated. That distinction, tooling versus operation, is where most vendors selling into GRC compliance software undersell their own product, because the pitch stops at the tool rather than the discipline that runs it.

Section 04

Selling GDPR compliance services without the theatre#

Every GRC vendor and security consultancy currently pitching gdpr compliance services has two ACRO-shaped case studies handed to them this month, and most will waste both by leading with fear rather than with the specific, checkable gap the ICO actually named.

The trap is well worn. A vendor reads "seven months undetected" and reaches for a slide about advanced persistent threats, when the ICO's own reprimand says the opposite: this was not sophisticated. It was an unpatched system and unread alerts. Marketing that mismatches the sophistication of the threat to the plainness of the failure loses credibility with exactly the buyer who reads the primary source, which any competent GRC lead will.

fox inspecting compliance files, a metaphor for data protection compliance audits
The tools were rarely the gap. The reading of them was.

The same discipline applies to soc 2 compliance services, a nearby but distinct sale. The AICPA's own description of SOC 2 scopes it to five trust service categories: security, availability, processing integrity, confidentiality and privacy, assessed over a defined review period. A UK GDPR reprimand asks a different, wider question: whether personal data was actually protected in practice, continuously, not just during the window an auditor happened to be watching.

ACRO's case is a useful teaching example precisely because it shows how an organisation can hold both correctly on paper, and still fail the second test if operational discipline lapses between formal reviews. Selling soc 2 compliance services on the back of this story only works if the pitch is honest about that gap, not if it implies a SOC 2 badge alone would have stopped ACRO's intrusion.

A reprimand does not say the tools were missing. It says the tools were not being read. That is a cheaper fix than most vendors want to sell, and a more honest one.
folkfox, on the ACRO and Metropolitan Police reprimands

For agencies and in-house teams marketing data protection compliance work, the practical move is narrower than most pitches allow: name the specific article breached, name the specific fix, and resist the urge to inflate a patching failure into a sophisticated-attacker story. The ICO already published the honest version. Competing with it by exaggerating only reads as marketing rather than expertise.

Section 05

Building a data protection compliance framework that survives a reprimand test#

A data protection compliance framework built to survive a fine is not the same shape as one built to survive a reprimand, because a reprimand tests operational discipline over months, not paperwork at a single audit point. ACRO's gap sat open for seven months. A framework that only gets exercised at renewal time will not catch that.

Five checks a reprimand-resistant framework runs monthly, not annually
Alert triage SLA

Every security alert gets a named owner and a maximum time to acknowledgement, checked monthly rather than assumed.

Patch deployment proof

Track deployment, not just release. A patch that shipped and was never applied is the exact ACRO failure mode.

Field-level review

Bulk email and document-sharing processes get a second pair of eyes before send, the control the Met Police case shows was missing.

Article-level mapping

Map each control to the specific UK GDPR article it satisfies, so a gap is visible before a regulator finds it.

Public register check

Read the ICO's enforcement register quarterly. Reprimands name specific failures your own framework can test against directly.

That last step is the one most compliance functions skip, and it is the cheapest. The ICO's enforcement register is public, dated, and increasingly the clearest evidence base available for what a UK regulator actually checks, ahead of what a certification body's marketing implies it checks.

A reprimand, an enforcement notice and a monetary penalty carry different obligations, and a data protection compliance framework should be built to answer all three, not just the one that makes headlines.
InstrumentDirect costWhat it requiresPublic record
ReprimandNoneAcknowledge the specific breach namedYes, published with detail
Enforcement noticeNone directlyFix named gaps within a set deadlineYes, published with deadlines
Monetary penaltyFinancialPayment, plus the same acknowledgementYes, published with amount

Third-party risk sits underneath all of this too. ACRO processes data on behalf of employers and visa authorities; the Met Police case touched documents shared with external parties. Any data protection compliance framework that stops at an organisation's own perimeter misses exactly the failure both August cases share: data moving to or through a process that was not being watched closely enough.

None of this is buried in obscure guidance. Article 32(1) of the UK GDPR itself asks controllers to take "appropriate technical and organisational measures" that account for the state of the art, the cost of implementation, and the actual risk to people whose data is processed. That is not a checklist, it is an ongoing judgement call.

That is exactly why a framework tested once a year misses a gap that opens in month two and closes in month nine, precisely ACRO's timeline. The Metropolitan Police case sits under a related but distinct duty, section 40 of the Data Protection Act 2018, the sixth law-enforcement processing principle, which requires "appropriate security" for data processed for policing purposes specifically.

The ICO publishes its own expectations for what "appropriate" looks like on its security guidance pages, and the UK's National Cyber Security Centre publishes the operational half of the same problem in its vulnerability management guidance, which frames patching as "business as usual" rather than an exceptional, on-demand task, precisely the discipline ACRO's reprimand shows was missing. A vendor selling into this space that cannot point a prospective client at both of these free, public documents is selling confidence rather than competence.

The full pattern is there for anyone who reads the register rather than the headlines. The ICO keeps a running, public list of every case it has taken action on at its enforcement action page, and a genuine data protection compliance framework treats that page as a live threat model, not an archive to skim once a quarter out of professional obligation.

Questions

Frequently asked questions#

What is data protection compliance?

Data protection compliance means an organisation's actual practices, not just its policies, meet the legal requirements for handling personal data, such as the UK GDPR. The ICO's reprimands against ACRO and the Metropolitan Police both found policies existed but operational practice had lapsed.

What are the three types of data protection?

Most frameworks group data protection into technical controls (encryption, patching, access management), organisational controls (staff training, incident response, vendor oversight) and legal or procedural controls (lawful basis, retention limits, breach notification). ACRO's reprimand named gaps in the first two.

Why did the ICO reprimand ACRO instead of fining it?

The ICO increasingly favours reprimands over fines: 65 reprimands against 58 monetary penalties since 2023. A reprimand still creates a permanent, public, named record of the specific failure, without a financial penalty attached.

What is a data protection compliance framework?

A data protection compliance framework is the documented set of technical, organisational and procedural controls an organisation runs to meet data protection law, ideally mapped article by article so a gap is visible before a regulator or auditor finds it.

Does a SOC 2 report cover UK GDPR compliance?

No. SOC 2 assesses whether a defined set of controls existed and operated correctly over a review period. UK GDPR compliance asks a broader, ongoing question: whether personal data is actually protected in practice, which is why an organisation can hold SOC 2 certification and still receive a reprimand.

How long did the ACRO data breach go undetected?

Seven months, from August 2022 to March 2023, according to the ICO's reprimand. The cause was an unpatched content management system and unread security alerts rather than a sophisticated attack.

Keep reading

Read more on this topic#

Ready to market compliance without the theatre?

folkfox builds the content, keyword and reporting layer for cybersecurity and GRC vendors who want to sell the honest version of their control, not an inflated one.