Back to Feed
PolicyAug 24, 2026

ICO (UK) - ACRO Criminal Records Office

UK ICO reprimands criminal records office for security failures leading to data breach.

Summary

The UK's ICO has reprimanded the ACRO Criminal Records Office for failing to implement adequate security measures, including patch management and security monitoring. This led to prolonged unauthorized access to systems containing sensitive personal data, potentially affecting up to 10,920 individuals. The breach involved data such as identification, financial information, criminal records, and sensitive personal details.

Full text

Help ICO (UK) - ACRO Criminal Records Office: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editVisualWikitext Revision as of 13:40, 21 August 2026 view sourceBms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators271 editsTag: Visual edit← Older edit Latest revision as of 07:05, 24 August 2026 view source Bms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators271 editsTag: Visual edit Line 92: Line 92: }}}} The ICO reprimanded a criminal records office for failing to implement appropriate security measures, including effective patch management and security monitoring, resulting in prolonged unauthorised access to systems containing sensitive personal data.The DPA reprimanded a criminal records office for failing to implement appropriate security measures, including effective patch management and security monitoring, resulting in prolonged unauthorised access to systems containing sensitive personal data. == English Summary ==== English Summary == Latest revision as of 07:05, 24 August 2026 ICO - ACRO Criminal Records Office Authority: ICO (UK) Jurisdiction: United Kingdom Relevant Law: Article 32(1) UK GDPRArticle 32(1)(b) UK GDPRArticle 32(1)(d) UK GDPR Type: Investigation Outcome: Violation Found Started: Decided: 07.08.2026 Published: Fine: n/a Parties: ACRO Criminal Records Office National Case Number/Name: ACRO Criminal Records Office European Case Law Identifier: n/a Appeal: Unknown Original Language(s): English Original Source: ICO (in EN) Initial Contributor: bms The DPA reprimanded a criminal records office for failing to implement appropriate security measures, including effective patch management and security monitoring, resulting in prolonged unauthorised access to systems containing sensitive personal data. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts ACRO Criminal Records Office, the processor, is a national police unit providing public services including Police Certificates, International Child Protection Certificates, Subject Access Requests and Record Deletion Requests. It processes personal data on behalf of 43 police forces whose Chief Constables act as joint controllers. Between July 2021 and June 2023, three separate security incidents affected the processor's customer portal and its content management system. The most significant incident occurred between August 2022 and March 2023, during which a threat actor maintained unauthorised access to the processor's website and Case Management System (hereinafter, CMS) environment. In February 2023, the threat actor staged personal data for possible exfiltration relating to Police Certificate applications, Subject Access Requests and International Child Protection Certificate forms. Due to insufficient logging, the processor could not determine whether the data had actually been exfiltrated. A maximum of 10,920 data subjects were potentially affected. The information concerned included identification and contact data, financial information, identification numbers, criminal conviction and offence data, information concerning domestic violence, disability, gender reassignment and sexual orientation, biometric data, and racial or ethnic origin. In April 2023, the processor notified 84,048 data subjects on a precautionary basis. Several data subjects subsequently complained about distress and concerns regarding identity theft and financial loss. Holding The DPA held that the processor infringed Articles 32(1), 32(1)(b) and 32(1)(d) UK GDPR. Regarding Article 32(1) UK GDPR, the DPA found that the processor had failed to implement appropriate organisational measures to ensure a level of security appropriate to the risk. In particular, responsibility for identifying required security patches was not clearly allocated and the processor did not itself monitor whether security patches were required. The DPA further found a violation of Article 32(1)(b) UK GDPR. The processor had operated an outdated version of the CMS between 2019 and 2023 despite the availability of multiple security hotfixes. It could not demonstrate that known vulnerabilities had been subject to documented risk assessments or formal governance processes and had no documented patching policy. In addition, multiple antivirus alerts indicating malicious activity were neither reviewed nor acted upon, allowing the threat actor to remain undetected. Finally, the DPA held that the processor infringed Article 32(1)(d) UK GDPR because it lacked effective processes for regularly testing and evaluating its security measures. The absence of a documented patching policy, continuous security monitoring and clearly assigned responsibility for reviewing security alerts prevented the processor from assessing whether its technical and organisational measures remained effective. Taking into account the seriousness and duration of the infringements, as well as mitigating factors and the remedial measures subsequently implemented by the processor, the DPA issued a reprimand. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the English original. Please refer to the English original for more details. UK GENERAL DATA PROTECTION REGULATION (Article 58(2)(b)) CORRECTIVE POWERS OF THE INFORMATION COMMISSIONER REPRIMAND DATED: 7 August 2026 To: ACRO Criminal Records Office Of: ACRO Criminal Records Office, ACRO, PO Box 481, Fareham, Hampshire, PO14 9FS I. INTRODUCTION AND SUMMARY 1. ACRO Criminal Records Office herein referred to as ‘ACRO’ are a national police unit providing a range of public services such as the issuing of Police Certificates, International Child Protection Certificates and the processing of Subject Access Requests and Record Deletion Requests. ACRO was founded in 2006. 2. ACRO are a data processor for processing activities set out in the S22A Collaboration Agreement under the Police Act 1996 acting on behalf of the 43 Police Forces that are party to the agreement. The Chief Constables party to the agreement are joint controllers. 1 Police Act 1996 2NON-CONFIDENTIAL - FOR PUBLICATION 3. The National Police Chiefs Council (NPCC) is the chair of the ACRO governance board that governs ACRO’s processing on behalf of the joint controllers. They fall under the NPCC ICO Registration. 2 4. It is the Information Commissioner’s (the “Commissioner”) understanding that three separate incidents of compromise occurred between July 2021 - June 2023, all involving the ACRO 3 customer portal website (www.acro.police.uk), a web application 4 built on the Kentico CMS at the time of the incidents taking place. 5. The Commissioner issues ACRO with this Reprimand pursuant to Article 58(2)(b) UK General Data Protection Regulation (“UK GDPR”). 6. The Commissioner finds that between the implementation of the UK GDPR on 25 May 2018 and 22 June 2023 (the “Relevant Period”), ACRO infringed Articles 32(1), 32(1)(b), and 32(1)(d) of the UK GDPR for the reasons set out in this Reprimand. 7. The Commissioner previously served ACRO with a Notice of Intent to issue a Reprimand (the “NOI”) on 10 June 2026. ACRO provided written representations (the “Representations”) in response to the NOI on 1 July 2026. The Commissioner has taken the Representations into account when deciding to issue this Reprimand. 2This Notice is issued by Jonathan Balmforth, Group Manager (Civil and Cyber Investigations), as the delegated authority on behalf of the Information Commissioner in accordance with paragraph 6(3) of Schedule 12 of the Data Protection Act 2018 and the ICO’s Scheme of Delegations, (approved July 2025). As stated in Annex 1 of the ICO’s Scheme of Delegations, the delegation of the Information Commissioner’s non-reserved functions se

Entities

ICO (vendor)ACRO Criminal Records Office (product)