ICO (UK) - ACRO Criminal Records Office
UK ICO reprimands ACRO Criminal Records Office for data security failures leading to prolonged unauthorized access.
Summary
The UK's Information Commissioner's Office (ICO) has reprimanded the ACRO Criminal Records Office for failing to implement adequate security measures. These failures, including poor patch management and security monitoring, resulted in prolonged unauthorized access to sensitive personal data between August 2022 and March 2023. The ICO found violations of UK GDPR articles related to security of processing, leading to a reprimand rather than a fine, considering mitigating factors and remedial actions.
Full text
Help ICO (UK) - ACRO Criminal Records Office: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Revision as of 12:09, 21 August 2026 view sourceBms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators269 edits Tag: Decisions [1.0] Latest revision as of 13:40, 21 August 2026 view source Bms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators269 editsTag: Visual edit (One intermediate revision by the same user not shown)Line 92: Line 92: }}}} The ICO reprimanded ACRO for failing to implement appropriate security measures, including effective patch management and security monitoring, resulting in prolonged unauthorised access to systems containing sensitive personal data.The ICO reprimanded a criminal records office for failing to implement appropriate security measures, including effective patch management and security monitoring, resulting in prolonged unauthorised access to systems containing sensitive personal data. == English Summary ==== English Summary == Line 99: Line 99: ACRO Criminal Records Office, the processor, is a national police unit providing public services including Police Certificates, International Child Protection Certificates, Subject Access Requests and Record Deletion Requests. It processes personal data on behalf of 43 police forces whose Chief Constables act as joint controllers.ACRO Criminal Records Office, the processor, is a national police unit providing public services including Police Certificates, International Child Protection Certificates, Subject Access Requests and Record Deletion Requests. It processes personal data on behalf of 43 police forces whose Chief Constables act as joint controllers. Between July 2021 and June 2023, three separate security incidents affected the processor's customer portal and its Kentico content management system. The most significant incident occurred between August 2022 and March 2023, during which a threat actor maintained unauthorised access to the processor's website and CMS environment.Between July 2021 and June 2023, three separate security incidents affected the processor's customer portal and its content management system. The most significant incident occurred between August 2022 and March 2023, during which a threat actor maintained unauthorised access to the processor's website and Case Management System (hereinafter, CMS) environment. In February 2023, the threat actor staged personal data for possible exfiltration relating to Police Certificate applications, Subject Access Requests and International Child Protection Certificate forms. Due to insufficient logging, the processor could not determine whether the data had actually been exfiltrated.In February 2023, the threat actor staged personal data for possible exfiltration relating to Police Certificate applications, Subject Access Requests and International Child Protection Certificate forms. Due to insufficient logging, the processor could not determine whether the data had actually been exfiltrated. Line 106: Line 106: In April 2023, the processor notified 84,048 data subjects on a precautionary basis. Several data subjects subsequently complained about distress and concerns regarding identity theft and financial loss.In April 2023, the processor notified 84,048 data subjects on a precautionary basis. Several data subjects subsequently complained about distress and concerns regarding identity theft and financial loss. === Holding ====== Holding === The DPA held that the processor infringed Articles 32(1), 32(1)(b) and 32(1)(d) UK GDPR.The DPA held that the processor infringed [https://www.legislation.gov.uk/eur/2016/679/contents Articles 32(1)], [https://www.legislation.gov.uk/eur/2016/679/contents 32(1)(b)] and [https://www.legislation.gov.uk/eur/2016/679/contents 32(1)(d) UK GDPR]. Regarding Article 32(1) UK GDPR, the DPA found that the processor had failed to implement appropriate organisational measures to ensure a level of security appropriate to the risk. In particular, responsibility for identifying required security patches was not clearly allocated and the processor did not itself monitor whether security patches were required.Regarding [https://www.legislation.gov.uk/eur/2016/679/contents Article 32(1) UK GDPR], the DPA found that the processor had failed to implement appropriate organisational measures to ensure a level of security appropriate to the risk. In particular, responsibility for identifying required security patches was not clearly allocated and the processor did not itself monitor whether security patches were required. The DPA further found a violation of Article 32(1)(b) UK GDPR. The processor had operated an outdated version of the Kentico CMS between 2019 and 2023 despite the availability of multiple security hotfixes. It could not demonstrate that known vulnerabilities had been subject to documented risk assessments or formal governance processes and had no documented patching policy. In addition, multiple antivirus alerts indicating malicious activity were neither reviewed nor acted upon, allowing the threat actor to remain undetected.The DPA further found a violation of [https://www.legislation.gov.uk/eur/2016/679/contents Article 32(1)(b) UK GDPR]. The processor had operated an outdated version of the CMS between 2019 and 2023 despite the availability of multiple security hotfixes. It could not demonstrate that known vulnerabilities had been subject to documented risk assessments or formal governance processes and had no documented patching policy. In addition, multiple antivirus alerts indicating malicious activity were neither reviewed nor acted upon, allowing the threat actor to remain undetected. Finally, the DPA held that the processor infringed Article 32(1)(d) UK GDPR because it lacked effective processes for regularly testing and evaluating its security measures. The absence of a documented patching policy, continuous security monitoring and clearly assigned responsibility for reviewing security alerts prevented the processor from assessing whether its technical and organisational measures remained effective.Finally, the DPA held that the processor infringed [https://www.legislation.gov.uk/eur/2016/679/contents Article 32(1)(d) UK GDPR] because it lacked effective processes for regularly testing and evaluating its security measures. The absence of a documented patching policy, continuous security monitoring and clearly assigned responsibility for reviewing security alerts prevented the processor from assessing whether its technical and organisational measures remained effective. Taking into account the seriousness and duration of the infringements, as well as mitigating factors and the remedial measures subsequently implemented by the processor, the DPA issued a reprimand.Taking into account the seriousness and duration of the infringements, as well as mitigating factors and the remedial measures subsequently implemented by the processor, the DPA issued a reprimand. Latest revision as of 13:40, 21 August 2026 ICO - ACRO Criminal Records Office Authority: ICO (UK) Jurisdiction: United Kingdom Relevant Law: Article 32(1) UK GDPRArticle 32(1)(b) UK GDPRArticle 32(1)(d) UK GDPR Type: Investigation Outcome: Violation Found Started: Decided: 07.08.2026 Published: Fine: n/a Parties: ACRO Criminal Records Office National Case Number/Name: ACRO Criminal Records Office European Case Law Identifier: n/a Appeal: Unknown Original Language(s): English Original Source: ICO (in EN) Initial Contributor: bms The ICO reprimanded a criminal records office for failing to implement appropriate security measures, including effective patch management and security monitoring, resulting in prolonged unauthorised access to systems containing sensitive personal data. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision Engli