Back to Feed
PolicyAug 21, 2026

ICO (UK) - ACRO Criminal Records Office

ICO reprimands ACRO for failing to implement adequate security measures, leading to prolonged unauthorized access.

Summary

The UK's Information Commissioner's Office (ICO) has reprimanded ACRO Criminal Records Office for significant security failings. These included a lack of effective patch management and security monitoring, which allowed a threat actor prolonged unauthorized access to systems containing sensitive personal data. The breaches, which occurred between July 2021 and June 2023, potentially affected up to 10,920 individuals.

Full text

Help ICO (UK) - ACRO Criminal Records Office: Difference between revisions From GDPRhub Jump to:navigation, search Newer edit →VisualWikitext Revision as of 12:09, 21 August 2026 view source Bms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators269 edits Tag: Decisions [1.0]Newer edit → (No difference) Revision as of 12:09, 21 August 2026 ICO - ACRO Criminal Records Office Authority: ICO (UK) Jurisdiction: United Kingdom Relevant Law: Article 32(1) UK GDPRArticle 32(1)(b) UK GDPRArticle 32(1)(d) UK GDPR Type: Investigation Outcome: Violation Found Started: Decided: 07.08.2026 Published: Fine: n/a Parties: ACRO Criminal Records Office National Case Number/Name: ACRO Criminal Records Office European Case Law Identifier: n/a Appeal: Unknown Original Language(s): English Original Source: ICO (in EN) Initial Contributor: bms The ICO reprimanded ACRO for failing to implement appropriate security measures, including effective patch management and security monitoring, resulting in prolonged unauthorised access to systems containing sensitive personal data. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts ACRO Criminal Records Office, the processor, is a national police unit providing public services including Police Certificates, International Child Protection Certificates, Subject Access Requests and Record Deletion Requests. It processes personal data on behalf of 43 police forces whose Chief Constables act as joint controllers. Between July 2021 and June 2023, three separate security incidents affected the processor's customer portal and its Kentico content management system. The most significant incident occurred between August 2022 and March 2023, during which a threat actor maintained unauthorised access to the processor's website and CMS environment. In February 2023, the threat actor staged personal data for possible exfiltration relating to Police Certificate applications, Subject Access Requests and International Child Protection Certificate forms. Due to insufficient logging, the processor could not determine whether the data had actually been exfiltrated. A maximum of 10,920 data subjects were potentially affected. The information concerned included identification and contact data, financial information, identification numbers, criminal conviction and offence data, information concerning domestic violence, disability, gender reassignment and sexual orientation, biometric data, and racial or ethnic origin. In April 2023, the processor notified 84,048 data subjects on a precautionary basis. Several data subjects subsequently complained about distress and concerns regarding identity theft and financial loss. Holding The DPA held that the processor infringed Articles 32(1), 32(1)(b) and 32(1)(d) UK GDPR. Regarding Article 32(1) UK GDPR, the DPA found that the processor had failed to implement appropriate organisational measures to ensure a level of security appropriate to the risk. In particular, responsibility for identifying required security patches was not clearly allocated and the processor did not itself monitor whether security patches were required. The DPA further found a violation of Article 32(1)(b) UK GDPR. The processor had operated an outdated version of the Kentico CMS between 2019 and 2023 despite the availability of multiple security hotfixes. It could not demonstrate that known vulnerabilities had been subject to documented risk assessments or formal governance processes and had no documented patching policy. In addition, multiple antivirus alerts indicating malicious activity were neither reviewed nor acted upon, allowing the threat actor to remain undetected. Finally, the DPA held that the processor infringed Article 32(1)(d) UK GDPR because it lacked effective processes for regularly testing and evaluating its security measures. The absence of a documented patching policy, continuous security monitoring and clearly assigned responsibility for reviewing security alerts prevented the processor from assessing whether its technical and organisational measures remained effective. Taking into account the seriousness and duration of the infringements, as well as mitigating factors and the remedial measures subsequently implemented by the processor, the DPA issued a reprimand. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the English original. Please refer to the English original for more details. UK GENERAL DATA PROTECTION REGULATION (Article 58(2)(b)) CORRECTIVE POWERS OF THE INFORMATION COMMISSIONER REPRIMAND DATED: 7 August 2026 To: ACRO Criminal Records Office Of: ACRO Criminal Records Office, ACRO, PO Box 481, Fareham, Hampshire, PO14 9FS I. INTRODUCTION AND SUMMARY 1. ACRO Criminal Records Office herein referred to as ‘ACRO’ are a national police unit providing a range of public services such as the issuing of Police Certificates, International Child Protection Certificates and the processing of Subject Access Requests and Record Deletion Requests. ACRO was founded in 2006. 2. ACRO are a data processor for processing activities set out in the S22A Collaboration Agreement under the Police Act 1996 acting on behalf of the 43 Police Forces that are party to the agreement. The Chief Constables party to the agreement are joint controllers. 1 Police Act 1996 2NON-CONFIDENTIAL - FOR PUBLICATION 3. The National Police Chiefs Council (NPCC) is the chair of the ACRO governance board that governs ACRO’s processing on behalf of the joint controllers. They fall under the NPCC ICO Registration. 2 4. It is the Information Commissioner’s (the “Commissioner”) understanding that three separate incidents of compromise occurred between July 2021 - June 2023, all involving the ACRO 3 customer portal website (www.acro.police.uk), a web application 4 built on the Kentico CMS at the time of the incidents taking place. 5. The Commissioner issues ACRO with this Reprimand pursuant to Article 58(2)(b) UK General Data Protection Regulation (“UK GDPR”). 6. The Commissioner finds that between the implementation of the UK GDPR on 25 May 2018 and 22 June 2023 (the “Relevant Period”), ACRO infringed Articles 32(1), 32(1)(b), and 32(1)(d) of the UK GDPR for the reasons set out in this Reprimand. 7. The Commissioner previously served ACRO with a Notice of Intent to issue a Reprimand (the “NOI”) on 10 June 2026. ACRO provided written representations (the “Representations”) in response to the NOI on 1 July 2026. The Commissioner has taken the Representations into account when deciding to issue this Reprimand. 2This Notice is issued by Jonathan Balmforth, Group Manager (Civil and Cyber Investigations), as the delegated authority on behalf of the Information Commissioner in accordance with paragraph 6(3) of Schedule 12 of the Data Protection Act 2018 and the ICO’s Scheme of Delegations, (approved July 2025). As stated in Annex 1 of the ICO’s Scheme of Delegations, the delegation of the Information Commissioner’s non-reserved functions set out in the Scheme of Delegations continue to apply notwithstanding the vacancy in the office of the Information Commissioner. The resignation of John Edwards does not affect the continuity or validity of the process leading to this Notice. 3Interactive platforms that allow users to perform tasks, process data, and engage with complex functionality through a browser. 4A content management platform primarily used for building and managing websites, online stores, intranets, and web applications. 3NON-CONFIDENTIAL - FOR PUBLICATION II. RELEVANT LEGAL FRAMEWORK 8. Article 58(2)(b), the Commissioner has the power “to issue reprimands to a controller or a processor where processing operations have infringed provisions of this Regulation”. 9. Article 32(1) states: “taking i

Indicators of Compromise

  • malware — Mimikatz

Entities

Kentico (vendor)Kentico CMS (product)threat actor (threat_actor)Trend Micro antivirus (product)