[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f5_b9vMf_xEia9Zaw_ZRCX5YKwmUP2gQ9OOJGHGXe4WI":3},{"article":4,"iocs":52},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":29,"category":30,"article_tags":34},"83eb75ea-a3c1-4e49-835e-53c1cc7e9c99","ICO (UK) - ACRO Criminal Records Office","ico-uk-acro-criminal-records-office-a26b5c","Created page with \"{{DPAdecisionBOX |Jurisdiction=United Kingdom |DPA-BG-Color= |DPAlogo=LogoUK.png |DPA_Abbrevation=ICO |DPA_With_Country=ICO (UK) |Case_Number_Name=ACRO Criminal Records Office |ECLI= |Original_Source_Name_1=ICO |Original_Source_Link_1=https:\u002F\u002Fico.org.uk\u002Fmedia2\u002Fnjrjayzm\u002Facro-reprimand-202608.pdf |Original_Source_Language_1=English |Original_Source_Language__Code_1=EN |Original_Source_Name_2= |Original_Source_Link_2= |Original_Source_Language_2= |Original_Source_Lang...\" New page {{DPAdecisionBOX |Jurisdiction=United Kingdom |DPA-BG-Color= |DPAlogo=LogoUK.png |DPA_Abbrevation=ICO |DPA_With_Country=ICO (UK) |Case_Number_Name=ACRO Criminal Records Office |ECLI= |Original_Source_Name_1=ICO |Original_Source_Link_1=https:\u002F\u002Fico.org.uk\u002Fmedia2\u002Fnjrjayzm\u002Facro-reprimand-202608.pdf |Original_Source_Language_1=English |Original_Source_Language__Code_1=EN |Original_Source_Name_2= |Original_Source_Link_2= |Original_Source_Language_2= |Original_Source_Language__Code_2= |Type=Investigation |Outcome=Violation Found |Date_Started= |Date_Decided=07.08.2026 |Date_Published= |Year=2026 |Fine= |Currency= |GDPR_Article_1= |GDPR_Article_Link_1= |GDPR_Article_2= |GDPR_Article_Link_2= |EU_Law_Name_1= |EU_Law_Link_1= |EU_Law_Name_2= |EU_Law_Link_2= |National_Law_Name_1=Article 32(1) UK GDPR |National_Law_Link_1=https:\u002F\u002Fwww.legislation.gov.uk\u002Feur\u002F2016\u002F679\u002Farticle\u002F32 |National_Law_Name_2=Article 32(1)(b) UK GDPR |National_Law_Link_2=https:\u002F\u002Fwww.legislation.gov.uk\u002Feur\u002F2016\u002F679\u002Farticle\u002F32 |National_Law_Name_3=Article 32(1)(d) UK GDPR |National_Law_Link_3=https:\u002F\u002Fwww.legislation.gov.uk\u002Feur\u002F2016\u002F679\u002Farticle\u002F32 |National_Law_Name_4= |National_Law_Link_4= |National_Law_Name_5= |National_Law_Link_5= |Party_Name_1=ACRO Criminal Records Office |Party_Link_1=https:\u002F\u002Fwww.acro.police.uk\u002Fs\u002F |Party_Name_2= |Party_Link_2= |Party_Name_3= |Party_Link_3= |Appeal_To_Body= |Appeal_To_Case_Number_Name= |Appeal_To_Status=Unknown |Appeal_To_Link= |Initial_Contributor=bms | }} The ICO reprimanded ACRO for failing to implement appropriate security measures, including effective patch management and security monitoring, resulting in prolonged unauthorised access to systems containing sensitive personal data. == English Summary == === Facts === ACRO Criminal Records Office, the processor, is a national police unit providing public services including Police Certificates, International Child Protection Certificates, Subject Access Requests and Record Deletion Requests. It processes personal data on behalf of 43 police forces whose Chief Constables act as joint controllers. Between July 2021 and June 2023, three separate security incidents affected the processor's customer portal and its Kentico content management system. The most significant incident occurred between August 2022 and March 2023, during which a threat actor maintained unauthorised access to the processor's website and CMS environment. In February 2023, the threat actor staged personal data for possible exfiltration relating to Police Certificate applications, Subject Access Requests and International Child Protection Certificate forms. Due to insufficient logging, the processor could not determine whether the data had actually been exfiltrated. A maximum of 10,920 data subjects were potentially affected. The information concerned included identification and contact data, financial information, identification numbers, criminal conviction and offence data, information concerning domestic violence, disability, gender reassignment and sexual orientation, biometric data, and racial or ethnic origin. In April 2023, the processor notified 84,048 data subjects on a precautionary basis. Several data subjects subsequently complained about distress and concerns regarding identity theft and financial loss. === Holding === The DPA held that the processor infringed Articles 32(1), 32(1)(b) and 32(1)(d) UK GDPR. Regarding Article 32(1) UK GDPR, the DPA found that the processor had failed to implement appropriate organisational measures to ensure a level of security appropriate to the risk. In particular, responsibility for identifying required security patches was not clearly allocated and the processor did not itself monitor whether security patches were required. The DPA further found a violation of Article 32(1)(b) UK GDPR. The processor had operated an outdated version of the Kentico CMS between 2019 and 2023 despite the availability of multiple security hotfixes. It could not demonstrate that known vulnerabilities had been subject to documented risk assessments or formal governance processes and had no documented patching policy. In addition, multiple antivirus alerts indicating malicious activity were neither reviewed nor acted upon, allowing the threat actor to remain undetected. Finally, the DPA held that the processor infringed Article 32(1)(d) UK GDPR because it lacked effective processes for regularly testing and evaluating its security measures. The absence of a documented patching policy, continuous security monitoring and clearly assigned responsibility for reviewing security alerts prevented the processor from assessing whether its technical and organisational measures remained effective. Taking into account the seriousness and duration of the infringements, as well as mitigating factors and the remedial measures subsequently implemented by the processor, the DPA issued a reprimand. == Comment == ''Share your comments here!'' == Further Resources == ''Share blogs or news articles here!'' == English Machine Translation of the Decision == The decision below is a machine translation of the English original. Please refer to the English original for more details. UK GENERAL DATA PROTECTION REGULATION (Article 58(2)(b)) CORRECTIVE POWERS OF THE INFORMATION COMMISSIONER REPRIMAND DATED: 7 August 2026 To: ACRO Criminal Records Office Of: ACRO Criminal Records Office, ACRO, PO Box 481, Fareham, Hampshire, PO14 9FS I. INTRODUCTION AND SUMMARY 1. ACRO Criminal Records Office herein referred to as ‘ACRO’ are a national police unit providing a range of public services such as the issuing of Police Certificates, International Child Protection Certificates and the processing of Subject Access Requests and Record Deletion Requests. ACRO was founded in 2006. 2. ACRO are a data processor for processing activities set out in the S22A Collaboration Agreement under the Police Act 1996 acting on behalf of the 43 Police Forces that are party to the agreement. The Chief Constables party to the agreement are joint controllers. 1 Police Act 1996 2NON-CONFIDENTIAL - FOR PUBLICATION 3. The National Police Chiefs Council (NPCC) is the chair of the ACRO governance board that governs ACRO’s processing on behalf of the joint controllers. They fall under the NPCC ICO Registration. 2 4. It is the Information Commissioner’s (the “Commissioner”) understanding that three separate incidents of compromise occurred between July 2021 - June 2023, all involving the ACRO 3 customer portal website (www.acro.police.uk), a web application 4 built on the Kentico CMS at the time of the incidents taking place. 5. The Commissioner issues ACRO with this Reprimand pursuant to Article 58(2)(b) UK General Data Protection Regulation (“UK GDPR”). 6. The Commissioner finds that between the implementation of the UK GDPR on 25 May 2018 and 22 June 2023 (the “Relevant Period”), ACRO infringed Articles 32(1), 32(1)(b), and 32(1)(d) of the UK GDPR for the reasons set out in this Reprimand. 7. The Commissioner previously served ACRO with a Notice of Intent to issue a Reprimand (the “NOI”) on 10 June 2026. ACRO provided written representations (the “Representations”) in response to the NOI on 1 July 2026. The Commissioner has taken the Representations into account when deciding to issue this Reprimand. 2This Notice is issued by Jonathan Balmforth, Group Manager (Civil and Cyber Investigations), as the delegated authority on behalf of the Information Commissioner in accordance with paragraph 6(3) of Schedule 12 of the Data Protection Act 2018 and the ICO’s Scheme of Delegations, (approved July 2025). As stated in Annex 1 of the ICO’s Scheme of Delegations, the delegation of the Information Commissioner’s non-reserved functions set out in the Scheme of Delegations continue to apply notwithstanding the vacancy in the office of the Information Commissioner. The resignation of John Edwards does not affect the continuity or validity of the process leading to this Notice. 3Interactive platforms that allow users to perform tasks, process data, and engage with complex functionality through a browser. 4A content management platform primarily used for building and managing websites, online stores, intranets, and web applications. 3NON-CONFIDENTIAL - FOR PUBLICATION II. RELEVANT LEGAL FRAMEWORK 8. Article 58(2)(b), the Commissioner has the power “to issue reprimands to a controller or a processor where processing operations have infringed provisions of this Regulation”. 9. Article 32(1) states: “taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the controller and the processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk.” 10. Article 32(1)(b) states organisations should: “ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems and services” 11. Article 32(1)(d) states organisations should have: “a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing.” III. BACKGROUND TO THE INFRINGEMENTS 12. This section summarises the relevant background to the findings of infringement. It does not seek to provide an exhaustive account of all the details of the events that have led to the decision to issue this Reprimand. Incident Overview 13. In March 2023, the Joint ICT (JICT) department of ACRO’s host Force, Hampshire and Isle of Wight Constabulary, notified ACRO 4NON-CONFIDENTIAL - FOR PUBLICATION that there had been an incident raised at the 5 This incident involved an SQL injection attack that exposed 15 username and password credentials, the majority of which related to ACRO employees. 14. After notification from the ACRO commissioned to carry out a forensic investigation which uncovered three distinct incidents in total, all involving the ACRO website and its Kentico CMS, with threat actor activity evidenced between 09 July 2021 - 22 June 2023. Two of these incidents either did not involve personal data or affected a small portion of user account credentials, herein these incidents are referred to as ‘Group B’ and ‘Group C’. 15. The most significant incident, herein referred to as ‘Group A’, occurred between 5 August 2022 - 14 March 2023, during which the threat actor maintained unauthorised access to ACRO’s website\u002FCMS environment. Between 15 - 16 February 2023, the 7 threat actor was able to stage data for exfiltration. The personal data staged related to Police Certificate Applications, Subject Access Request (SAR) forms and International Child Protection Certificate forms. Insufficient logs were retained by ACRO in order to definitively determine if this data was exfiltrated from their network. 16. The last evidence of threat actor access to the ACRO website \u002F CMS environment during the Group A incident was on 14 March 2023. ACRO took the customer portal section of their website offline on 21 March 2023 in response to the discovery of the Group B 5 A technique used to attack Structured Query Language (SQL) databases by injecting malicious commands into database queries. 7 Data Staging is the process of extracting data and storing it in a temporary holding place before complete exfiltration. 5NON-CONFIDENTIAL - FOR PUBLICATION incident, this limited external access to the compromised systems. However, the Commissioner considers that the end date for the Relevant Period should be taken from when the compromised infrastructure, which continued to be used to process limited amounts of personal data, was fully decommissioned on 22 June 2023. 17. In total, a maximum of 10,920 data subjects were potentially affected where their personal data was staged for exfiltration. Not all data subjects who had personal data staged for exfiltration would have had personal data falling into every category set out below: • Basic Personal Identifiers (first name, surnames, place of birth, date of birth, proof of address) • Economic and Financial (account and sort code) • Identification Numbers (national insurance number, driving license numbers and passport details) • Criminal Convictions and Criminal Offences (persons who have disclosed serious offending, persons who are the perpetrator of domestic violence) • Persons who have been subject to domestic violence. • Disability, Gender Reassignment and Sexual Orientation information • Biometric Data • Race & Ethnic Origin 18. The categories of data subjects potentially affected are applicants, third parties, nominated parties and, endorsers for Police Certificates and International Child Protection Certificates. As well as those requesting Subject Access and Record Deletion. 6NON-CONFIDENTIAL - FOR PUBLICATION 19. In total 84,048 data subjects were notified by ACRO on a precautionary basis in April 2023. The total of 84,048 data subjects reflects all individuals who submitted applications between 17 January 2023 - 21 March 2023, plus an additional 18 data subjects whose applications had been stored for an extended period. Damage and distress caused to the Data Subjects 20. ACRO received 35 complaints from data subjects potentially affected, which were evidenced to the Commissioner. The complaint information provided by ACRO reported distress and concern arising from the incident, including concerns about the risk of identity theft and financial loss. Complainants included those connected to Police Certificates, International Child Protection Certificates, and victims of domestic violence. ACRO advised that, in one instance, a These complaints have not been interrogated by the Commissioner. 21. The Commissioner separately received a further six complaints. These complaints report distress and anxiety arising from the breach, including concerns about identity theft and financial loss. These complaints have not been interrogated by the Commissioner. Mitigating factors 22. During the course of the ICO’s investigation, the Commissioner has noted that ACRO’s network segmentation measures prevented the threat actor from moving beyond the compromised environment into core policing systems, reducing the scale of harm. also 7NON-CONFIDENTIAL - FOR PUBLICATION confirmed no lateral movement into the wider JICT estate was observed. Remedial steps taken by ACRO Criminal Records Office 23. The Commissioner has also considered and welcomes the remedial steps taken by ACRO in light of this incident. This included decommissioning the compromised infrastructure, migrating to the Salesforce Experience Cloud, implementing a SIEM, enhancing visibilityand monitoring, and introducing stronger system hardening and network segmentation. 24. The Commissioner recognises that ACRO has made improvements to its patching arrangements since the incident, including through its move to Salesforce Experience Cloud, where patching is governed by Salesforce’s formal change management process and includes the evaluation and implementation of upgrades, patches and hotfixes. ACRO has also implemented as its SIEM solution, improving its ability to detect, analyse and respond to security threats in real time, and strengthening its response to security alerts. IV. THE COMMISSIONER’S FINDINGS OF INFRINGEMENT 25. The Commissioner has decided to issue a reprimand to ACRO Criminal Records Office in respect of the following infringements of the UK GDPR: 26. Article 32(1) which states: “taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of 8NON-CONFIDENTIAL - FOR PUBLICATION processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the controller and the processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk.” 27. Article 32(1)(b) which states organisations should: “ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems and services” 28. Article 32(1)(d) which states organisations should have: “a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing.” 29. Our investigation found infringements in relation to the security requirements of the UK GDPR, and these are set out below. Article 32(1) 30. ACRO did not have the correct organisational measures in place to ensure a level of security appropriate to the risk as per Article 32(1). ACRO did not clearly define who was responsible for monitoring for required security patches. ACRO’s web development supplier were responsible for the application of security patches, but not for identifying when patches were required. ACRO itself did not monitor for required security patches, meaning that there was an absence of oversight for this important security control. This demonstrated failings in the organisation’s wider obligations under the UK GDPR. 9NON-CONFIDENTIAL - FOR PUBLICATION Article 32(1)(b) 31. ACRO were not ensuring the ongoing confidentiality, integrity and resilience of their systems as per Article 32(1)(b). ACRO did not have the appropriate technical and organisational measures in place to ensure the level of security appropriate to risk. 32. Unpatched Content Management System (CMS) 33. ACRO’s website was built using the Kentico CMS. Between September 2019 - March 2023, this was running on version 12.0.0. This version of Kentico CMS had multiple known vulnerabilities at the time of the incident. The forensic investigation did not specify which vulnerability was exploited, however it is highly likely that the threat actor gained initial access by exploiting an unpatched Kentico software vulnerability. 9 34. Cumulative security hotfixes were released by Kentico between September 2019 - July 2023. None of these security hotfixes were applied, meaning the ACRO website remained on an unpatched and vulnerable version. 35. ACRO did not provide the ICO with evidence demonstrating that the security risks associated with known Kentico CMS vulnerabilities had been subject to documented risk assessment or formal governance processes in relation to CMS patching. 36. Content Management System Patching Responsibility 8 9National Vulnerability Database – Kentico Xperience 12.0.0 A vendor issued software update designed to quickly address a specific problem, usually a critical security vulnerability. 10NON-CONFIDENTIAL - FOR PUBLICATION 37. ACRO could not demonstrate clear accountability for identifying required security patches and hotfixes for Kentico CMS during the ICO’s investigation. 38. ACRO’s Managed Service Provider were responsible for Operating System (OS) patching and server maintenance where 12 monthly Microsoft security updates were applied to production 13 and staging servers . This excluded patching for the Kentico CMS as role was limited to infrastructure. 39. Application of Kentico CMS patches and hotfixes were assigned to as evidenced by an email exchange between ACRO and dated 14–20 February 2020, which explicitly confirmed that CMS updates fell within remit under the support agreement. While this confirmed responsibility for implementing and applying Kentico CMS patches and hotfixes, it did not establish whether was obligated to actively monitor for these. 40. The ambiguity around who was accountable for identifying necessary Kentico CMS patches created a gap where patches and hotfixes were missed which ultimately left ACRO’s website vulnerable. 41. Patching Policy 42. ACRO did not provide a documented patching policy covering CMS updates, despite the ICO requesting this during the investigation. 10The core software that manages a computer’s hardware and software resources, providing a platform for applications to run. 11The process of applying vendor issued updates to an operating system. 12The live environment where the application or website is fully deployed and accessible to end users. 13A pre-production environment that closely mirrors the production setup. 11NON-CONFIDENTIAL - FOR PUBLICATION 43. As a result, ACRO could not demonstrate how vulnerabilities were identified, prioritised and\u002For tested, nor how responsibility for these activities was assigned or assured. 44. The absence of such a policy reinforced the fragmented and poor approach to patch management, leaving critical responsibilities unclear. 45. Industry guidance is clear in relation to patching and vulnerability management: 46. NCSC’s 10 Steps to Cyber Security published in May 2021 includes guidance on vulnerability management, including updating software to address vulnerabilities. “Ensure all systems have a software update strategy. For devices that are not automatically updated, this should detail how and when updates get applied, and who is responsible for doing and checking the updates. The strategy should account for system availability requirements and relevant dependencies, while aiming to minimise the length of time before updates are applied.” “it is important (and essential for any systems that are exploitable from the internet) to install security updates as soon as possible to protect your organisation.” 47. NCSC’s Cyber Essentials v3.0 published in January 2022 includes an objective for Security Update Management. 14 1510 Steps to Cyber Security - NCSC.GOV.UK Cyber Essentials - Requirements for Infrastructure v3.0.pdf 12NON-CONFIDENTIAL - FOR PUBLICATION “Ensure that devices and software are not vulnerable to known security issues for which fixes are available.” 48. Response to Security Alerts 49. The infrastructure that supported the ACRO public facing website had Trend Micro antivirus software (Trend Micro) installed at the time of the incidents. This was designed to detect and quarantine 17 18 malware, such as credential harvesting tools and backdoors , by scanning files and monitoring system activity. 50. While Trend Micro did successfully detect and quarantine several threat actor tools during the incidents, the alerts that were generated were not reviewed or acted upon. 51. ACRO advised the ICO that, due to it was unable to establish what business processes existed for the assessment or handling of security alerts at the relevant time. Nor could it identify which roles were responsible for reviewing or escalating such alerts. As a result, the ICO was not provided with evidence demonstrating that Trend Micro alerts relating to the detection and quarantining of known threat actor tools were assessed, escalated, or investigated at the time they were generated. 16A solution developed by Trend Micro, designed to protect computers and networks from malware, viruses, ransomware, and other threats. 17A technique where a threat actor collects usernames, passwords, and other authentication data from a target system or user. 18A hidden method of bypassing normal authentication or security controls to gain unauthorised access to a system, application, or network. 13NON-CONFIDENTIAL - FOR PUBLICATION 52. Had the alerts been investigated by ACRO at the time, and an appropriate response conducted, it is likely that further malicious activity could have been prevented. 53. System and Security Monitoring 54. There was some level of monitoring in place as undertook monitoring activities in line with its contractual obligations. were contracted to provide ACRO with support, maintenance and management of ACRO’s environment. This environment contained a virtual firewall, virtual web servers and virtual SQL servers which together supported the ACRO public website and staging websites. ACRO did not subscribe to SIEM service. documents were provided to ACRO by these documents included a section that provided an opportunity to highlight any ongoing security issues, such as patching and security incidents. 55. As described above at paragraphs 49 – 52, there were multiple antivirus detections of malicious software during the incidents. On 23 February 2023 Trend Micro detected and quarantined four attempts to install the known credential harvesting tool Mimikatz . However, the February 2023 document does not include any reference to the malicious files quarantined by Trend Micro antivirus, this is despite being required by ACRO to reboot the affected server. 19 A solution that provides real time monitoring, analysis, and management of security events 20ross an organisation’s IT infrastructure. https:\u002F\u002Fattack.mitre.org\u002Fsoftware\u002FS0002\u002F 14NON-CONFIDENTIAL - FOR PUBLICATION 56. Despite Trend Micro successfully detecting and quarantining threat actor tools on multiple occasions, these alerts were not investigated or acted upon by any involved party. 57. The forensic investigation identified multiple historic Trend Micro Antivirus alerts related to detected and quarantined attacker tools. These alerts provided an early warning to the ongoing attack but were not reviewed or acted on. 58. ACRO advised the ICO that it could not establish which roles previously held responsibility for monitoring security alerts which occurred prior to and during the period of Group A threat actor activity. 59. The ambiguity around the role and responsibility of responding to security alerts, and the failure to act up the generated security alerts resulted in the threat actor being able to carry out its activity undetected. 60. Industry guidance is clear in relation to monitoring and visibility: 21 61. NCSC’s 10 Steps to Cyber Security published in May 2021 includes guidance on logging and monitoring. “the main priority should be the ability to respond to incidents and to do this, logs are required.” “Collecting logs is essential to understand how your systems are being used and is the foundation of security (or protective) 21 10 Steps to Cyber Security - NCSC.GOV.UK 15NON-CONFIDENTIAL - FOR PUBLICATION monitoring. In the event of a concern or potential security incident, good logging practices will allow you to retrospectively look at what has happened and understand the impact of the incident. Security monitoring takes this further and involves the active analysis of logging information to look for signs of known attacks or unusual system behaviour, enabling organisations to detect events that could be deemed as a security incident, and respond accordingly in order to minimise the impact.” 62. NCSC’s Secure Design Principles published in May 2019 22 states: “Ensure you log enough to perform root cause analysis in event of a failure. Will your logs hold the data you need to work out whether a failure happened as a result of a breach? Both infrastructure and application level logs may be needed.” “As well as collecting logs and capturing relevant events, you should ensure that the integrity of your logs would be maintained in event of a breach. The attacker should not be able to cover their tracks.” 63. The NIST 800-61 Rev 2 Computer Security Incident Handling Guide (3.2.4 – Incident Analysis) published in August 2012 23 states: “the incident response team should work quickly to analyze and validate each incident, following a pre-defined process and documenting each step taken. When the team believes that an incident has occurred, the team should rapidly perform an initial analysis” 22 23Secure design principles | National Cyber Security Centre SP 800-61 Rev. 2, Computer Security Incident Handling Guide | CSRC (nist.gov) 16NON-CONFIDENTIAL - FOR PUBLICATION 24 64. CIS Control 13 Network and Monitoring Defence published in 2021 states: “Centralize security event alerting across enterprise assets for log correlation and analysis. Best practice implementation requires the use of a SIEM, which includes vendor-defined event correlation alerts.” Article 32(1)(d) 65. ACRO did not maintain effective processes for testing or evaluating its security measures as per Article 32(1)(d). ACRO operated without a documented patching policy and continuous security monitoring, leaving the organisation unable to verify whether its technical and organisational measures were effective at any point during the periods of compromise. 66. ACRO lacked a structured process for analysing security alerts, as demonstrated by the failure to investigate multiple Trend Micro antivirus alerts indicating the presence of threat actor tools. 67. ACRO advised the ICO that it was unable to identify which roles previously held responsibility for reviewing such alerts This lack of defined responsibility meant that alerts were not reviewed, escalated, or acted upon, preventing ACRO from identifying or containing ongoing threat actor activity. 24 CIS stands for the ‘Center for Internet Security’, a nonprofit organisation dedicated to improving cybersecurity for public and private sector entities worldwide. 17NON-CONFIDENTIAL - FOR PUBLICATION V. DECISION TO ISSUE THIS REPRIMAND 68. Taking into account all of the circumstances of this case, including the nature, duration and seriousness of the infringements identified, as well as the mitigating factors and remedial steps taken by ACRO following the incidents, the Commissioner considers that it would be a reasonable and proportionate exercise of his powers to issue a reprimand to ACRO for infringements of Articles 32(1), 32(1)(b) and 32(1)(d) of the UK GDPR, as set out above, and that a reprimand would be an effective, proportionate and dissuasive measure. Dated: 7 August 2026 Signed: ………………………………… Jonathan Balmforth Group Manager, Civil and Cyber Investigations Information Commissioner’s Office Wycliffe House Water Lane Wilmslow Cheshire SK9 5AF 18","The UK's Information Commissioner's Office (ICO) has reprimanded ACRO Criminal Records Office for significant security failings. These included a lack of effective patch management and security monitoring, which allowed a threat actor prolonged unauthorized access to systems containing sensitive personal data. The breaches, which occurred between July 2021 and June 2023, potentially affected up to 10,920 individuals.","ICO reprimands ACRO for failing to implement adequate security measures, leading to prolonged unauthorized access.","Help ICO (UK) - ACRO Criminal Records Office: Difference between revisions From GDPRhub Jump to:navigation, search Newer edit →VisualWikitext Revision as of 12:09, 21 August 2026 view source Bms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators269 edits Tag: Decisions [1.0]Newer edit → (No difference) Revision as of 12:09, 21 August 2026 ICO - ACRO Criminal Records Office Authority: ICO (UK) Jurisdiction: United Kingdom Relevant Law: Article 32(1) UK GDPRArticle 32(1)(b) UK GDPRArticle 32(1)(d) UK GDPR Type: Investigation Outcome: Violation Found Started: Decided: 07.08.2026 Published: Fine: n\u002Fa Parties: ACRO Criminal Records Office National Case Number\u002FName: ACRO Criminal Records Office European Case Law Identifier: n\u002Fa Appeal: Unknown Original Language(s): English Original Source: ICO (in EN) Initial Contributor: bms The ICO reprimanded ACRO for failing to implement appropriate security measures, including effective patch management and security monitoring, resulting in prolonged unauthorised access to systems containing sensitive personal data. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts ACRO Criminal Records Office, the processor, is a national police unit providing public services including Police Certificates, International Child Protection Certificates, Subject Access Requests and Record Deletion Requests. It processes personal data on behalf of 43 police forces whose Chief Constables act as joint controllers. Between July 2021 and June 2023, three separate security incidents affected the processor's customer portal and its Kentico content management system. The most significant incident occurred between August 2022 and March 2023, during which a threat actor maintained unauthorised access to the processor's website and CMS environment. In February 2023, the threat actor staged personal data for possible exfiltration relating to Police Certificate applications, Subject Access Requests and International Child Protection Certificate forms. Due to insufficient logging, the processor could not determine whether the data had actually been exfiltrated. A maximum of 10,920 data subjects were potentially affected. The information concerned included identification and contact data, financial information, identification numbers, criminal conviction and offence data, information concerning domestic violence, disability, gender reassignment and sexual orientation, biometric data, and racial or ethnic origin. In April 2023, the processor notified 84,048 data subjects on a precautionary basis. Several data subjects subsequently complained about distress and concerns regarding identity theft and financial loss. Holding The DPA held that the processor infringed Articles 32(1), 32(1)(b) and 32(1)(d) UK GDPR. Regarding Article 32(1) UK GDPR, the DPA found that the processor had failed to implement appropriate organisational measures to ensure a level of security appropriate to the risk. In particular, responsibility for identifying required security patches was not clearly allocated and the processor did not itself monitor whether security patches were required. The DPA further found a violation of Article 32(1)(b) UK GDPR. The processor had operated an outdated version of the Kentico CMS between 2019 and 2023 despite the availability of multiple security hotfixes. It could not demonstrate that known vulnerabilities had been subject to documented risk assessments or formal governance processes and had no documented patching policy. In addition, multiple antivirus alerts indicating malicious activity were neither reviewed nor acted upon, allowing the threat actor to remain undetected. Finally, the DPA held that the processor infringed Article 32(1)(d) UK GDPR because it lacked effective processes for regularly testing and evaluating its security measures. The absence of a documented patching policy, continuous security monitoring and clearly assigned responsibility for reviewing security alerts prevented the processor from assessing whether its technical and organisational measures remained effective. Taking into account the seriousness and duration of the infringements, as well as mitigating factors and the remedial measures subsequently implemented by the processor, the DPA issued a reprimand. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the English original. Please refer to the English original for more details. UK GENERAL DATA PROTECTION REGULATION (Article 58(2)(b)) CORRECTIVE POWERS OF THE INFORMATION COMMISSIONER REPRIMAND DATED: 7 August 2026 To: ACRO Criminal Records Office Of: ACRO Criminal Records Office, ACRO, PO Box 481, Fareham, Hampshire, PO14 9FS I. INTRODUCTION AND SUMMARY 1. ACRO Criminal Records Office herein referred to as ‘ACRO’ are a national police unit providing a range of public services such as the issuing of Police Certificates, International Child Protection Certificates and the processing of Subject Access Requests and Record Deletion Requests. ACRO was founded in 2006. 2. ACRO are a data processor for processing activities set out in the S22A Collaboration Agreement under the Police Act 1996 acting on behalf of the 43 Police Forces that are party to the agreement. The Chief Constables party to the agreement are joint controllers. 1 Police Act 1996 2NON-CONFIDENTIAL - FOR PUBLICATION 3. The National Police Chiefs Council (NPCC) is the chair of the ACRO governance board that governs ACRO’s processing on behalf of the joint controllers. They fall under the NPCC ICO Registration. 2 4. It is the Information Commissioner’s (the “Commissioner”) understanding that three separate incidents of compromise occurred between July 2021 - June 2023, all involving the ACRO 3 customer portal website (www.acro.police.uk), a web application 4 built on the Kentico CMS at the time of the incidents taking place. 5. The Commissioner issues ACRO with this Reprimand pursuant to Article 58(2)(b) UK General Data Protection Regulation (“UK GDPR”). 6. The Commissioner finds that between the implementation of the UK GDPR on 25 May 2018 and 22 June 2023 (the “Relevant Period”), ACRO infringed Articles 32(1), 32(1)(b), and 32(1)(d) of the UK GDPR for the reasons set out in this Reprimand. 7. The Commissioner previously served ACRO with a Notice of Intent to issue a Reprimand (the “NOI”) on 10 June 2026. ACRO provided written representations (the “Representations”) in response to the NOI on 1 July 2026. The Commissioner has taken the Representations into account when deciding to issue this Reprimand. 2This Notice is issued by Jonathan Balmforth, Group Manager (Civil and Cyber Investigations), as the delegated authority on behalf of the Information Commissioner in accordance with paragraph 6(3) of Schedule 12 of the Data Protection Act 2018 and the ICO’s Scheme of Delegations, (approved July 2025). As stated in Annex 1 of the ICO’s Scheme of Delegations, the delegation of the Information Commissioner’s non-reserved functions set out in the Scheme of Delegations continue to apply notwithstanding the vacancy in the office of the Information Commissioner. The resignation of John Edwards does not affect the continuity or validity of the process leading to this Notice. 3Interactive platforms that allow users to perform tasks, process data, and engage with complex functionality through a browser. 4A content management platform primarily used for building and managing websites, online stores, intranets, and web applications. 3NON-CONFIDENTIAL - FOR PUBLICATION II. RELEVANT LEGAL FRAMEWORK 8. Article 58(2)(b), the Commissioner has the power “to issue reprimands to a controller or a processor where processing operations have infringed provisions of this Regulation”. 9. Article 32(1) states: “taking i","https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=ICO_(UK)_-_ACRO_Criminal_Records_Office&diff=52747&oldid=0","https:\u002F\u002Fgdprhub.eu\u002Fimages\u002Fa\u002Fa4\u002FLogoUK.png","2026-08-21T12:09:37+00:00","2026-08-21T14:00:15.462815+00:00",7,[18,21,24,27],{"name":19,"type":20},"Kentico","vendor",{"name":22,"type":23},"Kentico CMS","product",{"name":25,"type":26},"threat actor","threat_actor",{"name":28,"type":23},"Trend Micro antivirus","c5c77cdb-f7d7-4990-9436-c81dcbff1163",{"id":29,"icon":31,"name":32,"slug":33},null,"Policy","policy",[35,40,45,50],{"category":36},{"id":37,"icon":31,"name":38,"slug":39},"23e81061-ab06-449f-8807-cbe4bc305045","UK Data Protection","uk-data-protection",{"category":41},{"id":42,"icon":31,"name":43,"slug":44},"2e06f76c-d5b9-4f54-9eef-4d3447b10730","Breaches","breaches",{"category":46},{"id":47,"icon":31,"name":48,"slug":49},"53f9c4b6-8bc6-4964-9169-d09e5cd41d72","Compliance","compliance",{"category":51},{"id":29,"icon":31,"name":32,"slug":33},[53],{"type":54,"value":55,"context":56},"malware","Mimikatz","Credential harvesting tool detected by antivirus during incidents."]