ACRO Criminal Records Office – Violation Found (United Kingdom, 2026)

Violation Found
Information Commissioner's Office7 August 2026United Kingdom
final
Violation Found

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

ACRO Criminal Records Office faced scrutiny for security incidents that potentially exposed personal data. This is important because it shows that organizations must protect sensitive information from unauthorized access. Public agencies need to strengthen their security measures to safeguard personal data.

What happened

ACRO experienced security incidents that allowed unauthorized access to its customer portal and data management systems.

Who was affected

Up to 10,920 individuals whose personal data may have been exposed were affected.

What the authority found

The Information Commissioner's Office found that ACRO failed to implement adequate security measures to protect personal data.

Why this matters

This case highlights the necessity for organizations to have robust security protocols in place. Agencies must prioritize data protection to prevent breaches.

GDPR Articles Cited

Art. 32(1) GDPR
Art. 32(1)(b) GDPR
Art. 32(1)(d) GDPR
Source verified 22 August 2026
articles corrected
Full Legal Summary
Detailed

ACRO Criminal Records Office, the processor, is a national police unit providing public services including Police Certificates, International Child Protection Certificates, Subject Access Requests and Record Deletion Requests. It processes personal data on behalf of 43 police forces whose Chief Constables act as joint controllers. Between July 2021 and June 2023, three separate security incidents affected the processor's customer portal and its content management system. The most significant incident occurred between August 2022 and March 2023, during which a threat actor maintained unauthorised access to the processor's website and Case Management System (hereinafter, CMS) environment. In February 2023, the threat actor staged personal data for possible exfiltration relating to Police Certificate applications, Subject Access Requests and International Child Protection Certificate forms. Due to insufficient logging, the processor could not determine whether the data had actually been exfiltrated. A maximum of 10,920 data subjects were potentially affected. The information concerned included identification and contact data, financial information, identification numbers, criminal conviction and offence data, information concerning domestic violence, disability, gender reassignment and sexual orientation, biometric data, and racial or ethnic origin. In April 2023, the processor notified 84,048 data subjects on a precautionary basis. Several data subjects subsequently complained about distress and concerns regarding identity theft and financial loss. The DPA held that the processor infringed [https://www.legislation.gov.uk/eur/2016/679/contents Articles 32(1)], [https://www.legislation.gov.uk/eur/2016/679/contents 32(1)(b)] and [https://www.legislation.gov.uk/eur/2016/679/contents 32(1)(d) UK GDPR]. Regarding [https://www.legislation.gov.uk/eur/2016/679/contents Article 32(1) UK GDPR], the DPA found that the processor had failed to implement appropriate organisational

Outcome

Violation Found

The DPA found a violation but did not impose a fine.

Related Enforcement Actions (0)

No other enforcement actions found for ACRO Criminal Records Office in UK

This is the only recorded action for this entity in this jurisdiction.

Details

Decision Date

7 August 2026

Authority

Information Commissioner's Office

GDPRhub ID

gdprhub-10204

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. ACRO Criminal Records Office - United Kingdom (2026). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: