ACRO Criminal Records Office – Violation Found (United Kingdom, 2026)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
ACRO Criminal Records Office faced scrutiny for security incidents that potentially exposed personal data. This is important because it shows that organizations must protect sensitive information from unauthorized access. Public agencies need to strengthen their security measures to safeguard personal data.
What happened
ACRO experienced security incidents that allowed unauthorized access to its customer portal and data management systems.
Who was affected
Up to 10,920 individuals whose personal data may have been exposed were affected.
What the authority found
The Information Commissioner's Office found that ACRO failed to implement adequate security measures to protect personal data.
Why this matters
This case highlights the necessity for organizations to have robust security protocols in place. Agencies must prioritize data protection to prevent breaches.
GDPR Articles Cited
ACRO Criminal Records Office, the processor, is a national police unit providing public services including Police Certificates, International Child Protection Certificates, Subject Access Requests and Record Deletion Requests. It processes personal data on behalf of 43 police forces whose Chief Constables act as joint controllers. Between July 2021 and June 2023, three separate security incidents affected the processor's customer portal and its content management system. The most significant incident occurred between August 2022 and March 2023, during which a threat actor maintained unauthorised access to the processor's website and Case Management System (hereinafter, CMS) environment. In February 2023, the threat actor staged personal data for possible exfiltration relating to Police Certificate applications, Subject Access Requests and International Child Protection Certificate forms. Due to insufficient logging, the processor could not determine whether the data had actually been exfiltrated. A maximum of 10,920 data subjects were potentially affected. The information concerned included identification and contact data, financial information, identification numbers, criminal conviction and offence data, information concerning domestic violence, disability, gender reassignment and sexual orientation, biometric data, and racial or ethnic origin. In April 2023, the processor notified 84,048 data subjects on a precautionary basis. Several data subjects subsequently complained about distress and concerns regarding identity theft and financial loss. The DPA held that the processor infringed [https://www.legislation.gov.uk/eur/2016/679/contents Articles 32(1)], [https://www.legislation.gov.uk/eur/2016/679/contents 32(1)(b)] and [https://www.legislation.gov.uk/eur/2016/679/contents 32(1)(d) UK GDPR]. Regarding [https://www.legislation.gov.uk/eur/2016/679/contents Article 32(1) UK GDPR], the DPA found that the processor had failed to implement appropriate organisational
Outcome
Violation Found
The DPA found a violation but did not impose a fine.
Related Enforcement Actions (0)
No other enforcement actions found for ACRO Criminal Records Office in UK
This is the only recorded action for this entity in this jurisdiction.
Details
About this data
Cite as: Cookie Fines. ACRO Criminal Records Office - United Kingdom (2026). Retrieved from cookiefines.eu
Last updated: