Met Police Faces Questions Over Data Training Failures

Met Police Faces Questions Over Data Training Failures

Most Metropolitan Police personnel had not completed mandatory data protection training, according to figures discussed at the London Assembly, raising questions about how the force protects sensitive information after breaches exposed victims’ identities and contact details.

What Has Been Revealed?

At the Assembly’s Police and Crime Committee on 23 September, Kenny Bowie, director of strategy and MPS oversight at the Mayor’s Office for Policing and Crime, faced questions about training compliance.

Although coverage has highlighted a worryingly low completion rate of 30 per cent, his reported account put the earlier figure at around 30–40 per cent. That indicates a substantial shortfall, but should not be presented as a precise, current measurement of every officer’s training status.

Bowie acknowledged that completion needed to improve, pointing to responsibilities for individuals and supervisors, supported by technical safeguards. However, he didn’t give a firm timetable for achieving substantial compliance, leaving questions about how quickly the gap would close.

Why Does The Training Gap Matter?

The discussion follows enforcement action announced on 5 August by the Information Commissioner’s Office (ICO), the UK’s data protection regulator. Its investigation identified weaknesses in training, monitoring and management following two disclosures involving highly sensitive police cases.

These findings make the completion figures more than an administrative concern. For example, officers handle information that could expose someone to intimidation, unwanted contact or harm if shared incorrectly, making safe handling part of protecting the people who approach the police for help.

As the ICO’s Jo Stones said, “These incidents were foreseeable and preventable.” The regulator found wider organisational weaknesses rather than treating the disclosures as unrelated mistakes.

A Stalking Victim’s Details Exposed

In one case, an officer sent documents supporting a Stalking Protection Order application to the defendant without removing confidential information. They included the victim’s new address and telephone number, together with names and contact details belonging to three witnesses.

The victim had changed her contact details because of the risks she faced, but the defendant subsequently contacted her using the new number and said the information had come from police documents.

The ICO found that relevant officers had not received the required specialist training and that arrangements for preparing and checking the documents were inadequate. The failure therefore involved both what staff knew and whether the process could catch an error before information left the organisation.

When An Email Reveals More Than Its Contents

The second case involved an email sent to 18 people linked to Parliament who had been targeted through WhatsApp messages in a suspected attempt to gather compromising information. While updating them about a suspect’s bail date, an officer placed their addresses in the “To” field, exposing their names and email addresses to everyone receiving the message.

Although the email didn’t explicitly disclose sensitive details about each person, identifying them as part of the investigation could reveal information about their circumstances. The ICO therefore concluded that the force should have contacted them using a more appropriate method rather than sending one bulk email.

Its investigation also found that the officer hadn’t completed data protection training for more than four years, while the line manager had gone almost four years without relevant training, highlighting failures in both staff preparation and supervision.

What Has The Met Changed?

In response to the breaches, the Met notified those affected and offered further support to the stalking victim. It also provided additional specialist training and strengthened checks on Stalking Protection Order applications to help prevent confidential details being disclosed again.

Following the email incident, the force reminded personnel to complete mandatory training and introduced a tool that warns staff when they are emailing multiple external recipients. However, the ICO found that training completion remained low and that some wider safeguards had either not been fully introduced or had yet to be shown to work effectively.

The regulator therefore required further improvements to training, monitoring and oversight, with deadlines of three and 12 months for different measures. As Stones explained, “Policies and reminders are not enough if they are not followed, checked and enforced.”

What Does This Mean For Your Business?

For businesses, the immediate lesson here is to check whether mandatory training is actually being completed, including by managers. Someone should be responsible for following up overdue courses, making time available and checking that employees understand how the guidance applies to their work. A completion certificate has limited value if staff remain unsure how to redact a document or contact several customers without revealing their identities.

The incidents also show why training needs practical support. Sensitive documents should have appropriate checks before release, while confidential group communications may require individual messages or a secure service. Email warnings can help catch mistakes, but businesses should test whether staff understand and respond to them rather than assuming that installing a tool resolves the risk.

Also, reviews after a breach should examine the conditions that allowed it to happen. Workload, unclear instructions, weak supervision and unsuitable software can all undermine careful handling, even where an employee made the final mistake. Treating information protection as a management responsibility gives businesses a better chance of preventing repeat incidents and preserving the confidence of customers who trust them with personal details.