UK: ICO reprimands ACRO Criminal Records Office after data breach
The UK Information Commissioner's Office has formally reprimanded ACRO Criminal Records Office for violating UK GDPR security requirements following a data breach. ACRO is a national police unit that handles sensitive records including criminal history, Police Certificates, and International Child Protection Certificates.
Why this matters: ACRO does not hold ordinary data. It holds criminal records and child protection certificates — information people need for jobs, travel, and adoption, and information that can ruin lives if it ends up in the wrong place. A reprimand from the ICO is a formal finding that security was not good enough. The harder question is what a reprimand actually changes. No fine is mentioned. For the people whose records were exposed, accountability that stops at a letter is a thin result.
Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · AI governance
This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.