The Information Commissioner’s Office (ICO) has issued a reprimand to the Post Office following a data breach that exposed the personal information of hundreds of postmasters involved in the Horizon IT scandal.
The breach occurred when the Post Office’s communications team mistakenly published an unredacted version of a legal settlement document on its corporate website. The document contained the names, home addresses and postmaster status of 502 people who were part of a group litigation against the organisation.
It remained publicly accessible from 25 April to 19 June 2024, before being removed following notification from an external law firm.
When investigating the circumstances of this data breach, the ICO found that the Post Office failed to implement appropriate technical and organisational measures to protect people’s information. The data regulator found there to be a lack of documented policies or quality assurance processes for publishing documents on the corporate website, as well as insufficient staff training, with no specific guidance on information sensitivity or publishing practices.
“The people affected by this breach had already endured significant hardship and distress as a result of the Horizon IT scandal. They deserved much better than this,” Sally Anne Poole, head of investigations at the ICO, said.
“The postmasters have once again been let down by the Post Office. Our investigation highlighted that this data breach was entirely preventable and stemmed from a mistake that could have been avoided had the correct procedures been in place.
Recommended reading
- BCS Warns Against ‘AI Version’ of Post Office Scandal
- Wrongful Horizon IT Scandal Convictions to Be Quashed
- New £150M Taxpayer Bill for Horizon IT Scandal
- Tech and Digital Economy Minister Sacked In Cabinet Reshuffle
“Other organisations should take notice of this reprimand and apply its learnings, so they don’t find themselves making the same mistake. Data protection by design must be embedded into everyday operations so people’s information is handled appropriately.”
The ICO nearly issued the Post Office a fine of up to £1.094 million, but reconsidered, as it did not find the infringements to be so egregious under its public sector approach, which aims to mitigate fines in favour of engagement and reprimands.
Upon discovering the breach, the Post Office did offer compensation to affected individuals, as well as providing identity protection services. It also established an emergency working group to review the incident, and ensured that cached versions of the document were removed from archives.





