The MOPAC comes under scrutiny following a web error that potentially exposed the personal information of individuals filing complaints about the Metropolitan Police Service.
The Information Commissioner’s Office (ICO) has reprimanded MOPAC for the incident, emphasising the need for rigorous data protection measures, particularly in the realm of criminal justice.
“People used these forms for two reasons – to complain about the Metropolitan Police, or to contact the Victims Commissioner for London about the way they had been treated. This means highly personal and sensitive information could have been seen publicly. This was a completely avoidable error that has the potential to jeopardise public confidence in the criminal justice system,” said Anthony Luhman, director at the ICO.
The mishap stemmed from an error made by the Greater London Authority (GLA), responsible for managing the London.gov.uk website, which includes MOPAC’s pages and web forms.
According to the ICO, between November 11th and 14th 2022, an inadvertent action by a GLA staff member led to the unintended public accessibility of two web forms meant for contacting the Victims Commissioner for London and lodging complaints about the handling of complaints by the Met.
It was not until February 23rd 2023 that MOPAC became aware of the potential data breach following a notification from a vigilant member of the public. Subsequent investigation revealed that sensitive information such as names, addresses, and reasons for complaint submission could have been openly viewed due to the web form error.
Recommended reading
- ICO Releases Mental Health Emergency Data Sharing Guidance
- Met Police to Deploy ‘81% Inaccurate’ Live Facial Recognition Tech
- British Library Confirms Data Leaked On The Darkweb
In response, MOPAC notified 392 individuals who might have been affected by the breach, although there is no evidence to suggest that the exposed data was ever accessed by unauthorised parties.
“I am satisfied this was an honest mistake and I’m pleased by the remedial steps taken by MOPAC since the breach, which include providing additional staff training to prevent any repeated incidents,” continued Luhman.
“However, it is important that public bodies learn from this incident. The public should be able to trust that their sensitive data will be treated with the utmost care, particularly when it comes to crime.”





