The UK’s largest data protection regulator identified a breach of the Data Protection Act 2018 under section 38(4) which states “all reasonable steps must be taken to ensure that personal data which is inaccurate, incomplete or no longer up to date is not transmitted or made available for any of the law enforcement purposes.”
The breach is said to have taken place between April and July 2020, where a small set of test data in the live database system caused some files to be rejected. The incident went unnoticed for a considerable amount of time.
After the first incident, the MPS was found not to be updating sensitive files uploaded to their database which. As well as an incident where organised crime group records remained in the system when they should have been deleted. Both incidents were unnoticed by the MPS.
The ICO has confirmed that the organisation has now complied with the recommendations of the reprimand. Recommendations included reviewing how their codebase is managed and updating code breaches to incur protection, As well as better documenting how code is tested, reviewed and deployed for sensitive data.
The reprimand alleges that the MPS had not developed any form of automated system checks to ensure criminal record files were correctly loaded. The MPS responded to this by saying the system of checks during the time of investigation was “immature” according to the reprimand.
“Dealing with any personal information should be done so with the utmost care. This is of particular importance to the MPS, which handles sensitive information directly relating to criminal activity,” said Stephen Eckersley, ICO Director of Investigations.
Recommended
- Comment | The Cyber-crime Threat Landscape in 2023
- Scottish Enterprise and BP Invest £3.25M for Energy Incubator
- NCSC: ChatGPT Won’t Democratise Cyber-crime
While no files were lost since they were still accessible in the MPS system, the ICO argues that the fact that accurate information was not accessible in their database could have caused “significant damage” to the MPS’ partners.
“This reprimand reflects the ICO’s wider powers, including issuing reprimands and sharing good practice, to encourage greater compliance and empower organisations to use people’s data responsibly,” he said.
Image courtesy of MPS





