ACRO Criminal Records Office
Disclosed Aug 7, 20267 weeks agoConfirmed
UK ICO reprimand for security failings
The Information Commissioner (the Commissioner) issues a reprimand to ACRO Criminal Records Office for infringements of Articles 32(1), 32(1)(b) and 32(1)(d) of the UK GDPR. This enforcement action follows a cyber incident in which the personal data of approximately 10,000 UK data subjects may have been affected.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | Aug 7, 2026 |
| Attack | Not stated |
| Data exposed | Not stated |
| Sector | Government · GB |
| Status | Confirmed |
| Lawsuit or fine | UK ICO reprimand (2026-08-07) |
Sources
| Source | |
|---|---|
| UK ICO reprimand: ACRO Criminal Records Officeico.org.uk · Regulator | Regulator |
Notices filed
| Where | Filed | People |
|---|---|---|
| UK ICOregulator:GB | Aug 7 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (UK ICO), confirmed by UK ICO. Record counts are as reported. Not legal advice.