Hazard

Reprimands · Central government

ACRO Criminal Records Office

No fineReprimands
Root cause Cyber attack An external attacker got in and took data. Where the ICO's notice names the specific failure that let them, the case is filed under that instead.

What happened

The Information Commissioner (the Commissioner) issues a reprimand to ACRO Criminal Records Office for infringements of Articles 32(1), 32(1)(b) and 32(1)(d) of the UK GDPR. This enforcement action follows a cyber incident in which the personal data of approximately 10,000 UK data subjects may have been affected.

Summarised from the notice published by the ICO on 7 August 2026. Read the original notice — it is the authoritative version.