Reprimands · Central government
ACRO Criminal Records Office
No fineReprimands
Root cause
Cyber attack
An external attacker got in and took data. Where the ICO's notice names the specific failure that let them, the case is filed under that instead.
What happened
The Information Commissioner (the Commissioner) issues a reprimand to ACRO Criminal Records Office for infringements of Articles 32(1), 32(1)(b) and 32(1)(d) of the UK GDPR. This enforcement action follows a cyber incident in which the personal data of approximately 10,000 UK data subjects may have been affected.
Summarised from the notice published by the ICO on 7 August 2026. Read the original notice — it is the authoritative version.