ICO Reprimand Issued to ACRO Criminal Records Office 

The Information Commissioner’s Office has issued a reprimand to ACRO Criminal Records Office (ACRO) after cyber security failings left the personal data of up to ten thousand people potentially exposed. 

The ICO’s investigation found that between August 2022 and March 2023, a hacker gained unauthorised access to ACRO’s website and content management system (CMS). The attacker was able to stage personal data to be stolen, although ACRO could not conclusively determine whether the information was removed from its systems. 

The investigation found that up to 10,920 people may have been affected.
The data potentially exposed included names, dates of birth, addresses, National Insurance numbers, passport and driving licence details, bank account information, biometric data, and highly sensitive criminal offence and special category information. Those affected included applicants for Police Certificates and International Child Protection Certificates, subject access request applicants, and third parties connected to those applications. 

The ICO found ACRO had engaged third-party providers to deliver certain security services, including patch management. However, ACRO did not ensure clear responsibility for identifying and monitoring critical CMS security updates, failed to maintain an effective patch management process, and did not adequately investigate security alerts that could have identified the hacker’s activity earlier. 

In deciding to issue a reprimand, the ICO considered a number of mitigating factors. Network segmentation prevented the hacker from moving beyond the compromised website environment into core systems, reducing the potential scale of harm.
The ICO additionally welcomed the remedial action taken by ACRO following the incident, including decommissioning the compromised infrastructure, migrating services elsewhere, implementing security monitoring, improving visibility of cyber threats and strengthening network segmentation. 

The Reprimand mentions infringements of Articles 32(1), 32(1)(b) and 32(1)(d) of the UK GDPR. However some commentators have questioned whether it should be for breaches of Part 3 of the Data Protection Act 2018 which applies to law enforcement processing (See Jon Baines post here.) 

With the rapid advance of AI, including emerging threats from AI agents, it is critical that organisations focus on cyber security. The ICO has highlighted the following action points for organisations to avoid similar breaches: 

Make accountability clear: Define who is responsible for identifying, assessing and implementing security updates across all systems and suppliers. 

Act on warning signs: Ensure security alerts are actively monitored, investigated and escalated so threats are identified before they become major incidents. 

Get the basics right: Effective patch management, vulnerability management and regular security testing remain some of the most important defences against cyber attacks. 

The ICO’s guidance on cyber security can be read here

For more on this topic, listen to Caroline Wong, an AI cyber security expert, speaking on the Guardians of Data podcast. 

We have two workshops coming up (How to Increase Cyber Security in your Organisation and Cyber Security for DPOs) which are ideal for organisations who wish to upskill their employees about cyber security.  

Advanced Certificate in GDPR Practice

Are you an experienced Data Protection Officers seeking to refine and expand your DPO skills and expertise? 

The Act Now Advanced Certificate in GDPR Practice is one of the UK’s leading advanced qualifications for DPOs.   

Since its launch in 2020, this innovative course has attracted DPOs from across the public and private sectors. Feedback has been consistently positive with many participants commenting on how the course has given them the confidence and skills to be able to dissect complex data protection scenarios and give clear and practical compliance advice.  

Further advances in technology, especially in AI, has led us to revise the syllabus to ensure participants are engaging with the most up to date data protection issues and ICO/Tribunal decisions to inform their day to day work.  

New Assessment Format 

Based on extensive feedback from delegates over our suite of certificate programmes, we learned that delegates would prefer not to have to write extensive reports and want the opportunity to showcase their critical thinking and communication skills. 

The new assessment consists of two parts. The first part requires participants to submit a personal development plan about how their learning from the course will inform and improve their practice as a data protection practitioner. The second part requires them to draft an executive summary setting out the issues and recommendations in relation to the fictional case study discussed in Masterclass 4. This summary will then be presented by participants in an oral examination, known as a Viva.  

Watch Alex, one of our recent delegates, give his verdict on the course. 

There are just three places left on the next course starting on 21st October 2026. Click below to learn more.

New FOI Style Requirements for Housing Associations

From October, tenants of non-local authority social landlords, such as housing associations and housing co-operatives, will have new rights to access information about how their homes are managed. Tenants of local authority-owned housing can already access this information under the Freedom of Information Act 2000.  

In Autumn last year, The Ministry of Housing, Communities and Local Government published a policy statement following a consultation on the introduction of Social Tenant Access to Information Requirements (STAIRs). Some have dubbed this “FOI for the housing sector.”  

The Regulator of Social Housing has been directed to introduce a new standard requiring all non-local authority social landlords (also known as private registered providers or “PRPs”) such as housing associations to comply with the new requirements.

Publication Scheme 

From 1st October 2026, PRPs must proactively publish information that they hold relating to various matters such as governance and decision making, spending, housing stock management, performance, housing services, lists and registers and social housing management. 

They must make tenants aware of the publication scheme so that they can easily identify and access information. Just like under FOI, there is no requirement to create any new records to comply with this obligation and redactions may be made in certain circumstances e.g. to protects commercially sensitive or personal information. 

Information Requests 

From 1st  April 2027, PRPs must respond to their tenants’ requests for information that relate to the management of their social housing. Only tenants can make requests, unlike FOI where anyone can do so. Matters determined by local councils and information about property management that is not related to the social housing functions are not part of this obligation. 

Requests must be in writing. There will be a deadline of 30 calendar days to respond to a request for information, which may be extended in certain circumstances.  

PRPs cannot delete or alter information to prevent disclosure but the same exemptions set out in the FOI will apply under STAIRs. 

Review Process 

PRPs will also need to put in place a STAIRs review process to deal with any complaints related to either the publication scheme or information requests. Reviews will need to be completed within 30 calendar days. If the complainant is unhappy with the response they can they escalate this to the Housing Ombudsman. Responses to review requests should inform tenants of their right to access the Housing Ombudsman Scheme

Training 

PRPs need to prepare now for the new  STAIRs regime. They should ensure they have adequate policies and procedures in place including staff training.  

Please see our new STAIRS workshop with Naomi Mathews. We can also deliver this course on an in house basis customised to the needs of your staff (online or classroom). Get in touch for a quote.

Predictive Policing and the Think Family Database

Predictive Policing, or Predictive Analytics, is increasingly being promoted as a tool to help police forces prevent crime before it happens. Supporters argue that analysing vast amounts of data can help identify vulnerable people, allocate resources more effectively and enable earlier intervention. However, a recent investigation published by WIRED magazine raises important questions about whether these systems are accurate, transparent or fair enough to justify their growing use. 

WIRED, working in partnership with the nonprofit newsroom Liberty Investigates, plus the Bristol Cable and Lighthouse Reports, obtained hundreds of pages of documentation, using FOI requests, to build a comprehensive picture of a long-running partnership between Avon and Somerset Police and Bristol City Council to develop predictive policing and safeguarding tools. It reveals how the two organisations worked together to combine public sector data, develop machine-learning models and deploy risk-scoring systems intended to support policing and child protection.  

The Think Family Database 

One of these systems was the Think Family Database which was launched in 2016. According to WIRED, the database brought together information held by multiple public bodies, creating records covering almost half a million Bristol residents.
The council played a central role by contributing and managing information from housing, education, children’s services, social care and other local authority functions, while police intelligence and crime data were also incorporated. The intention was to provide practitioners across organisations with a more complete understanding of individuals and families who might require support, enabling earlier intervention and better coordination between agencies. 

Using this shared data, the two organisations developed numerous machine-learning models designed to predict a range of outcomes. These included identifying people considered at greater risk of offending, becoming victims of crime, going missing or failing to appear in court. Other models sought to identify children who might be vulnerable to criminal or sexual exploitation. 

On paper, these objectives reflected a broader ambition shared by many public sector organisations: using data more effectively to improve services and prevent harm before it occurs. Former project leaders interviewed by WIRED argued that combining information from different public bodies could provide frontline professionals with a richer understanding of vulnerability than any single agency could achieve alone. However, the investigation suggests that the practical reality proved far more challenging.  

Accuracy and Transparency  

One of the most significant findings reported by WIRED is that at least two of the predictive models were eventually withdrawn because staff no longer trusted their results. Bristol City Council commissioned independent evaluations of the programme, and council practitioners reportedly questioned whether some of the safeguarding models were accurately identifying the children they were intended to protect. According to the investigation, staff expressed concern that some vulnerable children were no longer appearing within the highest-risk groups, while other individuals received unexpectedly high risk scores. Internal reviews ultimately concluded that the models lacked sufficient reliability to support operational decision-making, leading to their withdrawal. 

The investigation also highlights wider concerns surrounding transparency and governance. Independent reviewers reportedly found that documentation explaining how some of the predictive models had been developed was incomplete or unavailable. In some, reviewers were unable to fully assess the systems because source code, technical documentation and records describing how models had been trained or validated could not be located. 

Predictive AI systems depend heavily on the information used to train them.
If historical datasets contain gaps, inaccuracies or existing biases, those weaknesses may also be reflected in the predictions generated by the models. 
Researchers interviewed by WIRED note that some variables used within the aforementioned systems could act as indirect indicators of poverty or wider social disadvantage. Factors such as housing support, school attendance or eligibility for free school meals may correlate with vulnerability, but they may also reflect structural inequalities rather than future criminal behaviour. This raises concerns that predictive systems could unintentionally reinforce existing patterns of disadvantage rather than objectively identifying risk. 

The investigation also reports that one external audit found many of the predictive models demonstrated relatively weak performance. According to WIRED, an independent AI auditing company concluded that several models produced a high number of false positives, meaning many individuals identified as high risk would never actually experience the outcomes the models were predicting. False positives are particularly significant within policing and safeguarding because they have the potential to influence professional judgement and the allocation of limited public resources. Even where algorithmic scores do not determine decisions directly, they may shape how practitioners prioritise cases or assess individuals. 

The investigation further explores issues surrounding public awareness and consent. Many residents reportedly had little knowledge that their information had been brought together within the Think Family Database. One campaigner only discovered that his information had been included within a police offender management system after pursuing legal action to obtain details of the records held about him.  

Interestingly, former project leaders interviewed by WIRED argued that frontline professionals often relied more heavily on their own experience than on the algorithmic predictions themselves. Social workers and other practitioners reportedly viewed the models as one source of information rather than definitive guidance.
While this may have reduced the practical impact of inaccurate predictions, it also raises legitimate questions about the value of developing complex predictive systems if experienced professionals ultimately lacked confidence in the results. 

Future Use 

The investigation also highlights Bristol City Council’s role in reviewing the future of the programme. The council has since stated that the current administration no longer uses predictive analytics for policing or safeguarding decisions, with the exception of analytical work aimed at identifying young people who may become Not in Education, Employment or Training (NEET) after leaving school. The council also maintained that predictive tools never replaced professional judgement and were intended only to support practitioners rather than automate decisions. 

Automated Racism 

In the next episode of the Guardians of Data Podcast (published on Wednesday we discuss predictive policing and its impact in detail. Our guest is Ilyas Nagdee who is the Racial Justice Director at Amnesty International UK and one of the authors of Amnesty’s report into predictive policing (“Automated Racism). Ilyas helps us unpack what the predictive policing tools actually are, how they’re being used, whether they work, and what the risks are, especially when combined with other technologies like facial recognition.  

Listen to a clip here. 

Follow the podcast to be the first to know when this episode is published on Wednesday.   

Also available on Apple Podcasts, Spotify, and all major podcast platforms.

ICO Publishes Edtech Report

Educational technology is now embedded in everyday school life, from classroom apps and learning platforms to safeguarding systems, behaviour tools and management information systems. While these technologies can support teaching, administration and pupil wellbeing, they also involve the collection and use of large amounts of children’s personal data, often in circumstances where pupils and parents have limited ability to opt out. From a data protection perspective schools and edtech providers must be clear about who is responsible for processing the data, why it is being used, how long it is kept, and whether the requirements of UK GDPR are being met in practice. 

Last week, the Information Commissioner’s Office (ICO) published ‘Edtech examined’, a report outlining how they “have worked directly with edtech providers to review and improve data protection practices within the sector.” The report details the findings from a programme of consensual audits carried out by the ICO during 2024 and 2025 with 28 edtech providers, whose products are widely used across primary and secondary schools in the UK. The audits examined a range of products including management information systems, safeguarding tools, behaviour management platforms, learning management systems, classroom apps, and data integration services.  

The ICO found positive practices, particularly around information security. 
However, they also identified and addressed compliance gaps across the sector. Common issues included providers not correctly identifying whether they were acting as data processors or controllers — particularly where children’s data was used for product development or analytics.   

The ICO also found: 

  • insufficiently detailed contracts with schools 
  • incomplete data flow mapping 
  • weak application of data minimisation and storage limitation principles  
  • outdated or inaccessible privacy information, and  
  • gaps in Data Protection Impact Assessments.  

The ICO says that, through the audits, it has successfully driven improvements across the sector, with providers accepting and putting in place 98% of the 596 recommendations that were made. It is now engaging with the Department for Education and devolved authorities on their work with schools to help improve how children’s personal information is handled in educational settings. It is also discussing introducing a new edtech code which could contribute to ensuring children’s data is better protected across the tools and platforms schools use widely. 

The Government’s Plans for Children’s Data 

Recent initiatives from the UK Government, such as the Schools White Paper and the Children’s Wellbeing and Schools Act 2026, have major implications for children’s privacy; from age verification to plans for a “Data Spine” to link information across the public sector.   

In Episode 8 of the Guardians of Data podcast, we analyse the Government’s plans for our children’s data, discuss children’s privacy in the internet age and the role Big Tech is playing in the collection storage and analysis of all our data.  We ask if the government is simply trying to do a better job of protecting children or if it is quietly building a surveillance system which will impact all of us. Listen here. 

See also our workshop: Working with Children’s Data.

New Podcast: Learning from a Journalist’s Use of FOI  

The Freedom of Information Act 2000 (FOI) is an essential tool for the journalist seeking to  hold public institutions to account. But for those handling FOI requests from journalists, the challenge is to balance minimising the resource burden on the organisation with maintaining opennesss and transparency. This requires a good understanding of journalists’ motivation, tactics and pressures. 

In the latest episode of the Guardians of Data podcast we are joined by Martin Rosenbaum. Martin spent 16 years at the BBC as the organisation’s leading specialist in using FOI for journalism. Over that time, he broke major stories, trained reporters, and took cases all the way to tribunal hearings. His investigations have covered everything from private conversations between Tony Blair and Bill Clinton, to the policing of Greenham Common protests, to the flaws in the honours system. 

Martin is also the author of Freedom of Information: A Practical Guidebook– a comprehensive, hands-on guide that explains the law, the process, and the tactics for using FOI effectively. 

In this podcast episode, we talk about: 

  • How journalists use FOI to uncover the truth and inform the public 
  • The tactics that make the difference between a successful request and a dead end 
  • How FOI has evolved since its introduction  
  • And what information professionals can learn from the media’s use of this powerful tool 

Whether you work in information governance, public service, or the media, or you simply believe in transparency and accountability, this conversation will give you practical insights into how FOI really works and why it still matters today. 

Listen on your preferred platform via our podcast page, or download the episode directly.

This podcast is sponsored by Phaselaw – a purpose-built solution for document disclosures, like subject access requests and FOI requests. Instead of redacting PDFs one by one, or forcing litigation software to do a job it wasn’t designed for, with Phaselaw you get collection, review, and redaction in one workflow. Teams across the World are using it to cut response times from weeks to days. 

For Guardians of Data listeners, Phaselaw is offering a two-month free trial; run it on live requests, see what it does to your backlog, decide from there. No card, no commitment. 

Head to https://www.phase.law/guardians to claim your free trial.  

Previous episodes of the Guardians of Data podcast have featured Tahir Latif talking about responsible AI deployment, Jen Persson, a privacy campaigner, explaining the privacy implications of the Government’s new plans for children’s data, Naomi Mathews and Ibrahim Hasan explaining the law on filming people in public for social media and Olu Odeniyi analysing recent cyber breaches and discussing the lessons learnt.

New Podcast: Building Trustworthy and Responsible AI Systems

“Information governance professionals are the bedrock for deploying good governance of AI. We need to be there at the start of the actual thinking process.” 

Tahir Latif, Global Practice Lead for Data Privacy & Responsible AI at Cognizant 

The last two years has seen a massive increase in AI deployment. Previously the domain of Science Fiction, AI is now everywhere – in our workplaces, our personal lives, and in the systems that shape society. From healthcare to security and law enforcement. But alongside the opportunities, there are some big risks: including lack of accuracy and transparency as well as bias and discrimination. 

In this episode, we dive into one of the biggest questions of our time: How do we build trustworthy and responsible AI systems? 

To help us answer this question, we are joined by someone who is right at the heart of the conversation. Tahir Latif is a distinguished expert on building responsible and transparent AI systems. He was formerly the Global Practice Lead for Data Privacy & Responsible AI at one of the largest global professional services companies. Tahir has led complex privacy and AI programmes across multiple industry sectors both in the UK and globally. He is also the Chief AI and Governance Officer and board member at the Ethical AI Alliance, a not for profit body which promotes ethical standards in AI development. Tahir is the co-author of Data Privacy – A Practical Handbook on Governance and Operation.

In this conversation, we explore how to cut through the complexity of ethical AI, what the future holds, and most importantly, what practical steps IG professionals can take to succeed in this new landscape. 

Listen on your preferred platform via our podcast page, or download the episode directly.

This podcast is sponsored by Phaselaw – a purpose-built solution for document disclosures, like subject access requests and FOI requests. Instead of redacting PDFs one by one, or forcing litigation software to do a job it wasn’t designed for, with Phaselaw you get collection, review, and redaction in one workflow. Teams across the World are using it to cut response times from weeks to days. 

For Guardians of Data listeners, Phaselaw is offering a two-month free trial; run it on live requests, see what it does to your backlog, decide from there. No card, no commitment. 

Head to https://www.phase.law/guardians to claim your free trial.  

Previous episodes of the Guardians of Data podcast have featured  Naomi Mathews and Ibrahim Hasan explaining the law on filming people in public for social media, Maurice Frenkel looking back at 20 years of the Freedom of Information Act, Olu Odeniyi analysing recent cyber breaches and discussing the lessons to learn and Raz Edwards talking about how to succeed as an IG leader. 

Data Protection Complaints Procedure Deadline Approaching

A new section 164A has been inserted into the Data Protection Act 2018 (DPA) by the Data (Use and Access) Act 2025 (DUA Act). 

From 19th June 2026, Data Controllers will be required to have a complaints procedure to handle data protection complaints. They must also: 

  • acknowledge receipt of complaints within 30 days of receiving them; 
  • without undue delay, take appropriate steps to respond to complaints, including making appropriate enquiries, and keep Data Subjects informed; and 
  • without undue delay, tell Data Subjects the outcome of their complaints 

Under the DPA, individuals are entitled to raise complaints where they believe there has been a breach of the UK GDPR e.g. not responding to a subject access request. This extends to any alleged non-compliance involving an individual’s personal data. The key requirement is that the issue must relate to the individual bringing the complaint. In other words, there needs to be a direct connection between the person and the alleged infringement. For example, if a complaint concerns deficiencies in a privacy notice, the individual will need to demonstrate how those shortcomings affect their own personal data, rather than simply pointing to general non-compliance. 

There is no prescribed format for handling complaints and organisations have discretion in designing their processes. The essential requirement is that individuals must have a clear way to submit a complaint, and that complaints are acknowledged and responded to. Data Controllers may wish to build on existing complaint-handling frameworks that are already in place and functioning effectively; for example your FOI complaints procedure. 

Notably, the legislation does not impose strict deadlines for issuing a final response. As long as responses are provided within a reasonable timeframe and individuals are kept informed of progress, there is no obligation to conclude an investigation within a fixed period. The ICO recently published its guidance explaining the new requirements. Data protection expert, and guest on the first Guardians of Data podcast, Jon Baines writes on his personal blog that in declining to suggest how long controllers should normally take to respond to data subject complaints, the ICO has missed an opportunity to provide regulatory clarity.  

If you are looking to implement the changes made by the DUA Act to the UK data protection regime, consider our very popular half day workshop.  

The newly updated UK GDPR Handbook (2nd edition) includes all amendments introduced by the DUA Act, with colour-coded changes for easy navigation and links to relevant recitals, ICO guidance, and caselaw that help make sense of the reforms in context. We have included relevant provisions of the amended DPA 2018 to support a deeper understanding of how the laws interact.

The Right to Erasure and Unfounded Malicious Allegations

The Victims and Prisoners Act 2024 (Commencement No. 10) and Data (Use and Access) Act 2025 (Commencement No. 8) Regulations 2026 brings into force an important change to Article 17 of the UK GDPR (the right to erasure).    

In 2023, Stella Creasy MP was subjected to a social services investigation after a man complained to Leicestershire Police that the MP’s children should be taken into care due to her “extreme views”. The Labour MP told Today on BBC Radio 4 that the complaint was made because the man disagreed with her campaign against misogyny. 

Waltham Forest Council launched an investigation, as it was legally required to do, following a referral from Leicestershire Police. But despite Ms Creasy being cleared, the council said it was legally prevented from removing the man’s complaint from its records. 

The MP then tabled an amendment to the Victims and Prisoners Bill which was going through Parliament. This was enacted as section 31 of the Victims and Prisoners Act 2024.  Section 31 inserts a new Article 17(1)(g) into the UK GDPR. It extends the grounds upon which a data subject has a right to erasure, to cases of unfounded malicious allegations where: 
 
“the personal data have been processed as a result of an allegation about the data subject- 

(i) which was made by a person who is a malicious person in relation to the data subject (whether they became such a person before or after the allegation was made),

(ii) which has been investigated by the controller, and 

(iii) in relation to which the controller has decided that no further action is to be taken” 
 
New Article 17(4) of the UK GDPR defines a “malicious person” as one who has been convicted of a specified offence or who is subject to a stalking protection order. 

At the same time, the 2026 order also commenced paragraph 32 of Schedule 11 of the Data (Use and Access) Act 2025, which extends the same provisions to Scotland and Northern Ireland. 

Listen to the Guardians of Data Podcast for the latest news and views on data protection, cyber security, AI and freedom of information.   

This and other data protection developments will be discussed in detail on our forthcoming  GDPR Update workshop. 

Iain Harrison

Act Now Training is deeply saddened to report the passing of our colleague and dear friend, Iain Harrison

Over a career spanning more than 20 years, Iain provided training and consultancy on information law related issues to a wide range of public, private, and voluntary sector organisations. Iain’s final job was Senior Information Assurance Officer at Leicester University. He also worked for Wolverhampton City Council, Wright Hassle LLP, Leicester City Council and Birmingham City Council.  

Alongside his day job, Iain was a Senior Associate at Act Now Training where he used his vast experience to deliver training on data protection and freedom information.  His courses were defined by his depth of knowledge, sound judgement, and an unwavering commitment to supporting others. Colleagues and clients alike valued Iain for his clarity, calm guidance and understated humour. Delegates always commented about his rare ability to make complex legal frameworks accessible and manageable. He always approached his work with patience, integrity and a genuine desire to help.  

Iain’s contribution to the field of information law, and to the many people and organisations he supported throughout his career, leaves a lasting legacy. He will be greatly missed by colleagues, clients and friends. 

Ibrahim Hasan, Director of Act Now Training, said: 

“I knew Iain for over 20 years, since his days at  Coventry City Council. Behind the quiet, unassuming person was a true expert, always willing to listen and help. Every interaction I had with him was filled with kindness and good humour. My thoughts and prayers are with his loved ones.”