ICO (UK) · 7 August 2026
ACRO Criminal Records Office
FineNo fineViolation found
- Regulator
- ICO (UK)
- Decided
- 7 August 2026
- Country
- United Kingdom
- Sector
- Not given
- Regulator’s reference
- ACRO Criminal Records Office
- Fino case number
- 2026/GB/009
What happened
The DPA reprimanded a criminal records office for failing to implement appropriate security measures, including effective patch management and security monitoring, resulting in prolonged unauthorised access to systems containing sensitive personal data.
Summary from GDPRhub (noyb), written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
The source doesn’t list which GDPR articles were involved.
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2026/GB/009.