
UK ICO Reprimands ACRO Criminal Records Office for GDPR Violations
Government_SectorData_BreachNon-US
The UK Information Commissioner’s Office (ICO) issued a reprimand to the ACRO Criminal Records Office (ACRO) for violating Articles 32(1), 32(1)(b), and 32(1)(d) of the UK GDPR. ACRO, a national police unit, provides services including Police Certificates, International Child Protection Certificates, and Subject Access Request processing. The breach involved failures in implementing appropriate technical and organizational measures to ensure data security. No specific date for the reprimand or breach was provided, nor were technical details or the number of affected individuals disclosed. The ICO’s action highlights compliance shortcomings in ACRO’s data protection practices.