
The UK Information Commissioner’s Office has imposed a penalty of £750,000 on the Police Service of Northern Ireland for exposing the sensitive personal information of its entire workforce in August last year.
In August 2023, PSNI stated that it suffered a significant data leak when a spreadsheet containing the personal data of police officers was released accidentally along with a Freedom of Information (FoI) request. This raised serious concerns about the safety and security of those whose personal data was compromised during the incident and their families.
The leaked data included current employees’ surnames and initials, ranks, departments, and locations. This sensitive information encompassed even the most delicate areas of the police service, including surveillance and intelligence.
The released data also included information about individuals currently on career breaks, potentially putting them at risk.
In a recent press release, the Information Commissioner’s Office said that its investigation into the data leak identified that “simple-to-implement procedures could have prevented the serious breach.”
“Mindful of the current financial position at PSNI and not wishing to divert public money from where it is needed, the Commissioner used his discretion to apply the public sector approach in this case. Had this not been applied, the fine would have been £5.6 million,” the information watchdog said.
In a statement shared with the media, John Edwards, UK Information Commissioner said, “I cannot think of a clearer example to prove how critical it is to keep personal information safe.
“It is impossible to imagine the fear and uncertainty this breach – which should never have happened – caused PSNI officers and staff. A lack of simple internal administration procedures resulted in the personal details of an entire workforce – many of whom had made great sacrifices to conceal their employment – being exposed.
“Whilst I am aware of the financial pressures facing PSNI, my role as Commissioner is to take action to protect people’s information rights and this includes issuing proportionate, dissuasive fines. I am satisfied, with the application of the public sector approach, this has been achieved in this case.
“Let this be a lesson learned for all organisations. Check, challenge and change your disclosure procedures to ensure you protect people’s personal information,” he added.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543