
The Post Office avoided a potential regulatory penalty of nearly £1.1 million after a 2024 data breach exposed the personal information of hundreds of postmasters involved in litigation against the organization. The Information Commissioner’s Office, the UK’s data protection regulator, issued a formal reprimand instead of a fine after determining the breach did not meet the threshold of “egregious” under its public sector enforcement approach.
The incident occurred between April 25 and June 19, 2024, when an unredacted version of a legal settlement document was made publicly accessible on the Post Office’s corporate website. The document related to ongoing litigation stemming from the Horizon IT scandal and included the names, home addresses, and postmaster status of 502 individuals.
The Horizon case is widely regarded as the most significant miscarriage of justice in modern British legal history. More than 900 sub-postmasters were wrongfully prosecuted for theft and false accounting due to errors in the Horizon IT system used by the Post Office. Many suffered imprisonment, financial ruin, and long-term reputational damage.
The investigation found that the Post Office failed to implement adequate technical and organizational safeguards to prevent the disclosure of sensitive information. The regulator determined that the organization lacked documented policies for publishing online content and did not have sufficient quality assurance processes in place. Staff training on recognizing and handling personal data was also deemed inadequate.
Although the ICO considered imposing a fine just under £1.1 million, it concluded that its public sector strategy favored alternatives to financial penalties. The regulator maintains that fines imposed on public bodies have limited deterrent effect and may further strain critical services. The Post Office is a government-owned limited company.
The ICO noted that the organization provided compensation and 24 months of identity protection services to affected individuals. It also worked with search engines to remove cached versions of the exposed document. In the wake of the breach, the Post Office created an emergency working group to strengthen internal controls and implemented a formal policy governing publication of content on its website.
The regulator highlighted key lessons for organizations handling sensitive information, urging clear multi-step approval processes for online publication, strong document classification protocols, centralized repositories with controlled access, and tailored training for staff responsible for managing and posting content.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543