gdpr cybersecurity data protection compliance ico enforcement

ICO Finds ACRO Cybersecurity Failures: Unclear Responsibilities Breach UK GDPR

The UK Information Commissioner's Office has determined that the criminal records office (ACRO) failed to clearly assign responsibility for critical cybersecurity updates, resulting in UK GDPR infringements. A cautionary tale for SME data governance.

Published 13 August 2026 · Source: MLEX/ICO

What Happened

On 12 August 2026, the ICO published a determination that ACRO's lack of clear cybersecurity accountability contributed to GDPR breaches. The failure to assign specific responsibility for critical security updates and alerts exposed sensitive data and breached personal privacy rights.

This mirrors the ICO's escalated enforcement stance: the regulator fined Capita £14 million in 2025 for cybersecurity failures that exposed 6.6 million people, and is now actively pursuing organisations with inadequate security governance.

Why It Matters

For SME directors and Ltd company owners, ACRO's case underscores a simple risk: unclear internal ownership of cybersecurity can quickly become an ICO compliance failure. Under UK GDPR, you are responsible for demonstrating that data security is properly managed—not just technically, but organisationally. If your business has never defined who owns security decisions, incident response, and vulnerability management, you are exposed.

The ICO's enforcement focus is shifting toward organisational failures, not just technical lapses. Six in ten organisations now face investigations that start with a data incident but escalate to probe whether governance was in place to prevent it.

What to Do

Review who in your business owns cybersecurity and data protection accountability. Assign clear responsibility (often to your IT lead or office manager), document it, and ensure that person is trained on incident reporting and HMRC requirements under GDPR. If you process personal data—including employee records, customer contact details, or supplier information—this matters to you.

For business compliance consulting, speak to your accountant or external advisor about building this into your governance framework.