Close this search box.

Why is the Metropolitan Police being sued for a data breach, when it wasn’t hacked?

The Metropolitan Police data breach has led to a flurry of lawsuits, raising an important question: why is the Met being sued when it wasn’t directly hacked? Understanding the intricacies of this situation requires a closer look at data protection laws, the role of third-party suppliers, and the responsibilities of data controllers.

A brief overview of the Met data breach

A brief overview of the Met data breach

In August 2023, a data breach was discovered involving the Metropolitan Police Service (Met) in London. The breach didn’t result from a direct attack on the Met’s systems but through a ransomware attack on Digital ID, an IT services company and supplier to the Met. Digital ID, responsible for producing warrant cards and identification badges, had a wealth of sensitive data about Met officers and staff, which cybercriminals managed to access.

The breach exposed a wide range of personal information, including:

  • Names
  • Ranks
  • Photos
  • Vetting levels
  • Pay numbers
  • Warrant numbers
  • Pass numbers
  • Geolocation data

The compromised data potentially affected tens of thousands of personnel, leading to significant concerns about the safety and security of officers, especially those in undercover or sensitive roles.

Why the Metropolitan Police is being sued

Why the Metropolitan Police is being sued

Despite the breach occurring at a third-party supplier, the Metropolitan Police is facing lawsuits. Here’s why:

Data Controller Responsibility

Under the UK General Data Protection Regulation (GDPR), the Metropolitan Police is a ‘data controller’, as it owns and manages the personal data of its officers and staff. As a data controller, the Met is legally responsible for ensuring that personal data is processed securely, regardless of whether the processing is done internally or by a third-party supplier. If the Met failed to adequately vet Digital ID’s security measures or neglected to monitor its compliance with data protection standards, it could be found negligent.

Affected individuals have the right to seek compensation for damages resulting from data breaches. Claimants can argue that the Met violated GDPR by failing to protect their personal data and not ensuring the supplier complied with necessary security standards.


The Metropolitan Police is being sued for a data breach that occurred at a third-party supplier because it is ultimately responsible for the security of the personal data it controls. This situation underscores the importance of robust data protection practices and the need for organisations to diligently manage their relationships with third-party suppliers.

Are you eligible to join the Metropolitan Police data breach compensation claim?

Could you qualify for a NO-WIN, NO- FEE Metropolitan Police compensation claim. Find out instantly with our easy-to-use eligibility checker!

If you have a claim, register your interest and we’ll connect you with a UK law firm running a Metropolitan Police data breach group action. 

Stay informed about compensation
YOU could be entitled to!

Subscribe to our newsletter and get breaking news on the latest consumer injustices and group claims.

Leave a Reply

Your email address will not be published. Required fields are marked *

You may also like:

In January 2024, the High Court ruled that drivers could sue BMW for fitting some diesel vehicles with devices that tricked emissions tests. The illegal devices made it seem like BMW’s diesel cars were less-polluting than they actually were.
The Equal Pay Act protects employees from unfair discrimination in the workplace. The law states that both men and women should be paid equally where they are doing the same job (or one of equal value). This means companies can't treat you differently based on your gender when it comes to pay.
After a cyberattack in March 2023, pension holders across the UK had their data stolen. In the wake of this breach, law firms are rallying to help those affected. Their mission: to pursue justice and secure compensation for victims of the Capita data breach.