Bulk email data protection: why BCC is not a control

In short: Bulk email data protection falls within the security duty in section 40 of the Data Protection Act 2018, which the Information Commissioner applied to the Metropolitan Police in a reprimand and enforcement notice dated 27 July 2026. Telling staff to use BCC was not a sufficient measure, and unevidenced training infringed section 40 on its own.
An organisation sending one email to a group of people has to decide where the addresses go. An address typed into the To or CC field is visible to every recipient, so each of them can see the whole distribution list. An address typed into the BCC field is not. The Information Commissioner has held that an instruction to staff to use BCC does not by itself discharge the security duty, and issued the Commissioner of Police of the Metropolis with a reprimand and an enforcement notice dated 27 July 2026, announced on 5 August 2026.
Two incidents and the section 40 findings
The Information Commissioner made findings on two incidents, each under section 40, the sixth data protection principle. In February 2024 an officer served a witness summons and unredacted evidential documents on the defendant in an application for an interim stalking protection order under section 1 of the Stalking Protection Act 2019. The papers included the victim’s new address and telephone number, which she had changed because of the risk he posed, and the names and telephone numbers of three witnesses. He later contacted her on the new number. The officer in charge was away on a training course and delegated the preparation to officers without the specialist stalking protection order training, and the force’s Directorate of Legal Services had advised that third-party information required redaction.
On 29 November 2024 an officer emailed people affected by the investigation the force calls the Honeytrap matter, telling them the suspect’s bail date had moved, and typed the addresses into the To field. Each of the 18 recipients could see the others’ addresses. A recall attempt at 15:36 failed and a message asking recipients to delete the email went at 17:04. The force reported the breach to the Information Commissioner the same day.
Why an instruction to use BCC did not secure the email
BCC hides an address from the other recipients, and the sensitivity of the message and of the people receiving it is a separate question. At paragraphs 129 to 138 of the notice the Information Commissioner held that BCC was not a suitably secure method for these data subjects, particularly where special category data could be inferred from the context, and that individual emails or a more secure means of delivery should have been considered.
The force’s own materials told staff to use BCC on group emails to members of the public to avoid breaches, and gave no direction to weigh sensitivity. The Information Commissioner treated that blanket instruction as part of the failure. The force said that mail merge was not a simple user-friendly solution, which the Information Commissioner declined to accept as a reasonable explanation for handling sensitive communications. Send-delay functionality was available across the force, and no group policy applied it. The Information Commissioner’s Email and security guidance of 30 August 2023, flagged on the page as under review following the Data (Use and Access) Act, says that BCC is not enough on its own to properly protect people’s personal information, and that a sender must consider bulk email services, mail merge or secure data transfer where the email relates to special category information.
Special category data inferred from a list of addresses
The email body contained nothing sensitive. At paragraphs 104 to 105 the Information Commissioner concluded that the addresses identified recipients by name and that special category data could be inferred from the character of the investigation connecting them, applying the position that information which does not itself reveal a special category may still permit one to be inferred. The address list was therefore data about each recipient’s connection to a criminal investigation.
Training records infringed the security duty on their own
The Information Commissioner found the training failure an infringement in its own right, running from no later than 5 June 2023 and continuing at the date of the notice, with no technical failure in issue. The sender had last completed data protection training in November 2020, four years before he sent the email. His line manager had last completed it in December 2020 and took the current course only in March 2025. The force introduced its Managing Information package on 5 June 2023.
Completion since introduction stood at roughly 30 per cent of operational staff and 19 per cent of non-operational staff, and at 12 per cent and 9 per cent in the year before the incident. The force called those figures disappointing. It had told staff that completion rates would be monitored, and confirmed that no auditing took place. The sender’s four-year gap never came up at his appraisal, conducted by a manager who was himself non-compliant. The Information Commissioner found negligence rather than intent, and found both incidents foreseeable and preventable.
Law enforcement processing under Part 3 and general processing under Article 32
Part 3 of the Data Protection Act 2018 governs processing for the law enforcement purposes, defined in section 31 as the prevention, investigation, detection or prosecution of criminal offences and the execution of criminal penalties, where a competent authority does the processing. The Commissioner of Police of the Metropolis is a competent authority under section 30(1)(a) and paragraph 9 of Schedule 7. A UK data controller outside that regime owes the parallel duty under Article 32 UK GDPR, and the Information Commissioner enforces both, as the scope of ICO regulation sets out.
The Information Commissioner records enforcement under each regime separately. The Information Commissioner reprimanded the ACRO Criminal Records Office on 7 August 2026 for infringing Article 32(1), 32(1)(b) and 32(1)(d), and recorded that action against the central government sector and the Metropolitan Police action against criminal justice. The Information Commissioner applied both regimes in a single case against Police Scotland: on 11 March 2026 the Information Commissioner found Part 3 infringements on phone extraction and UK GDPR infringements on a later misconduct disclosure, and imposed a fine of £66,000 alongside a reprimand. An earlier reprimand for cyber security failings is set out on this site.
| Point of comparison | Law enforcement processing (Part 3 DPA 2018) | General processing (UK GDPR) |
|---|---|---|
| Security duty | Section 40, the sixth data protection principle: appropriate technical or organisational measures | Article 32 UK GDPR, security of processing |
| Who must comply | A competent authority processing for the law enforcement purposes (sections 30(1)(a) and 31, Schedule 7 paragraph 9) | A UK data controller or processor processing for any other purpose |
| Enforcement notice | Failure to comply with Chapter 2 of Part 3 is a first-type failure under section 149(2)(a) | The Information Commissioner issues an enforcement notice under section 149 |
| Reprimand | Schedule 13 paragraph 2(c), covering Parts 3 and 4 | ACRO Criminal Records Office, 7 August 2026, Article 32(1), 32(1)(b) and 32(1)(d) |
| Recent action on bulk email | Metropolitan Police, 27 July 2026, section 40, recorded against criminal justice | ACRO Criminal Records Office, 7 August 2026, recorded against central government |
| Challenge | Enforcement notice appealable to the First-tier Tribunal (General Regulatory Chamber) under section 162(1)(c) within 28 days of the date sent; a reprimand is open to judicial review only | The same appeal route under section 162 applies to an enforcement notice |
What the enforcement notice requires of the force
Under Annex 1 the force has three months to review its policies and procedures for sending emails to multiple recipients and to consider whether more secure methods would reduce the risk, and twelve months to improve Managing Information completion rates, to follow up with staff who have not completed that training or the stalking protection order training, and to log and audit compliance under a monitoring programme. Progress updates go to the Information Commissioner every three months. One proposed term came out after the force evidenced 88 per cent compliance on stalking protection order training at 1 May 2026.
The Information Commissioner issued the reprimand under Schedule 13 paragraph 2(c) and the enforcement notice under section 149(2)(a), and section 150(2) requires the Information Commissioner to consider damage or distress before serving one. The force has 28 days from the date the notice was sent to appeal to the First-tier Tribunal under section 162(1)(c). Joanne Stones, a Group Manager, signed both instruments under delegated authority, and the notice records that John Edwards’s resignation as Commissioner does not affect their validity, the office being a corporation sole.
Viewpoint
I read paragraphs 129 to 138 as the durable part of this decision. A rule that says use BCC on group emails tells a member of staff which field to type an address into, and the Information Commissioner assessed it against the sensitivity of the recipients and the subject matter, which is where the analysis under Article 32 would also start.
The Information Commissioner treated the unapplied send-delay function as relevant to whether the measures in place were appropriate, so a control a UK data controller has bought and left switched off is evidence against it. The Information Commissioner made the training finding with no technical failure in issue, on completion figures the force called disappointing and nobody audited. The guidance behind the analysis is under review following the Data (Use and Access) Act, so the written position on bulk email may change, and the statutory duty does not depend on it.
For advice on bulk email data protection, on security measures under section 40 DPA 2018 or Article 32 UK GDPR, or on an ICO investigation into a personal data breach, contact Rob Bratby at Bratby Law. Our investigations and enforcement support page covers the scope of an instruction of that kind.
