Key facts
- The Metropolitan Police apologized for a data breach that exposed the email addresses of over 140 women alleging sexual abuse by Mohamed Al Fayed.
- The breach occurred when an email update regarding Operation Cornpoppy was sent to victims, with recipients' email addresses visible to others.
- The force has referred the incident to the Information Commissioner's Office (ICO) and is reviewing its processes.
- Joanna Brittan, one of the affected women, described the incident as a further personal data breach.
- The ICO had previously issued the Metropolitan Police with a reprimand and enforcement notice for unrelated data protection failures.
The Metropolitan Police has apologized after inadvertently disclosing the email addresses of around 140 women who claim they were sexually abused by the late Harrods owner Mohamed Al Fayed. Scotland Yard confirmed to the BBC that it copied in all recipients of a monthly email update for victims instead of using blind copy, making their addresses visible to others.
The update, sent on August 11, concerned Operation Cornpoppy, the investigation into individuals who may have facilitated or enabled Al Fayed's alleged sexual offending. The force stated that the issue was identified quickly and immediate action was taken, with everyone affected contacted directly on the day of the incident. They are reviewing processes to prevent recurrence and have referred the matter to the Information Commissioner's Office (ICO).
Joanna Brittan, one of the affected women, described the incident as a further personal data breach, noting her email was disclosed to 42 other survivors, and she received their addresses. She expressed shock, stating she was promised such an incident would not happen again after a previous, more egregious breach. Dame Jasvinder Sanghera, an advocate for survivors, reported that victims feel violated and have a lack of confidence in the police investigation, calling the apology insufficient.
This incident follows recent enforcement action by the ICO against the Metropolitan Police for two unrelated data breaches, which highlighted serious and ongoing shortcomings in data protection training and handling of sensitive personal data.