Anonymity Broken: The Met's Data Breach and Al-Fayed's Alleged Victims

Over the weekend, the Metropolitan Police Service issued an apology to the survivors of abuse by Harrods owner Mohamed Al-Fayed following a data breach.

Data Breach of Operation Cornpoppy

On the 11th of August, the MPS sent an email updating on the progress of “Operation Cornpoppy”, an investigation into the abuses of Mohamed Al-Fayed. The email was openly copied to a reported 140 individuals which included survivors and victims, and recipients could see the email addresses of other recipients. This comes shortly after two unrelated data breaches by the Met Police, where the Information Commissioner’s Office (ICO) called the MPS’s data protection ‘weak’ with ‘serious shortcomings’ in need of urgent addressing.

Operation Cornpoppy was launched by the Metropolitan Police in November 2024 to investigate whether the associates and staff of Al-Fayed helped facilitate and disguise his acts of sexual abuse and human trafficking. The force previously said that 154 victims had lodged reports against him, and it is thought that about 140 victims had signed up to the email update sent out in 5 different email groups.

A Pattern of Failure

The force faces serious challenge from the victims, their representatives, and others to improve their privacy protocols and investigate how such an invasive data breach occurred.

One survivor, Joanna Brittan, has waived her right to anonymity following the recent data breach and spoke to the BBC to describe a pattern of a ‘shocking’ lack of care by the Met Police. Brittan told the BBC her email address was leaked to 42 other victims and that she likewise had access to theirs. What Brittan considers most distressing is that they had not ‘learned their lesson’ from a similar breach of her private information given in her initial police report to an unauthorised third party in Australia. She emphasised that the recent leak was ‘more of the same, really, and deeply re-abusive,’ she told the BBC.

In a case where anonymity was often a precondition to their coming forward, the recent leak undermines victims’ trust in the officials handling their case, and their right to privacy over a highly distressing and personal subject.

The Legal Position

This latest breach follows a separate ICO reprimand issued on 5th August, in which the regulator found ‘serious and ongoing shortcomings’ in the Metropolitan Police’s data protection training after two unconnected incidents. The Met has referred itself to the ICO over the Cornpoppy breach, and the regulator has not yet issued findings on this specific incident. If the ICO finds that the Met is in breach, it could issue a hefty fine and in any event there could be a number of claims by victims for compensation for breach of their personal information.

As a data controller, the Met is bound by the security principle under Article 5(1)(f) UK GDPR, requiring ‘appropriate technical and organisational measures’ against unauthorised disclosure of personal data, the most basic form of which being using a blind carbon copy (BCC) when emailing a list of people who have not consented to being identified to one another. Separately from any regulatory penalty, those affected have their own right to compensation under Article 82 UK GDPR, via section 168 of the Data Protection Act 2018. Compensation under this provision is not limited to financial loss, and extends to distress, with the Court of Appeal recently confirming in Farley and others -v- Paymaster (1836) Limited (trading as Equiniti) that there is no minimum threshold of “seriousness” a claim must meet before that distress becomes compensable.

If You Have Been Affected

If you believe your details may have been exposed in this breach, you do not need to have already come forward publicly, or to have spoken to anyone else, to get confidential advice on your options.

If you would like to get in touch to discuss confidentially what this means for you, please send an email to enquiries@taylorhampton.co.uk and we will make arrangements. You can also contact our data protection team for a confidential consultation.

Disclaimer: This article is intended to provide general information only and should not be relied upon as legal advice. The law and procedural rules may change, and specific advice should always be obtained based on the facts of your individual case.

Search
Archive

For all enquiries please call Taylor Hampton on +44 20 7427 5970

Make An Enquiry