The UK's criminal records office, ACRO, has escaped a fine and received a regulatory reprimand after security failings potentially exposed highly sensitive data belonging to nearly 11,000 people.ACRO disclosed the "cybersecurity incident" in April 2023, and said at the time that it had no evidence to suggest that any data was compromised.However, it has now emerged that attackers maintained persistent access to ACRO's website and content management system for more than seven months, and staged sensitive data for possible exfiltration.
According to the Information Commissioner's Office (ICO), which reprimanded ACRO rather than imposing a financial penalty, the breach was uncovered in March 2023 only because ACRO was investigating a separate intrusion.
Busting ICO enforcement jargon
The ICO has a few enforcement tools in its belt when it comes to data protection offenders. Monetary penalties are pretty self-explanatory, but are reserved only for the very worst and most flagrant UK GDPR offenses. These can reach up to £17.5 million ($23.6 million), or 4 percent of the organization's total worldwide annual turnover, whichever is higher.Lesser powers include enforcement notices, which can be served to offenders and are essentially a list of mandatory corrective actions an offender must take to make the regulator leave it alone.And then the lesser of the three is a reprimand, which serves as a formal warning not to be naughty again. These are often used for public sector organizations to avoid draining public funds.








