- › The UK Information Commissioner's Office found the Metropolitan Police served a stalking suspect unredacted statements containing his victim's new address and phone number.
- › He contacted her on that number within days, and the ICO called the breach foreseeable and preventable.
- › The regulator's required fix was training completion and a quarterly review of email practice, not new technology.
- › Arizona runs an Address Confidentiality Program through the Secretary of State, which means Phoenix employers already hold substitute addresses for people whose safety depends on them.
- › Treat every field that reveals where a person can be found as a physical security control, and assess who can read it, export it, and send it.
Most Phoenix businesses have someone on the payroll whose home address is a safety matter. You will not know who. That is the point of the arrangement.
Arizona has run an Address Confidentiality Program out of the Secretary of State’s office since 2011, giving survivors of domestic violence, sexual offenses, and stalking a substitute address to use in place of their home, work, or school address (Arizona Secretary of State). State and local agencies are required to accept it. If you employ enough people in the Valley, some of them are enrolled, and the protection only holds if every organization holding their information handles it correctly.
Last week the UK’s data protection regulator published what happens when one does not.
What the Met Did
In January 2024 a Metropolitan Police superintendent authorized an interim Stalking Protection Order against a man arrested for harassment and malicious communications. The instruction to redact personal information was explicit. Officers served him the witness statements unredacted, including his victim’s new phone number, her new home address, and contact details for her friends and family.
She had moved. That was the entire strategy, and the police force running her protection order handed the new location to the person she moved away from.
Within days she reported that he had contacted her on the new number. He had already left the UK in breach of bail. He was arrested when he re-entered in July 2024, charged with stalking, and imprisoned after pleading guilty. The Information Commissioner’s Office issued an enforcement notice and a reprimand, finding the failures reflected wider weaknesses in policy and assurance. Its group manager, Jo Stones, called the incidents foreseeable and preventable (The Register).
The same investigation covered a second breach: an update sent to 18 people connected to Parliament, all in the To field instead of BCC. The officer who sent it had not completed data protection training in more than four years. Neither had that officer’s line manager.
The Business Case Is Not Abstract Here
Security spending usually gets justified against a probability. This category does not work that way, and it is worth being clear about the exposure before it lands on you.
An organization that discloses a protected address is carrying three costs at once. The regulatory one is real but survivable. The civil one is not bounded by a statutory cap, because the claim is negligence causing foreseeable physical harm, and the ICO has now written down that this class of failure is foreseeable. The third is the one that ends businesses: an employee was hurt, your records made it possible, and the story is legible to any customer in ten seconds.
Compare that to the cost of the controls, which we will get to. Every one of them is administrative. None require a purchase.
Why Technology Was Not the Remedy
Look at what the ICO actually ordered, because the remedy tells you where the failure was. The Met has twelve months to reach 100 percent data protection training completion, review email practices quarterly wherever multiple recipients are involved, explore more secure alternatives to email, and report progress monthly.
No platform. No encryption mandate. No maturity framework.
The control that failed was a person performing a step. The superintendent’s instruction to redact existed and was correct. Somebody did not do it, and no second person checked before the documents went out the door. That is an assurance gap, and assurance gaps do not get closed by procurement.
This is the same pattern we see in physical assessments constantly. The camera was installed, the policy was written, the door had a lock. Nobody verified that the control was operating, and a control nobody verifies is a control you are only assuming you have.
What to Assess This Quarter
Start with an assessment rather than a policy rewrite, because you cannot write a rule for a data flow you have not mapped. These five questions are the scope.
Which fields in your systems reveal where a person can be found
Home address is obvious. Emergency contact address, delivery address for equipment, the photo of a badge with a street sign behind it, a shipping label in a helpdesk ticket, the timestamped access log showing when someone leaves the building. Inventory them before you protect them.
Who can read those fields, and who can export them
Read access and export access are different risks with different answers. Most organizations have never separated them, so anyone who can view a record can also pull ten thousand of them into a spreadsheet. Restrict export separately and log it.
What happens when the address changes for safety reasons
Your human resources team needs a defined path for an employee who says their address is now confidential, and it has to reach payroll, benefits, IT asset shipping, the facilities badge system, and any third party you have already given the old record to. Arizona’s substitute address only works if your systems will accept it.
Who checks a redaction before something leaves
The Met case turns entirely on this. Any document going to an external party that was supposed to have information removed needs a second named person confirming it happened. Two minutes of somebody’s time, applied to the small number of documents where it matters.
Whether your training completion is real
The officer in the second breach was four years out of date, and so was their manager. Pull your own completion report today and look at the tail, not the average. The people who never complete training are rarely a random sample.
The Convergence Point
Physical security teams protect the building. Information security teams protect the data. The gap between them is where a person’s address sits, because it is a data field whose disclosure produces a physical outcome, and neither team has traditionally owned it.
Somebody has to. In our assessments we treat any record that locates a human being as a physical security asset, subject to the same access review, the same egress controls, and the same verification discipline as a key or a badge. It belongs in the same register.
Do not wait for the incident to assign the owner. Pull the list of who can export addresses out of your human resources and customer systems this week, and read it.
Want to know where your organization’s physical and information controls stop talking to each other? Take our free Human Attack Surface Score assessment, or contact us for a full risk assessment.
A leader defined by a 'bias for action,' Dusten specializes in physical security assessments that impact profitability. He leverages high-logic strategies to pinpoint high-ROI vulnerabilities, ensuring defense measures actually scale with the business.
View Author Page →