The data watchdog has ordered the Metropolitan Police to review its data protection policies after the address and phone number of a female stalking victim were sent to the defendant.

The Information Commissioner’s Office (ICO) said the Met’s policies were “weak” and had “serious shortcomings” after failings in two cases, including the Westminster honeytrap case.

In one case, a woman had to move house and change her phone number after a Metropolitan Police officer sent her details to a defendant in a stalking protection order (SPO) case. It also wrongly sent out the names and contact details of three witnesses to the defendant.

The defendant later contacted the victim on her new number and said he had received documents containing her new contact details from police.

In the other incident, involving the alleged “honeytrap” of former Conservative MP William Wragg, the Met emailed all of the people affected to tell them of a change to the suspect’s bail date.

However, in doing so they did not blind-copy, or hide, the names of all those being contacted – so all recipients could see each other’s names and email addresses.

The ICO said this meant “highly sensitive information could potentially be inferred about the recipients, even though the body of the email did not explicitly contain that information”.

It added that 18 people linked to Parliament were affected.

Earlier this year, former Labour councillor Oliver Steadman pleaded not guilty to blackmailing Mr Wragg.

Steadman, 29, from Islington, has been charged with one count of blackmail and five allegations of improper use of a public electronic communications network, over allegations that he was behind a series of “flirty” messages and explicit images sent to a series of MPs and Westminster figures.

Mr Wragg, who was Hazel Grove MP and an influential backbencher, resigned the Tory whip in April 2024 and stood down from Parliament at the subsequent general election after he admitted giving out the phone numbers of politicians to someone he met on dating app Grindr.

Steadman is accused of being the person who was in contact with Mr Wragg.

The trial is due to begin in October 2027.

A statement by the ICO said the issues showed “wider weaknesses” in the Metropolitan Police’s policies.

The officer who sent the email to those involved in the honeytrap case had not done data protection training for more than four years, and their manager had not done their relevant training for a similar period before.

The Met took action, including telling those affected and issuing reminders to staff. However, the ICO believed more action is needed, and has issued a reprimand and enforcement notice.

The Metropolitan Police has been contacted for comment.

Jo Stones, the ICO’s group manager for civil and cyber investigations, said: “People entrust the police with some of their most sensitive personal information, often at moments when they are vulnerable or at risk. They have the right to expect that information will be handled securely.

“In these cases, the Metropolitan Police Service failed to put in place the safeguards needed to protect people’s personal information.

“One breach exposed a stalking victim’s new contact details to the person she needed protection from. Another revealed the identities of people connected to a highly sensitive investigation.

“These incidents were foreseeable and preventable. Our action makes clear that organisations, particularly those in the public sector handling sensitive law enforcement information, must have effective training, monitoring and assurance in place.

“Policies and reminders are not enough if they are not followed, checked and enforced.”