The short version
- The Metropolitan Police inadvertently revealed the email addresses of roughly 140 women who have reported sexual abuse allegations linked to the late Mohamed Al Fayed.
- Survivors and advocates criticize the incident as a repeated failure to protect privacy, noting that previous data breaches had already eroded confidence in the force's ability to handle sensitive information securely.
- The police have referred themselves to the Information Commissioner's Office and are reviewing their communication protocols while continuing the investigation into facilitators of the alleged abuse.
The Metropolitan Police has issued an apology after a routine update regarding the investigation into sexual abuse allegations involving the late Harrods owner Mohamed Al Fayed resulted in the unintended disclosure of personal data. The breach affected approximately 140 women who had opted to receive monthly progress reports from Operation Cornpoppy, the specific inquiry tasked with examining individuals who may have facilitated or enabled the offending behavior. Instead of using a blind carbon copy feature, which would have hidden recipient identities from one another, officers inadvertently included all email addresses in the visible distribution list.
Scotland Yard confirmed that the error occurred when an update was sent on August 11. The message contained details about recent investigative progress, including the fact that three additional suspects in their seventies and eighties had been interviewed under caution. This development brought the total number of individuals interviewed in connection with the case to seven. While the force stated that the issue was identified quickly and immediate corrective actions were taken, the exposure of contact information for survivors has drawn sharp criticism from those involved in the case.
The incident has raised significant concerns regarding the Metropolitan Police's capacity to safeguard sensitive survivor information. Joanna Brittan, a victim who waived her statutory right to anonymity, described the breach as deeply distressing and indicative of a pattern of negligence. She noted that her email address was visible to dozens of other survivors, and she gained access to their addresses in turn. Brittan emphasized that recipients were identifiable as participants in a highly sensitive criminal investigation, making the exposure particularly intrusive.
Brittan’s reaction is compounded by previous failures in data protection by the same force. She revealed that she had previously received compensation for an earlier breach where sensitive details from her initial police interview were mistakenly disclosed to two individuals in Australia. Despite assurances at that time that lessons had been learned and such errors would not recur, Brittan expressed shock that a similar lapse occurred again. She characterized the repeated failure as re-traumatizing for victims who are already navigating the complexities of reporting abuse.
Advocates for survivors have echoed these sentiments, highlighting a broader crisis of confidence in the police investigation. Dame Jasvinder Sanghera, an advocate for those alleging abuse by Al Fayed, reported receiving numerous contacts from survivors who felt violated by the incident. She criticized the police response as inadequate, noting that the apology arrived five hours after the breach and was perceived as insincere by many victims. The lack of trust in the investigation’s integrity remains a persistent challenge for law enforcement officials managing this high-profile case.
In response to the breach, the Metropolitan Police has referred itself to the Information Commissioner's Office, the UK’s regulatory body for data protection. The force stated that it is conducting a priority investigation into the incident and is reviewing its internal processes to prevent similar errors in the future. Officials indicated they are considering alternative methods for updating victims that would minimize the risk of human error while maintaining transparency about investigative progress.
The breach affects a subset of the 154 victims who have reported allegations connected to Al Fayed. The police emphasized that supporting survivors remains central to Operation Cornpoppy, despite this setback. They confirmed that everyone affected by the data leak was contacted directly on the day the incident occurred. The force also stated that it would continue to monitor the circumstances and impact of the breach, aiming to restore trust through improved safeguards and consistent communication.
This latest disclosure underscores the delicate balance law enforcement must maintain between transparency and privacy in high-stakes investigations. As the inquiry continues to examine potential facilitators of the alleged abuse, the Metropolitan Police faces pressure to demonstrate that it can protect the wellbeing and privacy of those who have come forward. The outcome of the Information Commissioner's Office review will likely influence future protocols for handling sensitive data in similar cases.
Sources behind this briefing
Go to the original reporting
- BBC News↗Met Police apologises for data breach involving alleged Al Fayed victims