Cabinet Office has been issued with a formal reprimand after a data breach during January’s island‑wide electoral canvass exposed the personal details of more than 3,200 people.
The breach occurred on January 6, when letters sent to every household ahead of the September elections were addressed to “The Occupier” but contained the names, dates of birth and jury‑eligibility status of the last people registered to vote at each address.
Some of the information was out of date, meaning personal details were disclosed to current occupants.
An investigation by the Information Commissioner found the change in approach was made after officials discovered 53% of households did not have a nominated head of household.
Cabinet Office decided to pre‑populate all forms and address all envelopes to “The Occupier”, despite a risk assessment scoring the likelihood of a breach at 5/5.
Data Breach
The updated Data Protection Impact Assessment contained inconsistencies and still described the original, lower‑risk method. The Data Protection Officer approved the DPIA unaware of the late‑stage changes.
Complaints began arriving at the Information Commissioner’s Office as letters were delivered. Cabinet Office attempted to halt the remaining mail but the forms were already en route. A breach was reported on January 7.
The Commissioner noted Cabinet Office cooperated fully, reported promptly and took advice on public communications. However, the investigation concluded the department proceeded with processing it knew would infringe data protection law.
Information Commissioner Dr Alexandra Delaney‑Bhattacharya said: “Cabinet Office holds some of the island’s most sensitive personal data. For people to have trust in government institutions – particularly for something as important as people’s right to vote, it is essential their information is respected and protected.”
She added she was pleased to see Cabinet Office commit to strengthening its data protection practices.
You can read the full reprimand here.


