Dyfed-Powys Police has notified the Information Commissioner's Office after a cyber incident identified on 14 September disrupted some of its non-emergency systems and took its online and email contact channels offline for a period.
The force confirmed the incident in a statement published on 25 September, 11 days after it was identified. It said an investigation into the circumstances had been under way since then with support from cyber-security specialists, and that its systems had been subject to precautionary measures while specialist teams worked to restore services safely. The investigation is being managed by Tarian, the regional organised crime unit for southern Wales, through its regional cyber-crime unit.
The force said it remained fully operational and that its response to emergency incidents had not been affected. The 999 and 101 telephone services continued throughout, while online and email contact, which had been unavailable, had since been restored.
At this stage the investigation had found no evidence that personal data relating to members of the public had been accessed or compromised, the force said. It was, however, continuing to investigate whether any information relating to its staff may have been accessed or compromised, and was taking steps to protect that information and would provide advice to colleagues if required. The statement did not say when the ICO was notified, how the attackers gained access or who was believed to be responsible.
Police forces process personal data under two separate regimes. Processing for law enforcement purposes falls under Part 3 of the Data Protection Act 2018, which requires a controller to notify the Commissioner of a personal data breach without undue delay and where feasible within 72 hours of becoming aware of it, under section 67.
Processing of staff records and other general purposes falls under the UK GDPR, with the equivalent 72-hour notification requirement under Article 33 and the obligation under Article 34 to inform individuals without undue delay where a breach is likely to result in a high risk to them.
The force said it understood the potential concern the incident may cause and wanted to reassure the public that it had taken and would continue to take all necessary steps to protect its information and maintain the security of its systems. It said further updates would be provided when it was in a position to do so.
The incident follows a series of data security failures involving UK police forces in recent years, including the Police Service of Northern Ireland's 2023 disclosure of the personal details of its entire workforce in response to a freedom of information request, for which the ICO imposed a £750,000 monetary penalty, and the 2023 breach of a third-party supplier that exposed the details of Greater Manchester Police officers.

