4 min read

London's police made 700,000 data requests last year. Nobody had to ask a judge- 237

London's police made 700,000 data requests last year. Nobody had to ask a judge- 237

May 20, 2026

The Metropolitan Police made more than 700,000 requests to technology companies for communications data in 2025 alone, according to figures The Register obtained under the UK's Freedom of Information Act — a volume large enough to include monitoring takeaway delivery platforms, a nearly 500 percent surge in requests targeting a single low-cost mobile network used disproportionately by migrants, and disputed claims of data extraction from encrypted services that both Proton and Signal say never happened. What makes the scale possible is not a secret program but a mundane bureaucratic fact: communications metadata, unlike message content, can be authorized internally by a senior officer, with no judge required.

The mechanism behind that autonomy is worth stating plainly, because it is the structural feature that makes everything else in this story possible. UCL law lecturer Bernard Keenan explains that communications data — the metadata surrounding a message rather than its content — is treated in UK law as a less severe intrusion than intercepting message content itself, and while police still need formal authorization to obtain it, that authorization is delegated to designated senior officers rather than requiring judicial sign-off. The Met's own data collection reflects exactly what that low bar of internal self-authorization was likely to eventually produce at scale: 700,000-plus requests in a single year, reaching well beyond traditional telecoms into takeaway delivery apps and ride-hailing services, with Uber, Bolt, JustEat, Deliveroo, and Domino's collectively receiving 768 requests in 2025.

The claims involving encrypted platforms carry particular weight because both companies named dispute the Met's own figures. The force says it has obtained communications data from Proton Mail users 139 times since 2024 — data Proton doesn't dispute exists but insists never passed directly to foreign law enforcement, since all requests must instead route through Swiss authorities under Proton's stated legal framework, with non-compliant requests refused as "established practice." More strikingly, the Met also claims to have acquired data from ProtonVPN, a service Proton says technically cannot produce such data because it does not log user activity at all — meaning, in Proton's telling, there was simply nothing to hand over regardless of what was requested. Signal's dispute is similarly pointed: the Met's records suggest the platform provided data once since 2024, which Signal directly contradicts, stating it has not shared any user data in response to a UK legal request during that period. When The Register asked the Met to reconcile these contradictions, the force declined to discuss the specifics of how it obtained the data at all.

The oversight gap surrounding sensitive professionals is where the story's press-freedom implications sharpen. The most recent Investigatory Powers Commissioner's Office annual report found that communications-data authorizations across all UK law enforcement agencies affected lawyers 219 times and journalists 157 times in a single year, alongside 106 separate warrant applications specifically aimed at identifying journalists' sources — warrants that, unlike ordinary metadata requests, can also capture communications content itself. There is no legal requirement to inform a journalist or lawyer they've been targeted this way, and while standard law enforcement bodies must seek judicial approval for these more invasive source-identification warrants, intelligence and security services are exempt from that requirement entirely. Tim Dawson of the National Union of Journalists points to a concrete precedent for why this matters: journalists Barry McCaffrey and Trevor Birney were unlawfully surveilled by the Met and Police Service Northern Ireland while investigating a documentary on paramilitary killings during the Troubles, in an attempt to identify their source — a case a court later ruled had been conducted unlawfully, after the journalists pursued judicial review.

The most demographically pointed finding in the FOI data concerns LycaMobile, a low-cost network known for cheap international calling and popular among foreign nationals. Met requests to LycaMobile rose from 15,702 in 2024 to 93,527 in 2025 — a nearly 500 percent increase entirely absent across comparable providers like Vodafone, O2, Three, and Lebara. Migrants' Rights Network chief executive Fizza Qureshi frames the surge as evidence that "the digital border is expanding through policing," specifically targeting migrants and racialized communities for a level of surveillance she argues would not be tolerated against the broader population. The Met denies any immigration-specific motivation, suggesting the increase might simply reflect LycaMobile's growing popularity — an explanation that would require the network's user base to have grown from an estimated 2 million to 10 million people in a single year to remain mathematically consistent with the request volume, a jump LycaMobile itself has not confirmed and did not respond to comment on. The timing sits alongside newly enacted Home Office powers under the Border Security, Asylum, and Immigration Act 2025, which now permit immigration officers to search undocumented migrants for hidden SIM cards as part of broader phone-seizure authority — powers introduced despite a 2022 High Court ruling that a similar prior seizure and retention program affecting more than 2,000 migrants' phones had been unlawful.