ICO updates data protection by design guidance following DUAA commencement
The Information Commissioner’s Office (ICO) has published its updated guidance on data protection by design and by default alongside the commencement of key Data (Use and Access) Act 2025 (DUAA 2025) provisions. The guidance clarifies that organisations must build data protection considerations into the design and operation of systems, services, products, and processes, ensuring that only the minimum necessary personal information is collected, used, stored, and accessed for each defined purpose. It explains the need for appropriate technical and organisational measures, including robust security controls, clear retention practices, strong default privacy settings, and regular assessment of risks through data protection impact assessments.