ICO finalises updated encryption guidance following consultation responses
The Information Commissioner’s Office (ICO) has published its updated encryption guidance following a public consultation held between May and June 2025, which received 15 responses from stakeholders including technology providers, professionals, and members of the public. The guidance, currently under review due to the enactment of the Data (Use and Access) Act on 19 June 2025, clarifies how UK data protection law, particularly the UK GDPR, applies to encryption as a technical measure for securing personal data. Respondents generally found the draft clear and valued practical case examples, prompting the ICO to reinstate older scenarios, add new ones, and link to archived enforcement notices. Specific feedback on cloud computing led the ICO to defer detailed examples to future updates of its cloud computing guidance, while references to privacy-enhancing technologies were expanded. Requests for more detail on encryption tools and standards resulted in broader references to commonly used software, though discussions on password managers and authentication services were deemed more suitable for other guidance.