Refine By
Clear all filter
About 91978 results for "*"
NEWS
The Information Commissioner’s Office (ICO) has announced the appointment of seven non-executive members to the Information Commission Board. Established by the Data (Use and Access) Act 2025, the Information Commission will succeed the ICO as the UK’s independent data protection supervisory authority later in 2026. The appointees will serve initial three-year terms and assume their roles when the transition takes effect. The Department for Science, Innovation and Technology has also launched a recruitment campaign for the Chair of the Information Commission, with applications closing on 19 August 2026.
NEWS
The Information Commissioner’s Office (ICO) has announced that a former NHS 111 call centre advisor, Martin Swan has been found guilty and fined for illegally accessing the medical records of a child and his family. Swan accessed the personal records without consent or a legal reason to do so and proceeded to contact the child’s father in June 2016 and January 2017, threatening to report him for neglect. Swan pleaded guilty to five counts of unlawfully obtaining personal data in breach of section 55 of the Data Protection Act 1998 (DPA 1998) when he appeared at Uxbridge Magistrates’ Court on 15 February 2023. Swan received a fine of £630 with a victim surcharge and was ordered to pay court costs of £1,093.
NEWS
The Information Commissioner's Office (ICO) has announced that a former health adviser, Christopher O’Brien, has been found guilty of accessing patient records without a good reason. According to the ICO, O’Brien illegally accessed 14 patient records when he was working at the South Warwickshire NHS Foundation Trust, as he did not have a valid business reason or the knowledge of the Trust. O’Brien pleaded guilty of breaching section 170 of the Data Protection Act 2018 (DPA 2018) by unlawfully accessing personal data and has been ordered to pay £250 to 12 patients, totalling £3,000.
NEWS
The Information Commissioner's Office (ICO) has announced a monitoring programme to scrutinise how ten popular mobile games protect children's online privacy. The review will assess compliance with requirements on default privacy settings, geolocation controls and targeted advertising practices, alongside any other privacy issues identified during the review process. This initiative extends the ICO's Children's code strategy beyond social media and follows recent enforcement activity, including notices of intent to impose monetary penalties on MediaLab (Imgur) and Reddit, and engagement with Snap and Meta regarding geolocation data processing. The ICO has already secured improvements to children's privacy settings across ten platforms, including Twitch, Viber and Hoop, and has reviewed age assurance practices on 17 platforms, such as Discord, Pinterest and X.
NEWS
The Information Commissioner's Office (ICO) has outlined five key initiatives on 17 March 2025 aimed at balancing data protection with economic growth. The measures include creating a statutory Code of Practice on AI and automated decision-making, extending its regulatory sandbox for data-driven innovations, relaxing enforcement of consent rules for privacy-preserving advertising, expanding SME data protection training, and developing new guidance for international data transfers to support cross-border trade.
NEWS
The Information Commissioner’s Office (ICO) has announced that new legal requirements under the Data (Use and Access) Act 2025 (DUAA 2025) are now in force, requiring all organisations that handle personal data to provide a clear process for individuals to raise data protection complaints, acknowledge complaints within 30 days, investigate them appropriately, and communicate the outcome. The ICO stated that its focus is on supporting organisations to comply with the new requirements through guidance and practical examples covering common issues such as subject access requests, inaccurate personal data, and marketing concerns. Deputy Commissioner for Regulatory Policy at the ICO, Emily Keaney, said that effective complaints handling should become a routine part of good data protection practice, helping organisations resolve issues early, identify problems, and maintain customer trust. The ICO also noted that all remaining provisions of the DUAA 2025 are now in force following the completion of its 12-month commencement period and encouraged organisations to review and improve their complaints processes, highlighting that prompt and fair complaint handling can reduce the likelihood of issues escalating.
NEWS
The Information Commissioner’s Office (ICO) has announced the publication of a code of conduct developed by the Wales Accord on the Sharing of Personal Information (WASPI) which the ICO approved under Article 40 of the UK General Data Protection Regulation (UK GDPR). The code sets requirements for organisations sharing personal information in the delivery of public services in Wales, including health, education, social care and safeguarding. It requires organisations to use WASPI’s information sharing protocol template and sets out requirements for governance, quality assurance, accountability, regular reviews and ongoing monitoring. It is intended to help organisations share information lawfully and consistently while protecting individuals’ rights.
NEWS
The Information Commissioner's Office (ICO) has approved the Legal Services Operational Privacy Certification Scheme (LOCS) for legal service providers who process personal data. Certification schemes were introduced under the United Kingdom General Data Protection Regulation, Assimilated Regulation (EU) 2016/679 (UK GDPR) to ensure organisations were in compliance with data protection requirements and ensure confident use of these organisations' products, services and processes. The LOCS is applicable to both controllers and processors, which includes law firms, solicitors, barrister’s chambers, barristers, and other providers processing personal data regarding the legal services they provide. The scheme was approved on the 1 February 2024.
NEWS
The Information Commissioner's Office (ICO) has approved and published the first sector-owned code of conduct under the United Kingdom General Data Protection Regulation, Assimilated Regulation (EU) 2016/679 (UK GDPR), developed by the Association of British Investigators Limited for the private investigations sector. This UK GDPR Code of Conduct for Investigative and Litigation Support Services (the Code) addresses key data protection challenges faced by private investigators, including guidance on roles and responsibilities when acting as data controllers, joint controllers or processors, lawful bases for invisible processing such as covert surveillance, and examples of lawful tracing methods. The Code aims to ensure compliance with UK GDPR requirements while balancing investigative needs with privacy rights. Security Systems and Alarms Inspection Board has been appointed as the monitoring body, pending ICO approval, to independently assess and report on member compliance with the Code.
NEWS
The Information Commissioner’s Office (ICO) has clarified common misconceptions about how the Privacy and Electronic Communications Regulations (PECR) apply to storage and access technologies such as cookies, tracking pixels and device fingerprinting. It confirmed that PECR is not limited to personal data, that ‘strictly necessary’ must be judged from the user’s perspective, and that consent is required for non-exempt purposes. The ICO also noted that a draft impact assessment has been published and will be finalised following consultation.
NEWS
The Information Commissioner's Office (ICO) has announced the conclusion of its oversight of the Ministry of Defence's (MoD) internal investigation into a 2022 data breach affecting over 18,000 Afghan relocation applicants. The ICO confirmed the MoD's compliance with legal requirements by reporting the breach within the mandatory 72-hour timeframe after discovery in August 2023. Following review of the MoD's investigation and remedial actions, the ICO has determined that no further regulatory action is required, while maintaining the right to revisit this decision if new information emerges.
NEWS
The Information Commissioner’s Office (ICO) has confirmed that Information Commissioner, John Edwards, had resigned after submitting his resignation to the Department for Science, Innovation and Technology (DSIT), following an independent workplace investigation. The investigation concluded that there was a case to answer and found that Edwards’ behaviour fell below the standards expected of a public official. Edwards had voluntarily stepped back from his duties on 26 February 2026 to allow the investigation to take place, with responsibility for determining the next steps resting with DSIT. On 10 June 2026, the ICO introduced temporary governance arrangements under which Deputy Commissioner and Chief Executive, Paul Arnold, assumed the Information Commissioner’s non-delegable statutory responsibilities and was designated by DSIT as Temporary Acting Accounting Officer. The ICO said its board, chief executive and executive team had continued to lead the organisation throughout the investigation and would maintain these arrangements following Mr Edwards’ resignation to ensure continuity of leadership and regulatory work.