Refine By
Clear all filter
About 91978 results for "*"
NEWS
The Information Commissioner’s Office (ICO) has published its updated encryption guidance following a public consultation held between May and June 2025, which received 15 responses from stakeholders including technology providers, professionals, and members of the public. The guidance, currently under review due to the enactment of the Data (Use and Access) Act on 19 June 2025, clarifies how UK data protection law, particularly the UK GDPR, applies to encryption as a technical measure for securing personal data. Respondents generally found the draft clear and valued practical case examples, prompting the ICO to reinstate older scenarios, add new ones, and link to archived enforcement notices. Specific feedback on cloud computing led the ICO to defer detailed examples to future updates of its cloud computing guidance, while references to privacy-enhancing technologies were expanded. Requests for more detail on encryption tools and standards resulted in broader references to commonly used software, though discussions on password managers and authentication services were deemed more suitable for other guidance.
NEWS
The Information Commissioner’s Office (ICO) has issued an enforcement notice and a warning to the Home Office for failing to sufficiently assess the data protection risks arising from the GPS electronic monitoring of migrants arriving in the UK via unauthorised means. The Home Office had launched a pilot scheme, which placed ankle tags that tracked GPS location on 600 migrants who came to the UK and were on immigration bail. The ICO found that the pilot scheme did not provide migrants with clear information on what data was being collected and why, had failed to sufficiently assess the privacy risks from the continuous collection of people’s location information, and failed to assess the possible impact on people that may have been vulnerable due to their immigration status. The enforcement notice orders the Home Office to update its internal policies, guidance on access, and privacy information in relation to the data retained from the pilot scheme. A warning was also issued to the Home Office stating that any future processing on the same basis will be in breach of data protection law and may lead to enforcement action.
NEWS
The Information Commissioner’s Office has fined genetic testing company 23andMe £2.31m for failing to implement adequate security measures to safeguard UK users’ personal data during a 2023 cyber attack. A joint investigation with the Office of the Privacy Commissioner of Canada found serious failings in authentication, monitoring, and breach response. 23andMe now has until 16 July 2025 to pay the penalty or appeal.
NEWS
The Information Commissioner’s Office (ICO) has ordered American Express Services Ltd (Amex) to pay a £90,000 fine after sending over four million unsolicited marketing emails between 1 June 2018 and 21 May 2019. An investigation commenced following complaints from Amex customers that had opted out of marketing emails but were still being sent them. Amex argued that the emails were servicing emails, as opposed to marketing, but the ICO did not agree as they contained information on Amex reward schemes and encouraged customers to download the Amex app.
NEWS
The Information Commissioner’s Office (ICO) has fined Capita plc £8m and Capita Pension Solutions Limited £6m, totalling £14m, for failing to ensure the security of personal data following a cyber attack in March 2023. The breach resulted in hackers stealing information belonging to approximately 6.6 million individuals, including pension records, staff data, and sensitive financial and criminal information. The ICO found that Capita failed to ensure the secure processing of personal data, leaving its systems at risk, and had not implemented adequate technical and organisational measures to effectively prevent or respond to the attack.
NEWS
The Information Commissioner’s Office (ICO) has issued a formal reprimand to, and fined the Central Young Men’s Christian Association (YMCA) £7,500 for breaches of Articles 5(1)(f) and 32(1) and (2) of the United Kingdom General Data Protection Regulation, Retained Regulation (EU) 2016/679 (UK GDPR). The Central YMCA sent emails using ‘cc’ and not ‘bcc’ to individuals participating in a programme for people living with HIV consequently revealing recipients’ email addresses and making 166 individuals identifiable or potentially identifiable. As the email was an invite to an event for the programme, it could be inferred that those individuals were likely to be living with HIV and as such the disclosed personal data included health data, which is special category data. The ICO also found that the Central YMCA did not have sufficient written information security policies or procedures to prevent this breach.
NEWS
The Information Commissioner's Office (ICO) has fined KRA Consultancy Ltd £300,000 and issued an enforcement notice after finding that the company sent more than 5.5 million unlawful marketing text messages between April 2022 and May 2025. The ICO found that the Manchester-based company sent unsolicited texts promoting debt services to people whose loan applications had been declined without verifying whether they had consented to receive marketing communications, resulting in more than 60,000 complaints to the ICO and Mobile UK’s 7726 spam reporting service. The ICO also found that the company sent false bailiff messages designed to prompt recipients to engage with its services and uncovered evidence that it had sought to make its mass text campaigns difficult to trace. The ICO executed search warrants at the company's offices and at the home of director Khuram Rezvan Ahmad and said that KRA continued the unlawful marketing activity following the searches, leading to further complaints. The ICO further found that the company had not verified the accuracy of the data used in the campaign and was not registered with the Financial Conduct Authority despite directing consumers towards debt solutions. The enforcement notice requires KRA to stop sending marketing messages without consent within 30 days.
NEWS
The Information Commissioner's Office (ICO) has fined LastPass UK Ltd £1.2m following a 2022 data breach that compromised personal information of up to 1.6 million UK users. The ICO found LastPass failed to implement sufficiently robust technical and security measures after hackers gained unauthorised access through two connected incidents in August 2022, accessing customer names, emails, phone numbers and stored website URLs. The breach occurred when hackers first compromised a corporate laptop then targeted a senior employee's personal device to obtain decryption keys for the backup database.
NEWS
The Information Commissioner's Office (ICO) has fined Advanced Computer Software Group Ltd £3.07m following a 2022 ransomware attack that compromised personal data of 79,404 individuals, including National Health Service patients. The breach occurred due to inadequate security measures at Advanced's healthcare subsidiary, specifically incomplete multi-factor authentication coverage. Advanced agreed to a voluntary settlement, reduced from an initial £6.09m fine, after demonstrating cooperation with authorities including the National Cyber Security Centre and National Crime Agency.
NEWS
The Information Commissioner’s Office (ICO) has fined Police Scotland £66,000 and issued it with a reprimand after finding serious failures in its handling of sensitive personal information. It concluded that the force failed to apply basic safeguards when extracting and disclosing highly sensitive data. The ICO found that Police Scotland extracted the entire contents of a person’s mobile phone after they reported an alleged crime, without putting in place adequate safeguards to prevent access to irrelevant material. The download ran to 39,233 pages, including more than 10,000 pages of images and included private and special category data wholly unrelated to the investigation. The ICO concluded that the extraction was not ‘strictly necessary’ for law enforcement purposes and was excessive and unfair, in breach of sections 35 and 37 of the Data Protection Act 2018 (DPA 2018).
NEWS
The Information Commissioner’s Office (ICO) has fined Reddit £14.47m after finding it used children’s personal information unlawfully due to age assurance failures under UK data protection law. The ICO found Reddit failed to apply any robust age assurance mechanism or carry out a data protection impact assessment before January 2025, resulting in the unlawful processing of the personal information of children under 13 and exposing them to inappropriate and harmful content. Although Reddit introduced age verification and age declaration requirements in July 2025, the ICO highlighted that self‑declaration presents risks and confirmed it is keeping the platform’s processing of children’s personal information under review as part of its wider intervention to improve the safety of children’s data online. It emphasised that organisations must ensure they know the age of users, enforce minimum age requirements and apply appropriate and effective age assurance tools.
NEWS
The Information Commissioner’s Office (ICO) has fined South Staffordshire Plc and South Staffordshire Water Plc £963,900 following a cyberattack and data breach that resulted in the personal information of 633,887 customers and employees being extracted and published on the dark web. The cyberattack, which began with a phishing email traced back to September 2020 and largely took place between May and July 2022, went undetected for nearly two years and exposed failures in South Staffordshire’s approach to data security. The ICO notes that the company reached a voluntary settlement, admitting the infringement and agreeing to pay the reduced fine without appeal.