Refine By
Clear all filter
About 91978 results for "*"
NEWS
The Information Commissioner’s Office (ICO) has fined TikTok Information Technologies UK Limited and TikTok Inc (TikTok) £12.7m for breaching the UK's General Data Protection Regulation, Retained Regulation (EU) 2016/679 (UK GDPR), including the failure to use children’s personal data lawfully. The ICO estimates that in 2020 TikTok allowed up to 1.4m UK children under 13 to use its platform, despite its rules not allowing children that age to create an account, and did not follow UK data protection laws stipulate that if organisations use personal data when offering information society services to children under 13 they must have consent from their parents or carers. The ICO also found that although TikTok should have been aware of the underage children using its platform, it failed to carry out adequate checks to identify and remove them.
NEWS
The Information Commissioner’s Office (ICO) has fined two repair services companies a total of £120,000 for making unlawful marketing calls to individuals who have specifically opted out of receiving marketing communications via the Telephone Preference Service. A large proportion of the targeted individuals were elderly or those suffering with diseases such as dementia. WerepairUK Ltd was fined £80,000 for making such calls to 42,688 individuals, while Service Box Group Limited was fined £40,000 for making 5,361 calls in breach of regulation 21 of the Privacy and Electronic Communications (EC Directive) Regulations 2003, SI 2003/2426. Both companies were also issued with enforcement notices. WerepairUK Ltd appealed the ICO’s decision.
NEWS
The Information Commissioner's Office (ICO) has fined ESL Consultancy Services Ltd £200,000 for knowingly instigating unlawful loan promotion text messages. The ICO's investigation revealed that ESL used a third party to send marketing texts without ensuring valid consent, and attempted to conceal the sender's identity using unregistered SIM cards. The regulator executed search warrants, uncovering evidence of ESL's awareness of non-compliance and efforts to appear legitimate. In addition to the fine, ESL has been issued an enforcement notice. The ICO received 37,977 complaints related to this case, demonstrating the scale of the unlawful activity.
NEWS
The Information Commissioner's Office (ICO) has imposed a £90,000 fine on AFK Letters Co Ltd for breaching the Privacy and Electronic Communications Regulations (PECR) between January and September 2023. The enforcement action addressed 95,277 unsolicited marketing calls to Telephone Preference Service registrants, inadequate consent records, and non-compliant third-party data collection. The case highlights the ICO's interpretation of Regulation 21 requirements for valid marketing consent and proper record-keeping obligations.
NEWS
The Information Commissioner's Office (ICO) has fined home improvement companies, Poxell Ltd and Skean Homes Ltd, pursuant to section 55A of the Data Protection Act 2018, for making illegal marketing calls. The ICO received a total of 444 complaints from customers who had signed up with the Telephone Preference Service’s and Corporate Telephone Service’s ‘do not call’ register against Poxell and Skean Homes respectively. Poxell Ltd has been fined £150,000 for making over 2.6 million unlawful and very aggressive marketing calls between March and July 2022 to individuals with dementia and other serious illnesses, which breached regulations 21 and 24 of the Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR 2003), SI 2003/2426. Skean Homes Ltd has also been fined £100,000 for making over 600,000 unsolicited calls between March and May 2022, claiming to help improve energy efficiency and reduce household bills using false company names. Both companies did not take part in the investigation and refused to take accountability for their calls, which breached PECR 2003.
NEWS
The Information Commissioner's Office (ICO) has imposed a £200,000 fine on sole trader, Bharat Singh Chand, for sending 966,449 unauthorised marketing text messages between 3 December 2023 and 3 July 2024. The messages, which promoted debt solutions and energy saving grants, generated 19,138 complaints via the 7726 spam reporting service and breached the Privacy and Electronic Communications Regulations 2003, SI 2003/2426, by being transmitted without valid consent. The ICO also issued an enforcement notice ordering Chand to cease sending marketing messages without appropriate consent. The investigation found that Chand used evasion tactics, including providing false company names in follow-up calls. Chand has appealed the ICO's decision.
NEWS
The Information Commissioner’s Office (ICO) has fined the Conservative Party £10,000 for sending 51 marketing emails to people who did not want to receive them. The fine has been issued following an ICO investigation relating to emails sent from the Conservative Party in the name of the Prime Minister Boris Johnson after he was elected Prime Minister in 2019. The emails promoting the party’s political priorities were directly addressed to the people they were sent to by name and included a link directing them to a website for joining the Conservative Party.
NEWS
The Information Commissioner’s Office (ICO) has fined Allay Claims Ltd and ZMLUK Limited a total of £225,000 for sending millions of unsolicited marketing messages in breach of the Privacy and Electronic Communications (EC Directive) Regulations 2003, SI 2003/2426 (PECR 2003). Allay Claims Ltd was fined £120,000 for sending more than four million unlawful marketing text messages promoting payment protection insurance (PPI) tax refund services without valid consent and could not rely on the ‘soft opt-in’ exemption due to failures at the point of data collection. ZMLUK Limited was fined £105,000 for sending over 67 million marketing emails using third-party data where individuals were not given clear and informed choices, meaning the consent relied on was invalid.
NEWS
The Information Commissioner’s Office (ICO) has warned that people trying to access their care records are being systematically failed, citing widespread delays, poor communication, and significant gaps in information. Referencing its February–April 2024 review, the ICO notes that 71% of individuals experienced poor communication from their local authority, 69% said the process took longer than expected—with some still waiting up to sixteen years—and 87% were left with questions or concerns even after receiving their records. In response, the ICO has launched its Better Records Together campaign, issuing new standards for organisations, clear advice for people requesting records, and a UK-wide supervision pilot monitoring 19 bodies throughout 2025/26. The ICO has also warned senior leaders that failure to improve may lead to regulatory action, highlighting recent enforcement steps including an enforcement notice issued to Bristol City Council and an £18,000 fine imposed on Birthlink for destroying thousands of records. The campaign aims to provide practical resources to improve how care records are handled, from supporting people entering the care system to helping organisations respond lawfully and sensitively to record requests.
NEWS
The Information Commissioner's Office (ICO) has called on stakeholders to participate in the Department for Science, Innovation and Technology's (DSIT) call for evidence on its proposals to update the Network and Information Systems (NIS) Regulations 2018, SI 2018/506, through the Cyber Security and Resilience Bill (the Bill). The call for evidence seeks to assess the impact the changes would have on those regulated under the NIS Regulations or who will be regulated under the forthcoming Bill. This survey will be open until 21 November 2024.
NEWS
The Information Commissioner’s Office (ICO) has issued an enforcement notice and reprimand to the Metropolitan Police Service (MPS) after personal information was wrongly disclosed in two sensitive police matters. The ICO found that the MPS had failed to put in place appropriate technical and organisational measures to protect personal information, in breach of section 40 of the Data Protection Act 2018. The disclosures arose from an unredacted document served in a Stalking Protection Order case and a bulk email sent to people linked to the ‘Honeytrap matter’.
NEWS
The Information Commissioner's Office (ICO) has issued an enforcement notice to Bristol City Council (BCC) for failing to respond to subject access requests (SARs). The notice requires BCC to: (1) notify individuals with overdue SARs about the delays; (2) provide outstanding SAR responses by specified deadlines, prioritising the oldest cases from 2022 to be resolved within 30 days; (3) submit weekly progress updates to the ICO until all overdue SARs are resolved; (4) develop an action plan within 90 days to address the SAR backlog, including defined responsibilities, prioritisation and timelines; and (5) implement system and process improvements within 12 months, including adequate staffing, resources and staff training to ensure compliance with the UK General Data Protection Regulation requirements.