Refine By
Clear all filter
About 91978 results for "*"
NEWS
The Information Commissioner's Office (ICO) has issued an enforcement notice to South Wales Police (SWP) regarding delays in responding to subject access requests (SARs) within statutory timeframes. The ICO had identified breaches under Articles 12(3), 15(1), and 15(3) of the UK General Data Protection Regulation, along with section 45 of the Data Protection Act 2018. As a result, the enforcement notice requires SWP to: (1) provide overdue SAR responses to 352 individuals by 1 June 2026; (2) implement the recommendations set out in its Action Plan submitted to the ICO on 5 March 2025 by 1 June 2026; and (3) make changes to internal systems, policies and procedures by 24 April 2026 to ensure future SARs are identified and responded to in compliance with legal obligations.
NEWS
The Information Commissioner's Office (ICO) has published comprehensive guidance on 'consent or pay' business models for online tracking. The guidance addresses compliance with data protection law, focusing on key areas such as power imbalance, appropriate fees, equivalence, and privacy by design. ICO has outlined methods for assessing power imbalance, including market position and barriers to switching, as well as determining appropriate fees and ensuring equivalence between options. The guidance also emphasizes the importance of privacy by design principles in implementing these models and cautions against offering them to children.
NEWS
The Information Commissioner’s Office (ICO) has issued guidance for employers on sharing their workers’ personal information in a mental health emergency. The guidance sets out advice on when, and how, it is appropriate to share workers’ personal information where the employer believes that someone is at risk of causing serious harm to themselves or others due to their mental health. The ICO adds that it is good practice to plan ahead in order to make timely and better-informed decisions during a mental health emergency. The guidance considers what a mental health emergency is, how mental health information differs under data protection law, how to plan for information sharing and the lawful bases and special category conditions that are most likely to apply.
NEWS
The Information Commissioner’s Office (ICO) has issued information notices to Fruitlab, Frog, and Imgur regarding these companies' data practices. This takes place in the context of the ICO emphasising the duty for companies to improve their children’s privacy practices, including through its review of 34 social media and video sharing platforms, as part of its Children’s Code strategy. Following concerns raised during the review, the ICO specifically requested that 11 companies explain issues relating to default privacy settings, geolocation or age assurance, and show how their approach conforms with the Children's Code. However Fruitlab, Frog and Imgur did not comply, leading the ICO to issue the information notices. The ICO has also published the 'Children's Data Live 2024' report, which shows that youngsters are unaware of how companies collect and use their data.
NEWS
The Information Commissioner's Office (ICO) has issued a reprimand under Article 58(2)(b) of the UK General Data Protection Regulation, Retained Regulation (EU) 2016/679 (UK GDPR) to Chelmer Valley High School for breaching Article 35(1) of the UK GDPR. The school did not complete a Data Protection Impact Assessment (DPIA) before it introduced the facial recognition technology for cashless canteen payments, which meant that there was no prior examination of the risks to the children's information. The school had also not properly obtained consent to process the students’ biometric information. The ICO also recommended actions that the school can take to rectify the infringements it highlighted in the reprimand and ensure it complies with the UK GDPR.
NEWS
The Information Commissioner's Office (ICO) has issued a reprimand to Greater Manchester Police (GMP) following the internal loss of two hours of custody suite CCTV footage from February 2021. The breach occurred when GMP failed to properly retain footage requested for extended storage beyond the standard 90-day period. The ICO found GMP breached the Data Protection Act 2018 by failing to implement appropriate technical measures to prevent data loss and failing to provide the data subject access within statutory timeframes. The investigation revealed the loss resulted from unclear internal responsibilities for quality checks and inadequate retention policies, rather than external breach or unauthorized sharing. GMP has since upgraded its surveillance infrastructure and implemented stricter retention procedures.
NEWS
The Information Commissioner’s Office (ICO) has issued NHS Blood and Transplant (NHSBT) with a reprimand following the unintentional release of an untested development code for a future liver scheme into NHSBT’s live environment, which led to an error of prospective transplant patients being excluded from the NHSBT’s Liver Matching Run (LMR) and the security of personal data belonging to vulnerable individuals being compromised. The ICO issued the reprimand in accordance with Article 58 of the United Kingdom General Data Protection Regulation, Retained Regulation (EU) 2016/679 (UK GDPR), stating that NHSBT breached Article 32(1)(b) of the UK GDPR on security of processing. The ICO further recommended that NHSBT takes certain steps to improve its compliance with the UK GDPR and implements measures to enable a level of security appropriate to the risk to the integrity, availability, and resilience of its transplant matching systems.
NEWS
The Information Commissioner's Office (ICO) has issued a reprimand to Post Office Limited following a data breach affecting 502 postmasters involved in the Horizon IT scandal. The breach occurred between 25 April and 19 June 2024, when Post Office mistakenly published an unredacted legal settlement document on its corporate website. This document contained sensitive information, including names, addresses, and postmaster status. The ICO determined that the Post Office failed to implement appropriate technical and organisational measures. Specifically, the review highlighted a lack of documented policies and insufficient staff training as key shortcomings. Although the ICO initially considered imposing a fine of up to £1.094m, it ultimately opted to issue a reprimand under its public sector enforcement approach.
NEWS
The Information Commissioner's Office (ICO) has issued a reprimand to the Electoral Commission under Article 58(2)(b) of the UK General Data Protection Regulation, Assimilated Regulation (EU) 2016/679 (UK GDPR), following a hacking incident in August 2021 which allowed hackers access the Electoral Commission’s Microsoft Exchange Server which contained personal information of approximately 40 million people. The hackers had access to this information for over a year until October 2022 and were able to access the servers on several occasions without the Electoral Commission’s knowledge due to unsatisfactory security measures in place. These include failure to comply with the latest security updates and weak password policies.
NEWS
The Information Commissioner's Office (ICO) has launched a consultation on guidance for new 'charitable purpose soft opt-in' rules which the ICO indicates are expected to take effect in January 2026 under the Data (Use and Access) Act 2025 (DUAA 2025). The rules will allow charities to send electronic marketing messages to people who have expressed interest in supporting them without requiring prior consent, though existing database contacts are excluded. The consultation runs until 27 November 2025.
NEWS
The Information Commissioner's Office (ICO) has launched a consultation seeking feedback on its draft guidance regarding Distributed Ledger Technologies. The consultation is structured as a survey covering organisational impact, views on the guidance and general comments. The consultation runs until 7 November 2025.
NEWS
The Information Commissioner's Office (ICO) has launched a consultation to gather feedback on its draft guidance regarding the recognised legitimate interest basis for data processing. This guidance addresses the provisions introduced by the Data (Use and Access) Act 2025 (DUAA), which amends the UK GDPR, even though these provisions are not yet in force.