Refine By
Clear all filter
About 91978 results for "*"
NEWS
The Information Commissioner's Office (ICO) has announced a comprehensive strategy to address online tracking compliance across the UK's digital landscape. The ICO has expanded its focus from the top 200 to the top 1,000 UK websites, aiming to ensure meaningful user control over personal data tracking. The strategy includes new guidance on 'consent or pay' models, plans to tackle compliance in apps and connected TVs, and investigations into data management platforms in the adtech ecosystem. The ICO has also committed to publishing public-facing guidance to help individuals navigate their rights regarding online tracking.
NEWS
The Information Commissioner’s Office (ICO) has launched a consultation on the allocation of accountability for data protection compliance across the generative AI supply chain, forming chapter five of its consultation series on generative AI and data protection which it initially launched on 15 January 2024. This new consultation addresses the recommendation for ICO guidance on the allocation of accountability in AI as a Service context, and provides some indicative scenarios of processing activities. The consultation will close on 18 September 2024.
NEWS
The Information Commissioner's Office (ICO) has opened a consultation on its new Enterprise Data Strategy (EDS), which highlights how it will use data to inform and direct its corporate, regulatory and strategic priorities. The ICO is now seeking views from interested individuals, businesses and public sector on its EDS and how it can align and structure its data-driven activity to the opportunities and challenges the UK faces. The ICO also wants to find out how data it retains should be made available, in the interest of the public, to assist organisations develop and to minimise risk. The consultation will close on 12 March 2024.
NEWS
The Information Commissioner's Office (ICO) has opened formal investigations into X Internet Unlimited Company and X.AI LLC regarding their processing of personal data in relation to the Grok artificial intelligence system and its potential to produce harmful sexualised image and video content. The investigations follow reports that Grok has been used to generate non-consensual sexual imagery of individuals, including children. The ICO will assess whether personal data has been processed lawfully, fairly and transparently under UK data protection law, and whether appropriate safeguards were built into Grok's design and deployment to prevent the generation of harmful manipulated images using personal data. The investigation will examine the companies' legal bases, technical design choices, and safeguards applied to the Grok model. Under the UK GDPR and Data Protection Act 2018, the ICO can issue fines of up to £17.5m or 4% of an organisation's annual worldwide turnover. The ICO is coordinating with Ofcom and international regulators on the matter.
NEWS
The Information Commissioner’s Office (ICO) has secured the sentencing of a motor insurance employee to eight months’ imprisonment (suspended for two years). RAC employee Kim Doyle transferred personal data to an accident claims management firm without authorisation. Doyle pleaded guilty to conspiracy to secure unauthorised access to computer data and to selling unlawfully obtained personal data pursuant to section 1 of the Computer Misuse Act 1990. This was the ICO’s second prosecution under the Computer Misuse Act 1990.
NEWS
The Information Commissioner’s Office (ICO) has provisionally fined Advanced Computer Software Group Ltd £6.09m as a result of an initial finding that the IT and software services provider failed to implement measures to protect the personal information, including sensitive personal information like medical records, of 82,946 individuals. This preliminary fine follows a ransomware incident from August 2022, during which hackers accessed a number of the company’s health and care systems via a customer account which did not have multi-factor authentication.
NEWS
The Information Commissioner's Office (ICO) has published an Opinion on the use of live facial recognition (LFR) in public places by private companies and public organisations.
NEWS
The Information Commissioner's Office (ICO) has published a report outlining its advice to the Department for Science, Innovation and Technology (DSIT), recommending amendments to regulation 6 of the Privacy and Electronic Communications Regulations (PECR 2003), SI 2003/2426, to permit certain low-risk forms of online advertising without explicit consent. The ICO proposes a ‘first-party framework’ that would allow publishers to store and access device information for specific purposes, including ad delivery, contextual targeting, and measurement. At the same time, the framework maintains consent requirements for behavioural advertising and intrusive tracking. This approach is intended to alleviate consent fatigue and foster the development of innovative, privacy-preserving advertising models while continuing to safeguard user rights.
NEWS
The Information Commissioner's Office (ICO) has published its annual report for 2025–26, marking what it describes as the final full year before transitioning to the Information Commission, a new statutory board under the Data (Use and Access) Act 2025 (DUAA 2025). Key highlights include fines against Imgur and Reddit for children's data protection breaches, with major platforms improving online privacy for over 11 million children. Cookie compliance work brought 979 of the top 1,000 UK websites into compliance, giving an estimated 40 million people greater control over online tracking. The ICO also published an artificial intelligence and biometrics strategy, launched consultations on new guidance under the DUAA 2025 and championed the records of care-experienced people. Data protection complaints rose sharply to 76,743 from 42,315, freedom of information complaints increased to 10,713 from 7,369 and reported data breaches grew to 17,431 from 12,412. The ICO estimates its activities generated £233 million of economic value for UK businesses over five years.
NEWS
The Information Commissioner's Office's (ICO) informal Innovation Advice service has published a response as part of its publicly available 'previously asked questions' section, addressing the classification of 'strictly necessary' cookies under the Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR), SI 2003/2426. The ICO provides an example of online services offering cashback or rewards to customers who have signed up to these services previously and make purchases on participating merchants’ websites. In response to the issue of whether the use of cookies for providing a reward service qualifies the cookies as ‘strictly necessary’ (thus exempting them from the consent requirement under PECR) the ICO responds that this is likely the case when someone signs up to an online service offering cashback or rewards, as some cookies set by that service would be essential because the user has requested that service.
NEWS
The Information Commissioner’s Office (ICO) has published new research highlighting a gap between parents’ confidence in monitoring their children’s online activity and children’s actual online behaviour, alongside its latest children’s code strategy update. The research found that, although 91% of parents use parental controls or monitoring tools, 41% of children had tried to circumvent them, while 52% said they would try to bypass age checks and 36% talk or play online with people they know only online or do not know at all. The strategy update reports that ICO regulatory action has secured commitments from Snapchat to strengthen age assurance measures, improvements to Snapchat and Instagram’s location-sharing features, and action by EdTech providers on 98% of 596 recommendations made to 28 providers. The ICO estimates that improvements introduced across several major platforms since April 2024 have helped protect almost 5 million child users.
NEWS
The Information Commissioner’s Office (ICO) has published draft guidance aimed at helping manufacturers and developers of smart products comply with data protection law. The guidance, released on 16 June 2025, outlines expectations for the Internet of Things (IoT) sector, where products such as smart speakers, fitness trackers and Wi-Fi-enabled appliances collect substantial amounts of personal data, including sensitive information.