Refine By
Clear all filter
About 91978 results for "*"
NEWS
The Information Commissioner's Office (ICO) has published a notice in relation to enforcement action taken against First Choice Selection Services Ltd, after the company contravened Article 15 of the United Kingdom's General Data Protection Regulation, Retained Regulation (EU) 2016/679 (UK GDPR) and Article 15 of the EU General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR). First Choice was held to have failed to inform a data subject, without undue delay, whether their personal data was being processed by, or on behalf of, the controller, and further failed to provide access without undue delay to such personal data. First Choice was requested to, by 1 April 2021 at the latest, inform the individual who made the subject access request whether their data was being processed, and if so to provide the individual with a copy of their data, and to further carry out changes to internal systems, procedures and policies as necessary to ensure future compliance with Article 15 of the UK and EU GDPR.
NEWS
The Information Commissioner’s Office (ICO) has published a final version of its guidance on keeping employment records. The guidance is designed to assist employers who are required to process personal information to comply with their obligations under the General Data Protection Regulation and the Data Protection Act 2018. A draft version of the guidance, which was first added following a consultation by the ICO in 2023, was replaced by the final guidance on 5 February 2025. The ICO recommends that the guidance is used in conjunction with its suite of guidance on data protection and employment.
NEWS
The Information Commissioner's Office (ICO) has published its finalised guidance on Storage and Access Technologies (SATs) and updated its online tracking strategy. The guidance details how the Privacy and Electronic Communications (EC Directive) Regulations 2003, SI 2003/2426 (PECR 2003) and where applicable, the UK General Data Protection Regulation (UK GDPR), apply to cookies, tracking pixels, device fingerprinting and similar technologies. The guidance incorporates updates arising from two rounds of consultation and changes introduced by the Data (Use and Access) Act (DUAA 2025), providing new examples and clarifications to help organisations comply with the law. The guidance reflects the current law and is separate from the ICO's ongoing review of regulation 6 of PECR 2003 related to online advertising, on which further updates are to follow in the coming weeks.
NEWS
The Information Commissioner's Office (ICO) has published findings from its review into children's data handling practices across financial services providers offering current accounts, savings accounts, trust accounts, ISAs and prepaid cards. The report summarises evidence of good practice; evidence of risks to data protection compliance; and instances where the ICO found that improvements may be necessary to data practices. In particular, the review identified areas requiring improvement in governance, transparency, use of information and individual rights.
NEWS
The Information Commissioner’s Office (ICO) has published findings from consensual audits of five police forces in England and Wales on their use of facial recognition technology (FRT), identifying inconsistencies in data protection compliance and areas requiring improvement, particularly governance, training, awareness and storage limitation. The ICO made 107 recommendations across the audits, including 16 urgent and 54 high priority recommendations, covering matters including governance, lawful basis, data protection impact assessments, data minimisation, security management, accuracy and bias and information rights. The ICO says strong data protection governance, clear oversight, accountability and safeguards are essential as law enforcement use of FRT expands, including live facial recognition, retrospective facial recognition and emerging operator-initiated facial recognition. The participating police forces fully accepted 93 recommendations and partially accepted 14, rejecting none, and the ICO will conduct follow-up audits to assess progress against agreed action plans, with formal enforcement powers to be considered where there are concerns about compliance with data protection legislation.
NEWS
The Information Commissioner's Office (ICO) has published a findings report on the viability of a data protection Statutory Regulatory Sandbox (SRS). The report concludes that an SRS is feasible, subject to conditions including protection of the ICO's independence and the establishment of alternative but equivalent accountability and governance mechanisms for individual rights. The ICO further states that public trust and clear public benefit must underpin any SRS, and that demand for such a regime is niche. Any SRS would require changes to data protection legislation, with next steps to be determined by government. The ICO states the findings are intended to contribute to policy development in relation to the Regulating for Growth Bill and the Advisory AI Growth Lab (AIGL). The ICO also confirmed a commitment to improving its existing sandbox offering to deliver faster outputs and clearer conclusions for participants.
NEWS
The Information Commissioner's Office (ICO) has published guidance detailing its approach to handling data protection complaints, including the criteria used to determine the extent of investigations. The framework introduces a triage system that prioritises complaints involving high levels of harm, vulnerable individuals, or strategic priorities. Additionally, the ICO is developing a threshold system that could trigger intervention for organisations receiving multiple complaints over a specified period, although the exact details of these thresholds have not yet been disclosed.
NEWS
The Information Commissioner's Office has published several guidance documents and a working plan following the Data (Use and Access) Bill receiving royal assent on 19 June 2025 and becoming an Act of Parliament as the Data (Use and Access) Act 2025 (DUAA). The ICO notes that the main changes to the law include clarifying how personal information can be used for research, lifting restrictions on some automated decision making, setting out how to use some cookies without consent, allowing charities to send people electronic mail marketing without consent in certain circumstances and requiring organisations to have a data protection complaints procedure and introducing a new lawful basis of recognised legitimate interests. The ICO also underlines that the DUAA provides it with new powers including the ability to compel witnesses to attend interviews, request technical reports, and issue higher fines.
NEWS
The Information Commissioner’s Office (ICO) has published guidance on content moderation which highlights how data protection law applies to content moderation processes and how it affects people’s information rights. The ICO also announced, alongside, that the guidance will support people's information rights online by ensuring organisations understand their data protection obligations when seeking to make their platforms safer. The guidance will further help organisations in scope of the Online Safety Act 2023 to comply with data protection law as they carry out content moderation to meet their online safety duties.
NEWS
The Information Commissioner's Office (ICO) published guidance outlining new requirements for organisations to establish data protection complaints processes under the Data (Use and Access) Act. These requirements, set to come into force on 19 June 2026, mandate that all organisations provide a complaints mechanism, acknowledge complaints within 30 days, respond without undue delay and inform complainants of outcomes. Notably, there are no exemptions available under these provisions.
NEWS
The Information Commissioner’s Office (ICO) has published final guidance on the application of UK data protection law and the Privacy and Electronic Communications Regulations (PECR), SI 2003/2426, to consumer Internet of Things (IoT) products and services. The guidance is aimed at organisations involved in the design, development and operation of connected devices, including manufacturers, software developers, cloud providers and artificial intelligence (AI) service providers. It explains how data protection requirements apply to consumer IoT products such as smart speakers, connected televisions, wearables, home automation devices, security products and smart domestic appliances.
NEWS
The Information Commissioner's Office (ICO) has published guidance on using personal information to protect businesses from crime, explaining how data protection law applies when organisations collect, use and share criminal offence data, including closed-circuit television (CCTV) images and facial recognition technology (FRT). The guidance covers sharing information with the police, colleagues and other businesses, explains the safeguards required when processing criminal offence data, including data protection impact assessments (DPIAs) and appropriate policy documents (APDs), outlines when the use of FRT may be necessary and proportionate, and emphasises that publicly posting images of suspected offenders is unlikely to be justifiable. It also includes practical compliance checklists to help organisations meet their data protection obligations.