Refine By
Clear all filter
About 91978 results for "*"
NEWS
The Information Commissioner’s Office (ICO) has updated its guidance on international transfers of personal information. The update aims to make it quicker (streamline) for organisations to understand and comply with UK GDPR transfer rules. The updated guidance introduces a ‘three step test’ to help organisations identify if they are making restricted transfers, adds new content questions frequently questioned by organisation, adds new content on roles and responsibilities reflecting the complexity of multi-layered scenarios and provides a brief guide, FAQs and a glossary for organisations without specialist expertise. The ICO also intends to host a webinar to support organisations making or advising on restricted transfers.
NEWS
The Information Commissioner’s Office (ICO) has reaffirmed its approach to improving data protection standards across the UK public sector by prioritising early engagement and non-punitive measures over financial penalties. Following a public consultation, the ICO clarified which organisations fall within scope and when fines may be issued, confirming that warnings, reprimands, and enforcement notices are generally more effective in driving sustainable compliance. This approach focuses on fostering a compliance-first culture, embedding data protection by design, and encouraging investment in training and processes, while avoiding the unintended harm that fines can cause to public services. Evidence, such as improved subject access request compliance among Scottish local authorities, demonstrates its impact, while early engagement in projects like the NHS Federated Data Platform and Northern Ireland’s register of vulnerable customers has ensured privacy and accountability from the outset. The ICO maintains that this transparent, proactive strategy continues to strengthen data protection, uphold public trust, and will remain under review.
NEWS
The Information Commissioner’s Office (ICO) has released an audit outcomes report on the use of AI tools in recruitment. The report provides almost 300 recommendations to AI developers and providers to ensure job seekers’ information rights are protected and processed fairly. The report also summarises key findings from the ICO’s consensual audits conducted on several providers and developers of AI tools for recruitment. In addition, it provides case studies, good practice examples, and lessons learned for AI developers and recruiters. The report forms part of the ICO’s upstream monitoring of the wider AI ecosystem to understand how the development and provision of AI recruitment tools comply with UK data protection law.
NEWS
The Information Commissioner's Office (ICO) has released guidance on biometric recognition, which highlights how the United Kingdom General Data Protection Regulation, Assimilated Regulation (EU) 2016/679 (UK GDPR) applies when biometric data is used in biometric recognition systems. The guidance also looks at the uses of biometric recognition and explains how these involve processing special category biometric data. In parallel, the ICO has also issued an order against Serco Leisure to stop using facial recognition technology and fingerprints scanning to monitor attendance of leisure centre employees. The company failed to show why it is necessary or proportionate to use facial recognition and fingerprint scanning for this purpose, when there are less intrusive means available such as ID cards or fobs. Employees were not proactively offered an alternative to having their faces and fingers scanned to clock in and out of their place of work, and it was presented as a requirement in order to get paid. Due to the imbalance of power between Serco Leisure and its employees, it is unlikely that they would have felt able to say no to the collection and use of their biometric data for attendance checks.
NEWS
The Information Commissioner's Office (ICO) has published comprehensive guidance on anonymisation and pseudonymisation techniques on 28 March 2025, accompanied by a webinar scheduled for 22 May 2025. The guidance explains anonymisation and pseudonymisation concepts, outlines data protection obligations, and provides practical advice on implementing appropriate technical measures. It specifically addresses organisations using or considering anonymising personal data, including artificial intelligence developers, and details risk mitigation strategies for protecting individual privacy.
NEWS
The Information Commissioner's Office (ICO) has released a report highlighting the data protection concerns arising from the use of genomics. The rapid advancement of genomics in the healthcare, education, insurance, and law enforcement sectors gives rise to data security issues, including misuse or risk of re-identification as genomic data is difficult to anonymise, potential systemic discrimination, lack of transparency around data sharing, and the risk of data being used beyond its original purpose. The report also sets out concerns about family sharing of genomic data, as information shared about one family member can inadvertently reveal sensitive details about another. The ICO is therefore urging companies in these sectors to collaborate with its Regulatory Sandbox to develop privacy-compliant innovations in genomics.
NEWS
The Information Commissioner's Office (ICO) has released a report as a response to the Department for Science, Innovation and Technology's inquiry into its preparations for AI. The report lays out the ICO’s strategic approach to AI regulation and explains how the ICO is driving forward the principles set out in the AI Regulation White Paper and the UK government’s guidance on implementing the principles. The ICO also said it will prioritise children’s privacy and online tracking for 2024–2025.
NEWS
The Information Commissioner’s Office (ICO) has released a report containing data about the prevalence of data breaches. The report has practical advice to help organisations to understand common security failures as well as steps to improve security and preventing future data breaches before they can happen. The report focuses on five leading causes of cyber security breaches, namely phishing, brute force attacks, denial of service, errors and supply chain attacks. For each cause, the report explains how these attacks take place, some key considerations to mitigate the risk and likely future developments.
NEWS
The Information Commissioner’s Office (ICO) has issued a reminder to small businesses to strengthen their cyber security practices in response to a rise in cyber-attacks, with government data indicating 7.7 million incidents over the past year. The ICO emphasised that while some attacks are complex, many organisations continue to neglect basic safeguards. To mitigate risks and protect personal data, the ICO recommends measures such as regular encrypted data backups, strong passwords with multi-factor authentication, vigilance against phishing emails, secure device and network usage, controlled access to sensitive information, and proper disposal of outdated equipment. Businesses are also urged to report any data breaches within 72 hours and consult further guidance from the ICO and the National Cyber Security Centre.
NEWS
The Information Commissioner’s Office (ICO) on 12 December 2023 removed from its Employment information guidance page the employment practices code, supplementary guidance and quick guide to the employment practices code.
NEWS
The Information Commissioner’s Office (ICO) has taken action against two public services, Devon and Cornwall Police and Barking, Havering and Redbridge Hospitals NHS Trust, for failing to meet basic information request requirements, as set out under the Freedom of Information Act 2000 (FOIA). Devon and Cornwall Police and Barking, Havering and Redbridge Hospitals NHS Trust have been issued with enforcement notices by the ICO for their failings which requires them to devise and publish an action plan within 30 and 35 days respectively, detailing how they will tackle their FOI requests backlog.
NEWS
The Information Commissioner’s Office (ICO) has reported on two former RAC employees who have been handed a suspended prison sentence for copying and selling over 29,500 lines of personal information unlawfully. They were also ordered to complete 150 hours of unpaid work. The 61 year-old, Debbie Okparavero and 51 year-old, Maliha Islam, pleaded guilty to offences under the Computer Misuse Act 1990 and Data Protection Act 2018. Their conduct was discovered through a security monitoring software which revealed that Okparavero, accessed and copied the information and shared it with Islam via WhatsApp.