Refine By
Clear all filter
About 91978 results for "*"
NEWS
The Information Commissioner's Office (ICO) has reprimanded Levales Solicitors LLP for violations of Article 32(1)(b) and (d) the United Kingdom General Data Protection Regulation, Retained Regulation (EU) 2016/679 (UK GDPR) following a data breach. A threat actor accessed the firm's cloud-based server using legitimate credentials and published sensitive data on the dark web, impacting 8,234 UK individuals, with 863 classified as high risk due to the nature of the data involved. The ICO investigation found that the firm failed to maintain the ongoing confidentiality of its processing systems and did not implement adequate organisational measures to protect data.
NEWS
The Information Commissioner's Office (ICO) has issued a formal reprimand to ACRO Criminal Records Office (ACRO), a national police unit acting as data processor for 43 police forces, under Article 58(2)(b) of the UK General Data Protection Regulation (UK GDPR), on 7 August 2026. The ICO found infringements of Articles 32(1), 32(1)(b) and 32(1)(d) of the UK GDPR following three cyber incidents between July 2021 and June 2023 targeting ACRO's Kentico content management system (CMS)-based customer portal. The primary incident, having occurred between 5 August 2022 and 14 March 2023, resulted in data on up to 10,920 individuals—including biometric, financial and criminal offence data—being staged for potential exfiltration. Key failings included: (1) running unpatched Kentico CMS software from September 2019 onwards; (2) an absence of documented patch management policy; (3) unclear accountability between third-party suppliers for identifying required patches and (4) failure to investigate multiple antivirus security alerts. Mitigating factors, including ACRO’s effective network segmentation and post-incident remediation, were considered in the decision to issue a reprimand rather than a financial penalty.
NEWS
The Information Commissioner’s Office (ICO) has addressed Meta’s decision to resume using Facebook and Instagram user data for training generative AI, after Meta paused its plans in June 2024 at the ICO's request. This comes after Meta has made changes to its approach, including simplifying the process for users to object to the processing and providing a longer window for objections. The ICO reiterated that organisations must be transparent about the use of personal data, implement safeguards, and offer a clear route for objections. However, the ICO has not granted regulatory approval for Meta’s processing, leaving Meta responsible for ensuring and demonstrating compliance.
NEWS
The Information Commissioner's Office (ICO) has responded to a government request for proposals to boost economic growth and improve the investment climate. The ICO has emphasized the importance of data protection and information rights as fundamental to innovation and economic growth, fostering public trust and consumer confidence. The organisation has committed to developing ambitious, measurable plans focused on practical benefits for businesses and investors. The ICO aims to position itself as a pragmatic, business-friendly regulator, creating an attractive landscape for UK investment while building upon its existing efforts to promote responsible innovation and sustainable economic growth.
NEWS
The Information Commissioner's Office (ICO) has secured Proceeds of Crime Act 2002 (POCA 2002) confiscation orders totalling £118,852.32 against former RAC employees, Debbie Okparavero and Maliha Islam. At Manchester Crown Court on 29 May 2026, Okparavero was ordered to pay £85,727.32 plus costs of £3,550, within 3 months, with an 18-month custodial sentence in default of payment. Islam was ordered to pay £33,125 plus costs of £2,797.50 at a November 2025 hearing, and that order has since been paid in full. The POCA 2002 proceedings followed the sentencing of both defendants on 8 October 2024, after they pleaded guilty to conspiracy to commit offences under section 1 of the Computer Misuse Act 1990 and the Data Protection Act 2018, and each received 6-month suspended prison sentences and was ordered to complete 150 hours of unpaid work for unlawfully copying and selling approximately 30,000 lines of personal information.
NEWS
The Information Commissioner's Office (ICO) has secured a conviction against the director of Bridlington Lodge Care Home, Jason Blake, for blocking access to personal information following a subject access request. Blake was found guilty under section 173 of the Data Protection Act 2018 at Beverley magistrates' court on 3 September 2025 for concealing records between 12 April and 12 May 2023 to prevent disclosure of personal information requested by a resident's daughter, who held lasting power of attorney. The court ordered him to pay a £1,100 fine and £5,440 in costs.
NEWS
The Information Commissioner's Office (ICO) has secured guilty verdicts against eight individuals for data protection offences following its largest ever nuisance call investigation. On 26 June 2025, Craig Cornick was found guilty at Bolton Crown Court of conspiracy to unlawfully obtain personal data contrary to the Data Protection Act, joining seven others who had previously pleaded guilty to various offences under the Data Protection Act and Computer Misuse Act. The investigation uncovered approximately one million illegally accessed vehicle repair records between 2014-2017. The defendants are scheduled to return to court on 11 July 2025 for Proceeds of Crime Act proceedings, with sentencing to follow. The ICO has indicated a second phase of investigation is ongoing, targeting insurance companies and claims management firms.
NEWS
The Information Commissioner’s Office (ICO) has secured a £355,880.10 confiscation order against former Manchester motor insurance worker Rizwan Manjra, who was previously found guilty of securing unauthorised access to personal information on his work computer systems for financial gain. The order was granted at a Proceeds of Crime Act hearing at Manchester Crown Court on 15 May 2026, following Manjra’s 2024 guilty plea under the Computer Misuse Act 1990 of causing a computer to perform a function with intent to secure unauthorised access to personal information. The confiscation order, which reflects the financial advantage gained through illegal access and onward sale of personal information, must be paid within three months; failure to pay will result in a default prison sentence of three years and six months, with continued liability for the full amount. The action follows the ICO’s successful prosecution in December 2024, in which Manjra received a suspended prison sentence, and he was also ordered to pay £1,500 in costs within six months.
NEWS
The Information Commissioner's Office (ICO) is currently seeking stakeholder feedback on its guidance regarding the use of profiling tools for online safety, particularly in relation to the Online Safety Act 2023. The guidance addresses data protection and privacy considerations when using such tools in trust and safety systems. The consultation, open until 31 October 2025, includes a survey divided into sections about the respondent, their use of the guidance and its impact. The ICO aims to ensure regulatory coherence between data protection and online safety and will use the feedback to refine its guidance. While individual responses will remain confidential, aggregated insights may be published.
NEWS
The Information Commissioner's Office (ICO) has launched a call for evidence to inform its approach to applying data protection law to the distinctive capabilities and risks of agentic artificial intelligence (AI). The ICO is seeking feedback across several areas, including data security, transparency, accountability, automated decision-making, fairness, purpose limitation and lawfulness of processing. Responses will inform the ICO's approach and help it identify where greater clarity or practical support may be needed before it publishes the final version of its guidance. The call for evidence closes on 20 November 2026.
NEWS
The Information Commissioner’s Office (ICO) has set out its 2024-2025 priorities for protecting children’s privacy online. The new Children’s Code strategy focuses on introducing a default privacy setting and locking geolocation settings on children’s profiles, turning off targeted advertising, analysing the way in which recommender systems use children’s search results, and how information of children under 13 years is used. The ICO also aims to increase cooperation with Ofcom and international counterparts to raise the data protection standards of children in the UK.
NEWS
The Information Commissioner’s Office (ICO) has signed a new international multilateral agreement with the Global Cooperation Arrangement for Privacy Enforcement (Global CAPE) to cooperate in cross-border data protection and privacy enforcement. The ICO can now assist with investigations and share information with member countries without entering separate memorandums of understanding. Members of Global CAPE include Global CAPE members include the United States, Australia, Canada, Mexico, Japan, the Republic of Korea, the Philippines, Singapore, and Chinese Taipei. Global CAPE was created to supplement the Asian Pacific Economic Cooperation Cross-border Privacy Rules (APEC CBPR), which also facilitates cooperation and assistance in privacy and data security investigations among APEC’s Asian Pacific countries.