Refine By
Clear all filter
About 91978 results for "*"
NEWS
The Information Commissioner's Office (ICO) has issued an updated response to the Data (Use and Access) (DUA) Bill, following its passage through the House of Lords. The ICO's statement addresses the amendments made during the Lords stage and comments on significant areas of debate. This update comes after the Bill's introduction to Parliament in October 2024 and reflects the Information Commissioner's latest position on the evolving legislation, providing insight for legal practitioners on the Bill's development and potential implications.
NEWS
The Information Commissioner's Office (ICO) has updated its guidance on the right of access under UK General Data Protection Regulation (GDPR) to reflect changes introduced by the Data (Use and Access) Act 2025. The updated guidance establishes that organisations are only required to carry out reasonable and proportionate searches when responding to Subject Access Requests (SARs) and may stop the clock when seeking clarification on requests. The ICO has published the guidance in advance of some provisions coming into force to enable organisations to prepare for the changes. The guidance is aimed at data protection officers and those with specific data protection responsibilities in larger organisations, providing detailed coverage of SAR procedures, exemptions, and special cases including health, education and social work information.
NEWS
The Information Commissioner’s Office (ICO) has updated its guidance on the right of access to reflect changes introduced by the Data (Use and Access) Act 2025 (DUAA 2025) and to align with its revised detailed guidance on subject access requests (SARs). The guidance explains that individuals can request access to their personal data verbally or in writing, including through authorised representatives, and that organisations must usually respond within one month and free of charge. It clarifies when organisations may seek clarification or proof of identity, extend response times, or rely on exemptions, and requires them to conduct reasonable and proportionate searches, provide information securely and in an accessible format, and consider the rights of children and third parties. The guidance also sets out when a request may be refused, the information that must be provided when refusing a request, and the ICO’s enforcement powers for non-compliance.
NEWS
The Information Commissioner's Office (ICO) has responded to Google's announcement permitting fingerprinting techniques from February 2025, warning that businesses must still comply with data protection laws. The ICO has published draft guidance on how data protection law, including the Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR 2003), SI 2003/2426 applies to storage and access technologies such as fingerprinting. The ICO emphasises that organisations must provide transparency, obtain consent, and ensure fair processing when using fingerprinting for advertising purposes. The regulator plans to release a comprehensive strategy in the new year to give users meaningful control over personalised advertisement. A consultation on this guidance opens on Friday, 20 December 2024.
NEWS
The Information Commissioner's Office (ICO) has warned that businesses have one month remaining to implement data protection complaints processes before the new legal requirements under the Data (Use and Access) Act 2025 take effect on 19 June 2026. Under the new legislation, all organisations must establish clear complaint mechanisms that include acknowledging complaints within 30 days, investigating them without undue delay and informing complainants of the outcomes promptly. The ICO is particularly urging small and medium-sized enterprises to act, since such organisations are generally less likely to have formal complaints processes in place.
NEWS
The Information Commissioner’s Office (ICO) has issued a statement welcoming the Court of Appeal’s decision to allow its appeal against the Upper Tribunal’s ruling on DSG Retail Ltd. The Court of Appeal reinstated the interpretation that organisations have a protective duty to implement appropriate security measures to safeguard personal data from unauthorised access, regardless of whether individuals could be identified from the data exfiltrated by hackers. The case arises from the ICO’s imposition of a £500,000 fine on DSG in 2020 under the Data Protection Act 1998 (DPA 1998) after a cyber attack compromised the personal data of at least 14 million people. Following appeals by DSG to the First-tier Tribunal and the Upper Tribunal, the ICO appealed to the Court of Appeal in 2024. Although the case was decided under the DPA 1998, the Court of Appeal’s interpretation of organisations’ security duties provides guidance for similar requirements under the current data protection regime. The case will now return to the First-tier Tribunal to apply this interpretation to the facts of the DSG cyber attack.
NEWS
The Information Commissioner’s Office (ICO) has welcomed the Cyber Security and Resilience (Network and Information Systems) Bill, introduced to Parliament on 12 November 2025, as a significant step in strengthening the UK’s cyber defences, while calling for further clarity in secondary legislation. The ICO has said the Bill will expand its regulatory remit to include relevant managed service providers and critical suppliers, enhance its enforcement, information-gathering and cost-recovery powers, and support a shift from reactive to proactive, risk-based oversight of digital and managed service providers across the UK. It has highlighted the benefits of improved incident reporting, including a proposed 24-hour reporting window for significant cyber incidents, but has urged the government to provide clearer guidance on key concepts such as significant impact thresholds, security and resilience requirements, enforcement measures and the definition of critical suppliers. The ICO has also emphasised the need for adequate funding, coordination with other regulators and timely guidance to help organisations understand and comply with the new requirements as the legislation progresses through Parliament.
NEWS
The Information Commissioner's Office (ICO) has welcomed the government's launch of the advisory Artificial Intelligence (AI) Growth Lab, which will bring regulators together to provide AI innovators and adopters with practical guidance on how existing regulatory requirements apply to new AI applications. The ICO says that the first focus areas will be LawTech, legal services and conveyancing, with the initiative intended to support the responsible adoption of AI in the legal sector, improve access to justice and enable faster and more affordable legal services while maintaining quality standards. The ICO will collaborate with the Council for Licensed Conveyancers, the Solicitors Regulation Authority and the Legal Services Board to help innovators address cross-regulatory challenges associated with the use of AI.
NEWS
The UK Upper Tribunal (UT) has ruled in favour of the Information Commissioner’s Office (ICO) in its appeal against the First-tier Tribunal (FTT) decision concerning Clearview AI Inc, a US-based company fined £7.5m in 2022 for unlawfully scraping images of UK residents from online sources and using them in a facial recognition database. The UT upheld three of the ICO’s four grounds of appeal, finding that Clearview’s processing of personal data involves monitoring the behaviour of UK residents and therefore falls within the scope of UK data protection law, regardless of the company’s foreign operations or clients. It also held that the FTT had misapplied the law in concluding that the processing was outside the material scope of Article 2(1)(a) of the UK GDPR.
NEWS
The Information Commissioner’s Office (ICO) has welcomed a First-tier Tribunal ruling on 8 July 2025 confirming its power to issue a £12.7m monetary penalty to TikTok in April 2023 for breaching UK GDPR. The Tribunal dismissed TikTok’s claim that its processing fell under the 'special purposes' exemption for artistic use, finding the case centred on misuse of under-13s’ data. The appeal will now proceed to a full hearing.
NEWS
The Information Commissioner Office (ICO)’s data protection and journalism code of practice has entered into force on 22 February 2024. This follows the ICO submitting this code to the Department of Science, Innovation and Technology on 6 July 2023, the code’s laying before Parliament on 23 November 2023 and its issue on 1 February 2024 under section 125 of the Data Protection Act 2018. The code aims to help the media apply data protection law in a journalism context. It builds upon guidance for the media which the ICO published in 2014 following a recommendation from the Leveson Inquiry.
NEWS
The International Consumer Protection and Enforcement Network (ICPEN) and twenty consumer protection authorities, including Ireland's Competition and Consumer Protection Commission (CCPC), published an open letter on 1 May 2025 addressing environmental claims in fashion retail. The letter outlines principles for fashion retailers to ensure compliance with consumer protection laws, including avoiding vague environmental claims, requiring specific evidence-based statements, and proper use of certification schemes. The guidance aims to prevent misleading environmental marketing in the textile industry by requiring retailers to focus on current verifiable measures rather than future aspirations.