NEW: We’re excited to announce that we have joined the National Cyber Resilience Centre Group's National Ambassador programme! Cyber security is one of our key regulatory priorities and we’re committed to improving cyber resilience across the UK by helping organisations protect the personal information they hold. This new partnership will enable us to work alongside fellow National Ambassadors and the network of police-led Cyber Resilience Centres, to raise awareness of cyber security risks and connect small organisations in the UK with free and affordable support. Ian Hulme, our Group Director - Regulatory Assurance and Cyber, said: "As cyber threats continue to grow, helping organisations strengthen their cyber resilience remains a key priority for us. We are committed to supporting organisations to protect the personal information they hold, while taking action where poor security practices put people at risk. Joining the National Ambassador programme allows us to extend the reach of that work.” Cyber resilience will play a key part in this year’s Data Protection Practitioners’ Conference (13 October). We have two sessions on building resilience for cyber incidents, a panel in the morning and a seminar in the afternoon. Register for DPPC for free now: https://lnkd.in/eCwAqDgf
Information Commissioner's Office
Law Enforcement
The Information Commission's Office (ICO) exists to empower you through information. www.ico.org.uk
About us
The ICO is the UK's independent authority set up to uphold information rights in the public interest, promoting openness by public bodies and data privacy for individuals. We rule on eligible complaints, give guidance to individuals and organisations, and take appropriate action when the law is broken.
- Website
-
http://www.ico.org.uk
External link for Information Commissioner's Office
- Industry
- Law Enforcement
- Company size
- 201-500 employees
- Headquarters
- Wilmslow, Cheshire
- Type
- Government Agency
- Founded
- 1984
- Specialties
- Data Protection Act, Freedom of Information Act, Privacy and Electronic Communications Regulations, and Environmental Information Regulations
Locations
-
Primary
Get directions
Wilmslow, Cheshire, GB
Employees at Information Commissioner's Office
Updates
-
Information Commissioner's Office reposted this
We were delighted to welcome Paul Arnold MBE and William Malcolm from the Information Commissioner's Office to speak with DPC staff on Friday. It was an engaging discussion covering the challenges facing the ICO and the ways in which it is innovating to meet them. It also highlighted opportunities for both regulators to work together on issues of mutual interest. The discussion followed a highly productive bilateral meeting between the DPC and ICO, which took place at our Pembroke office in Dublin on Thursday.
-
-
Today marks the beginning of a new phase for our organisation. We’ve officially transitioned to the Information Commission under new governance arrangements introduced by the Data (Use and Access) Act. Alongside the transition, we've welcomed our new Board, appointed Maggie Carver as Deputy Chair and opened our new headquarters in Manchester. Paul Arnold, Chief Executive Officer of the Information Commission, said: "I'm delighted to be able to formally welcome our non-executive board members and Deputy Chair. Their appointments mark a further key milestone in our modernisation and transformation as a regulator." "Today is the beginning of an important new chapter for our organisation. As the Information Commission, we are building on more than four decades of experience while strengthening how we are governed and led. "Our new Manchester office and our new governance arrangements are both part of the same ambition: to become more connected to the people and organisations we serve, more capable of meeting the challenges of a rapidly changing digital world, and more confident in the contribution we can make. "The day-to-day work that people rely on from us continues. We will continue to provide organisations with the guidance and certainty they need, support responsible innovation, and hold organisations to account when people's information rights are not respected." Digital Government Minister at Department for Digital, Culture, Media and Sport Stephanie Peacock MP said: “People should have confidence that their personal information is being used responsibly, whether they are accessing public services, shopping online or using new digital technologies. The new Information Commission will continue to provide strong, independent oversight of data protection, while bringing together a range of expertise to ensure the regulator remains equipped to respond to future challenges and opportunities in a fast-changing digital world.” Maggie Carver, Deputy Chair of the Information Commission, said: “The new Board looks forward to supporting Paul and the executive of the ICO through this exciting time in its development.” While our governance arrangements are changing, the services and regulatory work people rely on continue unchanged. This next phase will help us become more connected to the communities and organisations we serve, more capable of responding to change and more confident in the contribution we can make. Read more about our new Board and what this means for the future of the organisation: https://lnkd.in/eRYikHi4
-
-
NEW: Lessons your organisation can learn from Norfolk and Suffolk Constabularies’ FOI spreadsheet breach. We’re calling on public authorities across the country to look at their processes and quality checks before disclosing information in response to FOI requests. ❓ What happened? Across both constabularies, FOI responses included Excel files containing hidden or embedded information. In Suffolk’s 2018 incident, a staff member uploaded a spreadsheet with multiple tabs to a website without realising that raw information sat behind the visible view, affecting the personal information of 74 people. Between 2021 and 2022, both constabularies shared spreadsheets that contained links to source data. When shared externally, these hidden datasets became accessible, affecting 846 people for which Norfolk Constabulary was the data controller and 362 for which Suffolk Constabulary was the data controller. There was no awareness of these Excel functions or how to check for them in Excel. This meant the constabularies published people’s personal information online, including names, dates of birth, offence details and other sensitive information linked to criminal investigations. We found the constabularies failed to implement appropriate technical and organisational measures to protect people’s information. View all the details about these cases: ➡️ Norfolk Constabulary: https://lnkd.in/eKXCc3Vi ➡️ Suffolk Constabulary: https://lnkd.in/eiTRNm52 💡 What can your organisation learn from this incident? Build strong pre-disclosure controls Our guidance makes it clear that pivot tables, metadata and embedded data should be checked and removed before disclosure. Clear checklists, standardised formats and simple safeguards such as converting files to CSV can prevent this type of breach. Provide adequate training Training should be practical, role-specific and refreshed regularly. Staff who handle information disclosures need to understand how common tools work. Keep policies current and usable Policies should reflect real risks and be easy to find and follow. They should clearly set out responsibilities, required checks and escalation routes. Strengthen governance Assign clear ownership for information management and ensure senior accountability. Regularly review your processes and learn from incidents across your sector. For more advice read our guidance on disclosing documents to the public securely: https://lnkd.in/egUzNctE
-
-
We’re supporting the Credit Services Association (CSA) in tackling misinformation around what people can and can’t do when their debt is sold or passed to a debt collection firm. The CSA saw a growing trend in people being wrongly advised that they are entitled to receive a Deed of Assignment (DOA) when their debt is sold or passed to a debt collection firm. Some people are also being incorrectly told to request a DOA through a Subject Access Request (SAR) under UK GDPR – all of which is incorrect and can be harmful. We have supported the CSA with their new guidance: https://lnkd.in/e-vgjkax
📢 CSA launches new webpage to tackle misinformation around Deeds of Assignment (DOA) and Data Subject Access Requests (SARs). The guidance, which members are encouraged to share with their customers, has been produced to create awareness of a growing trend in misinformation about a customer’s entitlement to a DOA when their debt is sold or passed to a debt collection firm. This misinformation is incorrect and can be harmful. It may lead to wasted court and regulatory resources, generate avoidable complaints, and create unnecessary legal costs (and prolonged financial difficulties) for people in debt. In response to this, and following discussions with the Information Commissioner's Office (ICO), the dedicated webpage was built to help make consumers more aware of the issues and help to address the common misconceptions around the sale and assignment of debt. The guidance provides clarity around what a DOA is, what it is not, and dispels some common myths including: Myth #1 - Firms must provide a DOA if it is requested. Myth #2 - Refusal means the debt does not have to be repaid. Myth #3 - It means their debt is unenforceable. Myth #4 - Complaining to the ICO or taking civil action will grant access to a DOA. By giving firms a clear and accessible resource to share with customers, the guidance should support greater consistency across the sector, help reduce consumer harm and build awareness and educate customers about the debt collection process. Read the new guidance on the CSA website: https://lnkd.in/e-vgjkax #CreditServices #DebtCollection #DebtPurchase #ConsumerDuty #ConsumerProtection #UKGDPR #DataProtection #DOA #ConsumerSupport #DebtAdvice #FinancialWellbeing #ConsumerRights #DataProtection #DebtAwareness
-
-
Interested in all things AI? In just two weeks at DPPC we're bringing together experts from our organisation and beyond to explore questions you want the answers to on AI and data protection! Whether AI is already part of your day-to-day work or you're trying to keep up with what's coming next, there'll be plenty for you to take away from our insightful AI sessions: 👉 Professor Keeley Crockett will be delivering a keynote on responsible AI, personal data and public trust: from principles to practice. 👉 Learn about AI agents and how they differ from generative AI and the latest on our agentic AI guidance. 👉 Explore AI and automated decision-making, the updated rules and how to assess whether there is meaningful human involvement in a decision making process. 👉 Hear how our FOI team are using AI and discuss the challenges practitioners are seeing as AI increasingly features in FOI requests. 👉 Learn from the UK Black Privacy Professionals Network on how DPOs can improve their AI literacy and stay ahead as technology continues to evolve. This is only part of the agenda for this year's conference! View the full agenda on our website and register for FREE: https://lnkd.in/eCwAqDgf
-
-
Happy FOI Day! Or, if you prefer the full title, the International Day for Universal Access to Information. Whether you're handling requests full-time or fitting them in alongside everything else, FOI practitioners are the people who turn the principle of transparency into something real. Over the past year we've seen plenty of examples of why that matters. We issued 31 practice recommendations and 14 enforcement notices. But these actions aren't just for the organisations receiving them. They are useful case studies for every practitioner. They show what good looks like, highlight common challenges and can provide valuable evidence when you're making the case for improvements in your own organisation. If you're looking for practical support, we're also bringing FOI practitioners together at #DPPC2026 with three sessions focused on some of the biggest challenges facing the profession today: 👉 FOI: ‘Ask me anything’ clinic: put your questions directly to experienced ICO FOI managers and case officers and get practical advice on FOI and EIR issues, whatever your level of experience. 👉 FOI: using technology to deal with rising caseloads: explore how AI is changing the FOI landscape, hear how the ICO is using technology internally and learn more about our new centralised FOI statistics reporting tool. 👉 FOI: applying the public interest test: a practical walk-through of applying the public interest test, including our updated guidance and the implications of the Supreme Court's Montague judgment. You can still register. So make sure you've blocked out the day in your diary. We’ll see you there! Register for DPPC 2026: https://lnkd.in/esGZBg4h FOI is often at its most visible when something goes wrong. Today is a good excuse to recognise all the work that goes into getting it right. Send this to the FOI colleague in your life. Enjoy FOI Day!
-
-
NEW: From safeguarding and social care to health and education, effective public services rely on trusted information sharing – the latest approved UK GDPR Code of Conduct will help public services in Wales to do just that. [Darllenwch y post yma yn Gymraeg: https://lnkd.in/ebZH8Wkx] Today, the Wales Accord on the Sharing of Personal Information / Cytundeb Rhannu Gwybodaeth Bersonol Cymru have launched their ICO approved Code of Conduct for Information Sharing Protocols. Chris Hogan, Head of Regulatory Strategy, said: "We are pleased to support the WASPI Code of Conduct which will help ensure responsible, lawful and accountable data sharing across Welsh public services. Approved under Article 40 of the UK GDPR, it builds on existing good practice within the established WASPI framework, giving organisations a clear and recognised way to demonstrate accountability, transparency and responsible data use. This kind of consistent approach is what helps promote and maintain public trust, particularly in areas like safeguarding, health and social care, where effective information sharing can be critical. We look forward to continuing to work with WASPI as they take this forward." The Code of Conduct introduces six key requirements covering governance, use of approved templates, quality assurance, accountability, reviews of information sharing arrangements and compliance with ongoing monitoring, providing participating organisations with a recognised framework to demonstrate compliance with key UK GDPR principles. You can read more about the code here: https://lnkd.in/e6Vr2MMy If you’re considering how a Code of Conduct could improve your sector’s compliance get in touch with our team: https://lnkd.in/e__6BmMn
-
-
NEWYDD: O ddiogelu a gofal cymdeithasol i iechyd ac addysg, mae gwasanaethau cyhoeddus effeithiol yn dibynnu ar rannu gwybodaeth mewn modd dibynadwy – bydd y Cod Ymddygiad diweddaraf o dan GDPR y DU yn helpu gwasanaethau cyhoeddus Cymru i wneud hynny. Heddiw, mae Cytundeb Rhannu Gwybodaeth Bersonol Cymru wedi lansio’u Cod Ymddygiad ar gyfer Protocolau Rhannu Gwybodaeth a gymeradwywyd gan yr ICO. Dywedodd Chris Hogan, Pennaeth y Strategaeth Reoleiddio: "Rydyn ni’n falch o gefnogi Cod Ymddygiad WASPI a fydd yn helpu i sicrhau bod data’n cael ei rannu mewn modd cyfrifol, cyfreithlon ac atebol ar draws gwasanaethau cyhoeddus Cymru. Mae wedi'i gymeradwyo o dan Erthygl 40 o GDPR y DU, ac mae'n adeiladu ar yr arferion da presennol o fewn fframwaith sefydledig WASPI, gan roi ffordd glir a chydnabyddedig i sefydliadau ddangos atebolrwydd, tryloywder a defnydd cyfrifol ar ddata. Y math yma o ddull cyson yw'r hyn sy'n helpu i hybu a chynnal ymddiriedaeth y cyhoedd, yn enwedig mewn meysydd fel diogelu, iechyd a gofal cymdeithasol, lle gall rhannu gwybodaeth yn effeithiol fod yn hanfodol. Rydyn ni’n edrych ymlaen at barhau i weithio gyda WASPI wrth iddyn nhw symud ymlaen â hyn." Mae'r Cod Ymddygiad yn cyflwyno chwe gofyniad allweddol sy'n ymdrin â llywodraethu, defnyddio templedi a gymeradwywyd, sicrhau ansawdd, atebolrwydd, adolygu trefniadau rhannu gwybodaeth a chydymffurfio a monitro parhaus, gan ddarparu fframwaith cydnabyddedig i’r sefydliadau sy'n cymryd rhan i ddangos eu bod yn cydymffurfio ag egwyddorion allweddol GDPR y DU. Gallwch ddarllen mwy am y cod yma: https://lnkd.in/exBsagyG Os ydych chi'n ystyried sut y gallai Cod Ymddygiad wella’r gydymffurfiaeth yn eich sector chi, cysylltwch â'n tîm: https://lnkd.in/ebJsDU-d You can read the English version of this post here: https://lnkd.in/ejEw-6uh
-
-
With the latest adaptation of Sense and Sensibility landing on our screens this week, it's got us wondering: if Jane Austen's characters had a Data Protection Officer, what would have kept them awake at night? 📜 A disgruntled servant reads their employer's mail and shares salacious gossip around the town. Today we'd call that inappropriate internal access. It's a reminder that access to personal information should be based on role and business need, with regular reviews of who can see what. https://lnkd.in/e6ZVTnZ8 🕊️ An aristocratic marriage proposal carried by pigeon is intercepted before reaching its intended recipient. With no confirmation or denial received from the gentleman, the young lady in question cannot show her face in high society out of shame. The lesson? Consider the security of the channels you use to share personal information and the risks when data is transferred between parties: https://lnkd.in/ex7sT5b3 🔥 A wax seal melts in an unusually hot British summer, exposing sensitive information. Even well-established controls can fail in unexpected circumstances. DPOs know the importance of reviewing risks and adapting safeguards as circumstances change. It's important to build in checks and stress tests to understand how robust your safeguards are in practice: https://lnkd.in/ejYNq5Td 🐎 The mail carriage is driven off the road and the contents of the letters sold to a criminal network. An Austen brute-force attack! You should ensure that cyber security risks are considered as part of your risk management approach: https://lnkd.in/eVyD9S3e 💃 A lost dance card is found and personal information is shared without consent. Data minimisation matters. Collecting, retaining and sharing only the information that's needed can reduce the impact when something goes wrong. https://lnkd.in/eJNsCYkx While Jane Austen's characters didn't have to worry about ransomware or phishing emails, the harm and impact on their social status remain surprisingly familiar.
-