Welcome to the ICO's Jul 2026 e-newsletter
You have received this email as example@emailaddress.test is currently subscribed to receive ICO communications.
Click to unsubscribe

Welcome to the ICO's April 2025 e-newsletter

 
 



John Edwards

Information Commissioner

Hello.

This is April’s newsletter, covering the last month of ICO activity.

We’re feeling nostalgic over here. We’re celebrating our 40th anniversary, marking the occasion with an exhibition. We’re showcasing 40 objects that encompass 40 years of the ICO, which we unveiled at our Back to the Future event in November. We had speakers with a breadth and depth of knowledge and experience, speaking about a common theme – what privacy meant to them, and what object they would add to our exhibition’s empty plinth.

The millennium bug. A school dinner tray. A Tesco Clubcard. An unlikely group, but three objects that were chosen to represent privacy.

This week I was pleased to officially open our physical exhibition for public viewing at Manchester’s Central Library. Seeing our 40 objects, and the stories behind them, I was struck at just how wide-ranging and encompassing our work is. Data protection lies behind some huge stories from the past 40 years.

We’ve witnessed a lot of change in that time, from the launch of social media to new laws giving you the right to access information. And yet, in many ways, very little has changed. The use of our personal information can either improve our lives or cause us harm.

I’d encourage you to go and visit the exhibition in person if you can. It’s available in Manchester Central Library until 30 June and you can see more details on our website.

If you can’t go in person, don’t worry. We have our online exhibition up and running, which includes videos and quotes from people who were part of the story, including previous Commissioners. You can see that, anywhere and at any time, on our website.

Privacy is unique. It means something different to each of us. There are things we're happy to share and things we like to keep private. There are technologies and services we trust and others that we are more suspicious of.

What item from the past 40 years would you add to our exhibition? We’d love to hear the stories behind the objects you put forward. Our empty plinth is waiting for your submissions. You can share your ideas with us on social media, using the hashtag #OurLivesOurPrivacy.

News from the ICO

Graphic of the DPPC 2025 logo in green and blue.

DPPC 2025 registration is now open!

We have now opened registration for this year's Data Protection Practitioners’ Conference (DPPC) taking place online on Tuesday 14 October 2025.

Reserve your seat in the virtual room today.

The event attracts over 5,000 data protection and FOI specialists each year. In 2024, 97% of delegates told us they found it useful and 85% that they had learned something new.

As a newsletter subscriber you'll be the first with all the latest news on speakers, workshops and session topics. We’re planning everything based on the information you share with us, so the sooner you register, the more influence you’ll have on shaping the agenda.

The conference is an opportunity to hear direct from the regulator on the data protection and freedom of information matters that affect you on a daily basis in your profession as information rights practitioners. 

Whether you're a seasoned professional or new to the discipline, you'll benefit from a constructive and accessible day of learning and professional development.

It's free. It's online. It's for you.

Register for the conference today
Four people stand with their backs towards the camera. They are looking at graphics of hexagons with a range of different icons overlaid. They look like they are solving an AI problem together.

Regulation as an enabler for AI opportunities

This month’s Responsible GenAI Forum at the DRCF highlighted how the rapid development of AI has impacts not just for data protection, but across all areas of regulation. And importantly showed why our close collaboration with our partners across the DRCF is so vital.

This nimble regulation and cross-regulatory collaboration means we're not regulating the technology itself but its use cases so that we can give organisations coherence and certainty, allowing the UK to rise to the challenge of AI.

We've already taken action against platforms looking to train their AIs on users' personal information, insisting they be transparent about how people’s data is being used and put effective safeguards in place to provide a clear and simple route for users to object to the processing.

Our recent position paper clarified how data law applies to generative AI so that those making and using AI can be confident they are using personal information responsibly. 

And our latest joint article with the CMA, shows how competition and data protection law apply to the development and deployment of foundational models, and the actions businesses can take to support competitive and innovative foundational model markets while protecting consumers and respecting people’s information rights.

From spurring scientific advances to enhancing productivity for people and businesses, AI can solve complex problems, drive economic growth and transform our lives for the better. And we believe rapid regulation can support that. 

Read the ICO-CMA article

Financial services should improve
how they look after children's information.

We've completed our review into the gathering of children’s data from services supplying them with current accounts, savings accounts, trust accounts, ISAs and prepaid cards.

Ian Hulme, ICO Director of Regulatory Assurance, said: “Children’s data needs specific protection, as they may be less aware of the risks and consequences of it being processed. Children are important customers to the financial services sector, and I would urge those working in this area to read this outcomes report to help them make the improvements that are needed.”  

Our findings include areas that financial services organisations need to make improvements in areas such as governance, transparency and consent.

Read the full findings
Sophie Turner, ICO Senior Regulation Officer for FOI. Sophie has shoulder length hair, glasses and is wearing an ivory jacket and a blue blouse.

20 years of FOIA
at the eCase FOI conference

Sophie Turner, ICO Senior Upstream Regulation Officer for FOI and Transparency, attended this year’s eCase FOI awards. She’s shared her reflections on the event.

It’s been 20 years since FOIA came fully into force and it was wonderful to see over 150 FOI practitioners gather together at the annual eCase FOI Conference and Awards to reflect on the future of FOI. 

Hearing John Edwards, UK Information Commissioner, and David Hamilton, Information Commissioner for Scotland, deliver their keynotes I was struck by how some of the most significant moments in recent UK history have come about as a result of FOI requests. Food hygiene ratings being displayed proactively, the MPs expenses scandal, the refurbishment of schools and other buildings built with RAAC - freedom of information law played a part in all of these, and more.

For me the highlight of the day was being able to be a part of the sessions. Hearing practitioners discuss some of the key issues in information governance like the use of AI in handling requests was a reminder that despite the transformation in technology over the past 20 years – the heart of our work remains the same. All sessions were recorded, and will be available here. I’d really recommend viewing for any FOI practitioners. 

Congratulations to all those who received awards, and thanks to eCase for hosting a great event!

New and updated guidance

➡️ New FOI bitesize products - aim to reduce the inappropriate use of exemptions in FOI responses and will be useful to all practitioners across the public sector.

➡️ Learnings from FOI Tribunal decisions  - Our approach to FOIA and the EIR is informed by case law, which develops through decisions of the courts and tribunals. We've published some learnings from ICO tribunal decisions.

We’ve added the following to our learnings from recent decision notices:
  • using WhatsApp for parish council business (section 3(2) FOIA); and 
  • being specific when applying section 43(2) FOIA (commercial interests). 

➡️ Latest FOI Decision Notices  - If you're looking to understand how WhatsApp messages are shareable under FOIA or EIR, or when you can extend the time to respond to a request, our decision notices should give you real life examples.

We’ve added the following to our learnings from the FOI Tribunals:
  • whether a survey’s privacy notice gave a reasonable expectation of privacy to elected officials (section 40(2) FOIA); and 
  • whether an ongoing inquiry was enough to cause an adverse effect on the disclosure of information (reg 12(5)(b) EIR). 

➡️Anonymisation guidance - will help you develop your understanding of anonymisation techniques, their strengths and weaknesses, and the suitability of their use in particular situations.

We regularly publish updates about all the new guidance, tools and resources due for publication.

Action we've taken

A series of linked icons, glowing blue on a black background. It depicts a network of people connected by data.

Software provider to the NHS, Advanced,
fined £3.07 million for cyber attack 

Our investigation found that hackers accessed certain systems of Advanced’s health and care subsidiary via a customer account that did not have multi-factor authentication. 

Advanced’s subsidiary didn’t have the appropriate technical and organisational measures in place to keep its systems secure prior to the attack. This included gaps in the deployment of multifactor authentication, a lack of comprehensive vulnerability scanning and inadequate patch management.

❔ What can organisations learn from this case? 

➡️ Regular vulnerability scanning and a robust patch management process helps to identify and address security issues promptly and is essential for maintaining the security of sensitive data.   

➡️ Ensure you have suitable access control in place and multi-factor authentication.  

➡️ Processors have a role to play – while as a processor you may have less independence over the data you process, there are legal obligations you must follow, including strong security measures.

Read the full story

Opportunities and events at the ICO

In case you missed it: DPPC is back for 2025!
 

Our free virtual flagship event, the Data Protection Practitioners' Conference (DPPC), is happening on 14 October 2025.

Aimed at people working in data protection, there will be something for everyone regardless of your experience or sector. Last year, more than 5,700 people tuned into our award-winning conference. 97% of them said they found the conference useful and 85% told us they learned something new.

So, put the date in your diary and sign up today

You can catch up with what happened at last year’s event on our dedicated DPPC pages.

Image of a computer with four people on a conference call
📍Our lives, our privacy: the 40 items that shaped 40 years of privacy rights
What: We’re marking our 40th anniversary through an in-person exhibition charting how privacy and information rights have played a pivotal role in prominent moments from the last four decades.
When: April - June
Where: First floor of Manchester Central Library
A picture of two people working at a computer.

Further your career at the ICO

We are currently looking to appoint the following roles:
 
Unsubscribe
If you wish to unsubscribe, please click on the link below.
Please note this is an automated operation.
Powered by Adestra https://newsletter.ico.org.uk/u/1hxTbzHDi5