You have received this email as example@emailaddress.test is currently subscribed to receive ICO communications.

Click to unsubscribe
 

Welcome to the ICO's July 2025 e-newsletter

 
 
A photo of Paul Arnold. Paul is wearing a smart blue suite with pink tie. The text reads:  "Paul Arnold MBE, Interim Chief Executive Officer"

Hello! I have the honour of welcoming you to July’s newsletter. I’m Paul, I’ve just been appointed CEO, a new role at the ICO brought about when the Data (Use and Access) Act received Royal Assent on 19 June 2025. You can read what this update to data protection law means for organisations like yours in this newsletter and on our website.
 
The changes from the DUAA will make it easier for UK businesses to protect people’s personal information while growing and innovating their products and services.  
 
But it also means changes at the top of the ICO with the creation of a new Board. I’ll be the new CEO, John Edwards (the current Information Commissioner) will be Chair, and there will be seven Non-Executive Directors (currently being recruited by the Department for Science, Technology and Innovation).  
 
The new board will then be the Information Commission. This change will make us more resilient as a regulator, increasing the diversity of our strategic leadership. 
 
All this will take time, but we’ll keep you updated on progress through a dedicated DUAA newsletter announcing when the new laws commence and when you can expect new guidance and support from us. So make sure you're subscribed.

We’ll also be taking you through it all at our annual #DPPC2025 conference in October, so please do register your place. It’s online, it’s free and there'll be plenty of opportunities to ask questions.

And before that you can join us on 17 July for a fireside chat with the Information Commissioner and the Chief Executive of the British Library as they unpack the lessons learned from the 2023 ransomware attack. More details below.

Enjoy this month’s newsletter.  

Paul Arnold MBE

A picture of a young woman working at her laptop. She has curly red hair and is wearing a light grey jumper. There is a yellow circular arrow around her with brown and yellow boxes for decoration around that.

UK organisations to benefit from new data protection laws

The Data (Use and Access) Act 2025 (DUAA) is new legislation that updates key aspects of data protection law, though it does not replace the UK GDPR, the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR). These changes are designed to make data protection law clearer and more flexible for organisations, while maintaining strong safeguards for individuals. 

Changes to the law include: clarifying how personal information can be used for research; lifting restrictions on some automated decision making; setting out how to use some cookies without consent; allowing charities to send people electronic mail marketing without consent in certain circumstances; requiring organisations to have a data protection complaints procedure and introducing a new lawful basis of recognised legitimate interests.   

The Act provides the ICO with new powers, including the ability to compel witnesses to attend interviews, request technical reports, and issue fines of up to £17.5 million or 4% of global turnover under PECR. 

The DPPC logo: DPPC in capital letters in green and blue with the numbers 2025 next to it on the right hand side. The logo is repeated decoratively as the background.

You've never been to DPPC?

It's great! DPPC is our annual data protection practitioners' conference. Last year 82% of delegates said they learned something new. Whether you are a beginner or specialist, or data protection is only part of your job, DPPC has something for everyone.
 
We will cover the things that are important to you - topics such as AI, cyber security and the DUAA changes Paul talked about in his introduction.

It's free, and there are no transport or overnight costs because it's all online. Register your place today for the conference on 14 October 2025. You're guaranteed a warm welcome.

Circles and triangles
A news icon

We surveyed over 2,000 data controller organisations, and they said....

Our Data Controller Study provides insight and support to our strategic, regulatory, and research activities. The study was launched in 2023 and we’ve just published the second year findings.

For example, the study showed:

  • an increase to 38% of organisations that agree data protection law has been an enabler that has positively influenced core activities
  • 78% of organisations reported facing no financial costs in order to comply with the UK GDPR in the last 12 months

Read the full findings.

New and updated guidance

➡️ Our plans for new and updated guidance where you'll see what we’re developing and when we expect to publish. We’ll update this information regularly so that you can confidently track a product as it develops.

➡️ Guidance for smart product manufacturers which gives clear expectations on how to comply with data protection law and use people’s personal information responsibly. 

➡️ Guide to international transfers now emphasises our expectation for organisation's to 'report early - update later' and includes content on how best to work with the ICO following a breach.

➡️ Learnings from ICO decision notices now includes advice and assistance when refusing under section 12 FOIA, prohibitions on disclosures (section 44 FOIA) and law enforcement exemptions (section 31 FOIA). 

➡️ Advice on when you can aggregate FOI requests which helps when a request would take longer than the "appropriate limit" to comply.


➡️ Catch up on our FOI video sessions featuring our FOI Upstream Regulation team.

Action we've taken

A DNA sequence on a black background. The text reads: "23andMe fined after hacker accessed personal details of over 155,000 UK users."

What happened? We fined 23andMe £2.31 million for failing to implement appropriate security measures to protect people’s information, following a large-scale cyber-attack in 2023.

Between April and September 2023, a hacker carried out a credential stuffing attack to gain unauthorised access to sensitive personal information, family histories and even health conditions of over 155,000 people in the UK. 

A lightbulb
a checklist

What can you take from this case? Don't let this happen to your organisation. Make sure you’ve implemented:
• Secure authentication and verification measures for users to log in such as multi-factor authentication
• Secure password requirements
• Processes to monitor for, detect and appropriately respond to cyber threats

We have guidance to help you:
➡️Comprehensive guidance on data security
➡️Our Learning From Mistakes of Others report explores the common mistakes that are made when it comes to cyber security

The crumpled front end of a black car. The text reads: "Crash details stolen from garages and traded to fuel distressing predatory calls"

Eight men guilty following our largest ever nuisance-call investigation.

What happened? From one initial complaint to us, our investigation snowballed into one of the largest nuisance-call cases we have ever dealt with. After identifying the eight men involved, our investigations team conducted nine warrants in the Manchester and Macclesfield areas. The devices seized under search warrant contained 241,000 emails, 4.5 million documents, 144,000 spreadsheets, 1.5 million images and 83,000 multimedia files.

The impact on you The defendants were found to have conspired together between 2014 and 2017, where they accessed or obtained personal data of people from vehicle repair garages without their consent. Approximately one million records were accessed by the defendants convicted of an offence under the Computer Misuse Act. This data was then sold onto claims management firms hoping to generate potential leads for personal injury claims.

We are continuing our investigations and anticipate further prosecutions of people embedded into insurance companies and claims management companies with the sole aim of stealing personal data.

Get involved with the ICO

Event icon
Event icon

📌 Fireside chat: Navigating a cyber incident - lessons from the British Library
Join us on 17 July (11:00am) for a fireside chat with John Edwards, UK Information Commissioner, and Rebecca Lawrence, Chief Executive of the British Library, where they will unpack the lessons learned from the 2023 ransomware attack. Register today.

📌 Our Innovation Services
These teams support businesses to bring privacy respectful products and services to market quickly, whilst protecting the public’s personal data. Read case studies of our previous Sandbox participants such as the Department for Education and Kestrix to learn more.

📌 Take our website user survey
We’d love your feedback on the ICO website. We’re working to make the ICO website easier to use and more helpful for everyone. This short survey is about your experience using the site. Your input will help us make the website clearer, more useful, and easier to navigate.

Icon of people
We are currently looking to appoint the following roles:
Unsubscribe
If you wish to unsubscribe, please click on the link below.
Please note this is an automated operation.
Powered by Adestra https://newsletter.ico.org.uk/u/1hxUlDPsKt