You have received this email as example@emailaddress.test is currently subscribed to receive ICO communications.

Click to unsubscribe
 

Welcome to the ICO's November 2025 e-newsletter

 
 
A photo of John Edwards. John is wearing a smart blue suit with blue striped tie. The text reads:  "John Edwards, Information Commissioner"

At last month’s DPPC, despite the headlines surrounding AI and cyber security, subject access requests remained the top topic in the Q&A. It didn’t surprise me. Responding to requests remains such a large part of the day-to-day work of data protection practitioners and at times it can be easy to lose sight of what this request really is:

A question someone needs answering.
Evidence someone needs to support their legal case.
Or in some cases, filling in the unknown parts of their own life story.

As we’re seeing in our work to help care-experienced people, accessing information can be a deeply personal and at times traumatic experience. It’s important to remember that subject access requests represent a fundamental human right.

Yet this month, we found South Wales Police falling far short of what we expect. Only 29% of SARs were answered on time last year and as of August there were 352 overdue. It is simply not good enough and so we have issued an enforcement notice requiring the backlog to be cleared by June 2026.

Enforcement notices are a key tool in our regulatory toolbox. They set clear expectations and legally binding deadlines for improvement. They give the organisation a chance to put things right. And in both this case and our action against Bristol City Council, they give the public the confidence that we will protect their right to access their information.

But let me be clear, where failings are serious, or persistent, we will go further. We fined Capita earlier this month following a cyber-attack that affected millions of people. We found the scale of the breach and its impact could have been prevented had sufficient security measures been in place. It simply is not good enough. No organisation is too big to ignore its responsibilities.

At the same time, we know organisations want certainty about how and when we act. That’s why we’ve launched a consultation on our updated data protection enforcement procedural guidance. It’s your chance to shape how we approach enforcement and to help us make our approach clear, fair and transparent.

Latest news from the ICO

Circles and triangles
Circles and triangles
A news icon

▶️ The UK Upper Tribunal handed down its judgment on the Clearview AI Inc case. The decision has clarified the material and territorial scope of the UK GDPR reaffirms that companies that wish to monitor the behaviour of UK residents will be in scope of UK data protection law, regardless of where the company is based in the world.  

▶️ We've published our Internal AI use policy as a helpful starter for anyone considering how to embed AI within their own organisation.

▶️ The ICO has joined 30 other data protection and privacy authorities worldwide to evaluate the privacy practices of websites and mobile applications popular with children, as part of the 2025 Global Privacy Enforcement Network (GPEN) privacy sweep.

New and updated guidance

▶️ You can watch all our DPPC recordings including the DPPC+ videos. Hear experts in the field answer your biggest questions on everything from AI to the changing world of FOI. 

▶️
 Work in charity? We've published our draft guidance on the upcoming changes to the "charitable purpose soft opt-in". It means charities will be able to send electronic mail marketing about their charitable purposes without the recipient’s consent, as long as they meet a number of requirements.
 

▶️ We're recommending organisations look at NCSC's Cyber Action toolkit. It's packed with the government's latest cyber security advice for small businesses and aims to help protect your business from the growing threat of hackers.


▶️ We've updated sections of our Part 3 law enforcement guidance. See new sections on logging, consent and national security exemption following Data Use and Access changes.

▶️We've published the our draft data protection enforcement procedural guidance. It sets out
the process we follow throughout the duration of an investigation, from opening the case and information gathering, through to reaching a decision on whether to use our statutory enforcement powers.


You can always stay up to date with our plans for new and updated guidance where you'll see what we’re developing and when we expect to publish. We’ll update this information regularly so that you can confidently track a product as it develops.

Paul Arnold



CEO's update

Paul Arnold 

This month, I had the privilege of joining the Modernising Employment All-Party Parliamentary Group for a vital discussion on "The AI Shift: Rethinking Work, Skills and Hiring".

AI has the potential to be a powerful force for good, but if deployed without safeguards, it risks amplifying existing inequalities. And that's why one of the key messages I wanted to share during the debate was that the ICO is here to help. We want to support businesses to innovate and show how they can do this, whilst still building in the protections that are set out in data protection law.

I also highlighted how transparency and robust safeguards are critical. Automated decision making can significantly influence people’s lives, including their employment opportunities. We committed to setting out clear expectations for responsible use of automated decision making in recruitment through our AI strategy launched in June. We’ve been working closely with organisations throughout this year and will publish our findings and regulatory expectations in the new year.

Our goal is simple: to ensure automated recruitment processes are fair, transparent and trusted, while supporting growth and innovation across the economy.

Action we've taken

Capita fined £14million for data breach affecting over 6 million people.

What happened? 

The attack began when a malicious file was unintentionally downloaded onto an employee device on 22 March 2023. Despite a high priority security alert being raised within 10 minutes of the breach and some immediate automated action being taken, Capita did not quarantine the device for 58 hours, during which the attacker was able to exploit its systems.
 

This file enabled the deployment of malicious software onto the Capita network, allowing the hacker to stay in the system, gain administrator permissions and access other areas of the network. Between 29 and 30 March 2023, nearly one terabyte of data was exfiltrated. On 31 March 2023, ransomware was deployed onto Capita systems and the hacker reset all user passwords, preventing Capita staff from accessing their systems and network. We received at least 93 complaints in relation to this attack.

A lightbulb
A lightbulb

What can you take from this case? We found that Capita failed to implement appropriate technical and organisational measures. Organisations should: 

➡️ Ensure the principle of privilege is applied across your organisation to prevent unauthorised lateral movement.

➡️ Build regular monitoring and incident response. The NCSC Exercise in a Box tool can help you practice your incident response in a safe environment.

➡️Share findings from penetration testing across your whole organisation so risks can be universally addressed.

A newspaper
A newspaper
A newspaper

A former insurance claims advisor has been sentenced for unlawfully accessing personal injury claim records

We've secured a winding up order shutting down Breathe Services Ltd, a company that made over four million unlawful marketing calls.
We've issued a £200,000 fine to a sole trader who sent nearly one million spam texts

We have issued Practice Recommendations to eight Stormont departments for failing to publish quarterly compliance statistics under FOI.

Get involved with the ICO

Event icon
Event icon
Event icon
Event icon

📢 We're looking for your input on our latest guidance, frameworks and policy positions - it's part of our commitment to create practical advice that works for you.

🚨 Closing this month: 


🚨 Still have time

Event icon

Join the ICO Sandbox: Now in its fifth year, our Regulatory Sandbox is a free service which offers bespoke, one-to-one support from our data protection experts. Visit ico.org.uk/SandboxApply by 14 November 2025.

  

job icon

Vacancies at the ICO
 

Unsubscribe
If you wish to unsubscribe, please click on the link below.
Please note this is an automated operation.
Powered by Adestra https://newsletter.ico.org.uk/u/1hxUT6jFzi