You have received this email as example@emailaddress.test is currently subscribed to receive ICO communications.

Click to unsubscribe
 

Welcome to the ICO's August 2025 e-newsletter

 
 
A photo of John Edwards. John is wearing a smart blue suit with blue striped tie. The text reads:  "John Edwards, Information Commissioner"

Hello – and welcome to the August newsletter.

I’ve spent much of my summer so far engaging with leaders across Parliament, government and industry. These conversations have spanned topics from artificial intelligence to organisational transformation, but they’ve all centred on a shared ambition and desire to ensure that the public sector innovation is built with privacy and data protection in mind. And that our work enables businesses to maximise their legitimate and responsible use of personal data

I’ve heard this in my meetings at DSIT alongside our newly appointed CEO, Paul Arnold. Together we met with Secretary of State Peter Kyle MP to reflect on the ICO’s next chapter following the passage of the Data Use and Access Act. And in my discussions on our AI strategy with Lord Ranger, a key voice in the AI debate and through conversations exploring the future of biometrics and policing with Sir Brian Leveson.  

What’s become increasingly clear through these exchanges is that personal data is no longer a side note in policy; it’s at the heart of the society we live in. From AI in policing, to digital transformation of public services, the use of personal information brings opportunities, innovation and real public benefits. But as those of us in the data protection community know all too well, that benefit comes with responsibility. When people entrust us with their data, we must ensure it is used responsibly and safeguarded at every step.

That principle was brought into sharp focus last month with the public announcement of the Ministry of Defence breach. It served as a stark reminder of both what’s at stake when personal data is mishandled and the important role that the ICO has as the regulator.

People rightly look to us to uphold and protect their information rights. And when things go wrong, they expect us to explain not only what happened but show how we’re working with organisations to help improve things. Our latest disclosing documents guidance is a step towards that. It includes practical steps and how-to videos to help organisations understand how to check documents for hidden personal information and reduce the risk of a data breach. We’re engaging with key stakeholders to make sure this advice is in front of those who need it. And we’re committed to help organisations get this right and ensure that a culture of privacy and data protection runs through all innovation.

Latest news from the ICO

A picture of a young woman working at her laptop. She has curly red hair and is wearing a light grey jumper. There is a yellow circular arrow around her with brown and yellow boxes for decoration around that.

What’s the one thing you want on the DPPC 2025 setlist this year? 
 

This year’s Data Protection Practitioners' Conference (DPPC) is on Tuesday 14 October and we’re proud to announce this year’s list of seminars.
 

The day includes all the things you told us you most wanted to hear about. Highlights include:  

  • The ultimate guide to DUAA  
  • Behind the headlines of cyber attacks  
  • Where to start with artificial intelligence  
  • Everyday data-sharing 
 

Whether this is your first time attending the DPPC, you haven’t been in a while or you are a seasoned guest, you can be sure that you will be spoilt for choice when it comes to the workshops on offer. So, if you are still yet to sign up or know someone that would enjoy this year’s free and virtual event, register now. We look forward to seeing you on 14 October! 

Register your place today 

Circles and triangles
Circles and triangles
A news icon

 Children’s Data Lives Research Our annual research looks at how children and young people view everything from privacy policies to age assurance mechanisms. A must read for DPOs and anyone designing online services for children.

What do the digitally disengaged think about privacy in our increasingly online world? For the first time our public attitudes survey on information rights has interviewed those with minimal online interactions to find out their views on online harms, data privacy and emerging issues such as consent or pay. 


Our Annual Report reflects on our 40 year history as the UK information rights regulator. It sets out how we've evolved and our work o meet the challenges of regulating a modern, data-driven society in 2024-2025. 

Warren Seddon


Director's Update

Warren Seddon Director of FOI

This year marks a significant milestone - 20 years since the Freedom of Information (FOI) Act came into force. For two decades, this legislation has empowered people to ask questions, seek transparency and hold public bodies to account on the issues that matter most to them.

As the regulator, one of our core responsibilities is to ensure that public organisations are meeting their legal obligations. As part of this we’ve taken a closer look at how one vital part of the public sector - NHS trusts in England - are performing when it comes to FOI compliance.

Our deep dive involved analysing data from 31 NHS trusts and visiting eight to hear directly from staff. We found compliance rates varied widely, from 10% to 100%, with smaller trusts generally performing better. Common challenges included rising request volumes, limited resources, and concerns around releasing sensitive IT information. The data indicates that only around 0.4% of FOI requests received by NHS trusts in England result in a complaint being dealt with by the ICO – suggesting that on the whole, NHS trusts are doing pretty well.

What can you take from this work? We'd encourage all practitioners to put thorough FOI processes in place, build networks of FOI champions, and publish frequently requested data.

Looking forward, in response to this insight we’re developing targeted support. This includes guidance on IT disclosures and sector-specific resources. 

New and updated guidance

➡️ Profiling tools for online safety guidance will help user-to-user services who are using, or considering using, profiling to meet their obligations under the Online Safety Act 2023.

➡️ Disclosing documents to the public securely is a practical guide to checking documents for hidden personal information with tips on how to remove or redact data.

➡️ We've published new advice for GPs on responding to FOI requests.

➡️  Watch our webinar with Rebecca Lawrence, CEO of the British Library to pick up practical steps and learn what it's like to deal with a ransomware attack.

➡️ We've added to our library of FOI case studies. Learn how NHS Informatics Merseyside have built a network to improve practice and Westmorland and Furness Council's response to a practice recommendation improved their compliance.

➡️ Our plans for new and updated guidance where you'll see what we’re developing and when we expect to publish. We’ll update this information regularly so that you can confidently track a product as it develops.

Action we've taken

Adoption charity fined £18000 after destroying irreplacable personal recrods

What happened? In January 2021, Birthlink reviewed whether they could destroy ‘Linked Records’ as space was running out in the charity’s filing cabinets where they were stored. ‘Linked Records’ are files of cases where people had already been linked with the person they sought and can include handwritten letters from birth parents, photographs, and copies of birth certificates. 

A Board meeting agreed that retention policies should apply to certain files, and only replaceable records could be destroyed. Birthlink destroyed an estimated 4,800 personal records, with up to ten percent considered irreplaceable. Due to poor records keeping Birthlink were unable to identify people affected by the breach.

A lightbulb

What can you take from this case? This case is a powerful reminder of the harm that can come from a loss information. 

It's crucial that you build a strong culture of records management into your business and that all staff understand the impact of this kind of data breach. Use our data protection audit toolkits to assess and take actions to improve your approach to records management.

A police conduct investigator has been fined £200 and orded to pay £2,000 costs after unlawfully obtaining sensitive case details. Mohammed Ejaz, a lead Independent Office for Police Conduct investigator, sent an email to his private Hotmail account containing restricted, sensitive information.  

A lightbulb

We've ordered four NHS trusts to take immediate steps to improve their FOI compliance due to extensive backlogs. We have issued three practice recommendations and one enforcement notice. 

Get involved with the ICO

Event icon
Event icon
Event icon
Event icon

📢 We're looking for your feedback on our latest guidance - it's part of our commitment to create practical advice that works for you. You can let us know your thoughts on our:
 


📢  Call for views on our approach to regulating online advertising  - closes 29 August 2025. We're exploring if there is an opportunity for new commercially viable advertising models that can support innovations to improve consumer privacy and boost economic growth.  Please let us know your thoughts to help shape our approach.

Icon of people
We are currently looking to appoint the following roles:
Unsubscribe
If you wish to unsubscribe, please click on the link below.
Please note this is an automated operation.
Powered by Adestra https://newsletter.ico.org.uk/u/1hxUtmyAtA