ICO launches consultations for Data (Use and Access) Act 2025 amendments

In response to the Data (Use and Access) Act 2025 (DUAA) coming into force, the Information Commissioner’s Office (ICO) has launched public consultations to help shape final guidance.   The ICO has produced and is consulting on draft guidance to support organisations in understanding and applying upcoming amendments. These include:  ‘recognised legitimate interest’ which is a new lawful basis, separate from the legitimate interests lawful basis; and  ‘data protection complaints’ which is a new requirement for all organisations to have a process in place for handling data protection complaints.   These guidance…

Read More

ICO release new guidance on disclosing documents to the public

The ICO have released published new guidance to help organisations disclose documents securely.   Their website states: From public authorities handling Freedom of Information requests to organisations responding to Subject Access Requests, many need to regularly disclose documents containing large amounts of information to the public.   Personal information can be hidden or not immediately visible in documents. If they are not checked properly, it may be disclosed by accident – sometimes with serious consequences.   Our guidance includes practical steps and how-to videos to help organisations understand how to…

Read More

Investigations announced into how social media and video sharing platforms use UK children’s personal information

ICO are announcing three investigations looking into how TikTok, Reddit and Imgur protect the privacy of their child users in the UK.  Our investigation into TikTok is considering how the platform uses personal information of 13–17-year-olds in the UK to make recommendations to them and deliver suggested content to their feeds. This is in light of growing concerns about social media and video sharing platforms using data generated by children’s online activity in their recommender systems, which could lead to young people being served inappropriate or harmful content.  Our investigations…

Read More

Direct marketing advice generator makes it easy for organisations to comply with the law

ICO have launched a free online tool to help organisations ensure their direct marketing activities comply with UK law – namely the Privacy and Electronic Communication Regulations (PECR), and the UK GDPR. By using the direct marketing advice generator, small organisations will get reliable compliance advice, tailored to their own direct marketing activities, in minutes. This allows organisations to reach out and promote their products and services to both new and existing customers, as well as share their aims and ideals – and can assist in making sure they’re contacting…

Read More

ICO intervention into AI recruitment tools leads to better data protection for job seekers

The ICO have issued a series of recommendations to AI developers and providers to ensure they are better protecting job seekers’ information rights. AI is increasingly being used in the recruitment process to save time and money, helping to source potential candidates, summarise CVs and score applicants. If not developed lawfully, these tools may negatively impact jobseekers who could be unfairly excluded from roles or have their privacy compromised.   The ICO audited several providers and developers of AI tools for recruitment and made almost 300 recommendations, such as ensuring personal…

Read More