ICO Investigations
The Information Commissioner’s Office (ICO) is calling for views on new guidance setting out how they approach investigations and take enforcement action.
They say that “The guidance aims to increase transparency about the process we follow when we suspect an organisation has failed to comply with its legal obligations to protect people’s personal information under the UK General Data Protection Regulation and Data Protection Act 2018”.
Among other things, the guidance explains:
- How the ICO decides whether to open an investigation and the other ways they may instead seek to resolve any concerns.
- What to expect from the ICO during an investigation.
- How they will use information gathering powers, including their new powers under the Data (Use and Access) Act 2025 to require people to answer questions and organisations to provide reports.
- How they decide on the outcome of an investigation and use of their enforcement powers, such as warnings, reprimands, and enforcement and penalty notices.
- When they consider settlement with a reduced fine is appropriate and the process involved.
Posted on 11/08/2025 by Ortolan



