惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
A
About on SuperTechFans
WordPress大学
WordPress大学
I
InfoQ
The GitHub Blog
The GitHub Blog
N
Netflix TechBlog - Medium
Hugging Face - Blog
Hugging Face - Blog
阮一峰的网络日志
阮一峰的网络日志
Last Week in AI
Last Week in AI
Recorded Future
Recorded Future
D
DataBreaches.Net
大猫的无限游戏
大猫的无限游戏
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
aimingoo的专栏
aimingoo的专栏
月光博客
月光博客
罗磊的独立博客
博客园 - 叶小钗
量子位
H
Hackread – Cybersecurity News, Data Breaches, AI and More
T
The Blog of Author Tim Ferriss
Vercel News
Vercel News
G
Google Developers Blog
F
Fortinet All Blogs
博客园 - 三生石上(FineUI控件)
Microsoft Security Blog
Microsoft Security Blog
Engineering at Meta
Engineering at Meta
IT之家
IT之家
S
SegmentFault 最新的问题
B
Blog RSS Feed
MyScale Blog
MyScale Blog
Jina AI
Jina AI
The Register - Security
The Register - Security
Stack Overflow Blog
Stack Overflow Blog
博客园 - Franky
Attack and Defense Labs
Attack and Defense Labs
Webroot Blog
Webroot Blog
H
Hacker News: Front Page
C
Check Point Blog
博客园_首页
云风的 BLOG
云风的 BLOG
Recent Announcements
Recent Announcements
Schneier on Security
Schneier on Security
T
Tailwind CSS Blog
The Last Watchdog
The Last Watchdog
宝玉的分享
宝玉的分享
B
Blog
O
OpenAI News
博客园 - 【当耐特】
有赞技术团队
有赞技术团队
D
Docker

Open Rights Group

Wanted: Government to fix the ICO Joint Letter: Protect VPNs Open letter for an investigation into the ICO over eVisas Civil society organisations call for ICO to be investigated over eVisas The end is nigh for US data transfers How AI in asylum decision-making drives failure and cost Dear Andy, we need a complete reset on digital policy John Edwards resignation is opportunity to appoint a regulator with teeth AI in Asylum Decisions: Transparency and Accountability Failures Stop Killing the Internet: New global movement launches MPs urged to vote for a Digital Sovereignty strategy The social media policy ratchet Starmer’s social media ban fails to address root causes of online harms This refugee week, take courage! The rise of copyright trolling Growing up in an online world: ORG Consultation Response Reset the ICO The ICO isn’t doing its job – why the data watchdog needs to be reset ORG response to ICO call for views on our approach to regulating online advertising ORG response to Consultation on the ICO’s approach to data protection complaint handling Companies and civil society warn that UK is undermining open web Papers Please! MPs back mass online digital ID checkpoints MPs call for publication of secret documents that outline chronic risks from UK’s dependence on Big Tech New report: UK needs digital sovereignty strategy to address threats from reliance on big tech The case for Digital Sovereignty and the Digital Commons After the LA Court verdict, the UK must disrupt surveillance capitalism business models 13 year olds could be compelled to use unregulated age verification Children’s Wellbeing and Schools Bill: Analysis of Amendment 38b ICO must investigate Reform ‘competition’ for data protection breaches Break privacy to make privacy? Age verification isn’t the answer Home Office use of AI in asylum cases likely to be unlawful, legal opinion finds Legal Opinion: The use of Artificial Intelligence tools in asylum cases MPs give ministers powers to restrict entire Internet Board Election Results Palestine Action ruling: Human rights organisations call for Ofcom to issue guidance on content takedowns
The ICO isn’t doing its job – why the data watchdog needs an overhaul
Mariano dell · 2026-05-15 · via Open Rights Group

Digital Privacy

The Information Commissioner’s Office (ICO) is currently missing its Commissioner, after unspecified HR complaints about John Edwards. Whatever the reasons for his absence, the Commissioner’s decision to step back from his role is an opportunity to take stock of the direction of travel of the ICO and outline why it needs a reset.

Under John Edwards’ leadership, the ICO has seen a steady erosion of independence and regulatory integrity. This has affected their ability to effectively oversee public bodies use of personal data.

On top of that, the ICO adopted a new, underwhelming policy to deal with data protection complaints, and signed a Memorandum of Understanding that further reduces their arms-length from government. It has also emerged that the ICO is advising the government on how to undercut the Freedom of Information Act, a pillar of government transparency and accountability.

Due to changes introduced by the Data (Use and Access) Act, the ICO is also due to be restructured into an Information Commission. Left to their own devices, however, there is little to suggest the ICO would self-heal with a change of leadership, or depart from the path they have been set upon.

This is why Open Rights Group has launched a petition calling for an overhaul of the ICO.

So how did we get here? And what do we need to do?

IT STARTED WITH POLITICAL SHIFT…


With GDPR coming into force, the ICO gained new powers to investigate and issue substantial fines. This led to some early and high-profile interventions, such as a record fine to British Airways, or the investigation into Facebook and Cambridge Analytica. These early, positive signals were short-lived.

Post Brexit, the Johnson government signalled that it wanted to dismantle meaningful data protection in favour of business monetisation, in its strategy, Data: a New Direction. The ICO’s behaviour was already too close too government, as ORG noted during the pandemic.

In 2021, the department for digital published the Data: a New Direction consultation, outlining a wholesale deregulation of UK data protection law and the biggest attack to this date on the British public’s right to data protection. That same year, Elizabeth Denham left the post of Information Commissioner, despite being only 5 years into her 7 year term.

ACCELERATED BY A POLITICAL APPOINTMENT…

Oliver Dowden, then minister for digital under Boris Johnson’s government, announced the selection of a new Information Commissioner as a first step toward reshaping the country’s approach to data protection. The move fitted a broader trend toward the politicisation of public appointments. The resulting vacancy notice stated that the Commissioner was expected to “support the government deregulatory agenda”. A cross-party group of 30 MPs and Lords called on the government “to halt the recruitment process and restart it”, after removing “recruitment criteria pertaining to matters of policy that are outside of the remit of this statutory regulator”.

Following the appointment of John Edwards, our worst fears materialised already during the debate around the UK data protection reform. The ICO muted some of its previous criticisms toward the reform, and quickly became the only regulator to fully support the government’s proposals against the concerns raised by the Equality and Human Rights Commission, the National Data Guardian, the Biometrics Commissioner, the Scottish Biometrics Commissioner, and the Northern Ireland Human Rights Commission.

When the 2024 election was called, the UK data protection reform was dropped. A response to a Freedom of Information request revealed that John Edwards expressed huge disappointment about the news, but explained the ICO would be reviewing what proposals of the reform could be salvaged “where legislative changes were not strictly required”. John Edwards was quick to cheer the new Labour government when they resurrected the reform.

PLACED A LEASH ON THE WATCHDOG…

Soon after his appointment, John Edwards announced the new, so-called public sector approach to enforcement, under which the ICO began to heavily rely of reprimands. These are non-enforceable, written notices where the ICO points out that the law has been broken without taking any regulatory action to remedy an infringement or holding law-breakers to account. This move was presented as part of the ICO25 strategy, shifting the focus away from the monitoring and application of UK data protection law, and toward “empowering people through information” instead.

As ORG’s alternative ICO annual report 2023-24 showed, reprimands lacked effectiveness and deterrence. Indeed, the ICO post-implementation review of the public sector approach will later reveal how the volume of complaints raised by UK residents about public sector organisations’ use of their data has increased substantially as a result.

The weakness of this approach reached its climax with the Afghan data breach: an unprecedented incident that, reportedly, led to the death of at least 49 people in the aftermath of the Taliban’s takeover of Afghanistan. The ICO decision to not even open an investigation led to a Parliamentary inquiry from the DSIT Select Committee, and an open letter from 70+ data protection experts lamenting a collapse in enforcement action. Dame Chi Onwurah, the Chair of the Committee, acknowledged the “institutional failure” of the ICO.

AND MADE THINGS WORSE NOT BETTER

The ICO are supposed to be a countervailing power, that ensures government policies are implemented without unjustly sacrificing our right to privacy and data protection. However, independence has historically been a weak spot. ORG’s report on data protection oversight during the pandemic already found that the ICO looked more interested in acting as the government’s “critical friend” rather than as a regulator. Since then, the UK data protection reform further tightened the government’s grip over the ICO. Then John Edwards capitulated to the Labour government’s demands to direct regulatory activities toward removing “barriers for businesses” and submitted to a number of pledges to “promoting growth”.

In fact, the ICO have recently taken steps to make things worse. By signing a new Memorandum of Understanding with the government, the ICO are moving toward what ministers have described as a “relationship of partnership rather than opposition”. By adopting a new complaints-handing policy, the ICO are effectively telling they will not be acting to investigate or remedy data protection infringement reported by the public.

Most recently, it has emerged that the ICO are advising the government on how to water down the Freedom of Information Act, and undercut the public’s ability to demand transparency. Like with the data protection reform before, the ICO are providing intellectual cover for the government’s plans to curtail the regulatory framework they are tasked to enforce.

NOW WE NEED CHANGE

As the Commissioner’s tenure comes to an end, it is time to acknowledge that the direction the ICO has taken is, for the greater part, negative. However, is is also true that the ICO current faults are rooted in government interference and lack of the necessary arms-length to carry out their job as written in the law. The faults which characterised the ICO under its current leadership will survive unless the ICO are shielded from executive pressures, and made accountable to Parliament and the law, rather than government.

This is why we are launching a campaign to reset the new Information Commission. We want the ICO to:

  • Be accountable, with a clear right to appeal for individuals who are let down by inaction.
  • Put the public first with a clear responsibility to enforce the law.
  • Be independent from government and directly accountability to Parliament.
  • Put rules in place that prevent revolving doors or other undue corporate influences in the Information Commission’s functioning.
  • Let public interest organisations like ORG represent the public, giving individuals alternative avenues to pursue justice when their data protection rights are infringed.

Things don’t need to get worse before they get better: sign up to our petition or join us in our fight to protect our rights in the digital age.

Petition: Reset the ICO

Protect the people, not the powerful with a regulator that will enforce data protection.

Sign now

Reset the ICO

Related Blogs

Digital Privacy

11 Feb 2026 By Open Rights Group

To consent or pay?

If you live in the UK and have a Facebook or Instagram account, you have probably received a message when you’ve logged in asking you if you “Want to subscribe or continue to use our Products for free with ads?

Find Out More

Digital Privacy

14 Jan 2026 By Jim Killock

Techno-Permacrisis

Musk’s latest venture, image generation in Grok that until Wednesday lacked sufficient guardrails to prevent the easy production of non-consensual sexual images and even child abuse images, provoked an Ofcom investigation and further EU Commission action as well as the promise of UK emergency legislation against apps that provide such images in less than a week.

Find Out More

Digital Privacy

18 Sep 2024 By Jim Killock

e-Visas: The Next Digital Windrush Scandal

Our report, “Hostile and Broken” released today, explains why e-Visas risk creating tens or hundreds of thousands of errors, with people potentially turned down for jobs, or unable to enter the country, as the result of electronic failures of the new online, real time re-checking inherent in the UK e-Visa scheme.

Find Out More

Digital Privacy

16 Jul 2024 By Mariano delli Santi

Meta Wants to Make Us its AI Guinea Pigs

Meta, the company that runs Facebook and Instagram, has announced plans to repurpose most of the personal data that they ever collected about you, to train their “artificial intelligence (AI) technologies” — without, of course, asking your permission to do so.

Find Out More

Digital Privacy

20 Mar 2024 By Mariano delli Santi

The ICO Must Toughen Up

As the House of Lords finally begins scrutiny of the UK data protection reform, Open Rights Group urges peers to support amendments that would strengthen the independence and effectiveness of the UK data protection authority, and bolster the public’s right of seeking a remedy against an infringement of their rights.

Find Out More

Digital Privacy

01 Aug 2013 By Jim Killock

Diane Abbott responds on web forum blocking

On a cycling forum, members who are rightly worried that their forum may be blocked by default filters, Skydancer posted a response he was given by Diane Abbott: I do not believe that the arrangements to protect children from hard core porn online will affect a forum to discuss cycling!

Find Out More

Digital Privacy

13 Jun 2013 By Jim Killock

Website filtering problems are a ‘load of cock’

The motion laid down by Labour says: That this House deplores the growth in child abuse images online; deeply regrets that up to one and a half million people have seen such images; notes with alarm the lack of resources available to the police to tackle this problem; further notes the correlation between viewing such images and further child abuse; notes with concern the Government’s failure to implement the recommendations of the Bailey Review and the Independent Parliamentary Inquiry into Online Child Protection on ensuring children’s safe access to the internet; and calls on the Government to set a timetable for the introduction of safe search as a default, effective age verification and splash page warnings and to bring forward legislative proposals to ensure these changes are speedily implemented.

Find Out More

Digital Privacy

26 Apr 2013 By Claudia Mateus

Digital Surveillance video

The Digital Surveillance report – to be launched at a public event on Monday – gives a history of surveillance policy, looks at the current state of the law, examines why technology poses a problem and offers alternative, more targeted and more accountable approaches.

Find Out More

Digital Privacy

28 May 2012 By Peter Bradwell

Reporting ‘over-blocking’ to mobile operators

Since we published our report ‘Mobile Internet censorship: what’s happening and what to do about it‘, jointly with LSE Media Policy project, a number of people have been in touch with us asking what to do if they discover their site is blocked incorrectly by mobile networks’ child protection filters.

Find Out More

Digital Privacy

23 Jan 2012 By Peter Bradwell

UK Mobile operators censor privacy tool ‘Tor’

Open Rights Group and Tor have established that UK mobile networks such as Vodafone, O2 and 3 are filtering UK users’ access to Tor’s primary website (meaning the HTTP version of the Tor Project website, rather than connections to the Tor network) on pre-paid contractless accounts.

Find Out More

Digital Privacy

01 Nov 2011 By Peter Bradwell

Joint letter to the Foreign Secretary

To coincide with the start of the London Conference on Cyberspace, eleven organisations and experts on freedom of expression and privacy online have today written to the Foreign Secretary stating that Britain’s desire to promote these ideals internationally is being hampered by domestic policy.

Find Out More

Digital Privacy

20 May 2010 By Jason Kitcat

Changing the way we vote

In the sixth of our series on the challenges facing the new government, Jason Kitcat looks at proposals for changes to the way our elections are run, including dangerous calls for e-voting.

Find Out More

Digital Privacy

17 Apr 2009 By Jim Killock

Wikipedia blocks Phorm

Wikipedia have announced that they are blocking Phorm as they consider the scanning and profiling of our visitors’ behavior by a third party to be an infringement on their privacy.

Find Out More

Digital Privacy

17 Mar 2008 By Becky Hogge

Phorm update

It’s difficult to tell which of today’s developments the UK’s major ISPs should be more worried about – the fact that Sir Tim Berners-Lee has publicly stated that he would change his ISP if it started employing systems, like Phorm, which could track his activity on the internet, or the news that UK digital rights gurus the Foundation for Information Policy Research (FIPR) have today written an open letter to the Information Commissioner, urging him to look at the legality of Phorm.

Find Out More

Digital Privacy

24 Oct 2007 By Jason Kitcat

Gould Review on Scottish Elections Published

The Electoral Commission and the separate review by Ron Gould that the Commission instituted have published their reports on the Scottish elections of May 2007 The Gould Review in particular identifies a number of important issues, many of which ORG addressed in our own report on the elections published this June.

Find Out More

Digital Privacy

03 Sep 2007 By Becky Hogge

Gordon Brown at the NCVO: e-Voting off the agenda?

In a speech to the National Council of Voluntary Organisations this morning, Gordon Brown announced he would be convening a Speaker’s conference on voting reform: Today I am proposing to the Speaker that he calls a conference to consider, against the backdrop of a decline in turnout, a number of important issues, such as electoral registration, weekend voting, and the representation of women and ethnic minorities in the House of Commons.

Find Out More

Digital Privacy

16 Jan 2007 By Michael Holloway

Taking the lid off e-voting

While the Department for Constitutional Affairs have left us in the dark with no news at all about the e-voting pilots due for May 2007, The Open Rights Group and FIPR have been hard at work.

Find Out More