Cybersecurity Policy Report, U.K.’s Information Commissioner Aims to Raise Public Sector Data Protection Standards, (Nov 12, 2025)
By Tony Foley
The United Kingdom’s Information Commissioner’s Office (ICO) often intervenes at specific organizations that fall short on data protection, but the ICO’s goal is to raise data protection standards across the U.K. public sector, Information Commissioner John Edwards said in a blog post yesterday.
“For the past three years, my office has focused on raising data protection standards across the UK public sector,” Commissioner Edwards said. “We've prioritised early engagement and other enforcement tools such as warnings, reprimands, and enforcement notices, while I’ve exercised my discretion to issue fines for only the most egregious breaches in the public sector.”
Commissioner Edwards said the ICO had reviewed its public sector approach and responded to concerns raised by organizations asking for greater clarity. After a consultation earlier in 2025, the ICO has published updated documentation on which organizations are within scope and the circumstances under which fines may be issued. The post cites the following three advantages to the agency’s public sector approach:
Focusing on improvements rather than punitive actions to build a compliance-first mindset for public sector organizations;
Minimizing unintended consequences to public services and people to avoid risks that may come with issuing large fines; and
Providing regulatory certainty by clarifying expectations before major decisions or investments are made by public sector organizations.
“I’m confident that by prioritising transparency, accountability, and early engagement, we are helping public bodies deliver services that respect people’s data rights while maintaining confidence and trust in the system,” Commissioner Edwards concluded. “But as I’ve said before, I’ll keep our approach under review and reconsider it if necessary.”
News: InternationalLegislation LitigationEnforcement DataPrivacy DataSecurity