Toxic ICO culture perpetuated by executive leadership existed before Edwards
Published: 17/07/2026
| Last Updated: 23/07/2026
| Computer Weekly
In the ongoing saga surrounding the resignation of the former Information Commissioner, John Edwards, an article in Computer Weekly reveals that a toxic workplace culture is being perpetuated by the senior leadership team at the Information Commissioner's Office (ICO). Multiple sources close to the ICO claim that this unhealthy environment has significantly undermined the regulator's effectiveness.
According to the article, staff reported feeling unable to challenge policy decisions or raise concerns due to a lack of psychological safety and a high-handed leadership approach that shut down internal debate.
An internal survey conducted in October 2025 showed that 10% of ICO staff had witnessed or experienced bullying and harassment, with female employees twice as likely to be affected as men. Employees pointed to controversial policy choices, such as Edwards' decision not to fine public-sector bodies for personal data protection breaches, as key examples in which staff input was ignored, causing widespread frustration.
Insiders characterised the issues as systemic, extending beyond Edwards to the wider executive team, including Deputy Commissioner and Interim Chief Executive Paul Arnold MBE. Staff criticised ICO leadership for failing to challenge Edwards, acting as uncritical yes-men, and failing to communicate the strategic rationale behind decisions. There is also a widely held belief that early complaints about Edwards were ignored or suppressed, and that leadership kept staff in the dark after an independent HR investigation led to his initial departure in February at his request.
Sources also noted that structural and cultural issues existed prior to Edwards' tenure. Employees expressed disillusionment with the executive, describing an ivory-tower dynamic and ineffective two-way communication, which resulted in a breakdown of trust, poor decision-making, and low morale. While the ICO has publicly pledged a safe and supportive working environment, staff representatives disputed this claim, calling for the Department for Science, Innovation and Technology (DSIT) or a parliamentary committee to investigate how senior leadership allowed the situation to persist for so long.
It's difficult to gauge the extent to which cultural issues are affecting performance, however, given the 76,743 data protection complaints the ICO received across its 2025-26 financial period. To put this number in context, it's a whopping 81% increase over the 42,315 complaints received the previous year. Other statistics in the ICO's latest annual report show increased activity in several key areas along with a corresponding fall in performance. So while it is apparent the ICO has cultural problems stemming from its senior leadership, it is also experiencing an unprecedented increase in its caseload.
Whatever came first, chicken or egg, it is undeniable that Edwards was and remains a highly unpleasant individual. His latest LinkedIn post, along with an accompanying Substack article for wider exposure, further illustrates this point. These actions reveal the bitterness he feels towards government officials who have justifiably criticised his appalling behaviour. Instead of stepping away quietly, Edwards seems determined to create as much turmoil as possible.
Commenting on Prime Minister Andy Burnham's cabinet announcement, Edwards expressed his personal view that neither Liz Kendall nor DSIT will be missed in digital regulation. He further alleged that Kendall lacked a coherent plan for DSIT, was hyper-fixated on daily media issues, refused to meet with executive leadership, and demonstrated indifference towards data protection and the ICO.
Regarding his thoughts on DSIT being disbanded, Edwards described the department as an inherently incoherent entity plagued by internal squabbling over AI leadership and disrupted by a bungled restructuring by its permanent secretary. In short, Edwards welcomed the decision to break up and redistribute the department across government, concluding that the cabinet reshuffle and structural changes provide a timely opportunity to reset UK digital policy.
Training announcement: Freevacy provides comprehensive training for new and existing practitioners on the changes introduced by the DUA Act to the UK General Data Protection Regulation (GDPR), the Data Protection Act 2018 (DPA18), and the Privacy and Electronic Communications Regulations 2003 (PEC-Regulations). Our courses are always up to date and provide a forum for learning and discussing how to ensure your data protection processes remain compliant. Find out more.
What is this page?
You are reading a summary article on the Privacy Newsfeed, a free resource for DPOs and other professionals with privacy or data protection responsibilities helping them stay informed of industry news all in one place. The information here is a brief snippet relating to a single piece of original content or several articles about a common topic or thread. The main contributor is listed in the top left-hand corner, just beneath the article title.
The Privacy Newsfeed monitors over 300 global publications, of which more than 3,250 summary articles have been posted to the online archive dating back to the beginning of 2020. A weekly roundup is available by email every Friday.