ICO publishes new draft data protection enforcement procedural guidance
31/10/2025 | ICO
The Information Commissioner's Office (ICO) has published new draft guidance and launched a public consultation on the process it follows when conducting investigations and taking enforcement action under the UK General Data Protection Regulation (GDPR) and the Data Protection Act 2018 (DPA18).
The guidance is intended to increase transparency for organisations that process personal data and their advisers by explaining the investigation process, from opening a case to gathering information and issuing the final decision on the use of statutory enforcement powers.
The draft guidance also incorporates new and amended investigatory and enforcement powers granted by the Data (Use and Access) Act 2025 (DUA Act), including the ability to require individuals to answer questions and mandate the preparation of compliance reports. When finalised, this guidance, along with the ICO's Data Protection Fining Guidance, will constitute the updated statutory guidance required under the DPA18.
The ICO notes that it intends to apply the same enforcement approach to the Privacy and Electronic Communications Regulations 2003 (PEC-Regulations) and the Electronic Identification and Trust Services for Electronic Transactions Regulations 2016 (EITSET), as their investigatory powers are now broadly aligned with the data protection legislation following the DUAA. However, the ICO is interested in views on whether to publish consolidated guidance or separate guidance for each regime.
This consultation closes on 23 January 2026.
Training Announcement: Freevacy offers a range of independent data protection qualifications from IAPP and BCS. Our certified courses are available at foundation and practitioner levels and cover multiple legal jurisdictions, data protection operations management, and the implementation of complex privacy solutions in technical environments. Find out more.
What is this page?
You are reading a summary article on the Privacy Newsfeed, a free resource for DPOs and other professionals with privacy or data protection responsibilities helping them stay informed of industry news all in one place. The information here is a brief snippet relating to a single piece of original content or several articles about a common topic or thread. The main contributor is listed in the top left-hand corner, just beneath the article title.
The Privacy Newsfeed monitors over 300 global publications, of which more than 6,250 summary articles have been posted to the online archive dating back to the beginning of 2020. A weekly roundup is available by email every Friday.