Information Commissioner Edwards provides an update on his public sector approach

11/11/2025 | ICO

In a blog article, Information Commissioner John Edwards provides an update on the public sector approach to enforcement at the Information Commissioner's Office (ICO). The approachintroduced in June 2022, prioritises raising data protection standards through engagement and non-punitive enforcement tools rather than awarding fines for regulatory infringements. This means that for the last three years, the ICO has focused on warnings, reprimands, and enforcement notices, exercising discretion to issue fines for "only the most egregious breaches."

Commissioner Edwards believes this approach has three clear advantages. First, it focuses on improvements over punitive actions, encouraging public authorities to adopt a compliance-first mindset and embed data protection by design and default. 

Second, the strategy minimises unintended consequences, as large fines risk harming the same people affected by a breach by reducing budgets for vital public services. Reprimands are viewed as effective, as their publication creates strong reputational incentives for compliance while providing valuable lessons for other organisations.

Third, early engagement provides regulatory certainty, clarifying data protection expectations before significant investments are made. Edwards cites the examples, including sustained engagement on the £330 million NHS Federated Data Platform and advising a Northern Ireland regulator on a vulnerable customer register. 

Following a report and consultation in December 2024, the ICO has now published a clearer definition of in-scope organisations and the specific circumstances under which a fine may be issued. The ICO has also published a summary of the consultation responses.


Training Announcement: Freevacy offers a range of short one-day courses on a range of data-related subjects, including data protection topics such as conducting DPIAs and privacy-by-design, as well as how to use AI tools responsibly, cybersecurity best practices, and information access. The interactive sessions cover basic concepts through to advanced examinations of specific areas. Find out more.

Read Full Story
ICO website

What is this page?

You are reading a summary article on the Privacy Newsfeed, a free resource for DPOs and other professionals with privacy or data protection responsibilities helping them stay informed of industry news all in one place. The information here is a brief snippet relating to a single piece of original content or several articles about a common topic or thread. The main contributor is listed in the top left-hand corner, just beneath the article title.

The Privacy Newsfeed monitors over 300 global publications, of which more than 6,250 summary articles have been posted to the online archive dating back to the beginning of 2020. A weekly roundup is available by email every Friday.