Arnold and ICO executive team 'appauled' by Edwards' behaviour
Published: 11/08/2026
A LinkedIn post by Jon Baines highlights two recent disclosures under the Freedom of Information Act 2000 (FOIA) by the Information Commissioner's Office (ICO) concerning the now disgraced former Information Commissioner, John Edwards. The disclosures reveal further details about the regulator's internal communications after Edwards resigned following an independent HR investigation that found a case to answer over claims of inappropriate sexual language, bullying, and discrimination.
In a cache of communications, the ICO disclosed an email sent to staff on 24 June by Deputy Commissioner and Interim Chief Executive Paul Arnold MBE, alongside the executive team. The email clarified that Edwards' resignation did not alter the investigation's findings regarding sexual harassment, bullying, and discrimination, describing his actions as completely at odds with organisational values.
Addressing the findings, the executive team expressed feeling "disgusted, appalled, and deeply let down." The email goes on to reject Edwards' attempt to characterise his behaviour as mere inappropriate humour or to attribute it to cultural or generational differences, stating that "there is no place for sexually explicit language or derogatory behaviour in any workplace." The email stressed that Edwards' behaviour went beyond inappropriate comments to involve conduct that made individuals feel disrespected and intimidated.
The leadership team further expressed deep disappointment over Edwards' attempts to minimise the incident and the absence of a clear apology to those affected. They noted that discretion had been exercised throughout the process to protect the integrity of the investigation and safeguard the careers of those who raised concerns.
Elsewhere in the disclosure, in Paul's blog dated 8 July, Arnold answered colleagues who were asking whether anyone else knew about this and how it was allowed to happen. Arnold responded, saying that "We must not and will not shy away from those questions."
We will have to wait and see whether this claim is carried through.
Meanwhile, in a separate FOI response, the ICO has refused to release details about the lessons-learned review "because it relates to an ongoing matter and disclosure at this time would prejudice not only the lessons learned exercise, but also our work as a regulator more broadly."
Training Announcement: Find out more about our range of independent accredited qualifications from BCS and IAPP. These include professional certifications for practitioners covering data protection and AI governance, information security and risk management, along with access to public information.
Image credit ICO. Permission granted from ICO on 5/1/22
What is this page?
You are reading a summary article on the Privacy Newsfeed, a free resource for DPOs and other professionals with privacy or data protection responsibilities helping them stay informed of industry news all in one place. The information here is a brief snippet relating to a single piece of original content or several articles about a common topic or thread. The main contributor is listed in the top left-hand corner, just beneath the article title.
The Privacy Newsfeed monitors over 300 global publications, of which more than 3,250 summary articles have been posted to the online archive dating back to the beginning of 2020. A weekly roundup is available by email every Friday.