ICO new approach to punishment for breaking data protection regulations revealed
25th November 2022
ICO new approach to punishment
Hit them where it hurts – for the greater good.
Perhaps that is rather a blunt summary, but to me, it sums up John Edwards’ speech at this week’s National Association of Data Protection Officers (NADPO), rather well.
The Information Commissioner gave the keynote speech to a room full of data protection specialists on 22nd November 2022. He used the opportunity to outline his new approach to enforcement, particularly with regard to the public sector, however, the private sector was also given fair warning.
In a departure from his predecessor, Edward doesn’t believe that it is the huge, headline-grabbing fines that will have the greatest impact in protecting the privacy of the UK citizen.
What he said made a lot of sense. One of the examples he cited was that of an NHS Trust – this was the catalyst for him reviewing his philosophy and approach to non-compliance held by the ICO. He realised that the fine would have had an even further detrimental effect on the people whose rights the law is there to uphold. By taking money from public authorities in the form of fines – the biggest victims are in fact always going to be the public. Additionally, he told the delegates that there is very little evidence to suggest that fines are a good way of improving compliance in public authorities.
Enforcement happens across a spectrum
Edwards talked about a “series of graduated responses” to non-compliance and reminded delegates that there is nothing in the law that says the enforcement must equal a fine. He quoted Article 58(2) of the GDPR which defines the Commissioner’s corrective powers :
“They’re 58(2)(i), in a list that runs from (a) ‘warnings’, past (b) ‘reprimands’, through (c) ‘compliance orders’ and so on through limitation orders, erasure of data and suspension of data flows”.
Edwards is not dismissing fines altogether, though. He will use them when they are justified. He referred to a recent example where he fined Easylife, a catalogue retailer, £1.35m under the UK GDPR for profiling their customers before illegally calling them.
All reprimands will now be published
Until this speech was given, the ICO website said that reprimands will not usually be published. John Edwards said on 22 November “that changes now.” He then set out his reasons for this.
As Edwards explained – it demonstrates to members of the public and those affected that the responsible organisation has been held to account.
Secondly, it demonstrates to everyone what happens if you breach the UK GDPR, whether you are public or private sector, you will, in effect be named and shamed. Your reputation will be tarnished. This hurts, whatever sector or business you are in. You will be held up as an example of having fallen short and it will be explained what was expected and what had to be done to put things right.
There will be certainty – this will always be the case. All organisations who are reprimanded will have their details published.
Edwards put a lot of emphasis on the importance of this transparency and certainty, and how this leads to flexibility, confidence, and innovation.
He referred to his Annual Action Plan which he launched last month: the ICO25 Strategic Plan in which he also put huge value on empowerment and confidence and how this can drive the economy forward.
His rallying call to the people in the room this week was to ask them to read ICO25 as it is his 3-year plan, setting out how the ICO will work to help businesses, to help people.
We will provide you with a summary of ICO25 in our next blog.
You can read the full script from John Edwards’ speech as prepared for the NADPO Conference here.
If you have any questions about the ICO’s new approach to punishment for breaking data protection regulations or any other data governance or GDPR training matter, please book your complimentary consultation with one of our specialists here.