The ICO fail to meet legal obligations in responding to Information Access Requests.

Spending £91m in 2024/25 alone, should we expect more from the ICO?.

30 May 2026

extract from the ICO report showing their "Ambitious" target.

While reading the Information Commissioner's Annual Report and Financial Statements 2024/25 we were surprised to note on page 36 under the heading of "commentary on measures rated as amber is set out below" that the ICO has set themselves a target to "respond to 100% of information access requests within statutory deadlines", as shown in the image above, taken from the report.

Given this is a Statutory Deadline, that isn't much of a target. Basically they are saying "we set ourselves a target not to break the law". Responding to requests within statutory deadlines is not an option they should be trying to achieve, it is an obligation they must achieve.

But the disappointing thing is firstly they believe this is an ambitious target and , secondly, they aren't achieving it. They don't actually state what their performance was but they do say that they have "made an improvement on our 97.6% achievement in 2023/24 and our highest compliance rate since 2017/18". So not only are they breaking the law, they have always broken the law.

What hope do we have for an institution that spent over £91m in 2024/25 to govern other people's ability to conform to the laws but they can't conform to those laws themselves. Not only that, but they proudly announce it in their annual report to The Government who do absolutely nothing about it.

To add insult to injury, The ICO have issued Our advice to government on potential changes to online advertising rules where they recommend that exceptions are created in PECR article 6 which currently states:

“Subject to schedule A1, a person must not store information, or gain access to information stored, in the terminal equipment of a subscriber or user.”

In effect what the ICO are saying is that Website owners are not allowed to spy on us, unless they have good commercial reason to do so. They state:

If government decides to amend the regulation 6 requirements, we propose permitting some online advertising purposes without consent within a ‘first-party framework’. This would allow the online service or the ‘publisher’ (the first party that the user is directly engaging with) serving online advertising to store and access information on the user’s device for specific purposes. Under this approach, third-party data sharing would be only permitted for controlled use cases and restricted compared to typical data sharing in programmatic advertising.



Don't they realise:

  1. This would be almost impossible to enforce. The ICO cannot meet their current obligations, adding to them would make the problem worse.
  2. BigTech will only develop solutions which they will enforce website owners to accept as "Their Own" so they claim to be first party tags / cookies / scripts while still sending data back to a centralised 3rd part service provider.
  3. Private industry and BigTech don't abide by the rules. These are not gentlemen who respect the people they are dealing with. They are, in some cases, multi billion pound industries who don't care about the outcome of their actions so long as it generates revenue for them. If we change the law to give them an inch, they will steal a light-year

Recent Blogs

09 May 2026

Life is a Compromise

As Kevin McCloud said "Life involves other people and it is a compromise" and this is certainly true of the Privacy / Security debate.

27 April 2026

What Is Privacy

In today's data driven super-highway what is privacy? Major Tech Companies (Google, Meta, Apple, Microsoft) are aware of our every move and, almost, our every thought. Does it matter?

Spotlight

20 May 2026

Humber Bridge Website Raises Privacy Concerns

The Humber Bridge revised toll system does away with the Toll Booths making it very difficult, and sometimes impossible, to make payments by any means other than their website which has a number of privacy concerns.