Information Commissioner's Office (ICO)
The Information Commissioner's Office (ICO) is the United Kingdom's independent regulator for information rights, responsible for enforcing the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations (PECR, governing cookies and electronic marketing), the Freedom of Information Act and related legislation. Under the Data (Use and Access) Act 2025 it is being restructured as the Information Commission, a board-led body, while keeping the ICO name in public-facing work.
The ICO has powers equivalent to those of an EU supervisory authority: information and assessment notices, enforcement notices, audits, and monetary penalties of up to GBP 17.5 million or 4% of worldwide turnover for the most serious infringements, and up to GBP 17.5 million for PECR breaches. In practice it has favoured reprimands and enforcement notices over large fines for public-sector and health bodies, while pursuing cookie compliance, nuisance marketing and cybersecurity failures. It receives breach notifications within 72 hours, handles complaints, approves BCRs and certification schemes, and issues statutory codes of practice.
For life sciences, ICO guidance on research provisions, on anonymisation and pseudonymisation, on AI and data protection, on DPIAs and on international transfers (the International Data Transfer Agreement and transfer risk assessments) is directly relevant, as is its joint work with the Health Research Authority and the Medicines and Healthcare products Regulatory Agency on trial and health data. Organisations outside the UK that process UK residents' data must appoint a UK representative under Art. 3A UK GDPR, through whom the ICO and data subjects can contact them; iliomad provides this service as UK Data Protection Representative.
