Information Commissioner's Office (ICO)
- Type
- Government body
- Lieu
- Royaume-Uni — United Kingdom
- Dernière vérification
- 2026-09-22
- Prochaine vérification
- 2027-03-21
Pas encore traduit — affiché en anglais.
Comment les joindre
- Make a complaint
- Concerns about how an organisation handled your information
- ICO helpline and live chat
- ICO calls for views and draft guidance consultations
- Homepage
Ce qu'il fait
Independent data protection and information rights regulator. Enforces UK GDPR and the Data Protection Act 2018, which govern AI training data, automated decision-making and profiling (Article 22 rights), and data subject rights. Can issue information notices and assessment notices, conduct audits, issue enforcement notices requiring a company to stop processing (including stopping a model's deployment), and fine up to £17.5m or 4% of global turnover. Also enforces PECR. Publishes AI and data protection guidance and runs a regulatory sandbox.
Ses pouvoirs
fine
Évaluation franche
The ICO complaint route is real and heavily used, but the practitioner experience is that individual complaints usually end in advice or a 'we have asked the organisation to improve' letter rather than enforcement; the ICO has been notably reluctant to fine large technology firms. The effective lever is the ICO's consultation and call-for-views process on AI guidance, where structured responses visibly move the text, and coordinated complaints that establish a pattern. Scope is personal data and automated decisions about individuals — NOT frontier or catastrophic risk. The ICO also has no jurisdiction over a model that harms no identifiable data subject.
Notes
The Data (Use and Access) Act has altered parts of the UK automated-decision-making regime; check current Article 22 equivalents before relying on pre-2025 guidance.