Information Commissioner's Office
(ICO)
The Information Commissioner's Office is the UK's independent authority for upholding information rights and data privacy. It enforces the UK GDPR, the Data Protection Act 2018, and the Freedom of Information Act 2000. The ICO can issue reprimands, enforcement notices, and fines of up to £17.5 million or 4% of global annual turnover for serious data protection breaches.
The ICO is a non-departmental public body sponsored by the Department for Science, Innovation and Technology; the Commissioner is appointed by the Crown and accountable to Parliament. Most organisations that process personal data must register with the ICO and pay an annual data protection fee (£40–£2,900 depending on size and turnover). The ICO investigates complaints from individuals about how their data has been handled and can take regulatory action, including issuing information notices, enforcement notices, civil monetary penalties (up to £17.5 million or 4% of global annual turnover for UK GDPR breaches), auditing organisations, and prosecuting unlawful data processing. The ICO also has enforcement powers under the Freedom of Information Act and the Privacy and Electronic Communications Regulations (PECR), which govern direct marketing, cookies, and electronic communications. Organisations must report certain personal data breaches to the ICO within 72 hours of becoming aware of them. Complaining to the ICO is free, but compensation is separate — individuals claim damages under Article 82 UK GDPR in the County Court within 6 years of the breach.
In practice, the ICO expects you to complain to the organisation first and give it a chance to put things right. Only if you are unhappy with the response, or you get no response within a month, should you escalate. Complaints made within three months of your last meaningful contact with the organisation are considered; older ones are often declined as out of time.
Worked example: Tom asks his former employer for a copy of his personnel file. Nothing arrives after six weeks. He writes again citing Article 15 and setting a deadline, then complains to the ICO with the dates of both letters. The ICO writes to the employer, which produces the file. Tom is disappointed to learn the ICO will not award him compensation for the delay — that is a separate County Court claim, and he would need to show actual damage or distress.
The common misconception is that the ICO acts as a consumer champion that recovers money for individuals. It does not: it is a regulator, so it takes action against organisations, publishes reprimands, and improves practice, but a fine goes to the Treasury rather than to you. Nor does the ICO handle every information complaint — financial services conduct sits with the FCA, and complaints about a public body's wider service usually belong with an ombudsman.
The ICO enforces UK GDPR and the Data Protection Act 2018, oversees subject access requests, and handles freedom of information appeals. Read our guide to the ICO complaints process before escalating.
Related terms
Related guides
Complaining to the Information Commissioner about a Data Breach
The Information Commissioner's Office (ICO) regulates data protection in the UK. They handle complaints about misuse of personal data, failure to respond to Subject Access Requests, marketing breaches under PECR, and breaches of UK GDPR. Many complaints are resolved with a written reminder to the organisation; serious breaches lead to fines up to £17.5 million. This guide explains how to use the ICO and how to claim separately for compensation.
10 min
UK GDPR Rights for Individuals
The UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA 2018) give individuals in the UK eight legally enforceable rights over how organisations collect, store, and use their personal data. These rights apply whether the data is held by a business, public body, or online platform.
6 min
Data Breach Compensation and ICO Complaints
This guide is about redress: getting the Information Commissioner's Office to act on a data breach, and recovering compensation from the organisation responsible. It covers what the ICO will and will not do, the evidence that decides a compensation claim, and how group actions work. If you have only just found out about a breach and want to know whether you should have been told and what to do first, start with <a href="/digital-rights/data-breach-rights">when a company has a data breach</a>.
8 min